South African authorities admit to mass surveillance
iafrikan.com
iafrikan.com
I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.
Now parts of our country are literally burning, yet there's no crime intelligence about the very threats to the state that SSA should be monitoring for. There was an act of terror that was nearly committed 2 days ago, but we're seeing poor leadership from those involved.
Please can you provide a link to more info on this?
https://www.iol.co.za/dailynews/news/kwazulu-natal/two-truck...
Which I suppose suggests that they didn't pay for it, and another nation state 'helped out' via intermediaries.
Get out more.
Every telco has locked rooms full of kit for this job.
We've been developing very high level intelligence tools for years in private/public partnerships. It's all just highly secretive, and one of the areas that really does work, so it doesn't get any attention. Most of us, like yourself, just assume that because other areas here are awful, that our intel community must be to, but nothing could be further from the truth.
Lastly don't forget JZ himself was Head of Intelligence, so he always held it in high regard, and gave it the funding it required.
Didn't know about the precursor tech being developed in Stellenbosch as well, do you have any sources on that? I'd be interested to see who was involved.
Agreed on the intel community generally being in a grey area as far as the law is concerned, it's a struggle enough keeping them impartial and not meddling in domestic affairs - talking about JZ being head of the ANC's intelligence in exile brings back memories of his ultimate succession of Thabo Mbeki and former spy chief Billy Masetlha's role in that.
[0] https://mg.co.za/article/2011-09-02-sa-firm-helped-gaddafi-s...
The company taking the risk gets a big fat government check every month, and the governments get to deny they're tapping anyone's data.
(BRB: making a pitch deck...)
It's not easy to tap submarine fibre optic cables. The US Navy has a Nuclear Sub dedicated to the task. You can't just pick them up and stick a tap in them.
The key word, though, was "uplink." Go straight to satellite, and let the intelligence agencies sift through what they want.
I have no knowledge of this area but I always thought sat links can't compete with multi gbps cables.
Maybe I'm wrong though.
Sure - people in privacy circles may suspect this and sneer at the general public for thinking it is news, but it is a big deal to have it confirmed, to raise awareness of it and actually do something about it
https://www.npr.org/2019/09/02/756673481/amateurs-identify-u...
The significance of that release was overblown because it helped support a narrative about Trump damaging national security that the media and people on social media liked. In reality it doesn't seem to have revealed anything about the US satellite imaging capabilities that wasn't already known.
I tried to tell my family about the Snowden leaks and the implications just a year ago. They are all university educated people.
They categorically did not believe that what I was saying was real, and when I showed them all the leaks they did not believe the content was true.
Billions of people simply don't believe it's true.
This is why it hasn't been ruled illegal. Do people actually believe that phone metadata collection is illegal but the crazy thing Greenwald misread PRISM to be is not? That's going to trip grecy's university-educated family's bullshit detector.
The fact that the UK government recently passed a law[0] to make this legal makes it pretty clear that this is real.
[0] https://www.theguardian.com/world/2016/nov/29/snoopers-chart...
(Not agreeing, just explaining.)
Did they not even investigate your claim? Or did they just settle with labeling you a crackpot conspiracy theorist?
While still billions of people believe in Allah, God or whatever without any evidence. I dont know how this can happen...
Isn't it obvious? In both cases people do the smart thing (which is not necessarily the "objectively correct" thing).
Faith in Allah, God etc, is a good social glue, and is personally comforting, helping regulate emotions, etc.
Similarly, not believing the Snowden story helps them fit with their social group (e.g. republicans), relaxes their mind from a whole lot of worries and concerns, helps re-enforce their personal beliefs (e.g. in good government), etc -- and most importantly, has no real disadvantage in their day to day life and work...
The leaks about mass-surveillance don't fit the criteria, as best I can tell. It's in their best interests not to, as you state.
You can very well waste all your life in pointless prayer, like the monk who basically imprinted his feet on the wooden floor by praying several hours a day for decades.
Even getting out of that room to help someone in a trivial task would have been much more useful than the praying.
Not to mention the huge amount of censorship over your own thoughts that some religions impose on your life.
So, IMO, if you get the wrong end of Pascal's wager, you can waste your only life, every infinitely valuable second of it (because there's no afterlife), over a non-existent afterlife.
That's a hell of a wager to lose.
They kind of settled half way between "I don't believe that's possible / I don't care".
For them, it makes zero difference in their lives, so they just don't want to invest time and energy into thinking about it.
People are not surprised, they are angry at people responsible. And rightly so in my opinion.
Let's just pause a bit here. In South Africa, if your phone gets stolen and you go to the police, they may well respond with: "Yes we know the guy, but we're not going to do anything." [1]
I think that surveillance doesn't have the same twang in South Africa that it has in the US and EU. Organised crime and unorganised violent crime for that matter in one thing that a lot of South Africans would like to see better monitored or "surveilled" if you will.
South Africa has this sort of dichotomy between illiteracy and high level tech that I think many people outside of Africa are not aware of. There is 60% youth unemployment [2] and at the same time it's the most developed African country. I heard a story that some of the surveillance tech that Muammar Gaddafi used was built by a company in Stellenbosch.
Most middle class people will have some form of armed response and cities especially are pro-surveillance for crime prevention, many of it by 3rd party security companies. I think that there is some kind of common sense notion of how to differentiate between security and privacy that the CIA or NSA could only dream of. Security means not being robbed; privacy means leave my life out of yours.
As mentioned in some of the comments, surveillance is not new at all in South Africa and in fact is much less than under the previous, non-democratic government.
But to summarise, South Africa is from a "freedom" point of view a really great country. You can pretty much do things and live the way you want. The level of crime and incompetency of the police is, however, too much to live with for some people.
This is a sort of sad irony of our day. It turns out that technology/accessibility are more important than ideology in determining how much surveillance happens. Non democratic surveillance states like apartheid SA or stazi East Germany might have been ideologically in favour of using surveillance to depress democracy but even ostensibly liberal-democratic regimes today do more of it.. because it's cheap, easy and "standard practice around the world."
Sure, you might catch some guys but as you yourself reported, it may not even matter if there is evidence.
But the incentive to abuse surveillance is certainly something western nations have readily helped with their active approval that couldn't even net results besides more civil resistance.
So I am not pointing the finger on South Africa here.
So, what value do the SA government have in intercepting these links now?
* If you have compromised a private key, you can get useful data from the cable intercept.
* If you can collect ciphertext today, and decrypt it tomorrow (with, say, quantum computers), the cable intercept is very useful.
They're a lot better than I thought! (over 90% in each direction, although no data here about certificate verification and the presence or absence of backbone downgrade attacks)
If you run your own mail service, check out my colleague's project at
It probably means your email to your aunt isn't intercepted and shoved onto an enormous pile of decrypted email to be parsed for keywords. Probably. But that's about all.
Against an adversary determined to intercept:
- They can probably just strip STARTTLS, so that everything happens in plaintext - Even if they can't do that because of MTA-STS or similar, they can probably just present self-signed certs and it'll pass the mandatory checks - If they can't do /that/ either (no idea what proportion of email but it may well be in the minority) they can downgrade because unlike in HTTPS nobody is just saying "Old garbage bad, never do that or we'll scream" and so people keep doing it. SSLv3 may even work with a lot of mail servers.
Still, what we have now with opportunistic SMTP encryption is equivalent to what you get with snail mail. The spooks CAN read anybody's mail, but it's a hassle so they mostly don't read yours.
The OC's point was by default, meaning/inferring clear-text is still the modus operandi for generally getting onto IRC services.
>Many applications still aren't encrypted by default, like IRC.
SSL and SASL aren't, precisely, user-friendly implementations with some clients (e.g.: IRSSI[0] - but if you're using IRSSI, you don't want a user-friendly GUI to begin with, so...).
SASL has less to do with the actual encryption mechanism and more to do with the authentication mechanism (think NTLM)[1].
If IRC services dropped clear-text, today, that would go a lot further to standardising (e.g.: making default) encryption but, back to the OC's original point, it is not the default today.
[0] - https://freenode.net/kb/answer/irssi
[1] - https://en.wikipedia.org/wiki/Simple_Authentication_and_Secu...
I mention SASL because it is relevant to security posture, especially if the user wasn’t connecting via TLS. Although of course the server could allow PLAINTEXT in practice there’s no point in supporting that because IRC already had native plaintext server authentication.
[1]: https://github.com/hexchat/hexchat/blob/3d1d9e1716d66abb6921...
It seems a ton of mobile apps are sending information with identifiers over HTTP (the ID is a key part for them legally to pick it up and store it in a DB, forever). I notified one developer that was sending real-time GPS data + an email address highlighted in one of the PPT slide's (just a screenshot of a spreadsheet-like table) and never got a response from the developer. It was a small Canadian company with an app with a few million downloads, so I told Citizenlab about it (don't remember the name, had something to do with sports IIRC).
This is a chart of TLS traffic sent via Chrome and across Google:
https://transparencyreport.google.com/https/overview?hl=en
2014 = ~50%
2019 = 94% of traffic encrypted for Chrome users which is great.
Linux users currently have the lowest when using Chrome with 86%. I'm curious why this is.
Again mobile apps seem to be the biggest problem right now and there was no red HTTPS sign when they sent your sensitive information over cleartext:
> Mobile devices account for the vast majority of unencrypted end user traffic that originates from a given set of surveyed Google services. Some older devices cannot support modern encryption, standards, or protocols.
Maybe Google PlayStore should start punishing apps for not using HTTPS? Just like how Google is trying to make the internet faster by ranking performant/mobile friendly sites higher.
The app testers should put fake identifying information in the various app forms + automatically measure the outbound HTTP traffic for cleartext versions of the IDs.
They probably browse quite a few old sites for documentation and tooling that are just not updated for HTTPS. A forum I post on to this day is still served over plain ole HTTP and they have no interest in changing.
I doubt kernel hackers make up a large enough demographic to skew the metrics...
A lot of popular Linux and developer related pages are HTTP only. I did a quick Google search for some Linux related tasks, and found plenty of sites that don't use HTTPS. e.g. man7.org, linuxhowtos.org, linuxcommand.org
The report does break down HTTPS traffic by country, and you're right that lower income countries do have a lower share of HTTPS traffic.
Wikis arent the problem!
Aside: I know at least for some orgs, ATS was helpful in convincing the older 'why isn't http good enough?' folks to finally get their act together. It may be shocking, but some people are quite resistant to typing in that extra 's'.
This doesn't surprise me when you consider that package management over HTTP is considered ok since it's separately authenticated and verified is a very common view
That this view would also spread to not requiring HTTPS on documentation and other sites would also not be surprising
The Linux world really needs to get it's act together with providing confidentiality via SSL/TLS
Remember that the intelligence agencies don't only want today's data, they want yesterday's data. You get yesterday's data by storing it today. Then you can decrypt it at your leisure, or when computers become powerful enough to break through.
I know a lot of people on HN earn a living making sure internet traffic is encrypted. But honestly, I really believe there are multiple TLA's that can decrypt whatever they want in real time. Maybe not en masse, but certainly targeted streams.
How? They've cracked modern public key crypto?
State of the non-TLA art is that modern https is completely impractical to break, even with enormous server farms working for years, let alone in real time.
I have no idea how they're doing it. But I believe it can be done simply because the intelligence agencies have the best, largest, fastest, most advanced machines that money can buy. Machines that none of us have even heard of, that are years ahead of anything any of us will ever touch in our lifetimes.
If you told me you thought they had cracked a common algorithm so they could do it in only 2^60 time that would at least be plausible. But the idea that they have hardware to straight up brute force it, though, is just impossibly wrong.
Seeing this photo makes me think that's more likely.
https://blog.encrypt.me/assets/img/posts/2013/11/05/nsa_slid...
Pardon the source but I'm on mobile.
(Disclosure: I work at Google)
It's probably more likely that they're just trudging along with side-channel attacks, CA fuckery, breaking into servers, and doing targeted attacks though. Cheaper and likely works well enough.
The more prosaic means you're describing, plus zero days and phishing (unless that's included in "targeted attacks"?), can still get them a long way.
You're probably right on the quantum computers of course, but I like comparing it against what was publicly know about say cryptanalysis vs what the NSA knew in the DES days, and also similar situations in the ww2 days.
That's a pretty bizarre thing to believe. Who is building these machines? Intel? No other organization within the US has the lithography capabilities to manufacture cutting-edge computing hardware, much less "years ahead of anything any of us will ever touch in our lifetimes". Perhaps it's aliens?
They reacted to the information becoming public.
2008 was when there were numerous undersea cable disruptions[1]. I wrote about them when it happened from the best sources I could find at the time[2].
It isn’t surprising to see that surveillance may have occurred as a result.
[1] - https://en.wikipedia.org/wiki/2008_submarine_cable_disruptio...
[2] - https://randomdrake.com/2008/02/12/the-submarine-cables-a-co...
The way things are going, wouldn’t be surprising if whole thing is a corrupt scheme linked to procurement of storage media.
Just because they can’t use it competently doesn’t mean they can’t abuse it.
> The way things are going, wouldn’t be surprising if whole thing is a corrupt scheme linked to procurement of storage media.
If anything, this is _more_ alarming because they are probably not securing the data they intercept all too well.
Reminds me a little bit of a guy I knew in the late 90's who repeatedly set off fire alarms at his company in order to convince management to allocate money for off-site backups.
When you buy a new SIM card, you have to register it using your identification document and proof of residence. Every legally obtained SIM card is accountable. That way they wil know they are intercepting communication of the right person.
As an aside, you and I both know how easy it is to get an activated sim card... But I agree with you comment; this article is not really "news".
Either we move to full e2e encryption or we organize democratically to tear down the modern Stasi.
The possibility of wiretapping will always exist, even if not carried out wholesale by the government itself. And so will commercial services touting convenience in exchange for being MITMed.
To forward a lot of it to the NSA [0], the same NSA that also messed with Germanys G10 laws to "legalize" these kinds of practices in the very first place [1] for exactly that reason.
edit: UK is pretty much also NSA, because unlike the German BND they are at least part of FiveEyes [2] because real global surveillance is a rather exclusive club.
[0] https://en.wikipedia.org/wiki/Operation_Eikonal
[1] http://www.europarl.europa.eu/document/activities/cont/20140...
The benefit is that it does not require any argumentation with other people, noone needs to be convinced or won over, and that it makes sense. It costs nearly nothing to deploy cryptographic solutions.
Maybe this is the same thing. We haven't upheld our ideals on privacy anyway.
> In addition to commercial motivations, the new fiber optic Silk Road could also have geopolitical and strategic implications. Russia and China evidently share a desire to shield themselves from U.S. and other Western intelligence agencies and probably believe that their own communications – both with one another and to and from Europe – will be better protected if cables run across their own territory rather than through the Indian Ocean or the U.S. The same motivation explains the announced Telebras cable, which will connect Brazil to Portugal without any U.S. technology, and the BRICS cable project, which will link Vladivostok to Brazil, via China, India and South Africa.
Here is one to make public key crypto practical using AI+Human derived mnemonics:
Btw, Jack Dorsey’s Twitter account was hacked recently, which is another interesting story.
https://docs.google.com/presentation/d/1f2k6fsIkDmIS1WyJAT0l...