If there’s any comfort to be had, South Africa’s intelligence agencies are a shambles, and unable to deal with real-life threats right under their noses. The idea that they’d be able to do anything actionable with bulk—collected electronic intel is laughable. The way things are going, wouldn’t be surprising if whole thing is a corrupt scheme linked to procurement of storage media.
South African authorities admit to mass surveillance
21–30 of 145 posts
Re: South African authorities admit to mass surveillance
#22> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.
Re: South African authorities admit to mass surveillance
#23If there’s any comfort to be had, South Africa’s intelligence agencies are a shambles, and unable to deal with real-life threats right under their noses. The idea that they’d be able to do anything actionable with bulk—collected electronic intel is laughable. The way things are going, wouldn’t be surprising if whole thing is a corrupt scheme linked to procurement of storage media.
Just because they can’t use it competently doesn’t mean they can’t abuse it.
Re: South African authorities admit to mass surveillance
#24Wasn't it 6 years ago when Snowden made public his revelations and Google said 'nope' and encrypted the lot? Who now sends traffic over these links and doesn't encrypt them? So, what value do the SA government have in intercepting these links now?
Re: South African authorities admit to mass surveillance
#25Wasn't it 6 years ago when Snowden made public his revelations and Google said 'nope' and encrypted the lot? Who now sends traffic over these links and doesn't encrypt them? So, what value do the SA government have in intercepting these links now?
It seems a ton of mobile apps are sending information with identifiers over HTTP (the ID is a key part for them legally to pick it up and store it in a DB, forever). I notified one developer that was sending real-time GPS data + an email address highlighted in one of the PPT slide's (just a screenshot of a spreadsheet-like table) and never got a response from the developer. It was a small Canadian company with an app with a few million downloads, so I told Citizenlab about it (don't remember the name, had something to do with sports IIRC).
This is a chart of TLS traffic sent via Chrome and across Google:
https://transparencyreport.google.com/https/overview?hl=en
2014 = ~50%
2019 = 94% of traffic encrypted for Chrome users which is great.
Linux users currently have the lowest when using Chrome with 86%. I'm curious why this is.
Again mobile apps seem to be the biggest problem right now and there was no red HTTPS sign when they sent your sensitive information over cleartext:
> Mobile devices account for the vast majority of unencrypted end user traffic that originates from a given set of surveyed Google services. Some older devices cannot support modern encryption, standards, or protocols.
Maybe Google PlayStore should start punishing apps for not using HTTPS? Just like how Google is trying to make the internet faster by ranking performant/mobile friendly sites higher.
The app testers should put fake identifying information in the various app forms + automatically measure the outbound HTTP traffic for cleartext versions of the IDs.
Re: South African authorities admit to mass surveillance
#262008 was when there were numerous undersea cable disruptions[1]. I wrote about them when it happened from the best sources I could find at the time[2].
It isn’t surprising to see that surveillance may have occurred as a result.
[1] - https://en.wikipedia.org/wiki/2008_submarine_cable_disruptio...
[2] - https://randomdrake.com/2008/02/12/the-submarine-cables-a-co...
Re: South African authorities admit to mass surveillance
#27Wasn't it 6 years ago when Snowden made public his revelations and Google said 'nope' and encrypted the lot? Who now sends traffic over these links and doesn't encrypt them? So, what value do the SA government have in intercepting these links now?
There were plenty of small samples in the various Snowden powerpoint slides of stuff NSA incepted from the pipes. It seems a ton of mobile apps are sending information with identifiers over HTTP (the ID is a key part for them legally to pick it up and store it in a DB, forever). I notified one developer that was sending real-time GPS data + an email address highlighted in one of the PPT slide's (just a screenshot of…
They probably browse quite a few old sites for documentation and tooling that are just not updated for HTTPS. A forum I post on to this day is still served over plain ole HTTP and they have no interest in changing.
Re: South African authorities admit to mass surveillance
#28> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.
It surprises me as a South African because I didn't know our government had the technical capability or capacity to store and process so much data, let alone splice undersea cables without detection.
Re: South African authorities admit to mass surveillance
#29Wasn't it 6 years ago when Snowden made public his revelations and Google said 'nope' and encrypted the lot? Who now sends traffic over these links and doesn't encrypt them? So, what value do the SA government have in intercepting these links now?
In addition to what the other replies are saying, there's a lot to be gathered from metadata alone, even when the bulk of the data is encrypted. Knowing who is talking to who and at what time is difficult to mask and quite valuable information.
Re: South African authorities admit to mass surveillance
#30If there’s any comfort to be had, South Africa’s intelligence agencies are a shambles, and unable to deal with real-life threats right under their noses. The idea that they’d be able to do anything actionable with bulk—collected electronic intel is laughable. The way things are going, wouldn’t be surprising if whole thing is a corrupt scheme linked to procurement of storage media.
Is that comforting? It just leaves all the risks associated with an invasion of privacy with none of the claimed security upsides. Just because they can’t use it competently doesn’t mean they can’t abuse it.
Then they changed the mission to identifying all kinds of criminal acts and passed the intel along to the FBI and other police agencies, who then lie about how they found out about the perpetrators and develop a "parallel construction" in order not to expose the intelligence collection apparatus. Unfortunately, parallel construction is illegal.
This is the America we live in.
I am patiently waiting for any justice to be visited in the right places. I will wait forever.