<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title>SysAdmin Journal · Cybercrime</title>
        <link>https://sysadmin-journal.com/tag/cybercrime</link>
        <description>Posts tagged with Cybercrime</description>
        <language>en</language>
        <lastBuildDate>Sun, 31 Oct 2021 13:06:51 +0000</lastBuildDate>
        <atom:link href="https://sysadmin-journal.com/tag/cybercrime/rss" rel="self" type="application/rss+xml" />
        <ttl>60</ttl>
        <item>
            <title>My thoughts on the Cybersecurity and Cybercrime Bill</title>
            <link>https://sysadmin-journal.com/thoughts-on-the-cybersecurity-and-cybercrime-bill</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/thoughts-on-the-cybersecurity-and-cybercrime-bill</guid>
            <pubDate>Sun, 31 Oct 2021 13:06:51 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Legislation</category>
            <category>Mauritius</category>
            <category>Cybercrime</category>
            <category>Cybersecurity</category>
            <description>TL;DR — Downloading movies, music and pirated software becomes a crime under this Bill. Failing to moderate online content will also become a crime. Service providers can be compelled to provide access to data and forced not disclose anything. Want to know more then read on!</description>
            <media:content url="https://images.unsplash.com/photo-1589829545856-d10d557cf95f?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwxMTc3M3wwfDF8c2VhcmNofDJ8fGxlZ2FsfGVufDB8fHx8MTYzNTY4MTk0OQ&amp;ixlib=rb-1.2.1&amp;q=80&amp;w=2000" medium="image" />
            <content:encoded><![CDATA[<p>This <a href="https://mauritiusassembly.govmu.org/Documents/Bills/intro/2021/bill1521.pdf">Cybersecurity and Cybercrime Bill</a> was presented to the National Assembly on the 22nd October 2021. It is meant to replace the current <a href="https://www.icta.mu/docs/laws/cyber.pdf">Computer Misuse and Cybercrime Act</a> that dates 2003.</p><p>A few people asked me about my opinion on the Bill and it is only today that I read the document and I share a few things that I found pertinent about the Bill.</p><p>At the beginning of the document, the Budapest Convention on Cybercrime is mentioned and the Bill is said to increase compliance with the same through additional criminal offences related to cybercrime and cybersecurity, <strong>improved investigation techniques</strong> and increased international cooperation.</p><blockquote>I don't see any improved investigation technique in this document. There does not seem anything that will drastically reduce the time to solve a cybercrime.</blockquote><p>Anything related to Mutual Assistance, obtaining data from service providers etc, was already possible under current legislation. This Bill will probably reduce the paperwork if there is a will for that but not improve the investigation technique.</p><h2 id="what-is-the-budapest-convention-on-cybercrime">What is the Budapest Convention on Cybercrime?</h2><p>It is the first international treaty that aims to harmonize laws on cybercrime and cybersecurity and increase cooperation among countries. It was initiated by the Council of Europe and opened for signature in November 2001. In two decades, 66 countries have acceded to the convention. Mauritius acceded to the convention in November 2013.</p><p>The convention provides a guideline to countries for implementing a legislation against cybercrime. The <a href="https://rm.coe.int/1680081561">full guideline</a> is available on the website of the Council of Europe. Some of the main articles of the guideline are (I refer to their article number):</p><p>Article 1 — Definitions<br>Article 2 — Illegal access<br>Article 3 — Illegal interception<br>Article 4 — Data Interference<br>Article 5 — System Interference<br>Article 6 — Misuse of devices<br>Article 7 — Computer-related forgery<br>Article 8 — Computer-related fraud<br>Article 9 — Offences related to child pornography<br>Article 10 — Offences related to infringements of copyright and related rights<br>Article 15 — Conditions and safeguards<br>Article 19 — Search and seizure of stored computer data<br>Article 20 — Real-time collection of traffic data<br>Article 21 — Interception of content data<br>Article 25 — General principles relating to mutual assistance</p><p><strong>The guideline highlights the importance of safeguards and the protection of human rights &amp; liberties in Article 15.</strong></p><h2 id="current-cybercrime-legislation">Current Cybercrime legislation</h2><p>The <a href="https://www.icta.mu/docs/laws/cyber.pdf">Computer Misuse and Cybercrime Act</a> came into force in 2003. Although, Mauritius hadn't yet acceded to the Budapest Convention on Cybercrime, the legislation had some provisions as stated in the Convention guideline.</p><h2 id="whats-new-in-the-cybersecurity-and-cybercrime-bill">What's new in the Cybersecurity and Cybercrime Bill?</h2><h3 id="new-terms-in-the-glossary-of-offences">New terms in the glossary of offences</h3><p>There are a few new definitions of terms that have been added in this Bill, especially to describe the new offences. Among them are the terms:</p><p><strong>Cyberbullying</strong></p><p>It has been defined as any behaviour by means of information and communication technologies which is repetitive, persistent and intentionally harmful or involves an imbalance of power between the perpetrator and the victim and causes feelings of distress, fear, loneliness or lack of confidence in the victim.</p><p><strong>Cyber extortion</strong></p><p>It means a form of cybercrime which occurs when a person uses the internet to demand money or other goods or behaviour from another person by threatening to inflict harm to his person, reputation, or property.</p><p><strong>Fake profile</strong></p><p>An untrue online representation, existent or or non-existent.</p><p><strong>Harm</strong></p><p>It includes physical, sexual, psychological, emotional or moral abuse, injury, neglect, ill-treatment, degradation, discrimination, exploitation or impairment of health or development.</p><p><strong>Pornography</strong></p><p>The representation in a book, magazine, photograph, film, computer data or any such other media, a scene of sexual behaviour in any form, that is erotic or lewd and is designed to arouse sexual interest.</p><p><strong>Sexual photograph or film</strong></p><p>An image or video that depicts nudity or a picture of someone who is engaged in sexual behaviour or posing in a sexually provocative way.</p><h3 id="offences">Offences</h3><p><strong>Misuse of fake profile</strong></p><p>Any person who individually, or with other persons, makes use of a fake profile to cause harm shall commit an offence. The penalty can be upto a million rupees fine or a maximum of 20 years imprisonment.</p><p><strong>Cyberbullying</strong></p><p>Any person who individually, or with other persons, commits cyberbullying, shall commit an offence. The penalty is again, upto a million rupees fine or a maximum of 20 years imprisonment.</p><p>Same penalty is mentioned for offences of <strong>cyber extorsion, cyberterrorism</strong> and <strong>revenge pornography</strong>.</p><p>How these new offences will help deter cybercrime or facilitate the task law enforcement, only time will reveal. In my opinion, new offences won't be of much help if the attitude of cybercrime officers remains the same. Not even a thousand new definitions will help if the officers do not improve their investigation techniques and become accountable.</p><p>In 2018 when the ICT Act was amended the then Attorney General, M. Gobin, used the same tune about social media to convince people on how useful the amendment will be to help in cases of <a href="http://www.govmu.org/English/News/Pages/ICT-Act-amended-to-regulate-and-curtail-harmful-and-illegal-contents-and-activities.aspx">online threats such as harassment, sextortion and cyber-bullying</a>. He participated in radio &amp; televised debates (on MBC) and at the University of Mauritius. However, since the amendments were made to the ICT Act, we've seen how poeple voicing out against the government are questioned and/or detained for breach of the ICT Act.</p><h2 id="copyright-protection">Copyright protection</h2><h3 id="downloading-pirated-software-movies-and-music">Downloading pirated software, movies and music</h3><p>Section 21 of the Bill mentions infringement of copyright and related rights. This section makes the <strong>download</strong> of music, movies and pirated software a criminal offence liable to upto one million rupees fine or 10 years of imprisonment.</p><h2 id="critical-information-infrastructure-increased-penalty">Critical Information Infrastructure &amp; increased penalty</h2><p>This Bill introduces a definition for Critical Information Infrastructure. The National Cybersecurity Committee will be tasked to select the Critical Information Infrastructures in Mauritius. A system providing life sustaining services (e.g water, health or energy), or has an important effect on the economy, or its disruption could result in massive casualties, will be called a Critical Information Infrastructure.</p><p>The penalty for a cybercrime related to a Critical Information Infrastructure is twice the fine for other crimes described in the Bill, i.e upto Rs 2 million and a maximum of 25 years imprisonment.</p><h2 id="failure-to-moderate-content">Failure to moderate content</h2><p>The failure to moderate content on a webpage, social media page or any other online platform, after having received a notice from an investigatory authority, will be a crime.</p><h2 id="compelling-service-providers-to-provide-access-to-store-data-or-collect-real-time-data">Compelling service providers to provide access to store data or collect real-time data</h2><p>If this Bill is passed, an investigatory authority upon issuance of a Judge's Order, may compel a service provider to provide access to stored data or record real-time traffic data, within its technical capabilities. Any disclosure of the investigation by the service provider will be considered a crime.</p><p>A example of traffic data is the history of your everyday websites and online platforms that you visit, including your mobile internet traffic, phone calls, SMS, etc.</p><p>A example of stored data is your email content if your email is hosted by the service provider. If your service provider is in Mauritius and the email service is hosted outside Mauritius, then irrespectively the service provider will be compelled to provide access to the emails.</p><h2 id="the-national-cybersecurity-committee">The National Cybersecurity Committee</h2><p>The Bill introduces a National Cybersecurity Committee. This committee will be composed of fourteen members including a Chairperson that will be appointed by the Prime Minister. A person from the private sector and another from the civil society will be on this committee and both of them will be appointed by the Minister of Technology, Communication and Innovation. Both persons should have experience in the field of cybersecurity and cybercrime.</p><p><strong>All members of the committee will be remunerated.</strong></p><p>The committee may call upon people who can be of assistance but those persons won't draw any remuneration nor have any voting right at the committee's meetings.</p><p>The composition of the committee seems to be tightly controlled by the minister and the committee will operate in complete opacity, although their decisions will impact everyone who use the Internet and other technological services.</p><h2 id="the-computer-emergency-and-response-team-cert-mu">The Computer Emergency and Response Team (CERT-MU)</h2><p>The CERT-MU is mentioned in Section 38. I read and ignored. In my opinion, the CERT-MU acts like a poster for the government to say that they do cybersecurity stuff. I have plenty of un-answered emails in which I questioned CERT-MU on cybersecurity matters. I believe CERT-MU will have to up the game and be more responsive to people irrespective of their religion, caste, color, political background, bank balance, social status, etc.</p><h2 id="will-the-possession-of-certain-software-be-criminalised">Will the possession of certain software be criminalised?</h2><p>Lastly, Section 13 of the Bill states that any person who intentionally procures for use, a computer system or any other device, designed or adapted primarily for the purpose of committing an offence under the Act shall commit an offence.</p><p>Let's take a deep breath. Is this bill going to make Tor, Wireshark, tcpdump, Linux distributions, and tons of other operating systems and software, become tools likely for the purpose of committing an offence?</p><p>I quote an officer of the Cybercrime Unit who once stood in front of the magistrate and said:</p><blockquote>Investigation has also revealed that Applicant is the head or the king pin of a network, well established network [...] Applicant is himself an IT Specialist with mastery of more than three operating systems, Linux is one of them.</blockquote><p>With this kind of mentality where the knowledge of an operating system can make you a prime suspect, imagine the havoc or damage that the officers might cause if they find you in possession of network pentesting tools.</p><p>A new legislation with the same understaffed, underskilled and underpaid division will not produce results.</p>]]></content:encoded>
        </item>
        <item>
            <title>Mauritius requested Google to remove content involving minister of technology from search results</title>
            <link>https://sysadmin-journal.com/computer-emergency-response-team-mauritius-requested-google-to-remove-content-from-search-results</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/computer-emergency-response-team-mauritius-requested-google-to-remove-content-from-search-results</guid>
            <pubDate>Sat, 22 Aug 2020 09:52:05 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Cybercrime</category>
            <category>Transparency</category>
            <description>Every six months Google publishes its transparency report which provides details on the different types of requests that the company received from government agencies from around the world</description>
            <content:encoded><![CDATA[<p>Every six months Google publishes its <a href="https://transparencyreport.google.com/">transparency report</a> which provides details on the different types of requests that the company received from government agencies from around the world.</p><p>The report includes requests made by governments to obtain information on Google users, to remove content, and provides data on political advertising (i.e ad spent per geography and who are the top advertisers). Data on <a href="https://transparencyreport.google.com/political-ads/home?hl=en">political advertising</a> is available only for the United States, European Union, UK, India and New Zealand.</p><p>Google's latest transparency report was published on 22 June 2020. While going through the report I noticed that a <a href="https://transparencyreport.google.com/government-removals/overview?request_country=period:Y2016H2;authority:MU&amp;lu=request_country">request was made by Mauritius</a> to delist a webpage from Google search results. The request was made by the <a href="http://cert-mu.govmu.org/English/Pages/default.aspx">Computer Emergency Response Team of Mauritius</a> (CERT-MU) and it involved a webpage accusing the Minister of Technology of domestic violence.</p><figure class="kg-card kg-image-card kg-width-wide kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2020/08/google-cert-mu-takedown-request.png" class="kg-image" alt="Google Transparency Report - CERT-MU" loading="lazy"><figcaption>Screenshot from the Google Transparency Report</figcaption></figure><p>The request was denied by Google and the webpage was not delisted. </p><p>The request appears in the transparency report of July - December 2016. Around that time, Etienne Sinatambou was the Minister of Technology, Communication and Innovation. Therefore, I searched for « Etienne Sinatambou » on Google and I found an article by <a href="https://www.5plus.mu/node/9299">5-Plus newspaper</a> that indeed refers to a domestic violence incident involving the minister.</p><figure class="kg-card kg-image-card kg-width-wide kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2020/08/etienne-sinatambou-5plus-article.png" class="kg-image" alt="Screenshot of Google Search" loading="lazy"><figcaption>Screenshot of Google Search</figcaption></figure><h2 id="requests-for-information-on-users">Requests for information on users</h2><p>In 2019, Google received a total of 350 requests for information on Google users from different countries through the mutual legal assistance treaty. Mauritius does not appear in the list of countries making requests in 2019. In fact, since all time, Mauritius has made only one request to obtain Google user information. The request was made in 2013.</p><p>Despite a known rise in cybercrime incidents in Mauritius, it appears that our law enforcement agencies do not make requests to Google during their investigation.</p>]]></content:encoded>
        </item>
    </channel>
</rss>
