<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title>SysAdmin Journal · Legislation</title>
        <link>https://sysadmin-journal.com/tag/legislation</link>
        <description>Posts tagged with Legislation</description>
        <language>en</language>
        <lastBuildDate>Sun, 31 Oct 2021 13:06:51 +0000</lastBuildDate>
        <atom:link href="https://sysadmin-journal.com/tag/legislation/rss" rel="self" type="application/rss+xml" />
        <ttl>60</ttl>
        <item>
            <title>My thoughts on the Cybersecurity and Cybercrime Bill</title>
            <link>https://sysadmin-journal.com/thoughts-on-the-cybersecurity-and-cybercrime-bill</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/thoughts-on-the-cybersecurity-and-cybercrime-bill</guid>
            <pubDate>Sun, 31 Oct 2021 13:06:51 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Legislation</category>
            <category>Mauritius</category>
            <category>Cybercrime</category>
            <category>Cybersecurity</category>
            <description>TL;DR — Downloading movies, music and pirated software becomes a crime under this Bill. Failing to moderate online content will also become a crime. Service providers can be compelled to provide access to data and forced not disclose anything. Want to know more then read on!</description>
            <media:content url="https://images.unsplash.com/photo-1589829545856-d10d557cf95f?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwxMTc3M3wwfDF8c2VhcmNofDJ8fGxlZ2FsfGVufDB8fHx8MTYzNTY4MTk0OQ&amp;ixlib=rb-1.2.1&amp;q=80&amp;w=2000" medium="image" />
            <content:encoded><![CDATA[<p>This <a href="https://mauritiusassembly.govmu.org/Documents/Bills/intro/2021/bill1521.pdf">Cybersecurity and Cybercrime Bill</a> was presented to the National Assembly on the 22nd October 2021. It is meant to replace the current <a href="https://www.icta.mu/docs/laws/cyber.pdf">Computer Misuse and Cybercrime Act</a> that dates 2003.</p><p>A few people asked me about my opinion on the Bill and it is only today that I read the document and I share a few things that I found pertinent about the Bill.</p><p>At the beginning of the document, the Budapest Convention on Cybercrime is mentioned and the Bill is said to increase compliance with the same through additional criminal offences related to cybercrime and cybersecurity, <strong>improved investigation techniques</strong> and increased international cooperation.</p><blockquote>I don't see any improved investigation technique in this document. There does not seem anything that will drastically reduce the time to solve a cybercrime.</blockquote><p>Anything related to Mutual Assistance, obtaining data from service providers etc, was already possible under current legislation. This Bill will probably reduce the paperwork if there is a will for that but not improve the investigation technique.</p><h2 id="what-is-the-budapest-convention-on-cybercrime">What is the Budapest Convention on Cybercrime?</h2><p>It is the first international treaty that aims to harmonize laws on cybercrime and cybersecurity and increase cooperation among countries. It was initiated by the Council of Europe and opened for signature in November 2001. In two decades, 66 countries have acceded to the convention. Mauritius acceded to the convention in November 2013.</p><p>The convention provides a guideline to countries for implementing a legislation against cybercrime. The <a href="https://rm.coe.int/1680081561">full guideline</a> is available on the website of the Council of Europe. Some of the main articles of the guideline are (I refer to their article number):</p><p>Article 1 — Definitions<br>Article 2 — Illegal access<br>Article 3 — Illegal interception<br>Article 4 — Data Interference<br>Article 5 — System Interference<br>Article 6 — Misuse of devices<br>Article 7 — Computer-related forgery<br>Article 8 — Computer-related fraud<br>Article 9 — Offences related to child pornography<br>Article 10 — Offences related to infringements of copyright and related rights<br>Article 15 — Conditions and safeguards<br>Article 19 — Search and seizure of stored computer data<br>Article 20 — Real-time collection of traffic data<br>Article 21 — Interception of content data<br>Article 25 — General principles relating to mutual assistance</p><p><strong>The guideline highlights the importance of safeguards and the protection of human rights &amp; liberties in Article 15.</strong></p><h2 id="current-cybercrime-legislation">Current Cybercrime legislation</h2><p>The <a href="https://www.icta.mu/docs/laws/cyber.pdf">Computer Misuse and Cybercrime Act</a> came into force in 2003. Although, Mauritius hadn't yet acceded to the Budapest Convention on Cybercrime, the legislation had some provisions as stated in the Convention guideline.</p><h2 id="whats-new-in-the-cybersecurity-and-cybercrime-bill">What's new in the Cybersecurity and Cybercrime Bill?</h2><h3 id="new-terms-in-the-glossary-of-offences">New terms in the glossary of offences</h3><p>There are a few new definitions of terms that have been added in this Bill, especially to describe the new offences. Among them are the terms:</p><p><strong>Cyberbullying</strong></p><p>It has been defined as any behaviour by means of information and communication technologies which is repetitive, persistent and intentionally harmful or involves an imbalance of power between the perpetrator and the victim and causes feelings of distress, fear, loneliness or lack of confidence in the victim.</p><p><strong>Cyber extortion</strong></p><p>It means a form of cybercrime which occurs when a person uses the internet to demand money or other goods or behaviour from another person by threatening to inflict harm to his person, reputation, or property.</p><p><strong>Fake profile</strong></p><p>An untrue online representation, existent or or non-existent.</p><p><strong>Harm</strong></p><p>It includes physical, sexual, psychological, emotional or moral abuse, injury, neglect, ill-treatment, degradation, discrimination, exploitation or impairment of health or development.</p><p><strong>Pornography</strong></p><p>The representation in a book, magazine, photograph, film, computer data or any such other media, a scene of sexual behaviour in any form, that is erotic or lewd and is designed to arouse sexual interest.</p><p><strong>Sexual photograph or film</strong></p><p>An image or video that depicts nudity or a picture of someone who is engaged in sexual behaviour or posing in a sexually provocative way.</p><h3 id="offences">Offences</h3><p><strong>Misuse of fake profile</strong></p><p>Any person who individually, or with other persons, makes use of a fake profile to cause harm shall commit an offence. The penalty can be upto a million rupees fine or a maximum of 20 years imprisonment.</p><p><strong>Cyberbullying</strong></p><p>Any person who individually, or with other persons, commits cyberbullying, shall commit an offence. The penalty is again, upto a million rupees fine or a maximum of 20 years imprisonment.</p><p>Same penalty is mentioned for offences of <strong>cyber extorsion, cyberterrorism</strong> and <strong>revenge pornography</strong>.</p><p>How these new offences will help deter cybercrime or facilitate the task law enforcement, only time will reveal. In my opinion, new offences won't be of much help if the attitude of cybercrime officers remains the same. Not even a thousand new definitions will help if the officers do not improve their investigation techniques and become accountable.</p><p>In 2018 when the ICT Act was amended the then Attorney General, M. Gobin, used the same tune about social media to convince people on how useful the amendment will be to help in cases of <a href="http://www.govmu.org/English/News/Pages/ICT-Act-amended-to-regulate-and-curtail-harmful-and-illegal-contents-and-activities.aspx">online threats such as harassment, sextortion and cyber-bullying</a>. He participated in radio &amp; televised debates (on MBC) and at the University of Mauritius. However, since the amendments were made to the ICT Act, we've seen how poeple voicing out against the government are questioned and/or detained for breach of the ICT Act.</p><h2 id="copyright-protection">Copyright protection</h2><h3 id="downloading-pirated-software-movies-and-music">Downloading pirated software, movies and music</h3><p>Section 21 of the Bill mentions infringement of copyright and related rights. This section makes the <strong>download</strong> of music, movies and pirated software a criminal offence liable to upto one million rupees fine or 10 years of imprisonment.</p><h2 id="critical-information-infrastructure-increased-penalty">Critical Information Infrastructure &amp; increased penalty</h2><p>This Bill introduces a definition for Critical Information Infrastructure. The National Cybersecurity Committee will be tasked to select the Critical Information Infrastructures in Mauritius. A system providing life sustaining services (e.g water, health or energy), or has an important effect on the economy, or its disruption could result in massive casualties, will be called a Critical Information Infrastructure.</p><p>The penalty for a cybercrime related to a Critical Information Infrastructure is twice the fine for other crimes described in the Bill, i.e upto Rs 2 million and a maximum of 25 years imprisonment.</p><h2 id="failure-to-moderate-content">Failure to moderate content</h2><p>The failure to moderate content on a webpage, social media page or any other online platform, after having received a notice from an investigatory authority, will be a crime.</p><h2 id="compelling-service-providers-to-provide-access-to-store-data-or-collect-real-time-data">Compelling service providers to provide access to store data or collect real-time data</h2><p>If this Bill is passed, an investigatory authority upon issuance of a Judge's Order, may compel a service provider to provide access to stored data or record real-time traffic data, within its technical capabilities. Any disclosure of the investigation by the service provider will be considered a crime.</p><p>A example of traffic data is the history of your everyday websites and online platforms that you visit, including your mobile internet traffic, phone calls, SMS, etc.</p><p>A example of stored data is your email content if your email is hosted by the service provider. If your service provider is in Mauritius and the email service is hosted outside Mauritius, then irrespectively the service provider will be compelled to provide access to the emails.</p><h2 id="the-national-cybersecurity-committee">The National Cybersecurity Committee</h2><p>The Bill introduces a National Cybersecurity Committee. This committee will be composed of fourteen members including a Chairperson that will be appointed by the Prime Minister. A person from the private sector and another from the civil society will be on this committee and both of them will be appointed by the Minister of Technology, Communication and Innovation. Both persons should have experience in the field of cybersecurity and cybercrime.</p><p><strong>All members of the committee will be remunerated.</strong></p><p>The committee may call upon people who can be of assistance but those persons won't draw any remuneration nor have any voting right at the committee's meetings.</p><p>The composition of the committee seems to be tightly controlled by the minister and the committee will operate in complete opacity, although their decisions will impact everyone who use the Internet and other technological services.</p><h2 id="the-computer-emergency-and-response-team-cert-mu">The Computer Emergency and Response Team (CERT-MU)</h2><p>The CERT-MU is mentioned in Section 38. I read and ignored. In my opinion, the CERT-MU acts like a poster for the government to say that they do cybersecurity stuff. I have plenty of un-answered emails in which I questioned CERT-MU on cybersecurity matters. I believe CERT-MU will have to up the game and be more responsive to people irrespective of their religion, caste, color, political background, bank balance, social status, etc.</p><h2 id="will-the-possession-of-certain-software-be-criminalised">Will the possession of certain software be criminalised?</h2><p>Lastly, Section 13 of the Bill states that any person who intentionally procures for use, a computer system or any other device, designed or adapted primarily for the purpose of committing an offence under the Act shall commit an offence.</p><p>Let's take a deep breath. Is this bill going to make Tor, Wireshark, tcpdump, Linux distributions, and tons of other operating systems and software, become tools likely for the purpose of committing an offence?</p><p>I quote an officer of the Cybercrime Unit who once stood in front of the magistrate and said:</p><blockquote>Investigation has also revealed that Applicant is the head or the king pin of a network, well established network [...] Applicant is himself an IT Specialist with mastery of more than three operating systems, Linux is one of them.</blockquote><p>With this kind of mentality where the knowledge of an operating system can make you a prime suspect, imagine the havoc or damage that the officers might cause if they find you in possession of network pentesting tools.</p><p>A new legislation with the same understaffed, underskilled and underpaid division will not produce results.</p>]]></content:encoded>
        </item>
        <item>
            <title>ICTA says it will summarize the comments &amp; suggestions, can we trust?</title>
            <link>https://sysadmin-journal.com/icta-says-it-will-summarize-the-comments-suggestions-can-we-trust</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/icta-says-it-will-summarize-the-comments-suggestions-can-we-trust</guid>
            <pubDate>Mon, 31 May 2021 03:41:42 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>In its latest press communique, the Information and Communication Technologies Authority, displayed a cheap tactic of manipulating public opinion, by publishing only a selection of paragraphs from Facebook&#039;s submission to show them in the good light.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/05/lie-detector-test-1.jpg" medium="image" />
            <content:encoded><![CDATA[<p>On the 21<sup>st</sup> May 2021, the Information and and Communication Technologies Authority (ICTA) issued a <a href="https://www.icta.mu/documents/2021/ICTA_Communique.pdf">communique</a><sup>1</sup> to mark the end of the comments submission to their <a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">consultation paper</a><sup>2</sup> on proposed amendments to the ICT Act for regulating the use and addressing the abuse and misuse of Social Media in Mauritius.</p><p>In the communique, ICTA expressed satisfaction on the debate that the consultation paper generated. The Officer-in-Charge of ICTA, Jérôme Louis, is quoted as saying that ICTA will publish a document summarizing the comments and suggestions.</p><blockquote><em>Nous allons synthétiser les réponses, et publierons sous peu un document résumant les suggestions et commentaires », indique Jérôme Louis, Officer-in-Charge de l'ICTA.</em></blockquote><h2 id="what-can-go-wrong"><strong>What can go wrong?</strong></h2><p>The communique itself gives an inkling on what can go wrong. ICTA mentioned in the communique that Facebook responded to the consultation paper on the 20<sup>th</sup> of May 2021. ICTA said that if both parties come to an agreement then there will be no need for a tool to decrypt Facebook traffic.</p><p>ICTA selectively quoted three paragraphs from the Facebook’s submission, from which one may be led to believe that Facebook is commending ICTA’s efforts, welcoming the regulation and providing full support to ICTA.</p><p>It didn’t make sense to many people who read the communique that a proposal which a few days earlier Google and Mozilla were highly critical about, now Facebook is supporting the same.</p><p>I <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6768.html">wrote to Jérôme Louis</a><sup>3</sup> on the 22<sup>nd</sup> May 2021, asking him whether for transparency sake ICTA could publish the full response received from Facebook. I also copied the Manager of Communications and Consumer Affairs at ICTA, Meera Vayapooree, but none of them replied.</p><h2 id="how-did-%C2%AB-we-%C2%BB-get-the-response-from-facebook"><strong>How did « we » get the response from Facebook?</strong></h2><p>On the 20<sup>th</sup> of May, before ICTA informs the public that they received Facebook’s comments, a colleague of mine, <a href="https://twitter.com/chitteshBMsham">Chittesh Sham</a><sup>4</sup> wrote to Facebook, telling them that there has been zero response from Facebook so far and questioned them on their indifference to the local authority's attempt to break the chain of trust between Facebook and its users in Mauritius.</p><p>Chittesh <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6765.html">received a reply</a><sup>5</sup> the next morning from Kezia Anim-Addo, the Head of Communications, Facebook Sub-Saharan Africa, who looped in two of her colleagues, mentioning that they might have been already in touch. Chittesh clarified that this is his first attempt to contact Facebook and highlighted the importance again for the organization to react on this matter.</p><p>On the 25<sup>th</sup> of May 2021, Chittesh wrote to Facebook requesting them for an update, informed them about ICTA's brief publication of Facebook's submission and asked whether they could publish the comments that they sent to ICTA. Facebook replied with their <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html">submission attached</a><sup>6</sup>.</p><figure class="kg-card kg-image-card kg-width-wide"><img src="https://sysadmin-journal.com/content/images/2021/05/facebook-email-reply-chittesh-sham.png" class="kg-image" alt="Facebook's reply on the Mauritius Internet Users list" loading="lazy" width="1218" height="836" srcset="/content/images/size/w600/2021/05/facebook-email-reply-chittesh-sham.png 600w, /content/images/size/w1000/2021/05/facebook-email-reply-chittesh-sham.png 1000w, /content/images/2021/05/facebook-email-reply-chittesh-sham.png 1218w" sizes="(min-width: 1200px) 1200px"></figure><p>Thanks to the Mauritius Internet Users mailing list &amp; its public archive, we have a <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html">record of these communications</a><sup>7</sup> for reference.</p><h2 id="conclusion"><strong>Conclusion</strong></h2><p>If Google and Mozilla or the 50 international organizations who criticized ICTA’s proposal didn’t make their statements public then ICTA could have easily led Mauritians to believe that tech companies and international organizations are agreeing with their proposal.</p><p>A cheap display of manipulating public opinion was clear in ICTA’s latest communique.</p><p>Based on these recent events and knowing the political climate, how political nominees act like dolls on boards, it is difficult to trust ICTA being capable of showing impartiality and producing a concise summary of comments &amp; suggestions that they received during the public consultation exercise.</p><p><strong>I will write a separate blog post on what Facebook meant in its 12 pages submission to ICTA.</strong></p><p><em>Cover photo by <a href="https://unsplash.com/@ashkfor121?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Ashkan Forouzani</a> on <a href="https://unsplash.com/s/photos/lie?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a>.</em></p><ol><li><a href="https://www.icta.mu/documents/2021/ICTA_Communique.pdf">https://www.icta.mu/documents/2021/ICTA_Communique.pdf</a></li><li><a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf</a></li><li><a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6768.html">http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6768.html</a></li><li><a href="https://twitter.com/chitteshBMsham">https://twitter.com/chitteshBMsham</a></li><li><a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6765.html">http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6765.html</a></li><li><a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html">http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html</a></li><li><a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html">http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html</a></li></ol>]]></content:encoded>
        </item>
        <item>
            <title>Internet Society and Mauritius IGF react to ICTA&#039;s consultation paper</title>
            <link>https://sysadmin-journal.com/internet-society-and-mauritius-igf-react-to-icta-consultation-paper</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/internet-society-and-mauritius-igf-react-to-icta-consultation-paper</guid>
            <pubDate>Wed, 19 May 2021 06:27:33 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>Mauritius IGF and Internet Society respond to ICTA&#039;s consultation paper.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/05/mahen-busgopaul-mauritius-igf.jpg" medium="image" />
            <content:encoded><![CDATA[<p>At last, the Internet Society and Mauritius IGF published their <a href="https://drive.google.com/file/d/1XlGmzzdV3P6wSmoBPWcBYhq4txez12ps/view?usp=sharing">response</a><sup>1</sup> to the <a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">ICTA consultation paper</a><sup>2</sup> on regulating social media. I was hoping that Mauritian NGOs would react faster and in a more collaborative way but nevertheless this response is welcomed.</p><p>It was easier for me to get in touch with Access Now, Article 19 and the Electronic Frontier Foundation and get a response from them.</p><p><em>Disclaimer: I admit I didn’t reach out to Mahen Busgopaul, whom I have met during past events. However, I <a href="https://atlarge-lists.icann.org/pipermail/afri-discuss/2021-May/007093.html">reached out</a><sup>3</sup> to Dave Kissoondoyal, who signed an email to ICANN as the President of IGF Mauritius, but I didn’t receive any response.</em></p><p>Ramblings aside, let’s come to gratitude.</p><p>The Mauritius IGF and ISOC’s response is signed jointly by Mahendranath Busgopaul, as the Director of Mauritius IGF and Olaf Kolkman as the Principal - Internet Technology, Policy and Advocacy at the Internet Society.</p><p>I am grateful to both of them for the response they submitted to the Information and Communication Technologies Authority, which they also released publicly.</p><p>In their summary, they highlighted the importance of encryption for both personal and national security. They aligned themselves with the points already raised in the <a href="https://www.accessnow.org/cms/assets/uploads/2021/05/Mauritius-ICT-Act-Submission.pdf">joint civil society statement</a><sup>4</sup> by Access Now.</p><blockquote>Cover photo, Mahen Busgopaul, Director of Mauritius IGF, photo credits to <a href="https://www.harelmallac.com/connexion/blog/the-man-behind-the-mauritius-internet-governance-forum-mahen-busgopaul">Harel Mallac</a><sup>5</sup>.</blockquote><ol><li><a href="https://drive.google.com/file/d/1XlGmzzdV3P6wSmoBPWcBYhq4txez12ps/view?usp=sharing">https://drive.google.com/file/d/1XlGmzzdV3P6wSmoBPWcBYhq4txez12ps/view?usp=sharing</a></li><li><a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf</a></li><li><a href="https://atlarge-lists.icann.org/pipermail/afri-discuss/2021-May/007093.html">https://atlarge-lists.icann.org/pipermail/afri-discuss/2021-May/007093.html</a></li><li><a href="https://www.accessnow.org/cms/assets/uploads/2021/05/Mauritius-ICT-Act-Submission.pdf">https://www.accessnow.org/cms/assets/uploads/2021/05/Mauritius-ICT-Act-Submission.pdf</a></li><li><a href="https://www.harelmallac.com/connexion/blog/the-man-behind-the-mauritius-internet-governance-forum-mahen-busgopaul">https://www.harelmallac.com/connexion/blog/the-man-behind-the-mauritius-internet-governance-forum-mahen-busgopaul</a></li></ol>]]></content:encoded>
        </item>
        <item>
            <title>Writer Ariel Saramandi &amp; ICTA Chairman Dick Ng Sui Wa respond to BBC&#039;s journalist on ICTA&#039;s consultation paper</title>
            <link>https://sysadmin-journal.com/writer-ariel-saramandi-icta-chairman-dick-ng-sui-wa-respond</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/writer-ariel-saramandi-icta-chairman-dick-ng-sui-wa-respond</guid>
            <pubDate>Sat, 15 May 2021 04:16:40 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>On Friday 14th May 2021, writer Ariel Saramandi and the ICTA Chairman, Dick Ng Sui Wa, spoke on the BBC Newsday1 programme.

They both spoke on ICTA&#039;s consultation paper on proposed amendments to the...</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/05/bbc-sounds-1.jpg" medium="image" />
            <content:encoded><![CDATA[<p>On Friday 14<sup>th</sup> May 2021, writer Ariel Saramandi and the ICTA Chairman, Dick Ng Sui Wa, spoke on the BBC Newsday<sup>1</sup> programme. </p><p>They both spoke on ICTA's consultation paper on proposed amendments to the ICT Act of Mauritius.</p><!--kg-card-begin: html--><iframe width="100%" height="166" scrolling="no" frameborder="no" allow="autoplay" src="https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/1049084731&color=%23ff5500&auto_play=false&hide_related=false&show_comments=true&show_user=true&show_reposts=false&show_teaser=true"></iframe><div style="font-size: 10px; color: #cccccc;line-break: anywhere;word-break: normal;overflow: hidden;white-space: nowrap;text-overflow: ellipsis; font-family: Interstate,Lucida Grande,Lucida Sans Unicode,Lucida Sans,Garuda,Verdana,Tahoma,sans-serif;font-weight: 100;"><a href="https://soundcloud.com/user-599603786" title="Ish Sookun" target="_blank" style="color: #cccccc; text-decoration: none;">Ish Sookun</a> · <a href="https://soundcloud.com/user-599603786/ariel-saramandi-dick-ng-sui-wa-respond-to-bbcs-journalist-on-ictas-consultation-paper" title="Ariel Saramandi &amp; Dick Ng Sui Wa respond to BBC&#x27;s journalist on ICTA&#x27;s consultation paper" target="_blank" style="color: #cccccc; text-decoration: none;">Ariel Saramandi &amp; Dick Ng Sui Wa respond to BBC&#x27;s journalist on ICTA&#x27;s consultation paper</a></div><!--kg-card-end: html--><p>I uploaded a 5m36s extract of the programme on SoundCloud. The programme content is owned by BBC. Its publication here is for solely for information purposes.</p><ol><li><a href="https://www.bbc.co.uk/sounds/play/w172xv2mgsm68vl?fbclid=IwAR0CvtL_StmwYNjj6DK4L5Oq-oIHksEU2vwk2-UffF86fbW-36fLvZ2Bzds">https://www.bbc.co.uk/sounds/play/w172xv2mgsm68vl</a></li></ol>]]></content:encoded>
        </item>
        <item>
            <title>What did Mozilla &amp; Google say, what did ICTA understand and what does the Chairman tell BBC?</title>
            <link>https://sysadmin-journal.com/what-did-google-mozilla-say-what-did-icta-understand-what-does-the-chairman-tell-bbc</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/what-did-google-mozilla-say-what-did-icta-understand-what-does-the-chairman-tell-bbc</guid>
            <pubDate>Fri, 14 May 2021 16:23:28 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>The ICT Authority remains in complete denial despite Mozilla and Google&#039;s strong statement asking ICTA to abandon the idea of the proposed frameworks in their consultation paper.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/05/bbc-sounds.jpg" medium="image" />
            <content:encoded><![CDATA[<h2 id="what-did-mozilla-google-say">What did Mozilla &amp; Google say?</h2><p>On Wednesday 12<sup>th</sup> May 2021, Mozilla and Google filed a joint submission<sup>1</sup> to the Information and Communications Technologies Authority (ICTA) of Mauritius in response to their consultation paper<sup>2</sup> on proposed amendments to the ICT Act. I quote from the Mozilla and Google's response;</p><p><em>« As proposed, the ICT Act's technical enforcement measures would work to undermine the trust of the fundamental security infrastructure that currently serves as the basis for the security of at least 80% of websites on the the web that use HTTPS (...) The ICTA's proposal would thus not only put Mauritian's privacy at risk but would also compromise the integrity and security of the system that Mauritius and many other nations depend upon for essential services. The result would be a less secure internet for Mauritian citizens, one that puts them at greater risk of fraud, identity theft, and surveillance. »</em></p><p>In their final remark, they call on ICTA to abandon the idea of implementing the framework proposed in the consultation paper. I quote;</p><p><em>« We agree with the Authority's statement that the "proposed statutory framework will undoubtedly interfere with the Mauritian people's fundamental rights and liberties in particular their rights to privacy and confidentiality and freedom of expression" and urge the Authority not to pursue this approach. »</em></p><h2 id="what-did-icta-understand">What did ICTA understand?</h2><p>On Thursday 13<sup>th</sup> May 2021, ICTA released a press communique<sup>3</sup> in which they say that for companies like Google or Mozilla expressing themselves on the subject means that it is a global problem and not just affecting Mauritius. I quote:</p><p><em>« Pour l’ICTA, le fait que des compagnies aussi importantes que Google ou Mozilla se soient exprimées sur cette question prouve qu’il s’agit d’une problématique internationale, qui ne touche pas uniquement Maurice. »</em></p><h2 id="what-does-the-chairman-tell-bbc">What does the Chairman tell BBC?</h2><p>On Friday 14<sup>th</sup> May 2021, i.e today, the Chairman of ICTA, Dick Ng Sui Wa, replied to a journalist's question on BBC Newsday<sup>4</sup>. He started by relating Capitol incidents (in the U.S.A) where five people lost their lives and compared ICTA to Ofcom, UK's communication regulator.</p><!--kg-card-begin: html--><iframe width="100%" height="166" scrolling="no" frameborder="no" allow="autoplay" src="https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/1048771474&color=%23ff5500&auto_play=false&hide_related=false&show_comments=true&show_user=true&show_reposts=false&show_teaser=true"></iframe><div style="font-size: 10px; color: #cccccc;line-break: anywhere;word-break: normal;overflow: hidden;white-space: nowrap;text-overflow: ellipsis; font-family: Interstate,Lucida Grande,Lucida Sans Unicode,Lucida Sans,Garuda,Verdana,Tahoma,sans-serif;font-weight: 100;"><a href="https://soundcloud.com/user-599603786" title="Ish Sookun" target="_blank" style="color: #cccccc; text-decoration: none;">Ish Sookun</a> · <a href="https://soundcloud.com/user-599603786/bbc-newsday-journalist-questions-icta-chairman-on-google-mozillas-statement" title="BBC Newsday - Journalist questions ICTA Chairman on Google &amp; Mozilla&#x27;s statement" target="_blank" style="color: #cccccc; text-decoration: none;">BBC Newsday - Journalist questions ICTA Chairman on Google &amp; Mozilla&#x27;s statement</a></div><!--kg-card-end: html--><p>The journalist stopped him and said that he is comparing ICTA to Ofcom but Google or Mozilla have not said to the British regulator that their measures will place the privacy and security of Internet users at grave risk.</p><p><strong>ICTA's Chairman replies, « no, I think they did not contact us directly to say this is not correct. »</strong></p><p>I let you all draw your own conclusions.</p><hr><p>The cover photo used is property of <a href="https://www.bbc.co.uk">BBC</a>. Source of the image is the webpage meta information provided at <a href="https://www.bbc.co.uk/sounds/stations">https://www.bbc.co.uk/sounds/stations</a>.</p><p>The audio was recorded from BBC Newsday<sup>4</sup> on 14<sup>th</sup> May 2021 and its publication here is solely for information purposes.</p><ol><li><a href="https://blog.mozilla.org/netpolicy/files/2021/05/Mozillas-Response-to-the-Mauritian-ICT-Authoritys-Consultation.pdf">https://blog.mozilla.org/netpolicy/files/2021/05/Mozillas-Response-to-the-Mauritian-ICT-Authoritys-Consultation.pdf</a></li><li><a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf</a></li><li><a href="https://www.icta.mu/mediaoffice/2021/comm_icta_fait_le_point.html">https://www.icta.mu/mediaoffice/2021/comm_icta_fait_le_point.html</a></li><li><a href="https://www.bbc.co.uk/sounds/play/w172xv2mgsm68vl">https://www.bbc.co.uk/sounds/play/w172xv2mgsm68vl</a></li></ol>]]></content:encoded>
        </item>
        <item>
            <title>Several international NGOs, people affiliated with academia, Google and Mozilla, call on ICTA to abandon the idea of decrypting social media traffic</title>
            <link>https://sysadmin-journal.com/several-international-ngo-call-on-icta-to-abandon-the-idea-of-decrypting-social-media-traffic</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/several-international-ngo-call-on-icta-to-abandon-the-idea-of-decrypting-social-media-traffic</guid>
            <pubDate>Thu, 13 May 2021 22:40:38 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>International NGOs called on the Mauritian government and ICTA to retract the consultation paper and explore more proportionate and rights-protective measures for the regulation of illegal conduct on social media.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/05/idiots-are-in-charge.jpg" medium="image" />
            <content:encoded><![CDATA[<p>On Wednesday 12<sup>th</sup> May 2021, Access Now, an international NGO that defends digital rights and fights Internet shutdowns, published a joint statement<sup>1</sup> signed by over thirty other NGOs and several individuals affiliated with the school of law from Harvard and Korea University. The statement refers to the consultation paper<sup>2</sup> published by the ICT Authority (ICTA) proposing amendments to the ICT Act of Mauritius.</p><p>These organizations made it clear that ICTA has proposed disproportionate measures which are radical and would set a dangerous precedent. They called on the Mauritian government and ICTA to retract the consultation paper and explore more proportionate and rights-protective measures for the regulation of illegal conduct on social media.</p><p>A day later, two major browser makers, Google and Mozilla, filed a joint submission<sup>3</sup> in which they say that the technical enforcement measures by ICTA will undermine the trust of the fundamental security infrastructure of websites that use HTTPS. They mention that in the past when a device manufacturer or government entity abused on similar dangerous mechanisms both Google and Mozilla took measures to protect their users and secure their products.</p><p>In short, if the government of Mauritius would adopt the proposals of ICTA, Google and Mozilla will take the necessary steps to make sure that Chrome, Android and Firefox users are protected.</p><p>Today, exactly one month since the publication of the consultation paper, ICTA has pinned Mauritius on the world map for the wrong reasons. As a responsible regulator and under the current conditions due the pandemic and businesses having been severely affected, the ICT Authority should have facilitated us to export our ICT expertise to the region. Instead, they published a shameful and dictatorial proposal not suitable for a free society, leaving us looking like a joke to the rest of the world. 😐</p><p></p><ol><li><a href="https://www.accessnow.org/cms/assets/uploads/2021/05/Mauritius-ICT-Act-Submission.pdf">https://www.accessnow.org/cms/assets/uploads/2021/05/Mauritius-ICT-Act-Submission.pdf</a></li><li><a href="https://www.icta.mu/documents/2021/10/Social_Media_Public_Consultation.pdf">https://www.icta.mu/documents/2021/10/Social_Media_Public_Consultation.pdf</a></li><li><a href="https://blog.mozilla.org/netpolicy/files/2021/05/Mozillas-Response-to-the-Mauritian-ICT-Authoritys-Consultation.pdf">https://blog.mozilla.org/netpolicy/files/2021/05/Mozillas-Response-to-the-Mauritian-ICT-Authoritys-Consultation.pdf</a></li></ol><blockquote>Cover photo was taken during the Wakashio protest in Port-Louis, Mauritius, on 29 August 2020.</blockquote>]]></content:encoded>
        </item>
        <item>
            <title>S. Moonesamy&#039;s thoughts on ICTA&#039;s proposals</title>
            <link>https://sysadmin-journal.com/s-moonesamy-thoughts-on-icta-proposals</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/s-moonesamy-thoughts-on-icta-proposals</guid>
            <pubDate>Sun, 09 May 2021 18:01:27 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Legislation</category>
            <category>Mauritius</category>
            <description>Based on the technical information provided in the consultation paper, S. Moonesamy developed a proof of concept and confirms that it is possible to decrypt the login credentials of social media users.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/05/markus-winkler--fRAIQHKcc0-unsplash.jpg" medium="image" />
            <content:encoded><![CDATA[<h2 id="who-is-s-moonesamy">Who is S. Moonesamy?</h2><p>To some of us, in the IT industry, S. Moonesamy is a well-known figure. For the sake of clarity though, I will briefly introduce him in this post.</p><p>S. Moonesamy is a recognized member of the DNS community. He has been a <a href="https://www.iana.org/dnssec/tcrs">Trusted Community Representative</a> (TCR) DNSSEC Root Zone since 2010.</p><p><em>As part of the joint effort to secure the domain name system (DNS) and the Root DNSSEC key management process, a number of persons acting as trusted representatives of the Internet community participate in the root key generation and signing ceremonies. These persons are called Trusted Community Representatives (TCRs).</em></p><p>He is the author of <a href="https://datatracker.ietf.org/person/S%20Moonesamy">three approved RFCs</a>, Internet standards for the Internet Engineering Task Force (IETF), and has drafted several others, among which my favorite is the draft on <a href="https://datatracker.ietf.org/doc/draft-moonesamy-traffic-peeking/">traffic peeking</a>.</p><p>He currently also serves as the Board Chairman for <a href="https://afrinic.net/board">AFRINIC</a>.</p><p>S. Moonesamy <a href="http://www.elandsys.com/~sm/mauritius-social-media-consultation.html">published his conclusion</a> on the ICT Authority's consultation paper on 3 May 2021.</p><p><em>Disclaimer: Please note that S. Moonesamy's thoughts are not endorsement from organizations he represents.</em></p><hr><p>S. Moonesamy starts his report with an introduction of the consultation paper published by the Information &amp; Communication Technologies Authority of Mauritius.</p><p>The report shows a screenshot of a mobile browser showing a security notification when visiting <code>fb.com</code> saying that the website maybe impersonating <code>www.fb.com</code> to steal financial information. </p><p>What is the meaning of the screenshot? It appears to be a proof-of-concept showing what does the browser do if the chain of trust with regards to HTTPS websites is broken. It alerts the user of an impersonation attempt.</p><p>He then comments on measures taken by other countries, namely Germany, United Kingdom (UK), France, and the European Union (EU). The EU &amp; the mentioned countries were referred as examples in ICTA's consultation paper.</p><p>Commenting on measures taken by NetzDG in Germany through the <a href="https://www.bmjv.de/SharedDocs/Gesetzgebungsverfahren/Dokumente/NetzDG_engl.pdf;jsessionid=36F9F10CD7B4DED1059BCA0C34BF0B36.1_cid334?__blob=publicationFile&amp;v=2">Network Enforcement Act</a>, S. Moonesamy, refers to a <a href="https://www.counterextremism.com/sites/default/files/CEP-CEPS_Germany%27s%20NetzDG_020119.pdf">research report</a> by William Echikson and Olivia Knodt of the Counter Extremism Project. In their report Echikson &amp; Knodt conclude that it remains "uncertain whether NetzDG has achieved significant results in reaching its stated goal of preventing hate speech".</p><p>In Mauritius, the ICT Act was amended in 2016, and it became more stringent. Did the amendment help to deter cyber bullying or cyber crime?</p><p>S. Moonesamy commented on the United Kingdom's <a href="https://www.gov.uk/government/consultations/online-harms-white-paper/outcome/online-harms-white-paper-full-government-response">Online Harms White Paper</a> specifying that content published by newspapers on the websites will be outside the scope of the regulatory framework.</p><p>ICTA's consultation paper, on the other hand, despite saying "social media platforms" and specifying in the communiques that only Facebook will be subject to "filtering", does not amount to enough assurance. The consultation paper itself refers to Section 18(1)(m) of the ICT Act as the mandate of the authority and the reason behind this proposal to regulate social media. However, Section 18(1)(m) is not limited to "social media platforms" but it mentions the Internet and other information and communication services.</p><p>While commenting on how social media related offences are handled in Mauritius, S. Moonesamy referred to Section 46 of the ICT Act and said that in some cases the court relied on the dictionary definition of the word « annoyance » because the Act does not define the word.</p><blockquote>The lack of a definition causes uncertainty and puts a common person using social media at a significant risk given that it is difficult for the person to know what is permissible.</blockquote><p>He refers to a similar provision in the Information &amp; Communications Act of Kenya, which <a href="http://kenyalaw.org/caselaw/cases/view/121033/">was struck out by the Kenyan High Court</a> on the grounds that individuals do not know the parameters within which their communication falls. </p><p><strong>Based on the technical information provided in the consultation paper, S. Moonesamy developed a proof of concept and confirms that it is possible to decrypt the login credentials of social media users.</strong></p><blockquote>Cover photo by <a href="https://unsplash.com/@markuswinkler?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Markus Winkler</a> on <a href="https://unsplash.com/s/photos/typewriter?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a>.</blockquote>]]></content:encoded>
        </item>
        <item>
            <title>ICTA&#039;s Consultation Paper prepared by specialists, criticized by many</title>
            <link>https://sysadmin-journal.com/icta-controversial-consultation-paper-prepared-by-specialists</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/icta-controversial-consultation-paper-prepared-by-specialists</guid>
            <pubDate>Tue, 04 May 2021 08:03:03 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Legislation</category>
            <category>Mauritius</category>
            <description>The Electronic Frontier Foundation has criticized the Mauritius ICT Authority&#039;s Consultation Paper on Social Media regulatory proposals, as being horrifying and the worst.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/05/glen-carrie-ra4vJwxnvAo-unsplash.jpg" medium="image" />
            <content:encoded><![CDATA[<p>I read the interview of ICTA's Chairman, Dick Ng Sui Wa, published on <a href="https://www.lemauricien.com/opinions/interview/me-dick-ng-sui-wa-le-president-de-licta-ce-qui-ne-serait-etre-publie-dans-un-journal-ne-peut-etre-ecrit-sur-les-reseaux-sociaux/420474/">lemauricien.com</a>.</p><p>To a question on errors &amp; contradictions in the paper, the Chairman answered that the paper was prepared by specialists and it was accepted by the Board of ICTA after considering the opinion of the Communications Manager of the ICT Authority. I quote him;</p><blockquote>Ce papier, qui ne contient ni erreur ni contradictions, a été rédigé par des spécialistes de la question. Il a été proposé au conseil d’administration qui l’a accepté, après avoir demandé l’avis de la responsable de communication de l’ICTA.</blockquote><p>However, the paper prepared by specialists has been criticized by many in Mauritius already, and recently it received <a href="https://www.eff.org/deeplinks/2021/04/proposed-new-internet-law-mauritius-raises-serious-human-rights-concerns">criticisms</a> from the Electronic Frontier Foundation (EFF).</p><p>Jillian C. York, the Director for International Freedom of Expression at EFF, calls ICTA's consultation paper the most horrifying social media regulatory proposal she's read so far.</p><figure class="kg-card kg-embed-card"><blockquote class="twitter-tweet"><p lang="en" dir="ltr">I just finished reading all of the details of the amendments to Mauritius&#39; ICT Act and this is, in fact, the most horrifying social media regulatory proposal I&#39;ve seen so far (THREAD) <a href="https://t.co/kdI5VAZhHo">https://t.co/kdI5VAZhHo</a></p>&mdash; Jillian C. York (@jilliancyork) <a href="https://twitter.com/jilliancyork/status/1388092625291468803?ref_src=twsrc%5Etfw">April 30, 2021</a></blockquote>
<script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
</figure><p>David Greene, the Civil Liberties Director at EFF, calls the regulatory proposal from Mauritius as one of the worst.</p><figure class="kg-card kg-embed-card"><blockquote class="twitter-tweet"><p lang="en" dir="ltr">We&#39;re seeing really bad internet regulatory proposals around the world. And this new one from Mauritius is one of the worst, raising both free speech and cybersecurity concerns. <a href="https://t.co/M2oy0PbrJ1">https://t.co/M2oy0PbrJ1</a></p>&mdash; David Greene (@davidgreene) <a href="https://twitter.com/davidgreene/status/1388248436877631490?ref_src=twsrc%5Etfw">April 30, 2021</a></blockquote>
<script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
</figure><p>In the interview, Dick Ng Sui Wa, stresses (again) that only public posts are concerned by the proposal and he does not understand why people are comparing it to ICTA "opening letters and reading them" before the letters reach their ultimate recipients.</p><p>This is a major contradiction.</p><p>The Chairman of the ICT Authority, very sadly, fails to understand the basic principle of establishing a HTTPS connection. The message in transit, be it a public or private post, is already in an envelope <strong>NOT DESTINED FOR ICTA</strong>. It's only after opening it ICTA will know that it was intended to be published for the public, a single recipient or a group of recipients.</p><p>Dick Ng Sui Wa uses the example of open letters published in newspapers. Intercepting all letters, opening them and reading, to see which is the "open letter" intended for the newspaper, before it reaches the publisher, is what ICTA has proposed in the paper. Simple as that.</p><blockquote>Cover photo by <a href="https://unsplash.com/@glencarrie?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Glen Carrie</a> on <a href="https://unsplash.com/?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a>.</blockquote>]]></content:encoded>
        </item>
        <item>
            <title>ICTA says only public posts on Social Media will be archived — Wrong!</title>
            <link>https://sysadmin-journal.com/icta-says-only-public-posts-on-facebook-will-be-archived-wrong</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/icta-says-only-public-posts-on-facebook-will-be-archived-wrong</guid>
            <pubDate>Fri, 23 Apr 2021 09:32:31 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Legislation</category>
            <category>Mauritius</category>
            <description>The Information and Communication Technologies Authority published a Consultation Paper on 14 April 2021 which contains proposals to amend the ICT Act.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/04/michal-matlon-4ApmfdVo32Q-unsplash.jpg" medium="image" />
            <content:encoded><![CDATA[<p>On 19 April 2021, the ICT Authority issued a <a href="https://www.icta.mu/mediaoffice/2021/comm_media_platform.html">communique</a> to bring some clarifications after people started commenting and reacting on social media about the <a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">Consultation Paper</a> that ICTA had published a few days earlier.</p><p>After reading the Consultation Paper last week-end, I wrote a <a href="https://sysadmin-journal.com/ict-authority-proposal-to-monitor-the-internet-in-a-nutshell/">blog post</a> explaining how the ICT Authority intends to decrypt Facebook traffic.</p><p>I quote paragraph two of ICT Authority's communique.</p><blockquote>It has never been the intention of the ICTA to regulate the use of online messaging applications since these types of communication are of a private nature as opposed to public postings on social media platforms.</blockquote><p>This above statement is misleading. ICTA itself is amalgamating messaging applications (WhatApp, Telegram, Signal etc) and social media. They should stick to clear and concise examples.</p><p><strong>With the proposed toolset the ICT Authority will be able to decrypt &amp; see all content whether of public or private nature on facebook.com, messenger.com and instagram.com.</strong> Let us not amalgamate by bringing other communication platforms and divert from the topic.</p><p>For simplicity &amp; clarity I refer to Facebook in all my examples.</p><p>People communicate via Facebook, whether by publishing posts (private or public), commenting in groups (private or public) and through private messages.</p><p>ICTA will filter all incoming/outgoing Internet traffic in Mauritius in order to segregate social media traffic. Then, ICTA says that they will not regulate (ie. decrypt, archive &amp; decide whether to block or not) private social media content but only public postings.</p><p><strong>This is wrong, misleading and false.</strong></p><p>All traffic to and from Facebook are encrypted. In order for the ICT Authority to identify what is public and what is private they will have to decrypt ALL and archive ALL content of the Facebook users in Mauritius.</p><blockquote>Behold! Everybody's pants down. 🤦‍♂️</blockquote><p>In a statement on a <a href="https://www.facebook.com/watch/live/?v=805756616693631&amp;ref=watch_permalink">private radio</a> an ICTA staff said that the proposed infrastructure will allow the ICT Authority to identify the authors of fake accounts through meta information (e.g the public IP address) from the Facebook traffic.</p><p>In order to do so, once again, ICTA will have to decrypt and archive all traffic in order to inspect at a later stage whether they have the IP address of someone when an "illegal content" was posted. If they do not archive the data then they will not have the meta information at the time an offence was committed.</p><p>Therefore, in my opinion, the ICTA communique is a desperate attempt to control the damage. There is no refuting that the proposed toolset will have to decrypt &amp; archive all of the Facebook content (public posts, private posts, privates messages, private photos, private videos) in order for ICTA to achieve what they say they want to achieve.</p><blockquote>Cover photo by <a href="https://unsplash.com/@michalmatlon?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Michal Matlon</a> on <a href="https://unsplash.com/?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a>.</blockquote>]]></content:encoded>
        </item>
        <item>
            <title>ICT Authority&#039;s proposal to monitor the Internet, in a nutshell</title>
            <link>https://sysadmin-journal.com/ict-authority-proposal-to-monitor-the-internet-in-a-nutshell</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/ict-authority-proposal-to-monitor-the-internet-in-a-nutshell</guid>
            <pubDate>Sun, 18 Apr 2021 23:17:32 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Legislation</category>
            <category>Mauritius</category>
            <description>The Information and Communication Technologies Authority published a Consultation Paper on 14 April 2021 which contains proposals to amend the ICT Act. The ICT Authority proposes two frameworks and a set of tools to decrypt and archive traffic on social media platforms for inspection purposes.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/04/dole777-EQSPI11rf68-unsplash.jpg" medium="image" />
            <content:encoded><![CDATA[<p>The Information and Communication Technologies Authority (ICTA) invites the public to comment on a <a href="https://www.icta.mu/documents/2021/10/Social_Media_Public_Consultation.pdf" rel="noreferrer">Consultation Paper</a> on amendments to the <a href="https://www.icta.mu/docs/laws/ict_act.pdf">ICT Act</a> which the authority proposes in order to regulate Social Media in Mauritius.</p><p>I read the Consultation Paper and in my humble opinion the authors of the paper could not define the problem they want to address.</p><p>In Section 3.1 they mention incidents that happened in Myanmar and India based on rumours on WhatsApp and Facebook. Relating issues in Mauritius, the authors mention in Section 3.3 that « we » which I assume to be law enforcement officers face a language barier when reporting offensive and abusive content posted in creole. They mention that in majority of the cases complaints made by local authorities to the social media administrators remain unattended or are not addressed in a timely manner.</p><p>It is unclear whom the authors are calling "social media administrators", whether administrators of individual groups/pages on social media platforms or the operators of the service.</p><p>There is no mention of any specific case that disturbed social harmony and where social media companies did not collaborate or were slow to respond to the requests of local authorities. The only local data which is shared is a table of incidents reported via the Mauritian Cybercrime Online Reporting System (MAUCORS). The paper mentions a total of 2,051 incidents reported between January 2020 and January 2021.</p><p>However, these are incidents reported via an online tool. No further information is provided about specific cases or how many of these online reported incidents were formally lodged, investigated and people prosecuted. Also, what were the difficulties when investigating or prosecuting, whether social media companies did not cooperate etc?</p><p>Anyway, half of the 24 pages document talks a lot with no verifiable data in Mauritius on actual cases and yet their conclusion to the « problem » can be summed up as follows:</p><ul><li>local authorities should be able to block harmful &amp; illegal content on social media without the intervention of social media companies,</li><li>local authorities should be able to identify people who post on social media platforms without the intervention of social media companies.</li></ul><p>In order to achieve the above, the authors propose to amend the ICT Act to do three things. </p><ul><li>set up a committee called the National Digital Ethics Committee (NDEC), which will comprise of people who will decide what can be deemed « harmful » on the Internet,</li><li>set up a technical unit called the Technical Enforcement Unit, which will comprise of ICTA staff personnel who will operate the technical infrastructure of monitoring Internet traffic in Mauritius,</li><li>deploy an Internet monitoring infrastructure that will intercept all incoming/outgoing Internet traffic in Mauritius, segregate social media traffic, decrypt the traffic and archive the data for inspection purposes and encrypt the traffic again.</li></ul><p>I am not going to focus on the flaws with the NDEC &amp; Enforcement Unit proposals. Let us instead look at what will the technical implementation of this monitoring infrastructure look like.</p><h2 id="in-a-nutshell">In a nutshell</h2><p>ICTA wants to peek into your social media traffic. How can they do that since your social media traffic is encrypted? Let's see.</p><p>If the proposed amendments are passed as law and the ICT Authority deploys their Internet monitoring infrastructure, this is what will happen.</p><ul><li>You will type facebook.com in your browser but the request won't go to the Facebook servers.</li><li>The request will go to the ICTA proxy server.</li><li>The proxy server will in turn take your browser's request and forward it to the Facebook servers.</li><li>When Facebook returns the login page, it also returns the necessary cryptographic information to start a secure connection using a username &amp; password.</li><li>ICTA's proxy server will present you the facebook.com login page with the HTTPS padlock shown in the brower's address bar.</li><li>When you enter your username and password and press enter, they will be encrypted and sent to the ICTA's proxy server which has the key to decrypt this information.</li><li><strong>The proxy servers reads your username &amp; password, makes a copy and archives it for inspection purposes.</strong></li><li>The proxy server then re-encrypts your username &amp; password using the cryptographic information Facebook sent it earlier and sends the encrypted data to facebook.com.</li><li>Facebook decrypts it, confirms your username &amp; password, and grants the proxy server access to your Facebook account.</li><li>The proxy server decrypts the answer from Facebook, copies it and archives the same, and then re-encrypts the page before sending it to your browser.</li><li><strong>This process continues for all transactions between your browser and Facebook, thus allowing the ICT Authority's proxy server to make a copy of everything you do on Facebook.</strong></li></ul><h2 id="how-does-an-encrypted-communication-with-facebook-looks-like-normally">How does an encrypted communication with Facebook looks like normally?</h2><figure class="kg-card kg-image-card kg-width-wide"><img src="https://sysadmin-journal.com/content/images/2021/04/ICTA-01.jpg" class="kg-image" alt="" loading="lazy" width="1200" height="517" srcset="/content/images/size/w600/2021/04/ICTA-01.jpg 600w, /content/images/size/w1000/2021/04/ICTA-01.jpg 1000w, /content/images/2021/04/ICTA-01.jpg 1200w" sizes="(min-width: 1200px) 1200px"></figure><p>You make a request to facebook.com, Facebook servers return you an empty box and a public key. You put your username/password inside the box and lock it with the public key. You send the locked box back to Facebook. Now, this box can only be opened with the private key on the Facebook servers and no one else. If someone alongs the way copies the box, it will be useless because the box won't open.</p><h2 id="how-does-an-encrypted-communication-with-facebook-in-ictas-new-world-will-look-like">How does an encrypted communication with Facebook in ICTA's new world will look like?</h2><figure class="kg-card kg-image-card kg-width-full"><img src="https://sysadmin-journal.com/content/images/2021/04/ICTA-02-2.jpg" class="kg-image" alt="" loading="lazy" width="1600" height="521" srcset="/content/images/size/w600/2021/04/ICTA-02-2.jpg 600w, /content/images/size/w1000/2021/04/ICTA-02-2.jpg 1000w, /content/images/2021/04/ICTA-02-2.jpg 1600w"></figure><p>You make a request to facebook.com and the ICTA proxy server sends you an empty box and a public key. Your browser trusts this « facebook.com » which in fact is the ICTA proxy server because it trusts the certificate presented by the proxy server. We will explore this detail later. Now, you put your username/password in the box, lock it with the public key you obtained and send it the ICTA proxy server. The latter unlocks the box with its private key, makes a copy of the data, i.e your username/password. It then puts your username/password in another box which Facebook sent it and locks it with Facebook's public key. Finally, Facebook unlocks the box and confirms your username/password and the rest of the communication follows the same process ensuring every bit of information being copied at the ICT Authority's proxy server.</p><p>In cybersecurity terms this is called a Man-In-The-Middle attack, whereby an attacker relays information between two parties who believe they are communicating with each other directly.</p><h2 id="art-of-deception">Art of deception</h2><p>For the ICTA proxy server to be able to do this it has to impersonate you when communicating with Facebook and it impersonates Facebook when it communicates with you.</p><p>To allow such a deception the ICT Authority will ask you to install a Certification Authority (CA) certificate in your browser. Once you do so, your browser will trust all websites that the ICTA proxy server impersonates.</p><h3 id="what-happens-if-you-do-not-install-the-certificate">What happens if you do not install the certificate?</h3><p>Your browser will tell you that the website you are visiting poses a risk and it will discourage you from continuing. If you decide to accept the risk and continue visiting the site it means you have granted your browser permission to establish a connection with the proxy server despite the risk. Thereafter, everything's the same as specified above. If you neither install the certificate nor accept to continue with a risky &amp; untrusted connection, then you won’t be able to visit the websites that the NDEC decide to actively monitor &amp; regulate.</p><p>I specifically did not mention VPN services or Tor because the proposed amendments should simply not pass as law. We should not be talking about how to bypass the infrastructure but rather explain to more people about the implications of these amendments and encourage them to send their comments to socialmediaconsultation@icta.mu by latest 5 May 2021 at 16h00.</p><p>You can read comments to the ICT Authority <a href="https://drive.google.com/file/d/1kJ-eeUBfI82bxBT8Mu7uz0yUaLHYO-iF/view?usp=sharing">here</a>.</p><blockquote>Encrypted communication illustration made by <a href="https://littleshelly.me">Shelly</a> using icons by <a href="https://www.freepik.com/">freepik</a>.<br><br>Cover photo by <a href="https://unsplash.com/@dole777?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">dole777</a> on <a href="https://unsplash.com/s/photos/social-media?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a>.</blockquote><p></p><p></p>]]></content:encoded>
        </item>
        <item>
            <title>Mauritius: Cybersecurity Bill</title>
            <link>https://sysadmin-journal.com/cybersecurity-bill-mauritius</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/cybersecurity-bill-mauritius</guid>
            <pubDate>Sat, 26 Sep 2020 06:53:46 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Legislation</category>
            <category>Cybersecurity</category>
            <category>Mauritius</category>
            <description>The Minister of Technology, Communication and Innovation (TCI), Deepak Balgobin, announced that the Cybersecurity Bill will be introduced to the National Assembly of Mauritius as parliament resumes on the 3rd of November 2020</description>
            <content:encoded><![CDATA[<p>The Minister of Technology, Communication and Innovation (TCI), Deepak Balgobin, <a href="https://defimedia.info/le-cybersecurity-bill-presente-au-parlement-en-novembre">announced</a> that the Cybersecurity Bill will be introduced to the National Assembly of Mauritius as parliament resumes on the 3rd of November 2020.</p><p>I haven't heard about any public consultation regarding this bill, neither have I heard from anyone from the local tech user groups speaking about it. Therefore, I am assuming that none of the active user groups of Mauritius were invited to share their opinion on a legislation that could affect a whole community of internet users in the country.</p><p>Copying &amp; pasting a legislation from other parts of the world is not a solution.</p>]]></content:encoded>
        </item>
        <item>
            <title>Drive slow, drive safe &amp; don&#039;t receive penalties</title>
            <link>https://sysadmin-journal.com/drive-slow-drive-safe-dont-receive-penalties</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/drive-slow-drive-safe-dont-receive-penalties</guid>
            <pubDate>Fri, 31 Jul 2020 10:31:35 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>Lately I noticed a strong presence of police officers, particularly on roads through sugar cane fields, right after a round-about, where visibility of an officer would be poor from several metres away</description>
            <content:encoded><![CDATA[<p>Lately I noticed a strong presence of police officers, particularly on roads through sugar cane fields, right after a round-about, where visibility of an officer would be poor from several metres away. </p><p>I am writing this because I had to pay a fine for driving above the prescribed speed limit. No! I was not racing. I was driving at a comfortable speed not to doze off on the wheel especially when one is surrounded by green fields on both sides. Alas, what I considered a comfortable and safe speed was unfortunately above the 60 km/h speed limit on that road. I was driving at 76 km/h.</p><blockquote>I discourage drivers from speeding, not just to avoid a fine, but for the safety of people using the road.</blockquote><p>Since the past two weeks I have been trying to keep my focus on the road while driving slow; that is not to fall asleep. Music helps with that.</p><h3 id="what-does-the-law-say">What does the law say?</h3><p>Section 124 of the <strong><a href="http://attorneygeneral.govmu.org/English/Documents/A-Z%20Acts/R/Page%204/Road%20Traffic%20Act-I9.pdf">Road Traffic Act</a></strong> mentions the speed limit. In particular paragraph (4)(a) states that:</p><blockquote>Any person who drives a motor vehicle on a road at a speed exceeding a prescribed limit shall commit an offence and shall, on conviction, be liable to a fine not exceeding 5,000 rupees or, in case of a third or subsequent conviction, to a fine exceeding Rs 10,000 rupees.</blockquote><p>I was not aware of Section 124(4)(b) until today.</p><blockquote>An offender under paragraph (a) shall not be liable to be convicted solely on the evidence of one witness to the effect that, in the opinion of that witness, the offender was driving the motor vehicle at any particular speed.</blockquote><p>In most cases of speeding drivers either receive a Fixed Penalty Notice (FPN) by a police officer or receive a Photographic Enforcement Device Notice by post. In the case of the former, if a driver refuses to accept the offence and he/she does not pay the fixed penalty then criminal proceedings are instituted against the driver; where of course the driver may plead "not guilty" and defend himself/herself. I was told so by the police officer issuing the FPN and it corroborates with Section 193 of the Road Traffic Act.</p><p>A fixed penalty must be <strong>paid within 21 days of notice</strong>.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2020/07/fpn-rta-mauritius.png" class="kg-image" alt loading="lazy"><figcaption>Source: Seventh Schedule of the Road Traffic Act (Mauritius)</figcaption></figure><p>The amounts for the fixed penalties for exceeding speed limits were increased in a <a href="http://mauritiusassembly.govmu.org/English/bills/Documents/intro/2018/bill1018.pdf">proposed amendment of the Road Traffic Act</a> in 2018, such that the new penalties became:</p><ul><li>Rs 2,500 for exceeding speed limit by not more than 15 km/h.</li><li>Rs 5,000 for exceeding speed limit by more than 15 but not more than 25 km/h.</li><li>Rs 10,000 for exceeding speed limit by more than 25 km/h.</li></ul><p>In order to pay for a fixed penalty, the driver should attend the appropriate Court as specified in the FPN, produce his/her original driving license and National Identity Card, and pay the specified fine.</p><p>Payments are done at the Cash Office of the District Courts, between 09h30 - 12h00 and 13h00 - 14h30 on Monday to Friday. The Moka District Court's Cash Office is open on Saturdays also between 09h30 - 11h00. District Courts are closed on Sundays and public holidays.</p><p>In case the last day to pay a fine falls on a Sunday or public holiday then payment can be done the next day without any further penalty. Otherwise, the fine amount is <strong><u>doubled</u></strong> if the last day is missed. 🥺</p>]]></content:encoded>
        </item>
        <item>
            <title>New legislation to replace the Computer Misuse and Cybercrime Act in Mauritius</title>
            <link>https://sysadmin-journal.com/new-legislation-to-replace-computer-misuse-and-cybercrime-act-in-mauritius</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/new-legislation-to-replace-computer-misuse-and-cybercrime-act-in-mauritius</guid>
            <pubDate>Sat, 25 Jul 2020 10:11:05 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>The latest Cabinet decisions, of 24 July 2020, mention the Cabinet&#039;s approval for the Ministry of Technology, Communication and Innovation to issue instructions to the Attorney General&#039;s office for repealing the Computer Misuse and Cybercrime Act in order to draft a new a legislation that meets with</description>
            <content:encoded><![CDATA[<p>The latest <a href="http://pmo.govmu.org/English/Documents/Cabinet%20Decisions%202020/Cabinet_Decisions_taken_on_24_July_2020.pdf">Cabinet decisions</a>, of 24 July 2020, mention the Cabinet's approval for the Ministry of Technology, Communication and Innovation to issue instructions to the Attorney General's office for repealing the current Computer Misuse and Cybercrime Act in order to draft a new a legislation that meets with the evolution of technology and the internet.</p><p>This new legislation should accommodate;</p><ul><li>new offences for new types of threats and conditions in the cyberspace,</li><li>reinforced provisions for critical information infrastructure,</li><li>investigation procedures,</li><li>international co-operation against cyberthreats,</li><li>international best practices,</li><li>provisions of Conventions to which Mauritius has adhered such as the Budapest and the African Union Conventions on cybersecurity,</li><li>provisions for alignment with the new proposed National Cybersecurity Strategy.</li></ul>]]></content:encoded>
        </item>
        <item>
            <title>Facebook user in Mauritius arrested for calling Member of Parliament a &quot;dirtbag&quot; in her timeline post</title>
            <link>https://sysadmin-journal.com/facebook-user-in-mauritius-arrested-for-calling-member-of-parliament-a-dirtbag-in-timeline-post</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/facebook-user-in-mauritius-arrested-for-calling-member-of-parliament-a-dirtbag-in-timeline-post</guid>
            <pubDate>Thu, 23 Jul 2020 06:54:27 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>Since amendments were made to the ICT Act of Mauritius, politicians, mainly Members of the National Assembly have grown &quot;sensitive&quot; to comments made about them on social media and they show almost zero tolerance to critics that might contain harsh words</description>
            <content:encoded><![CDATA[<p>This morning <a href="https://www.lexpress.mu/article/380280/arretee-pour-un-post-sur-tania-diolle-farihah-ruhomaully-interrogee-en-ce-moment">l'express</a> reported on its website that a Facebook user, Farihah Ruhomaully, was arrested after having commented on her timeline post, calling a Member of the National Assembly, Tania Diolle, an "opportunist dirtbag".</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2020/07/lexpress-fp-post-20200723.jpg" class="kg-image" alt loading="lazy"><figcaption>Image source: lexpress.mu article</figcaption></figure><p>Since amendments were made to the ICT Act of Mauritius, politicians, mainly Members of the National Assembly have grown "sensitive" to comments made about them on social media and they show almost zero tolerance to critics that contain harsh words.</p><p>The <a href="https://www.oxfordlearnersdictionaries.com/definition/english/dirtbag?q=dirtbag">Oxford Advanced Learner's Dictionary</a> defines a <strong>dirtbag</strong> as:</p><blockquote>a dirty or very unpleasant person</blockquote><p>So, here, my understanding is that Farihah Ruhomaully got arrested for calling the Member of the National Assembly, an <strong>opportunist and a very unpleasant person</strong>. 🤔</p><h2 id="what-does-the-ict-act-say">What does the ICT Act say?</h2><p>Section 46(h) of the <a href="https://www.icta.mu/docs/laws/ict_act.pdf">Information and Communication Technologies Act 2001</a> of Mauritius states the following;</p><p>Any person who —<br>uses, in any manner other than that specified in paragraph (ga), an information and communication service, including telecommunication service, —</p><p>(i) for the transmission or reception of a message which is grossly offensive, or of an indecent, obscene or menacing character; or</p><p>(ii) which is likely to cause or causes annoyance, humiliation, inconvenience, distress or anxiety to that person;</p><p>(iii) for the transmission of a message which is of a nature likely to endanger or compromise State defence, public safety or public order; shall commit an offence.</p><p>In December 2018 the Electronic Frontier Foundation wrote that the amendments to the ICT Act of Mauritius poses risks to the freedom of expression. </p><h2 id="provisional-charge">Provisional Charge</h2><p>The provisional charge is a criminal procedure law that dates back to the British Colonial Rule of 1852. The Deputy of Public Prosecutions, Satyajit Boolell, wrote in a <a href="http://dpp.govmu.org/English/Documents/Issue54.pdf">newsletter in 2015</a> that "although no reference to a provisional charge is made in our statute books, it has survived as a settled practice and is probably unique to Mauritius."</p><h2 id="update">Update</h2><p>Farihah Ruhomaully was <a href="https://www.lexpress.mu/article/380305/violation-licta-arretee-farihah-ruhomaully-liberee-meme-jour">freed on bail</a> on the same after paying the bail amount of Rs 8,000 and signing a bond of Rs 50,000. Police did not object to her request for bail.</p>]]></content:encoded>
        </item>
        <item>
            <title>Ministry of Commerce removes the price control over certain products</title>
            <link>https://sysadmin-journal.com/ministry-of-commerce-and-consumer-protection-removes-the-price-control-over-certain-products</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/ministry-of-commerce-and-consumer-protection-removes-the-price-control-over-certain-products</guid>
            <pubDate>Sat, 04 Jul 2020 08:42:14 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>As per the cabinet decisions published on the Prime Minister Office&#039;s website, the cabinet has &quot;noted&quot; that cases of abusive prices has decreased and thus cabinet decided to remove certain products from the price control</description>
            <content:encoded><![CDATA[<p>It has been a month now since the sanitary curfew has been lifted in Mauritius and "things" have gradually started to take a normal course; or we are rather accepting the "new normal" trend.</p><p>The Government had laid strict guidelines for businesses previously but now they have been easing most of the restrictions. The latest being the removal of price control over certain products which the Ministry of Commerce and Consumer Protection had imposed after receiving complaints of pricing malpractices by supermarkets and shops owners during the curfew period.</p><p>As per the cabinet decisions of 3 July 2020, <a href="http://pmo.govmu.org/English/Documents/Cabinet%20Decisions%202020/Cabinet_Decisions_taken_on_03_July_2020.pdf">published</a> on the Prime Minister Office's website, the cabinet has "noted" that cases of abusive prices have decreased and thus cabinet decided to remove certain products from the price control. These products include:</p><ul><li>Butter</li><li>Spreads and margarine</li><li>Breakfast cereals</li><li>Processed cheese</li><li>Pasta</li><li>Pulses</li><li>Baby and adult diapers</li></ul><p>Expect a price hike next time you visit your local supermarket for grocery shopping.</p>]]></content:encoded>
        </item>
        <item>
            <title>Why the COVID-19 Bill is nothing new?</title>
            <link>https://sysadmin-journal.com/why-the-covid-19-bill-is-nothing-new</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/why-the-covid-19-bill-is-nothing-new</guid>
            <pubDate>Wed, 13 May 2020 17:46:04 +0000</pubDate>
            <dc:creator>Nirvan Pagooah</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>Just my 2 cents as regards the new COVID-19 Bill. When you compare the COVID-19 Bill to the complexity of the Biometric Identity Case [1] back in 2014, you will understand that, this is a futile battle</description>
            <content:encoded><![CDATA[<p>Just my 2 cents as regards the new COVID-19 Bill. When you compare the COVID-19 Bill to the complexity of the Biometric Identity Case [1] back in 2014, you will understand that, this is a futile battle. Ish Sookun was among the few Mauritians who initiated the battle, sacrificed part of his career, and even went to jail for poking his nose in matters, which I think should not have been opened. If you remember his ordeal [2], you'd probably understand why the COVID-19 Bill is totally pointless and how you're all being hypocrites [3]. Sanjeev Teeluckdharry took the case went to the Privy Council but unfortunately, the State won the case and now everyone is forced to give their biometric data.</p><p>It was only a very few who were concerned at that particular time. Later, the government spent around Rs 19 billion on the Safe City Project which breaches basic human privacy but again unfortunately. no one came forward to contest the project. Did we?</p><h2 id="hidden-agendas">Hidden Agendas </h2><p>It was the same Roshi Bhadain [4] who was the advocate of PKJ. The one who stood for the Government at that time. Today, he's on the other side of the table questioning the integrity of the Government. I'll let you take out your own conclusion. Personal motives or hidden agendas? Roshi Bhadain was the Minister of Technology, Communication and Innovation at the same time when Ish Sookun was arrested. </p><blockquote>Roshi Bhadain<em> was totally in favour of the MNIC case which gives power to the government to handle your biometric information and today, he's saying that the government is giving more power to the Police Force. Which is which here? Contradiction.</em></blockquote><p>Everyone have their (hidden) agenda. As soon as it does not concern you, you won't do anything. Bunch of hypocrites, that's who you all are.</p><p>Don't call me anti-patriotic because I'm not part of the battle, I'm just fed up being part of the same people working and voicing out again and again, while the people who should be concerned are the majority of our population. I was part of bigger battles, but when you look back at the end of the day, there's nobody to support you, why should I do something now?</p><p><em>Now it's definitely out of the question to give police more power. I totally object to this. The MPF is a fully funded institution using taxpayers' money. They are recruited under the Commission on Public Service. Do whatever you want it isn't going to change. The day the MPF becomes an independent institution, that's the day you'll see the country change.</em></p><h2 id="foia">FOIA</h2><p>Why isn't anyone concerned about the Freedom of the Information Act which was promised by the same Government back in 2014. The FOIA was on the agenda/manifesto but never put at work. It's already been 1980 days since we're waiting for that. <strong>Oh, it does not concern you or your work, that's why.</strong></p><figure class="kg-card kg-image-card"><img src="https://sysadmin-journal.com/content/images/2020/05/Screenshot-2020-05-13-at-21.20.23.png" class="kg-image" alt="https://www.lexpress.mu/politique" loading="lazy"></figure><p>Source: <a href="https://www.lexpress.mu/politique">https://www.lexpress.mu/politique</a></p><p>There is a proverb which says:</p><blockquote>It takes a strong fish to swim <em><strong>against the current</strong></em>. Only the dead ones <em><strong>go</strong></em> with the flow.</blockquote><p>[1] Madhewoo (Appellant) v The State of Mauritius<br>and another (Respondents) (Mauritius)<br><a href="https://www.jcpc.uk/cases/docs/jcpc-2016-0006-judgment.pdf">https://www.jcpc.uk/cases/docs/jcpc-2016-0006-judgment.pdf</a></p><p>[2] <a href="https://www.lexpress.mu/article/275151/ish-sookun-je-mets-police-au-defi-publier-preuves">https://www.lexpress.mu/article/275151/ish-sookun-je-mets-police-au-defi-publier-preuves</a></p><p>[3] <a href="https://www.lexpress.mu/article/275408/accuse-sous-pota-ish-sookun-confie-apres-sa-liberation">https://www.lexpress.mu/article/275408/accuse-sous-pota-ish-sookun-confie-apres-sa-liberation</a></p><p>[4] <a href="https://business.mega.mu/2014/04/22/biometric-id-card-mr-bhadain-roshi-law-allows-police-access-database/">https://business.mega.mu/2014/04/22/biometric-id-card-mr-bhadain-roshi-law-allows-police-access-database/</a></p>]]></content:encoded>
        </item>
        <item>
            <title>Are people abusing the ICT Act of Mauritius?</title>
            <link>https://sysadmin-journal.com/are-people-abusing-the-ict-act-of-mauritius</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/are-people-abusing-the-ict-act-of-mauritius</guid>
            <pubDate>Sat, 18 Apr 2020 15:36:16 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>The ICT Act of Mauritius was amended in 2018 and it made a specific section of the legislation more ambiguous than before. Section 46 of the Act describes the offences under that legislation. The amendment introduced words such as humiliation, distress and anxiety to the list of &quot;inconveniences&quot;</description>
            <content:encoded><![CDATA[<blockquote><strong>Disclaimer</strong><br>People who are easily annoyed, distressed or may feel an « inconvenience » should not read this post. I will not be liable for any inconvenience caused to the reader.</blockquote><h2 id="information-and-communication-technologies-act-2001">Information and Communication Technologies Act 2001</h2><h3 id="section-46-h-">Section 46(h)</h3><p>Any person who —<br>uses, in any manner other than that specified in paragraph (ga), an information and communication service, including telecommunication service, —</p><p>(i) for the transmission or reception of a message which is grossly offensive, or of an indecent, obscene or menacing character; or</p><p>(ii) which is likely to cause or causes annoyance, humiliation, inconvenience, distress or anxiety to that person;</p><p>(iii) for the transmission of a message which is of a nature likely to endanger or compromise State defence, public safety or public order; shall commit an offence.</p><hr><p>The ICT Act of Mauritius was amended in 2018 and it made a specific section of the legislation more ambiguous than before. Section 46 of the Act describes the offences under that legislation. The amendment introduced words such as <em>humiliation</em>, <em>distress</em> and <em>anxiety</em> to the list of "inconveniences" in part (ii).</p><p>The Electronic Frontier Foundation <a href="https://www.eff.org/deeplinks/2018/12/amendments-mauritius-ict-act-pose-risks-freedom-expression">says that the amendments of the ICT Act</a> are in line with the laws of countries such as Egypt, the UAE and Jordan — none of which are democracies.</p><hr><p>On 15 April, while the whole country was under curfew, a team of policemen proceeded to <a href="https://www.lexpress.mu/article/374965/breach-icta-secretaire-gurib-fakim-arretee-apres-avoir-partage-un-meme">arrest a young woman</a> for breach of the ICT Act, after receiving a complaint by a government nominated <a href="https://www.icta.mu/about.html#ab2">board member</a> of the ICT Authority.</p><p>The Centre for Law and Democracy <a href="https://www.law-democracy.org/live/mauritius-fake-news-arrest-for-political-satire-not-legitimate/">expressed their concern</a> regarding such an arrest for political satire.</p><p>The young woman spent a night in police custody for having posted an image showing a news broadcaster with a captioned photo of the Mauritian Prime Minister and text that joked about world leaders who are going to hold a press conference to ask the Mauritian Prime Minister about his miracle treatment &amp; method for COVID-19.</p><p>As it appears the meme or joke caused such annoyance and inconvenience to the ICT Authority's board member that he decided to spend 2 hours at the CCID Cybercrime Unit to complain about it. L'express newspaper <a href="https://www.lexpress.mu/article/375178/arrestation-rachna-seenauth-incoherences-dans-laction-police">reported</a> that the board member expressed on Facebook that he did so for <strong>his boss, his PM, and his country</strong>.</p><p>Now, one may wonder whether this board member of the ICT Authority really has acted out of love for his prime minister or is it a show of loyalty; often the case with persons holding a nominated position in government offices. Whichever reason the complainant may have, this particular incident points towards an abuse of the ICT Act, through the <a href="https://www.lexpress.mu/article/375116/arrestation-rachna-seenauth-rouben-mooroongapillay-parle-disturbing-factors">manner of the arrest</a> and <a href="https://www.lexpress.mu/article/375005/avocats-rachna-seenauth-verbalises-pour-breach-curfew-order">act of intimidation</a> on behalf of people of authority.</p><h2 id="updates">Updates</h2><ul><li>A photograph <a href="https://www.lexpress.mu/article/375180/propos-diffamatoires-jameel-peerally-porte-plainte-contre-kaushik-jadunundun">lodged a complaint</a> against the ICTA board member following videos that he posted on his Facebook profile in which he made verbal attacks against the photograph.</li><li>After 4 hours of interrogation at the Central Criminal Investigation Division in the presence of his lawyer, the ICT Authority board member, was <a href="https://www.lexpress.mu/article/375194/propos-diffamatoires-kaushik-jadunundun-passera-nuit-en-cellule">arrested</a> for the breach of the ICT Act. He will have to spend the night in police custody.</li><li>He was <a href="https://www.lexpress.mu/article/375239/propos-humiliants-sur-facebook-kaushik-jadunundun-libere-sous-caution">released on bail</a> in the afternoon of Sunday 19 April after paying Rs 15,000 and signing an acknowledgement of debt of amount Rs 100,000. He remains accused of breach of the ICT Act of Mauritius.</li><li>On Monday 20 April, a Member of the Parliament (representing constituency No. 3), <a href="https://www.lexpress.mu/article/375312/breach-icta-eshan-juman-remet-quatre-videos-police">lodged a complaint</a> against the same board member of the ICT Authority at the CCID Cybercrime Unit. He submitted four videos which he claims have been now removed from the Facebook wall of the ICTA board member. The latter is said to have made verbal attacks and threats against the MP in the videos.</li><li>On Wednesday 22 April, the young woman who was arrested following the complaint lodged by the ICTA board member, came up with <a href="https://www.lexpress.mu/article/375461/rachna-seenauth-reclame-rs-20-millions-letat-pour-entrave-droits-constitutionnels">legal retaliation</a>. She is suing the ICTA board member, the Commissioner of the Mauritius Police Force, the Prime Minister and several police officers. In her plaint with summons she mentions a constitutionally "incestuous" relationship between the ICTA board member and the current Prime Minister of Mauritius. She describes the ordeal she was subjected to at the hands of Police officers.</li></ul>]]></content:encoded>
        </item>
        <item>
            <title>Workshop on Model Law Access to Information</title>
            <link>https://sysadmin-journal.com/workshop-on-model-law-access-to-information</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/workshop-on-model-law-access-to-information</guid>
            <pubDate>Sat, 27 Feb 2016 08:02:00 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>It&#039;s the second workshop around the subject &quot;Freedom of Information&quot; that I attended within less than six months. The first being last December by the United States Embassy.</description>
            <content:encoded><![CDATA[<p>It's the second workshop around the subject "Freedom of Information" that I attended within less than six months. The first being last December by the <a href="https://hacklog.mu/freedom-of-information-act-when/">United States Embassy</a>.</p><p>I arrived at Saint Georges Hotel yesterday morning for the workshop, slightly late as I had a minor confusion on the parking space of the hotel. The conference room was three-quarter full. I was however a bit disappointed not finding the familiar faces from the previous workshop. I was expecting to find among attendees several others who attended the workshop by the U.S Embassy, since they received the invitation too.</p><p>Yesterday's workshop was organized by the <a href="http://www.macoss.mu/">Mauritius Council of Social Service (MACOSS)</a> in collaboration with the <a href="http://www.chr.up.ac.za/">Centre for Human Rights of the University of Pretoria</a>.</p><p>I told myself, okay, it's time to make some new friends. In the third row, though, S. Moonesamy from the Mauritius Internet Users sat and was listening attentively to Kadiri Maxwell from the Open Society. As usual, S. Moonesamy was taking notes on his laptop. He reported back to the group. The message which can be read on the <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2016/02/5307.html">Mauritius Internet Users public archives</a>, also contains the presentations of Kadiri Maxwell (Legal Officer, <a href="https://www.opensocietyfoundations.org/about/programs/open-society-justice-initiative">Open Society Justice Initiative</a>), Chantal Kisoon (Gauteng Provincial Manager, <a href="http://www.sahrc.org.za">South African Human Rights Commission</a>) and Lola Shyllon (Programme Manager, Freedom of Expression and Access to Information, Centre for Human Rights, University of Pretoria).</p><p>A few people asked questions right after the presentation by Kadiri Maxwell. While complementing Mr Maxwell's answers, Ms Kisoon added that she noticed that a media group in Mauritius published a counter that shows the number of days since the current Government promised a Freedom of Information Act. She also said while the action is laudable, it should have been a collective initiative whereby more media groups raised the awareness and exerted pressure, as well as it's needed that the citizens also voice out. When I got my chance to ask a question, I added that the counter is published by La Sentinelle Group in the "politique" section of <a href="http://www.lexpress.mu/politique">lexpress.mu</a>. In fact, I showed the counter ticking using my mobile phone. I then added I do not totally blame people for not voicing out. People do not voice out fearing repercussions at work. It's not unknown that people go through political repression once they start voicing out bad practices and corruption occurrences. We cannot expect a total shift in the culture within a few days, but I do hope that the courage shown by a few might push others to re-think, ponder over their inaction.</p><figure class="kg-card kg-image-card"><img src="https://sysadmin-journal.com/content/images/2019/10/lexpress-mu-foia-counter.jpg" class="kg-image" alt loading="lazy"></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2019/10/human-rights-commission-south-africa.jpg" class="kg-image" alt loading="lazy"><figcaption>Chantal Kisoon, Gauteng Provincial Manager, South African Human Rights Commission</figcaption></figure><p>Chantal Kisoon's <a href="http://www.elandsys.com/~sm/access-to-information-AVIEWFROMTHEINSIDE.pptx">presentation</a> was titled "a view from the inside". During the tea break I had a chat with her which turned out to be inspiring; such that she takes it as a firm duty to convince the younger generation not to be discouraged and to follow the rightful path defending human rights.</p><p>During the breaks &amp; lunch, I met several people from different NGOs and Government agencies. We had healthy discussions. I sincerely look forward to more events on the "Freedom of Information" theme so as the pressure builds up enough for concerned agencies to take matters seriously and start working on the bill.</p><hr><p>I will elaborate more on the "Model Law on ATI" in a separate blog post.</p>]]></content:encoded>
        </item>
        <item>
            <title>Freedom of Information Act. When?</title>
            <link>https://sysadmin-journal.com/freedom-of-information-act-when</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/freedom-of-information-act-when</guid>
            <pubDate>Sun, 13 Dec 2015 07:48:00 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>Last Friday the U.S Embassy organized a workshop on &quot;what would a model of Freedom of Information Act look like for Mauritius&quot;. I attended as a member of the Mauritius Internet Users, and introduced myself as a System Administrator at La Sentinelle and a member of the ICT Advisory Council.</description>
            <content:encoded><![CDATA[<p>Last Friday the U.S Embassy organized a workshop on "what would a model of Freedom of Information Act look like for Mauritius". I attended as a member of the Mauritius Internet Users, and introduced myself as a System Administrator at La Sentinelle and a member of the ICT Advisory Council. The workshop happened at Maritim Hotel and along the way I picked up Om and Sun. When we arrived at the hotel the workshop had started. We were shown our seats, which were on different tables. That intrigued me. Each table had eight persons, not from the same group or organization. It struck me that there should be some sort of brainstorming/activity later.</p><p>Corrina Zarek, Senior Advisor for Open Government, USA, as she finished a short discourse on the Freedom of Information, invited us to introduce ourselves to the rest of the room.</p><!--kg-card-begin: html--><center>
<font size="5"><strong>FOIA gives the legal right to request government for information and government must respond</strong></font>
</center>
<br /><!--kg-card-end: html--><p>Corrina took us back in history relating the circumstances under which the first Freedom of Information Act was implemented. That happened in 1766 in Sweden, followed by Finland in 1951. The United States of America adopted the freedom of information laws in 1966. Today around 95 countries in the world have implemented some form of freedom of information legislation, with <a href="http://www.unesco.org/new/en/communication-and-information/freedom-of-expression/freedom-of-information/foi-in-africa/">a dozen countries in the African continent</a>, namely Angola, Rwanda, Uganda, Zimbabwe among others.</p><!--kg-card-begin: html--><center>
    <font size="5"><strong>Mauritius does not figure in the list</strong></font>
</center>
<br /><!--kg-card-end: html--><p>I was attentive and I particularly liked the part where Corrina described the "request process", mentioning the use of email. Yes, I have some very good examples of <a href="http://lists.elandnews.com/archive/mauritius/internet-users/">email requests</a> that government officers did not respond to.</p><p>In fact, S. Moonesamy reported back to the group with a <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2015/12/4379.html">summary of the workshop</a>. I recommend reading that as it elaborates the workshop as it happened.</p><p>During the lunch time, I had an informal chat with two board members, Gayle Yerriah and Kaushik Jadunundun, of the ICT Authority. I believe it is a positive sign that ICTA board members participated in the Freedom of Information workshop, <a href="http://www.lexpress.mu/article/269847/achats-daudi-licta-krishna-oolun-libere-sous-caution">after the recent Audi issues</a>. I briefly said "hello" to the Officer-in-Charge of the ICT Authority, <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2015/04/1146.html">Trilock Dabeesing</a>, who expressly joined the workshop for lunch. I could not discuss <a href="https://hacklog.mu/ict-authority-annual-reports-missing/">the missing annual reports</a> with him since he was not to be found after lunch. I nevertheless expressed my concerns to Kaushik.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2019/10/sm-freedom-of-information-workshop.jpg" class="kg-image" alt loading="lazy"><figcaption>S. Moonesamy talks about the implementation of a Freedom of Information Act</figcaption></figure><h3 id="how-to-prepare-after-foia-is-enacted">How to prepare after FOIA is enacted?</h3><p>There was a brainstorming session where participants were shuffled in various groups and asked to come up with a plan on how to prepare the government and requester once the FOIA is enacted. In my group, we discussed whether there should be a centralized information desk or each ministry having an information unit. The group agreed that we could have a separate office like that of the Data Protection Office with a commissioner with "authority" at its head. Each ministry could have an information officer, in the equivalence of data controllers. That way, we'll ensure that each ministry has one person who is well versed in the Freedom of Information Act. We also discussed on the need of training for "front desk"; which comprises of officers answering phone calls, replying emails and attending requests at the office counter. When answering a requester the officer should remind the requester his right according to FOIA and cite the relevant exception in case a piece of information cannot be provided.</p><p>Concerning requesters, our group reflected that, contrary to a limited budget which the Data Protection Office seem to be suffering from, this new office should be given a proper budget to make good use of media for information dissemination. Newspapers, TV and radio are good channels to educate citizens about the legislation and how they can exercise their right.</p><p>The last activity involved having people in groups of three and they had to act in the role of a requester, information officer and an expert. The situation given was that a road had repairs pending and the requester inquires with the information officer regarding details of the project, who in turn seek this information from the transport expert. The whole thing boils down to a difficult situation where an information officer would usually be crushed between the requester and the lazy/stubborn expert.</p><p>Corrina then thanked everyone for taking part in the activities and left it to us on how we should push forward. In fact, at the beginning I did ask Corrina about the outcome of the workshop, whether it'll be a report sent to the government, which might ultimately lie among a pile of files. What happens after the workshop depends on how serious and willing are we to get a Freedom of Information Act in Mauritius.</p><figure class="kg-card kg-image-card"><img src="https://sysadmin-journal.com/content/images/2019/10/freedom-of-information-mauritius.png" class="kg-image" alt loading="lazy"></figure><p>There was a comment that the press could put pressure and get our voices heard, but then I answered that lexpress.mu has put a counter on it's homepage to show the number of days since the Freedom of Information Act was promised by the current government, but sadly, few people show interest in this.</p><p>To be honest, I am not sure of the willingness of people to question the authority and ask for their rights to information. A handful of concerned citizens will raise their voice and might continue the fight though, I just hope to add a little contribution to the collective effort in some way or the other.</p><hr><p>Two publications appeared on lexpress.mu following the workshops by Corrina Zarek in Mauritius:</p><p><a href="http://www.lexpress.mu/article/272787/legislation-freedom-information-act-en-2016">Législation: la Freedom of Information Act en 2016</a><br><a href="http://www.lexpress.mu/article/272862/corinna-zarek-senior-advisor-open-government-maison-blanche-il-est-grand-temps-que">Il est grand temps que le Freedom of Information Act entre en vigueur</a></p>]]></content:encoded>
        </item>
    </channel>
</rss>
