<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title>SysAdmin Journal · Mauritius</title>
        <link>https://sysadmin-journal.com/tag/mauritius</link>
        <description>Posts tagged with Mauritius</description>
        <language>en</language>
        <lastBuildDate>Mon, 02 Jan 2023 06:32:52 +0000</lastBuildDate>
        <atom:link href="https://sysadmin-journal.com/tag/mauritius/rss" rel="self" type="application/rss+xml" />
        <ttl>60</ttl>
        <item>
            <title>How to add a missing road in Google Maps?</title>
            <link>https://sysadmin-journal.com/how-to-add-a-missing-road-in-google-maps</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/how-to-add-a-missing-road-in-google-maps</guid>
            <pubDate>Mon, 02 Jan 2023 06:32:52 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Internet Community</category>
            <description>Google Maps is a web mapping platform and consumer application offered by Google. It offers satellite imagery, aerial photography, street maps, 360° interactive panoramic views of streets, real-time traffic conditions, etc.</description>
            <content:encoded><![CDATA[<p>I was not actively contributing to Google Maps until very recently. In fact, I drew inspiration from <a href="https://twitter.com/zcoldplayer">Pritvi</a> after his presentation at the <a href="https://sysadmin-journal.com/google-devfest-2022-mauritius/">Google Developers Festival (DevFest 2022)</a> earlier this month.</p><p>« Google Maps is a social network » says Pritvi. With features like posting reviews, following other local guides, earning points, liking &amp; sharing other people's reviews, indeed Maps is a social network. </p><p>After DevFest 2022, I started contributing to Google Maps more often, starting with a few missing places in my village, Providence.</p><!--kg-card-begin: html--><center>
    <iframe src="https://www.google.com/maps/embed?pb=!1m18!1m12!1m3!1d7486.403259116851!2d57.615609128268005!3d-20.250470930014597!2m3!1f0!2f0!3f0!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0x217c58403fb3971d%3A0x706081da5361503f!2sProvidence!5e0!3m2!1sen!2smu!4v1672128671122!5m2!1sen!2smu" width="600" height="450" style="border:0;" allowfullscreen="" loading="lazy" referrerpolicy="no-referrer-when-downgrade"></iframe>
</center><!--kg-card-end: html--><p>Living in Providence, it is very common to hear that « lin alle acheter gato kot <a href="https://goo.gl/maps/mxpE29iZrvMdLEUr9">Aziz</a> » or « mo p alle zuer lotto kot <a href="https://goo.gl/maps/HdYkmbmNEzGGCiZX9">Samy</a> » and yet these two places were not on Google Maps.</p><p>Then, I added village temples that were missing, like the Kalimaye (a Hindu shrine dedicated to Mother Kali). There are four such shrines in Providence, that I know of and I added three of them to Maps. While doing do I noticed a road was not named and it is the Kalimaye Road itself.</p><p>I followed the <a href="https://support.google.com/local-guides/answer/9157791?hl=en-GB">Google Local Guides Help</a> to add the « missing » road but to my surprise, I could not. After I submitted the details about the road, Maps said, "We cannot fix issues in this region yet."</p><p>I tweeted about it and tagged <a href="https://twitter.com/googlemaps">@googlemaps</a>.</p><p>Within an hour, @googlemaps replied the tweet, asking me to follow them so that they can DM me to help.</p><!--kg-card-begin: html--><center>
    <blockquote class="twitter-tweet"><p lang="en" dir="ltr">Hi Ish, we&#39;re happy to help! Please follow us so that we can direct message you and help you.</p>&mdash; Google Maps (@googlemaps) <a href="https://twitter.com/googlemaps/status/1606351529811873815?ref_src=twsrc%5Etfw">December 23, 2022</a></blockquote> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
</center><!--kg-card-end: html--><p>Thus, I followed @googlemaps and they sent me a DM asking the coordinates for the the missing road. I replied with those details including pictures of the road sign and surroundings.</p><p>A few days later, Kalimaye Rd appeared on Google Maps. 😊</p><!--kg-card-begin: html--><center>
    <blockquote class="twitter-tweet"><p lang="en" dir="ltr">Thank you <a href="https://twitter.com/googlemaps?ref_src=twsrc%5Etfw">@googlemaps</a>! Kalimaye Rd now appears in the map for Providence, <a href="https://twitter.com/hashtag/Mauritius?src=hash&amp;ref_src=twsrc%5Etfw">#Mauritius</a>. <a href="https://t.co/5Att1C014W">https://t.co/5Att1C014W</a> <a href="https://t.co/q4PZYuTVu2">pic.twitter.com/q4PZYuTVu2</a></p>&mdash; Ish Sookun (@IshSookun) <a href="https://twitter.com/IshSookun/status/1607642190775455745?ref_src=twsrc%5Etfw">December 27, 2022</a></blockquote> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
</center><!--kg-card-end: html-->]]></content:encoded>
        </item>
        <item>
            <title>AlmaLinux mirror in Mauritius 🐧</title>
            <link>https://sysadmin-journal.com/almalinux-mirror-in-mauritius</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/almalinux-mirror-in-mauritius</guid>
            <pubDate>Sat, 01 Oct 2022 14:56:37 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Linux</category>
            <category>Mauritius</category>
            <description>AlmaLinux is a Linux distribution which is binary compatible with Red Hat Enterprise Linux (RHEL). It was created by CloudLinux and it is currently maintained by the AlmaLinux OS Foundation, a non-profit to steward ownership and governance of the project.</description>
            <content:encoded><![CDATA[<p>In January 2014, Red Hat <a href="https://www.redhat.com/en/about/press-releases/red-hat-and-centos-join-forces">announced that it is joining forces</a> with CentOS to speed open source innovation. What it meant for the many users of <a href="https://centos.org/">CentOS</a>, was that Red Hat was acquiring the project and it will decide the future of the distribution. Indeed, six years later, in December 2020, Red Hat announced that <a href="https://www.redhat.com/en/blog/centos-stream-building-innovative-future-enterprise-linux">the future of CentOS is CentOS Stream</a>, an upstream project for Red Hat with a rolling-release model.</p><p>There was a lot of discontentment following that announcement. Many users enjoyed the stability of CentOS and its binary compatibility with RHEL and its long term support. The news of turning CentOS into an upstream project for RHEL changed all of that.</p><p><a href="https://www.cloudlinux.com/">CloudLinux</a> is one of many CentOS supporters that was not happy with the news.</p><p>In response to the shift in project direction of CentOS, CloudLinux backed the development of AlmaLinux, a clone of RHEL. CloudLinux has been in the "Linux business" since 2009, providing a customised Linux distribution for hosting companies. Its products were mainly based on RHEL/CentOS. Thus, their commitment to the AlmaLinux project meant they would be heavily invested. In fact, CloudLinux financially backs the AlmaLinux OS Foundation.</p><h2 id="the-almalinux-mirror-%F0%9F%98%8A">The AlmaLinux mirror 😊</h2><p>After that short history lesson, let's come to the present.</p><p>David Venter, the Founder &amp; Director of <a href="https://cloud.mu">cloud.mu</a>, and I were having a usual "Linux mirrors" conversation and David said "we should also really do AlmaLinux". I was like, "I just read their doc, it's the easiest mirror documentation I have seen so far".</p><p>Well, the next day, David provisioned the mirror server and I did the rest of the configuration. Once the server had sync'ed completely, I <a href="https://github.com/AlmaLinux/mirrors/pull/615">submitted</a> it to AlmaLinux for review. Soon after, <a href="https://almalinux-mirror.cloud.mu/">almalinux-mirror.cloud.mu</a> appeared on <a href="https://mirrors.almalinux.org">mirrors.almalinux.org</a>.</p><figure class="kg-card kg-image-card kg-width-wide"><img src="https://sysadmin-journal.com/content/images/2022/10/almalinux-mirror-mauritius.png" class="kg-image" alt loading="lazy" width="1506" height="1018" srcset="/content/images/size/w600/2022/10/almalinux-mirror-mauritius.png 600w, /content/images/size/w1000/2022/10/almalinux-mirror-mauritius.png 1000w, /content/images/2022/10/almalinux-mirror-mauritius.png 1506w" sizes="(min-width: 1200px) 1200px"></figure><p>If you head to almalinux.org and click on the download button, it takes you to the mirrors page and there you can see the list of the closest mirrors to you. Being in Mauritius you should see <strong>almalinux-mirror.cloud.mu</strong> at the top of that list, followed by other mirrors in Africa.</p><h3 id="sponsorship">Sponsorship</h3><p>Improving the Linux updates experience in Mauritius would not be possible without mirrors. I am extremely thankful to <a href="https://cloud.mu">cloud.mu</a> for the server/bandwidth sponsorship and their commitment to make Linux thrive in Mauritius.</p>]]></content:encoded>
        </item>
        <item>
            <title>S. Moonesamy writes to the Data Protection Office regarding the alleged data capture at the Baie Jacotet Submarine Cable Landing Station</title>
            <link>https://sysadmin-journal.com/s-moonesamy-writes-to-the-data-protection-office-regarding-the-alleged-data-capture-at-the-baie-jacotet-submarine-cable-landing-station</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/s-moonesamy-writes-to-the-data-protection-office-regarding-the-alleged-data-capture-at-the-baie-jacotet-submarine-cable-landing-station</guid>
            <pubDate>Wed, 27 Jul 2022 11:01:33 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Internet Community</category>
            <description>The Data Protection Office of Mauritius operates under the aegis of the Ministry of Technology, Communication and Innovation, since February 2009 when the Data Protection Act 2004 came into force. ​This office aims at protecting privacy rights of individuals.</description>
            <content:encoded><![CDATA[<p>About a month ago, Manvendra (Sherry) Singh <a href="https://defimedia.info/demission-tres-emu-sherry-singh-quitte-mt-acclame-par-des-employes">resigned</a> from his post of Chief Executive Officer of the Mauritius Telecom. The next day, he revealed on TéléPlus/Radio Plus that he resigned because the Prime Minister, Pravind Kumar Jugnauth, had <a href="https://www.youtube.com/watch?v=o8-LevJXuKk">instructed him to allow a foreign third-party</a> to install a sniffing equipment at the Baie Jacotet Submarine Cable Landing Station (SCLS).</p><p>The Baie Jacotet SCLS is where the South Africa Far East (SAFE) submarine cable lands in Mauritius.</p><p>The days that followed, several more revelations were made.</p><p>P. K. Jugnauth himself <a href="https://www.youtube.com/watch?v=ysIW6nvLX-k">revealed that he asked the Prime Minister of India</a>, Narendra Modi, to send a technical team from India to carry out a survey at the landing station. At no point does Jugnauth give details on the nature of the survey or the precise reason that required a survey at the landing station. He only cites "national security" to hide away from questions.</p><p>Jugnauth also confirmed that Singh had refused to give access to the landing station, hence he phoned him. Later Singh allowed access.</p><p>Singh made <a href="https://www.facebook.com/watch/live/?ref=watch_permalink&amp;v=1385874455267359">further revelations</a> in subsequent interviews, thereby stating that a three-member technical team was accompanied to the Baie Jacotet SCLS by the Chief Technical Officer of Mauritius Telecom, Girish Guddoy on 15 April 2022. The Indian technicians attempted to capture data from the SAFE consortium equipment which is provided by Alcatel Submarine Networks. They failed to do so twice. Thus, they captured data on eleven links of Mauritius Telecom instead. As per Singh, the Indian technicians in a meeting in his office on 14 April 2022 had informed that they intend to capture a 2 mins internet traffic data from the SAFE cable.</p><p>The allegation of allowing a foreign state to sniff internet traffic in Mauritius has been refuted by the Prime Minister.</p><p>Today, Subramanian Moonesamy, who is well reputed in the internet community, <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2022/07/6798.html">sent an email to the Data Protection Office</a> citing the <a href="https://www.youtube.com/channel/UCHOHGGVV6_YbnyGBOMqJYtA">36th International Conference of Data Protection and Privacy Commissioners</a>.</p><p>S. Moonesamy mentioned that one of the results of the conference was a resolution of Big Data that states —</p><!--kg-card-begin: html--><pre>
To be transparent about which data is collected, how the data is processed, for which
purposes it will be used and whether or not the data will be distributed to third 
parties.
</pre><!--kg-card-end: html--><p>The conference was <a href="http://www.govmu.org/English/News/Pages/Mauritius-Hosts-36th-International-Conference-of-Data-Protection-and-Privacy-Commissioners.aspx">hosted by Mauritius</a> in 2014.</p><p>S. Moonesamy stated in the email that several newspapers in Mauritius have featured a data capture at the Baie Jacotet cable landing station. He asked the Data Protection Office whether the 2014 Resolution is relevant to the data capture at Baie Jacotet.</p><h3 id="who-is-subramanian-moonesamy">Who is Subramanian Moonesamy?</h3><p>S. Moonesamy is a <a href="https://www.iana.org/dnssec/tcrs">Cryptographic Officer</a> of the Internet Assigned Numbers Authority. He is a Trusted Community Representative of the DNS technical community. He is involved in the DNSSEC key signing process of the root zone.</p><p>He has <a href="https://datatracker.ietf.org/person/sm+ietf@elandsys.com">drafted internet standards</a> for the Internet Engineering Task Force. He is currently Board Director for AFRINIC for Seat 3 – Indian Ocean.</p>]]></content:encoded>
        </item>
        <item>
            <title>Baie Jacotet SCLS, a restricted area</title>
            <link>https://sysadmin-journal.com/baie-jacotet-scls-a-restricted-area</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/baie-jacotet-scls-a-restricted-area</guid>
            <pubDate>Sat, 16 Jul 2022 20:14:19 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Privacy</category>
            <description>A lot of people have been searching about Baie Jacotet on the Internet, ever since the Prime Minister of Mauritius, P. K. Jugnauth, mentioned the Baie Jacotet Submarine Cable Landing Station, while answering on allegations made against him by the former CEO of Mauritius Telecom, S. Singh.</description>
            <content:encoded><![CDATA[<figure class="kg-card kg-image-card kg-width-wide"><img src="https://sysadmin-journal.com/content/images/2022/07/BAIE_JACOTET_GOOGLE_TRENDS_2022.png" class="kg-image" alt loading="lazy" width="1810" height="870" srcset="/content/images/size/w600/2022/07/BAIE_JACOTET_GOOGLE_TRENDS_2022.png 600w, /content/images/size/w1000/2022/07/BAIE_JACOTET_GOOGLE_TRENDS_2022.png 1000w, /content/images/size/w1600/2022/07/BAIE_JACOTET_GOOGLE_TRENDS_2022.png 1600w, /content/images/2022/07/BAIE_JACOTET_GOOGLE_TRENDS_2022.png 1810w" sizes="(min-width: 1200px) 1200px"></figure><p>Last Tuesday, the Prime Minister of Mauritius, P. K. Jugnauth, was replying to a question asked by a Member of Parliament, E. Juman, during the first session of the <a href="https://mauritiusassembly.govmu.org/Documents/Hansard/2022/hansard2022.pdf">parliamentary debate</a>.</p><p>P. K. Jugnauth confirmed that the Security Division of his office had requested the former CEO of Mauritius Telecom, S. Singh, to extend all necessary assistance to a three-member technical team from India who would field a survey mission at the South Africa Far East (SAFE) Submarine Landing Station at Baie Jacotet, Bel Ombre.</p><p>P. K. Jugnauth stated that in the morning of 15 April 2022, he was informed that Mauritius Telecom had not made the necessary arrangements for the team to have access at the Landing Station. Therefore, he telephoned the former CEO of Mauritius Telecom, S. Singh, and asked him to make arrangements for the survey to be carried out.</p><p>The SAFE Submarine Cable Landing Station at Baie Jacotet was declared a <strong>restricted area</strong> through Government Notice 183 of 2004. The <a href="https://pmo.govmu.org/CabinetDecision/2004/Cabinet-Decisions-taken-on-08-October-2004.aspx">decision</a> was taken by the cabinet on 8 October 2004 and the SAFE SCLS at Baie Jacotet has been a restricted area since 11 November 2004 in accordance with Section 13B of the Police Act.</p><h2 id="what-is-a-restricted-area">What is a restricted area?</h2><p>Section 13B of the <a href="https://attorneygeneral.govmu.org/Documents/Laws%20of%20Mauritius/A-Z%20Acts/P/PoliceAct-I9.pdf">Police Act</a> defines the meaning of a restricted area in Mauritius. It states that —</p><!--kg-card-begin: html--><pre>
(1) The Commissioner may, where he considers it necessary or expedient 
    in the interest of public safety or public order, order that 
    special measures be taken to control the movement and conduct of 
    persons in any area, and, by Order, declare that area to be a 
    restricted area.

(2) (a) The Commissioner may issue to a person a permit authorising
        him to enter and leave a restricted area.
    (b) The permit may be issued subject to such conditions as the
        Commissioner thinks fit to impose and may be cancelled.
</pre><!--kg-card-end: html--><h2 id="what-do-we-know-about-conditions-to-access-the-landing-station">What do we know about conditions to access the landing station?</h2><p>Until now, neither S. Singh nor P. K. Jugnauth, has provided any information regarding the conditions set by the Commissioner of Police in order to access the SAFE Submarine Cable Landing Station. </p><p>Thus, we do not know whether the staff personnel of Mauritius Telecom can access the landing station at any day and any time, whether they need to inform the Commissioner of Police of such access, whether they can bring people who are not personnel of Mauritius Telecom along with them, whether the identity of the people should be disclosed to the Commissioner of Police, etc.</p><h2 id="context">Context</h2><p>30 June 2022 — Sherry Singh <a href="https://www.lexpress.mu/article/410614/sherry-singh-depart-mt-profonds-desaccords-pravind-jugnauth">resigns</a> as CEO of Mauritius Telecom.</p><p>1 July 2022 — Nawaz Noorbux of Téléplus, Défi Media, interviews Sherry Singh. The latter discloses the reason behind his resignation. He says that the Prime Minister, <a href="https://youtu.be/wEvCwYPMzok?t=868">P. K. Jugnauth had phoned him to ask</a> him to do something which is illegal, against the interests of Mauritius Telecom, against the interests of the citizens of Mauritius, against the country and against certain friendly states. Nawaz asks him what is it exactly. Singh says that P. K. Jugnauth phoned him to give him instructions to allow a third-party to install equipments in Mauritius Telecom which will sniff all incoming and outgoing Internet traffic in Mauritius.</p><p>6 July 2022 — P. K. Jugnauth <a href="https://youtu.be/2JrYeWjgXYw?t=73">confirms</a> that he had a phone conversation with the S. Singh and that he had asked him to give a technical team access to the Baie Jacotet Landing Station. He says that at no moment during the conversation he mentioned a sniffing equipment. While answering a journalist regarding the third-party, he says that there was a matter of security and that there was a need for the survey. He says that in Mauritius we do not have the technicians that can do such a survey, or even if there are, he decided to hire foreign technicians. He says that he spoke to the Prime Minister of India, N. Modi, to get a team of technicians that can do the survey.</p><p>12 July 2022 — Prime Minister, P. K. Jugnauth, while replying to a question in the National Assembly, confirms that he has lodged a police complaint against S. Singh.</p><p>12 July 2022 — Axcel Chenney of l'express <a href="https://www.facebook.com/100761789539/videos/1385874455267359">interviews</a> Sherry Singh who promised further revelations. Singh described chronologically what led to his resignation. Axcel says that the Prime Minister has denied any attempt for surveillance and questions Singh that he is saying the opposite. Singh confirms that it was about surveillance. Singh also confirms that the technical team did several « interventions » in the network and that he has proof. He does not show any proof during the interview. He says he will provide all proofs to the authorities when the time comes.</p><h2 id="update">Update</h2><p>S. Moonesamy replied to my <a href="https://twitter.com/IshSookun/status/1548407114321735681">tweet</a> about this article and indicated that companies who have to maintain their equipment at the Baie Jacotet SCLS have to designate the persons who should be granted access to the site and the identity of the persons would be in a log book.</p><!--kg-card-begin: html--><center>
    <blockquote class="twitter-tweet" data-conversation="none"><p lang="en" dir="ltr">The companies who have to maintain their equipment designates the persons who should be granted access to the site. The identity of the visitors would be in the log book. <a href="https://t.co/W4z9bhUTpl">pic.twitter.com/W4z9bhUTpl</a></p>&mdash; S Moonesamy (@sminmu) <a href="https://twitter.com/sminmu/status/1548427358159634432?ref_src=twsrc%5Etfw">July 16, 2022</a></blockquote> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
</center><!--kg-card-end: html--><p>The document that S. Moonesamy referred to in his tweet is Mauritius Telecom's Master Agreement for Inter-Connection at the Submarine Cable Landing Station.</p><p>An <a href="https://www.icta.mu/documents/2021/11/cable_cross_connection.pdf">explanatory memorandum</a> to Cross-Connection at the Submarine Cable Landing Station (SCLS), published by the Information &amp; Communication Technologies Authority (ICTA) provides details about the Baie Jacotet SCLS and includes a copy of Mauritius Telecom's Master Agreement.</p><p>Page 13 of the document includes a site plan of the Baie Jacotet SCLS.</p><figure class="kg-card kg-image-card kg-width-wide kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2022/07/Baie-Jacotet-SCLS.png" class="kg-image" alt="Baie Jacotet Submarine Cable Landing Station (SCLS) site plan" loading="lazy" width="1636" height="888" srcset="/content/images/size/w600/2022/07/Baie-Jacotet-SCLS.png 600w, /content/images/size/w1000/2022/07/Baie-Jacotet-SCLS.png 1000w, /content/images/size/w1600/2022/07/Baie-Jacotet-SCLS.png 1600w, /content/images/2022/07/Baie-Jacotet-SCLS.png 1636w" sizes="(min-width: 1200px) 1200px"><figcaption>Baie Jacotet Submarine Cable Landing Station (SCLS) site plan</figcaption></figure><p>The site plan provides a layout of the building and which section the building contains Consortium's infrastructure and which section contains Mauritius Telecom's infrastructure.</p><hr><p>In an <a href="https://sundaytimesmauritius.com/rajen-valayden-lile-maurice-est-devenue-un-centre-nevralgique-de-renseignements/">interview</a> given to Sunday Times, R. Valayden, the Chief Editor of <a href="https://www.capital-media.mu/">Capital Media</a> provided some details about the persons who had access to the Baie Jacotet SCLS on 15 April. Details that no other media outlet has published so far. I quote what he said in the interview —</p><blockquote>Selon mes recoupements, vers 12h58, trois véhicules sont arrivés. La première voiture, une Mercedes, était conduite par Girish Guddoy, ‘<em>Chief Technical Officer</em>’ (CTO) de MT. Le ‘<em>Manager</em>’ de MT était au volant de la deuxième voiture, une Hyundai. Et la dernière voiture, une Honda Vezel, avait, à son bord, trois ressortissants étrangers. Les agents de la SMF ont été informés par le CTO que tous les occupants du véhicule sont des employés de MT et que leur visite ne devait pas figurer sur le registre. Les deux cadres de MT ont ensuite introduit les étrangers dans la salle des opérations. Le CTO de MT a demandé au personnel sur place de se retirer et a prononcé les mots « <em>Top Secret</em> ». Les techniciens étrangers n’ont pas accédé au câble SAFE mais se sont concentrés sur le panel en utilisant un logiciel médiateur (‘<em>middleware</em>’). L’intervention sur chaque connexion nécessite d’abord un court-circuitage occasionnant une panne de 30 secondes lors de la connexion du logiciel et idem lors de la déconnexion. Le ballotage de 60 secondes est inévitablement répercuté dans les rapports techniques. L’équipe est partie vers 19h15. C’est le ‘<em>Manager</em>’, un des cadres les plus aguerris de MT, qui a assisté les techniciens étrangers alors que son chef hiérarchique se rongeait les ongles à l’extérieur.</blockquote><p>R. Valayden, for obvious reasons, did not reveal his source of information, but one could imagine that it must be coming from one of the MT employees present during the visit.</p><p>R. Valayden said that S. Singh had both moral and legal responsibilities to refuse such a request coming from the Prime Minister, since Singh had all executive powers to do so.</p><p>He also casts doubts on the claims of S. Singh, saying that in spite of Singh not receiving a formal request for the survey by the Prime Minister, Singh could still follow up by an email the same day to keep it on record.</p>]]></content:encoded>
        </item>
        <item>
            <title>What is the SAFE submarine cable?</title>
            <link>https://sysadmin-journal.com/what-is-the-safe-submarine-cable</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/what-is-the-safe-submarine-cable</guid>
            <pubDate>Thu, 14 Jul 2022 18:19:08 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Internet Community</category>
            <description>Submarine cable networks are fiber optic cables laid in the ocean to connect two or several landing points. There are hundreds of submarine cables around the globe connecting continents. These cables are able to transfer huge amounts of data very rapidly.</description>
            <content:encoded><![CDATA[<p>The South Africa Far East (SAFE) cable is an optical fiber submarine cable that connects South Africa, Mauritius, Réunion, India and Malaysia. It is about 13,500 km long and has <strong>landing points</strong> in these locations:</p><ul><li>Melkbosstrand, South Africa</li><li>Mtunzini, South Africa</li><li>Saint Paul, Réunion</li><li>Baie Jacotet, Mauritius</li><li>Cochin, India</li><li>Penang, Malaysia</li></ul><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2022/07/safe-cable-TeleGeography-5.png" class="kg-image" alt="Source: TeleGeography" loading="lazy" width="1000" height="719" srcset="/content/images/size/w600/2022/07/safe-cable-TeleGeography-5.png 600w, /content/images/2022/07/safe-cable-TeleGeography-5.png 1000w" sizes="(min-width: 720px) 720px"><figcaption>Source: TeleGeography</figcaption></figure><p>The SAFE cable is owned by a consortium of network operators. The operators are AT&amp;T, Angola Telecom, BICS, Camtel, China Telecom, Chunghwa Telecom, Ghana Telecommunications Company, KPN, KT, Liquid Intelligent Technologies, Maroc Telecom, Mauritius Telecom, NATCOM (Nigeria), OPT, Orange, Orange Cote d’Ivoire, PCCW, Singtel, Sonatel, T-Mobile, Tata Communications, Telecom Italia Sparkle, Telecom Namibia, Telefonica, Telekom Malaysia, Telkom South Africa, Telstra, Verizon and Vodafone.</p><p>It became operational in April 2002.</p><p>The SAFE cable is considered to part of a longer submarine cable that connects Europe, Africa and South-East Asia. The complete submarine cable is referred as the <strong>SAT3 / WASC / SAFE</strong> cable.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2022/07/safe-sat3-wasc-submarine-cable-TeleGeography-2.png" class="kg-image" alt="SAT3 / WASC / SAFE submarine cable, source: TeleGeography" loading="lazy" width="1000" height="719" srcset="/content/images/size/w600/2022/07/safe-sat3-wasc-submarine-cable-TeleGeography-2.png 600w, /content/images/2022/07/safe-sat3-wasc-submarine-cable-TeleGeography-2.png 1000w" sizes="(min-width: 720px) 720px"><figcaption>SAT3 / WASC / SAFE submarine cable, source: TeleGeography</figcaption></figure><p>The information about the SAFE submarine cable provided in this post has been taken from <a href="https://www.submarinecablemap.com/submarine-cable/safe">TeleGeography</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title>What is a network sniffer?</title>
            <link>https://sysadmin-journal.com/what-is-a-network-sniffer</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/what-is-a-network-sniffer</guid>
            <pubDate>Wed, 06 Jul 2022 22:10:19 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Privacy</category>
            <category>Mauritius</category>
            <description>Network sniffer, packet sniffer, protocol analyzer, and other such names are often given to network analysis tools that are used for debugging and security purposes. A network sniffer can also be used for malicious purposes.</description>
            <content:encoded><![CDATA[<p>I was on my way back home today with my wife, Shelly, when she asked me if I could explain to her more about this «swindler» device that has become the talk of the town.</p><p>I replied to her that it is not «swindler» but network sniffer.</p><p>In this blog post I try to explain what is a network sniffer device or software? But before we understand that there a few things we should become familiar with.</p><p>I think most of the Internet users today know that every device connected to the Internet is identified by a string of numbers called the <strong>IP address</strong>. A phone number is the identifier of a physical telephone. Phone numbers allow calls to be made among fixed telephones and mobile phones. Similarly, devices connected to the Internet are able to find each other and initiate communication protocols using the IP address of each device.</p><h2 id="lesson-no-1-%E2%80%94-internet-protocol-ip-addresses">Lesson no. 1 — Internet Protocol (IP) addresses</h2><p>Your computer, mobile phone and Smart TV in your house, each one is assigned a <strong>private IP address</strong> by your router (which is usually given to you by your Internet Service Provider, e.g Mauritius Telecom or Emtel).</p><p>An example of a private IP address is 192.168.100.10. All devices connected to the WiFi of your home router will have IP addresses in that range (192.168.100.11, 192.168.100.12, etc). These addresses are assigned to your home devices by the ISP router and they allow your devices to communicate with each other. The IP addresses are not reachable from the Internet. Therefore, if I need to communicate with your smartphone at your place, which has an IP address of let's say, 192.168.100.10, then I won't be able to do so from the comfort of my home, because that address is not reachable from the Internet.</p><p>For communication to happen on the Internet, <strong>public IP addresses</strong> are required. Your ISP provides you a router which is also a modem. The modem connects to your ISP network and a public IP address is assigned to it which is unique on the Internet. This IP address allows you to communicate on the Internet.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2022/07/IP-Address-Explained.svg" class="kg-image" alt="Diagram depicting private and public IP addresses" loading="lazy" width="800" height="418"><figcaption>Diagram created using Figma, icons sourced from flaticon.com</figcaption></figure><p>When you open Netflix on your Smart TV, the request is sent to your router first and from there it is the router that sends the request on the Internet, to the Netflix server. Your router knows which of your devices made the request and therefore when a response is received from Netflix, it forwards that information to your Smart TV.</p><blockquote>The range of IP addresses 197.224.0.0 – 197.225.255.255 is allocated to <a href="http://telecom.mu/">Mauritius Telecom</a> by <a href="https://afrinic.net/">AFRINIC</a> (the Regional Internet Registry for Africa &amp; the Indian Ocean region). Many such IP address ranges are allocated to Mauritius Telecom and other Internet Service Providers in Mauritius. There are five Regional Internet Registries in the world that allocate the use of the IP addresses to organisations such as ISPs, universities, cloud companies, etc.</blockquote><h2 id="lesson-no-2-%E2%80%94-network-packets">Lesson no. 2 — Network Packets</h2><p>Okay, now we know how the Smart TV sends a request to Netflix on the Internet and it receives a response. Let's see what are the requests and responses made of.</p><p>When someone needs to send a picture to somebody over the Internet, let's say using WhatsApp, that picture isn't sent as single item over the network. It is broken down into many pieces before it is sent over. The pieces travel from one router to another, across the world, until they reach the intended destination (which is another device, e.g a smartphone). At the destination device, all the pieces are reassembled to make up the picture like it was on the sender's device.</p><p>These small pieces are called <strong>packets</strong>. One may rightly ask, how many packets is a single JPEG file broken into before sending over the network?</p><p>The number of packets may vary depending on how network devices are configured. Network devices such as routers are configured to allow a maximum size for a single packet. This is referred to as the Maximum Transmission Unit (MTU) and it's usually 1500 bytes. Therefore, we could say that a 1 MB JPEG file would be broken into about 665 pieces of ~1500 bytes each before it is sent to someone on the Internet.</p><p>It is that single piece of 1500 bytes data that is called <strong>a packet</strong>.</p><p>A packet itself is composed of two parts.</p><ul><li>a header</li><li>a payload (also referred as data)</li></ul><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2022/07/Packet_Header.svg" class="kg-image" alt="Diagram detailing a network packet" loading="lazy" width="800" height="418"><figcaption>Image source: Khan Academy</figcaption></figure><h2 id="header">Header</h2><p>The header part contains information about the source, destination, protocol and packet number. This information is important for the routers to know where to send the packet and upon reaching its destination how the packets needs to be reassembled. The header part is not encrypted because this information should be readable by all networking devices that will carry the packet until its final destination.</p><h2 id="payload">Payload</h2><p>The payload is the actual data that needs to be sent. In the example of the 1 MB JPEG file, the payload of the packet will contain part of the image data. If an encrypted communication is established on the Internet, then this payload will contain part of that encrypted data.</p><p>If the payload is not encrypted, then the packets can be captured by a network analysis tool (a sniffer) and the complete file reconstructed, e.g a 1 MB JPEG file can be reconstructed and viewed in any image application.</p><p>If the payload is encrypted, then the packets can be still be captured by the tool and the reconstructed file will be an encrypted JPEG file.</p><h1 id="network-sniffer">Network Sniffer</h1><blockquote>The former CEO of Mauritius Telecom, S. Singh, stated in a <a href="https://www.youtube.com/watch?v=wEvCwYPMzok">radio programme</a> on Friday 1st July 2022 at 17h00, that the Prime Minister of Mauritius, asked him to allow a third-party to install a network sniffer in the premises of the ISP.</blockquote><p>The statement by S. Singh shook many people and it sends chills down the spine thinking that the biggest Internet Service Provider could be breaching the privacy of hundreds of thousands of Internet users in Mauritius.</p><p>But, wait a minute? In his statement, S. Singh did not reveal the name of the third-party and the actual device or software that intended to sniff the Internet traffic. Unless those information are revealed, one can only speculate on sinister possibilities.</p><p>That being said, now let's look at what does a Network Sniffer do. </p><p>A network sniffer is a tool that can capture network packets and analyse them. Some network sniffers can even reconstruct whole files if the payload is not encrypted or do signature-based Deep Packet Inspection (DPI) on the payload to identify its nature if the payload is encrypted.</p><p>There are network sniffers that are also capable of man-in-the-middle (MITM) attacks. Therefore, they can decrypt the network traffic and give a complete view of everything that a person does on the Internet.</p><h2 id="how-are-network-packets-captured">How are network packets captured?</h2><p>A network sniffer can be installed on any device to capture the traffic of that particular device. For example, if someone wants to analyse his/her own incoming &amp; outgoing traffic on a laptop, a sniffer can be instructed to capture the traffic from a network interface, which can be an ethernet (cable) port or a WiFi.</p><p>Some routers also allow packet capturing from the router's ports and the file produced during the capture can be analysed using other tools.</p><p>Enterprise-grade firewalls are often equipped with advanced network packet capturing and Deep Packet Inspection (DPI) capabilities.</p><h2 id="clearing-confusions">Clearing confusions</h2><p>In 2021, the Information and Communication Technologies Authority (ICTA) <a href="https://sysadmin-journal.com/ict-authority-proposal-to-monitor-the-internet-in-a-nutshell/">proposed amendments</a> to the ICT Act, which would have allowed the authority to apply an MITM approach and control the Internet traffic in Mauritius.</p><p>It had also become public knowledge, that ICTA intended to use <a href="https://www.netsweeper.co.uk/">Netsweeper</a> which had the MITM capabilities to decrypt HTTPS traffic.</p><p>Many organisations, including international privacy-focussed organisations, browser makers, and the citizens of Mauritius strongly opposed the proposal and condemned the authority to even think of such an approach.</p><p>At that time, I made a <a href="https://sysadmin-journal.com/proof-of-concept-proxy-shows-user-account-passwords-and-private-photos-can-be-decrypted/">proof-of-concept</a> using a web proxy called Fiddler Everywhere, to demonstrate how HTTPS traffic can be decrypted on the fly.</p><p>It's been a week since S. Singh's statement on radio and we still do not have any information regarding which software maker and what type of «sniffer» was the subject of discussion between Singh and the Prime Minister.</p><p>Therefore, what we can retain here is that if Mauritius Telecom would have installed a sniffer <strong>without doing any MITM attack</strong>, then it would have to rely on signature-based Deep Packet Inspection. That approach would not have given MT employees access to your email messages, listen to your WhatsApp calls or read your Facebook messages, etc. It would have allowed the tool to reconstruct your browsing history partly.</p><h3 id="can-an-isp-monitor-the-internet-traffic-of-all-its-subscribers">Can an ISP monitor the Internet traffic of all its subscribers?</h3><p>An ISP could decide whether to monitor and capture the traffic of all its subscribers, some of them or a just a few.</p><h3 id="is-it-not-costly-to-monitor-such-amount-of-internet-traffic">Is it not costly to monitor such amount of Internet traffic?</h3><p>Deep Packet Inspection on a high traffic network is costly, indeed. However, using a network tap, the ISP can copy the traffic of a specific network segment or specific IP addresses, for analysis, without impeding the actual traffic. There are several approaches that can reduce the cost of operation.</p><h3 id="can-a-third-party-have-access-to-the-network-traffic">Can a third-party have access to the network traffic?</h3><p>If a third-party operates the network device or the «sniffer» then yes, it can have access.</p><hr><h2 id="erratum">Erratum</h2><p>I initially described the packet as being composed of three parts – header, payload (data) and footer. After S. Moonesamy pointed out on the Mauritius Internet Users mailing list to check whether the footer part is incorrect, I read Section 3.1 of the <a href="https://datatracker.ietf.org/doc/html/rfc791">RFC 791 – Internet Protocol</a> to cross-verify. Section 1.3 of the same RFC describes an example where a TCP module would call on the internet module to take a TCP segment (including the TCP header and user data) as the data portion of an internet datagram. These information provide clarity on the packet composition as having a header and the data.</p><p>There are articles online that refer to the packet as a frame and then mention the frame as having a "trailer" part. The trailer is mentioned in <a href="https://datatracker.ietf.org/doc/html/rfc1661">RFC 1661 – Point-to-Point Protocol (PPP)</a>.</p><p>RFCs are documents that contain <a href="https://www.ietf.org/standards/rfcs/">technical specifications for the Internet</a>. They are produced by the Internet Engineering Task Force. Software developers, hardware manufacturers, and network operators around the world voluntarily implement and adopt the technical specifications described by RFCs.</p>]]></content:encoded>
        </item>
        <item>
            <title>MIXP Management Committee election result announced</title>
            <link>https://sysadmin-journal.com/mixp-mancom-election-result-announced</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/mixp-mancom-election-result-announced</guid>
            <pubDate>Wed, 29 Jun 2022 11:38:33 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>MIXP</category>
            <category>Internet Community</category>
            <category>Mauritius</category>
            <description>The Mauritius Internet Exchange Point (MIXP) is the first Internet exchange point in Mauritius, where any network operator can peer and improve its network efficiency.</description>
            <content:encoded><![CDATA[<p>The Management Committee (ManCom) of the Mauritius Internet Exchange Point (MIXP) is composed of seven members elected by the peering members.</p><p>The final candidate slate for the ManCom 2022 — 2023 was published on Friday 10th June on the MIXP Announce mailing list by Keessun Fokeerah (MIXP Secretariat). Electronic voting through the Helios platform started on Monday 13th June and ended on Monday 27th June.</p><p>Twelve candidates from different organisations ran in this election.</p><p>The election result was announced today, via a Zoom conference call, where several peering members and interested folks from the Internet community joined in. Keessun computed the tally on Helios and the result was available within seconds.</p><h2 id="election-result">Election Result</h2><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Name</th>
<th>No. of votes</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>Nishal Goburdhan</strong></td>
<td><strong>14</strong></td>
</tr>
<tr>
<td><strong>Dr. Amreesh Phokeer</strong></td>
<td><strong>13</strong></td>
</tr>
<tr>
<td><strong>Ranveer Kumar Seetaloo</strong></td>
<td><strong>13</strong></td>
</tr>
<tr>
<td><strong>Jason Leong Son</strong></td>
<td><strong>10</strong></td>
</tr>
<tr>
<td><strong>Eric Loos</strong></td>
<td><strong>9</strong></td>
</tr>
<tr>
<td><strong>Ganesh Ramalingum</strong></td>
<td><strong>6</strong></td>
</tr>
<tr>
<td><strong>Sharma Baljinder</strong></td>
<td><strong>6</strong></td>
</tr>
<tr>
<td>Eddy Lareine</td>
<td>5</td>
</tr>
<tr>
<td>Bhaveshdeo Sreekeessoon</td>
<td>4</td>
</tr>
<tr>
<td>Ravi Pudaruth</td>
<td>4</td>
</tr>
<tr>
<td>Tejas Pagooah</td>
<td>3</td>
</tr>
<tr>
<td>Zaheer Ramjaun</td>
<td>3</td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p>Therefore, the ManCom 2022 — 2023 will be composed of Nishal Goburdhan, Dr. Amreesh Phokeer, Ranveer K. Seetaloo, Jason Leong Son, Eric Loos, Ganesh Ramalingum and Sharma Baljinder.</p><p>I congratulate the newly elected members of the MIXP ManCom and thank all those who stepped up.</p>]]></content:encoded>
        </item>
        <item>
            <title>Final candidate slate for the MIXP Management Committee 2022 – 2023</title>
            <link>https://sysadmin-journal.com/final-candidate-slate-for-the-mixp-management-committee-2022-2023</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/final-candidate-slate-for-the-mixp-management-committee-2022-2023</guid>
            <pubDate>Fri, 10 Jun 2022 09:18:31 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>MIXP</category>
            <category>Internet Community</category>
            <category>Mauritius</category>
            <description>The Mauritius Internet Exchange Point (MIXP) is the first Internet exchange point in Mauritius. It is open to any network operator that believes that they can make their network more efficient through peering. The MIXP Management Committee is composed of 7 members elected by the peering members.</description>
            <content:encoded><![CDATA[<p>The final candidate slate for the Management Committee 2022 – 2023 was announced today by the MIXP Secretariat, Keessun Fokeerah, on the <a href="https://lists.mixp.org/pipermail/mixp-announcement/2022q2/000032.html">MIXP Announce</a> mailing list.</p><p>The candidates are:</p><ul><li>Dr. Amreesh Phokeer</li><li>Mr. Bhaveshdeo Sreekeessoon</li><li>Mr. Eddy Lareine</li><li>Mr. Eric Loos</li><li>Mr. Ganesh Ramalingum</li><li>Mr. Jason Leong Son</li><li>Mr. Nishal Goburdhan</li><li>Mr. Ranveer Kumar Seetaloo</li><li>Mr. Ravi Pudaruth</li><li>Mr. Sharma Baljinder</li><li>Mr. Tejas Pagooah</li><li>Mr. Zaheer Ramjaun</li></ul><p>The biodata of each candidate is available at <a href="https://www.mixp.org/#elections2022">www.mixp.org/#elections2022</a>.</p><p>Voting in this election will be done electronically using Helios. Only MIXP peers can vote in this election. Instructions on how to vote will be sent by email to peering members. Electronic voting will start on Monday 13th June 2022 at 14h00 MUT and shall close on Monday 27th June 2022 at 14h00 MUT.</p><p>Each MIXP peer can vote for up to 7 persons.</p><p>Some of the above mentioned candidates introduced themselves during the MIXP session at the Africa Internet Summit 2022 at Le Méridien Hotel, last week.</p><!--kg-card-begin: html--><center>
    <blockquote class="twitter-tweet"><p lang="en" dir="ltr"><a href="https://twitter.com/IXP_Mu?ref_src=twsrc%5Etfw">@IXP_Mu</a> meetup #3 happening during <a href="https://twitter.com/AIS_Africa?ref_src=twsrc%5Etfw">@AIS_Africa</a> now! now serving up to 22 peers and growing! <a href="https://t.co/w2mslj3K0t">pic.twitter.com/w2mslj3K0t</a></p>&mdash; Nishal Goburdhan (@ngoburdhan) <a href="https://twitter.com/ngoburdhan/status/1531875786721992704?ref_src=twsrc%5Etfw">June 1, 2022</a></blockquote> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
</center><!--kg-card-end: html--><p>The MIXP enables its peers to have settlement-free peering and keep intra-island traffic purely local. Therefore, peers do not have to pay any setup fee or other bandwidth related fees. By design, the MIXP treats all its peers equally and there is no traffic prioritisation or any filtering rules for specific participants.</p><p>I would highly recommend that network operators in Mauritius peer at the MIXP, not just to improve their network efficiency but help in making the overall Internet experience better on the island.</p>]]></content:encoded>
        </item>
        <item>
            <title>Benjamin Eshun appointed as Chairman &amp; Dr. Abdalla Omari, Vice-Chairman of AFRINIC</title>
            <link>https://sysadmin-journal.com/benjamin-eshun-appointed-as-chairman-afrinic-and-dr-abdalla-omari-vice-chairman</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/benjamin-eshun-appointed-as-chairman-afrinic-and-dr-abdalla-omari-vice-chairman</guid>
            <pubDate>Tue, 07 Jun 2022 07:47:26 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>AFRINIC</category>
            <category>Internet Community</category>
            <category>Mauritius</category>
            <description>The AFRINIC Annual General Members’ Meeting (AGMM) is held once a year, usually during an AFRINIC Public Policy Meeting.</description>
            <content:encoded><![CDATA[<p>Last Friday, the Annual General Members Meeting of AFRINIC was held at Le Méridien Hotel, Mauritius. The AGMM was held in a hybrid format – members could attend the meeting on-site or virtually via an online meeting platform.</p><p>Representatives of Resource Members could vote on polls either on-site or online, through the my.afrinic.net members portal.</p><p>The AGMM was scheduled to start at 10h00 UTC. A few members protested that the meeting cannot start as several members had not yet receive their online meeting token. Some members reported that the token they received was not good.</p><p>The first meeting token I received was not good either and I instantly reported that to legal@afrinic.net. A few minutes later I received another token which allowed me the join the meeting.</p><p>Observers could attend the meeting on-site in a separate meeting room and the meeting was also live streamed on YouTube. Observers cannot vote in polls, comment on the proceedings or ask questions.</p><p>The meeting atmosphere remained heated during the whole time.</p><p>The meeting was adjourned for 1 hour, allowing tokens to be re-generated and sent to all registered members. However, the next few hours the meeting scene remained the same.</p><p>Motions were raised, polls were called, but the overall aim of the AGMM, in my opinion, remained unfulfilled. Firstly, the Board Elections could not be carried out due to a court injunction preventing the same. Secondly, the motion to adopt the audited financial accounts failed.</p><h2 id="appointments-on-the-afrinic-board">Appointments on the AFRINIC Board</h2><p>Among all these upheaval, a <a href="https://afrinic.net/20220606-appointments-on-afrinic-board">Board of Directors meeting</a> was held on Sunday, 5 June 2022 and Mr. Benjamin Eshun was appointed as the new Board Chairmain. Dr. Abdalla Omari was appointed as Vice-Chairman.</p><p>Disagreements followed on the AFRINIC Members mailing list. Some members claimed that the requirement of 5 directors to make a quorum could not have been fulfilled since three seats are now vacant in the Board and therefore, these appointments are not valid.</p><p>I wish the new Chairman and Vice-Chairman all the best ahead. I thank S. Moonesamy, former Board Chair and Prod. H. Youssef, former Vice-Chair for their time, guidance and leadership on the AFRINIC Board.</p>]]></content:encoded>
        </item>
        <item>
            <title>AFRINIC restricts attendance to the Annual General Members Meeting (AGMM) even ONLINE 😐</title>
            <link>https://sysadmin-journal.com/afrinic-restricts-attendance-to-the-annual-general-members-meeting-even-online</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/afrinic-restricts-attendance-to-the-annual-general-members-meeting-even-online</guid>
            <pubDate>Tue, 31 May 2022 19:23:43 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>AFRINIC</category>
            <category>Internet Community</category>
            <category>Africa</category>
            <category>Mauritius</category>
            <category>Conference</category>
            <description>The Africa Internet Summit (AIS) is an annual, regional, multi-stakeholder ICT conference. AIS&#039;22 is jointly organised by the Africa Network Information Centre (AFRINIC) in collaboration with the African Network Operators Group (AfNOG).</description>
            <content:encoded><![CDATA[<p>The Africa Internet Summit 2022 is being held on 30th May – 3rd June at Le Méridien Hotel, Pte aux Piments in Mauritius. The AFRINIC Annual General Members Meeting (AGMM) is scheduled on the last day of the Africa Internet Summit, i.e Friday 3rd June 2022.</p><p>Many AFRINIC Resource Members look forward to this meeting and they travel every year to attend the meeting in person. Others who cannot make it can still participate and ask questions via the online conference system.</p><p>I have been attending AFRINIC Meetings since 2017. I have attended a few meetings online and two of the meetings in-person. I have attended the meetings as a Resource Member since 2019. I have never seen AFRINIC restricting Resource Members from attending the AGMM in the past.</p><p>Today, in a email the AFRINIC Legal Team informed members that due to the prevailing sanitary protocol in Mauritius, only one representative of a Resource Member will be allowed to attend the meeting in-person. However, to the astonishment and incomprehension of several members, the legal team also stated that only one representative per Resource Member will be allowed to join the meeting via the online conference system.</p><p>Several members have raised questions over this statement. I questioned the legal team about it and in <a href="https://lists.afrinic.net/pipermail/community-discuss/2022-May/005251.html">response</a> the AFRINIC Communications team stated that —</p><blockquote>Article 12.14(9) provides, inter-alia as follows - "Corporations may act by representative. A corporate body, which is a Member, may appoint a representative to attend an Annual General Members’ Meeting on its behalf in the same manner as that in which it could appoint a proxy.”.</blockquote><p>The <a href="https://afrinic.net/bylaws">AFRINIC Bylaws</a>, from which the above article is quoted, does not state that a corporate body, which is a Member, can be represented by one person only.</p>]]></content:encoded>
        </item>
        <item>
            <title>Front-end Coders Meetup</title>
            <link>https://sysadmin-journal.com/front-end-coders-meetup</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/front-end-coders-meetup</guid>
            <pubDate>Sun, 17 Apr 2022 07:25:34 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Meetup</category>
            <category>Mauritius</category>
            <description>The Front-end Coders are back on the meetup scene. This blog post is a sum-up of the meetup that happened on Saturday 9 April 2022 at Prodigious, Ebène.</description>
            <content:encoded><![CDATA[<p>The Front-end Coders organised a meetup on Saturday, 9 April. I was keen to attend this meetup because, like many others, I've been waiting for the meetup-scene to be a normal thing again in Mauritius.</p><blockquote>Earlier in January, we had perhaps the <a href="https://sysadmin-journal.com/linux-user-group-of-mauritius-meets-lubos-kocman/">first meetup</a>, non-virtual, in a very long time, which was organised by the Linux User Group of Mauritius.</blockquote><p>The Front-end Coders meetup was scheduled between 10h00 — 14h00 in the office premises of <a href="https://prodigious.com/mauritius">Prodigious</a>. I had never been to their office before but finding the place was not a trouble. Also, there was no issue finding a parking space.</p><p><a href="https://twitter.com/Shelly_Bhujun">Shelly</a> dropped me at Prodigious. We picked up Renghen along the way, from the University of Mauritius campus. We were at Prodigious at around 10h00. Kushul's and Sandeep's cars were in the parking lot of <a href="https://goo.gl/maps/hqtMWsQGxCXkVZuF7">Maeva Tower</a>.</p><p>I called <a href="https://twitter.com/kushul_soomaree">Kushul</a> to ask whether the presentations had begun. He said that people were still coming. Within a few minutes he came down the parking lot to show us the way to the office, which is on the 2nd floor of the building — a spacious and cozy place.</p><p>By 10:30 most people who had RSVP'ed had arrived. Some 20+ people attended the meetup.  <a href="https://twitter.com/__Sun__">Sandeep</a> made an introductory speech.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2022/04/sandeep-ramgolam-front-end-coders-april-2022.jpg" class="kg-image" alt="Sandeep Ramgolam — Intro. speech" loading="lazy" width="1200" height="900" srcset="/content/images/size/w600/2022/04/sandeep-ramgolam-front-end-coders-april-2022.jpg 600w, /content/images/size/w1000/2022/04/sandeep-ramgolam-front-end-coders-april-2022.jpg 1000w, /content/images/2022/04/sandeep-ramgolam-front-end-coders-april-2022.jpg 1200w" sizes="(min-width: 720px) 720px"><figcaption>Sandeep Ramgolam — Intro. speech</figcaption></figure><p>He talked about the Front-end Coders and the agenda of the day. He thanked the meetup sponsors, Prodigious for the venue and <a href="https://www.ringier.com/location/africa/">Ringier</a> for sponsoring lunch. He mentioned that they are trying to bring back the monthly meetups. The next one will be in May and the topic will be React, although no date has been fixed yet. In fact, they are still looking for a venue sponsor — so, if someone can arrange that, it would be a great help!</p><p>Sandeep mentioned that he closed the Front-end Coders page on Meetup.com. He explained the reason. The Meetup.com subscription costs about $120 yearly and while there were no meetups during Covid-19 restrictions in Mauritius, he still had to pay those fees. He said the meetup announcements are now made on their <a href="https://www.facebook.com/frontendcodersmauritius/">Facebook</a> page instead and they also have setup a <a href="https://front-end-coders-mauritius.netlify.app/">website</a> to publish the events details.</p><p>The first presentation of the day was done by <a href="https://twitter.com/MahimaRamgolam">Mahima</a>. She did an introduction to Tailwind CSS. She explained the concept of utility classes and did live coding to explain Grid and Flexbox concepts using Tailwind CSS.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2022/04/mahima-ramgolam-intro-to-tailwind-css.jpg" class="kg-image" alt="Mahima Ramgolam — Intro. to Tailwind CSS" loading="lazy" width="1200" height="674" srcset="/content/images/size/w600/2022/04/mahima-ramgolam-intro-to-tailwind-css.jpg 600w, /content/images/size/w1000/2022/04/mahima-ramgolam-intro-to-tailwind-css.jpg 1000w, /content/images/2022/04/mahima-ramgolam-intro-to-tailwind-css.jpg 1200w" sizes="(min-width: 720px) 720px"><figcaption>Mahima Ramgolam — Intro. to Tailwind CSS</figcaption></figure><p>Mahima gave an overview of some new features in Tailwind CSS v3.0 such as the Just-in-Time (JIT) engine and fancy underline styles. You can read more about these new features from the Tailwind CSS v3.0 <a href="https://tailwindcss.com/blog/tailwindcss-v3">blog post</a> by Adam Wathan.</p><p>The next presentation was done was <a href="https://twitter.com/mk_jules">Jules</a>. He spoke about Reactivity. He used the <a href="https://vuejs.org/api/reactivity-core.html">Vue.js Reactivity API</a>. I am not familiar with Vue.js, less even with concepts of reactivity in JavaScript. Nevertheless, Jules did an extremely fun demo to engage the audience.</p><figure class="kg-card kg-image-card"><img src="https://sysadmin-journal.com/content/images/2022/04/reactivity-demo-by-jules-mike.jpg" class="kg-image" alt loading="lazy" width="1200" height="674" srcset="/content/images/size/w600/2022/04/reactivity-demo-by-jules-mike.jpg 600w, /content/images/size/w1000/2022/04/reactivity-demo-by-jules-mike.jpg 1000w, /content/images/2022/04/reactivity-demo-by-jules-mike.jpg 1200w" sizes="(min-width: 720px) 720px"></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2022/04/jules-mike.jpg" class="kg-image" alt="Jules (Mike) Giovanni — Live demo using Vue.js Reactivity API" loading="lazy" width="1200" height="674" srcset="/content/images/size/w600/2022/04/jules-mike.jpg 600w, /content/images/size/w1000/2022/04/jules-mike.jpg 1000w, /content/images/2022/04/jules-mike.jpg 1200w" sizes="(min-width: 720px) 720px"><figcaption>Jules (Mike) Giovanni — Live demo using Vue.js Reactivity API</figcaption></figure><p>Jules talked about reactivity in browsers and the different methods to achieve it, starting from legacy methods, such as JQuery, to modern frameworks like Vue.js, React, Angular, Svelte, etc. He pointed out a useful resource to <a href="https://johnresig.com/apps/learn/">Learn Advanced JavaScript</a>, by John Resig, the creator of JQuery.</p><p>Jules then explained how he could leverage the Vue.js Reactivity API in non-Vue.js applications — i.e using it outside Vue.js. He showed the <a href="https://github.com/mgjules/reactivity_everywhere.js/blob/master/src/simultaneous.js">code a of Node.js CLI application</a> that he wrote to demonstrate the same.</p><p>The Vue.js website has a clear &amp; concise documentation that explains <a href="https://vuejs.org/guide/extras/reactivity-in-depth.html">Reactivity fundamentals</a>. If you want to delve further into the topic, give it a hit.</p><blockquote>At lunch time, we gathered in the mess room and we shared pizza from <a href="https://www.facebook.com/Aqua-Farina-Pizzeria-2178042812246215/">Aqua Farina</a>, which was sponsored by folks from Ringier.</blockquote><p>After lunch, we had a final presentation. It was done by Sandeep and the topic was Open Data in Mauritius. He went though a few of his pet projects for which he used data available locally from various sources — such as the <a href="https://ceb.mu/">CEB website</a>, the <a href="http://metservice.intnet.mu/">Meteorological Services website</a> and the <a href="https://data.govmu.org/dkan/">Open Data portal</a> of the Government of Mauritius.</p><p>He explained the hassle and difficulty in obtaining weather related data from the Meteorological Services of Mauritius. He shared his experience on meeting the Meteo personnel and trying to convince them to provide the data in an open format. The latter didn't seem to show any interest in such and instead told Sandeep that whatever data is available on the Meteo website, he can use for free. That entails scraping and parsing data from an HTML page.</p><p>Sandeep had to do adopt a similar approach when he built the page on <a href="https://power-outages-mauritius.netlify.app/">Power Outages in Mauritius</a>.</p><p>On the other hand, the Open Data portal provides statistical data in a more programmable way, but the hiccup is it's not always up-to-date.</p><p>Meetup ended some time past 14h00. It was a great catch-up after a very long time and I hope to see as many people or more in the next meetup.</p><figure class="kg-card kg-image-card"><img src="https://sysadmin-journal.com/content/images/2022/04/front-end-coders-meetup-april-2022.jpg" class="kg-image" alt loading="lazy" width="1200" height="674" srcset="/content/images/size/w600/2022/04/front-end-coders-meetup-april-2022.jpg 600w, /content/images/size/w1000/2022/04/front-end-coders-meetup-april-2022.jpg 1000w, /content/images/2022/04/front-end-coders-meetup-april-2022.jpg 1200w" sizes="(min-width: 720px) 720px"></figure>]]></content:encoded>
        </item>
        <item>
            <title>Hindi film « The Kashmir Files » has been rejected by the Film Classification Board of Mauritius — an appeal has been made by mCine</title>
            <link>https://sysadmin-journal.com/hindi-film-the-kashmir-files-banned-in-mauritius</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/hindi-film-the-kashmir-files-banned-in-mauritius</guid>
            <pubDate>Wed, 16 Mar 2022 12:09:08 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Censorship</category>
            <category>Mauritius</category>
            <description>The Kashmir Files is a Hindi film directed by Vivek Ranjan Agnihotri. The film&#039;s story is based on video interviews of the first generation victims of the Genocide of Kashmiri Pandit Community In 1990. Among the cast are film stars like Anupam Kher, Mithun Chakraborty, Pallavi Joshi &amp; Puneet Issar.</description>
            <content:encoded><![CDATA[<p>Hindi film « The Kashmir Files » was released in India on 11 March 2022. The movie was scheduled to release in Mauritius on Tuesday  15 March 2022 at <a href="https://www.facebook.com/mcinemauritius">mCine</a>.</p><p>My wife Shelly and I, we had planned to watch the movie on Thursday and I was supposed to buy the tickets today. However, before I phone mCine to confirm whether tickets are still available for Thursday, to my surprise I read on mCine's Facebook page that the film has been rejected by the Film Classification Board.</p><!--kg-card-begin: html--><center>
    <iframe src="https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fmcinemauritius%2Fposts%2F3481538352073030&show_text=true&width=500" width="500" height="629" style="border:none;overflow:hidden" scrolling="no" frameborder="0" allowfullscreen="true" allow="autoplay; clipboard-write; encrypted-media; picture-in-picture; web-share"></iframe>
</center><!--kg-card-end: html--><p>In another update, mCine informed that they had appealed against the rejection and the decision could be taken today (Wednesday 16 March).</p><!--kg-card-begin: html--><center>
    <iframe src="https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fmcinemauritius%2Fposts%2F3482313161995549&show_text=true&width=500" width="500" height="667" style="border:none;overflow:hidden" scrolling="no" frameborder="0" allowfullscreen="true" allow="autoplay; clipboard-write; encrypted-media; picture-in-picture; web-share"></iframe>
</center><!--kg-card-end: html--><p>At the time of writing this blog post, no further update was published by mCine and <a href="https://www.imdb.com/title/tt10811166/">The Kashmir Files</a> remains banned in Mauritius.</p><p>I wanted to know more about the Film Classification Board and its members. More precisely, I wanted to know the reasons behind the banning of this movie. However, on the <a href="https://culture.govmu.org/Pages/Department/Fcb.aspx">website</a> of the Ministry of Arts and Culture Heritage, the names of the Board members are not available. I could only find the email and phone number of the Assistant Secretary, Mr. Ajay Hooloomann. Therefore, I sent Mr. Hooloomann a <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2022/03/6783.html">request for information</a> to obtain the list of members on the Film Classification Board and members of the Film Classification Consultative Panels.</p><p>I haven't received any reply yet.</p><p>Nevertheless, in a <a href="https://gazettes.africa/archive/mu/2019/mu-government-gazette-dated-2019-01-12-no-4.pdf">Government Gazette of 2019</a>, I found the list of members on the Film Classification Board. This list contains 41 Deputy Chairpersons and 99 Board members.</p><p>Grateful to someone on Facebook who pointed me to the publication of this list in the Government Gazette.</p><h2 id="update-%E2%80%93-16-march-2021-2124">Update – 16 March 2021 21:24</h2><p>About half an hour ago, MCine has posted on its Facebook page that « The Kashmir Files » has been awarded VISA 18. The film will play in MCine cinema halls as from tomorrow. Strict sanitary protocols to be observed.</p><!--kg-card-begin: html--><center>
    <iframe src="https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fmcinemauritius%2Fposts%2F3483226021904263&show_text=true&width=500" width="500" height="787" style="border:none;overflow:hidden" scrolling="no" frameborder="0" allowfullscreen="true" allow="autoplay; clipboard-write; encrypted-media; picture-in-picture; web-share"></iframe>
</center><!--kg-card-end: html-->]]></content:encoded>
        </item>
        <item>
            <title>My thoughts on the Cybersecurity and Cybercrime Bill</title>
            <link>https://sysadmin-journal.com/thoughts-on-the-cybersecurity-and-cybercrime-bill</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/thoughts-on-the-cybersecurity-and-cybercrime-bill</guid>
            <pubDate>Sun, 31 Oct 2021 13:06:51 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Legislation</category>
            <category>Mauritius</category>
            <category>Cybercrime</category>
            <category>Cybersecurity</category>
            <description>TL;DR — Downloading movies, music and pirated software becomes a crime under this Bill. Failing to moderate online content will also become a crime. Service providers can be compelled to provide access to data and forced not disclose anything. Want to know more then read on!</description>
            <media:content url="https://images.unsplash.com/photo-1589829545856-d10d557cf95f?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwxMTc3M3wwfDF8c2VhcmNofDJ8fGxlZ2FsfGVufDB8fHx8MTYzNTY4MTk0OQ&amp;ixlib=rb-1.2.1&amp;q=80&amp;w=2000" medium="image" />
            <content:encoded><![CDATA[<p>This <a href="https://mauritiusassembly.govmu.org/Documents/Bills/intro/2021/bill1521.pdf">Cybersecurity and Cybercrime Bill</a> was presented to the National Assembly on the 22nd October 2021. It is meant to replace the current <a href="https://www.icta.mu/docs/laws/cyber.pdf">Computer Misuse and Cybercrime Act</a> that dates 2003.</p><p>A few people asked me about my opinion on the Bill and it is only today that I read the document and I share a few things that I found pertinent about the Bill.</p><p>At the beginning of the document, the Budapest Convention on Cybercrime is mentioned and the Bill is said to increase compliance with the same through additional criminal offences related to cybercrime and cybersecurity, <strong>improved investigation techniques</strong> and increased international cooperation.</p><blockquote>I don't see any improved investigation technique in this document. There does not seem anything that will drastically reduce the time to solve a cybercrime.</blockquote><p>Anything related to Mutual Assistance, obtaining data from service providers etc, was already possible under current legislation. This Bill will probably reduce the paperwork if there is a will for that but not improve the investigation technique.</p><h2 id="what-is-the-budapest-convention-on-cybercrime">What is the Budapest Convention on Cybercrime?</h2><p>It is the first international treaty that aims to harmonize laws on cybercrime and cybersecurity and increase cooperation among countries. It was initiated by the Council of Europe and opened for signature in November 2001. In two decades, 66 countries have acceded to the convention. Mauritius acceded to the convention in November 2013.</p><p>The convention provides a guideline to countries for implementing a legislation against cybercrime. The <a href="https://rm.coe.int/1680081561">full guideline</a> is available on the website of the Council of Europe. Some of the main articles of the guideline are (I refer to their article number):</p><p>Article 1 — Definitions<br>Article 2 — Illegal access<br>Article 3 — Illegal interception<br>Article 4 — Data Interference<br>Article 5 — System Interference<br>Article 6 — Misuse of devices<br>Article 7 — Computer-related forgery<br>Article 8 — Computer-related fraud<br>Article 9 — Offences related to child pornography<br>Article 10 — Offences related to infringements of copyright and related rights<br>Article 15 — Conditions and safeguards<br>Article 19 — Search and seizure of stored computer data<br>Article 20 — Real-time collection of traffic data<br>Article 21 — Interception of content data<br>Article 25 — General principles relating to mutual assistance</p><p><strong>The guideline highlights the importance of safeguards and the protection of human rights &amp; liberties in Article 15.</strong></p><h2 id="current-cybercrime-legislation">Current Cybercrime legislation</h2><p>The <a href="https://www.icta.mu/docs/laws/cyber.pdf">Computer Misuse and Cybercrime Act</a> came into force in 2003. Although, Mauritius hadn't yet acceded to the Budapest Convention on Cybercrime, the legislation had some provisions as stated in the Convention guideline.</p><h2 id="whats-new-in-the-cybersecurity-and-cybercrime-bill">What's new in the Cybersecurity and Cybercrime Bill?</h2><h3 id="new-terms-in-the-glossary-of-offences">New terms in the glossary of offences</h3><p>There are a few new definitions of terms that have been added in this Bill, especially to describe the new offences. Among them are the terms:</p><p><strong>Cyberbullying</strong></p><p>It has been defined as any behaviour by means of information and communication technologies which is repetitive, persistent and intentionally harmful or involves an imbalance of power between the perpetrator and the victim and causes feelings of distress, fear, loneliness or lack of confidence in the victim.</p><p><strong>Cyber extortion</strong></p><p>It means a form of cybercrime which occurs when a person uses the internet to demand money or other goods or behaviour from another person by threatening to inflict harm to his person, reputation, or property.</p><p><strong>Fake profile</strong></p><p>An untrue online representation, existent or or non-existent.</p><p><strong>Harm</strong></p><p>It includes physical, sexual, psychological, emotional or moral abuse, injury, neglect, ill-treatment, degradation, discrimination, exploitation or impairment of health or development.</p><p><strong>Pornography</strong></p><p>The representation in a book, magazine, photograph, film, computer data or any such other media, a scene of sexual behaviour in any form, that is erotic or lewd and is designed to arouse sexual interest.</p><p><strong>Sexual photograph or film</strong></p><p>An image or video that depicts nudity or a picture of someone who is engaged in sexual behaviour or posing in a sexually provocative way.</p><h3 id="offences">Offences</h3><p><strong>Misuse of fake profile</strong></p><p>Any person who individually, or with other persons, makes use of a fake profile to cause harm shall commit an offence. The penalty can be upto a million rupees fine or a maximum of 20 years imprisonment.</p><p><strong>Cyberbullying</strong></p><p>Any person who individually, or with other persons, commits cyberbullying, shall commit an offence. The penalty is again, upto a million rupees fine or a maximum of 20 years imprisonment.</p><p>Same penalty is mentioned for offences of <strong>cyber extorsion, cyberterrorism</strong> and <strong>revenge pornography</strong>.</p><p>How these new offences will help deter cybercrime or facilitate the task law enforcement, only time will reveal. In my opinion, new offences won't be of much help if the attitude of cybercrime officers remains the same. Not even a thousand new definitions will help if the officers do not improve their investigation techniques and become accountable.</p><p>In 2018 when the ICT Act was amended the then Attorney General, M. Gobin, used the same tune about social media to convince people on how useful the amendment will be to help in cases of <a href="http://www.govmu.org/English/News/Pages/ICT-Act-amended-to-regulate-and-curtail-harmful-and-illegal-contents-and-activities.aspx">online threats such as harassment, sextortion and cyber-bullying</a>. He participated in radio &amp; televised debates (on MBC) and at the University of Mauritius. However, since the amendments were made to the ICT Act, we've seen how poeple voicing out against the government are questioned and/or detained for breach of the ICT Act.</p><h2 id="copyright-protection">Copyright protection</h2><h3 id="downloading-pirated-software-movies-and-music">Downloading pirated software, movies and music</h3><p>Section 21 of the Bill mentions infringement of copyright and related rights. This section makes the <strong>download</strong> of music, movies and pirated software a criminal offence liable to upto one million rupees fine or 10 years of imprisonment.</p><h2 id="critical-information-infrastructure-increased-penalty">Critical Information Infrastructure &amp; increased penalty</h2><p>This Bill introduces a definition for Critical Information Infrastructure. The National Cybersecurity Committee will be tasked to select the Critical Information Infrastructures in Mauritius. A system providing life sustaining services (e.g water, health or energy), or has an important effect on the economy, or its disruption could result in massive casualties, will be called a Critical Information Infrastructure.</p><p>The penalty for a cybercrime related to a Critical Information Infrastructure is twice the fine for other crimes described in the Bill, i.e upto Rs 2 million and a maximum of 25 years imprisonment.</p><h2 id="failure-to-moderate-content">Failure to moderate content</h2><p>The failure to moderate content on a webpage, social media page or any other online platform, after having received a notice from an investigatory authority, will be a crime.</p><h2 id="compelling-service-providers-to-provide-access-to-store-data-or-collect-real-time-data">Compelling service providers to provide access to store data or collect real-time data</h2><p>If this Bill is passed, an investigatory authority upon issuance of a Judge's Order, may compel a service provider to provide access to stored data or record real-time traffic data, within its technical capabilities. Any disclosure of the investigation by the service provider will be considered a crime.</p><p>A example of traffic data is the history of your everyday websites and online platforms that you visit, including your mobile internet traffic, phone calls, SMS, etc.</p><p>A example of stored data is your email content if your email is hosted by the service provider. If your service provider is in Mauritius and the email service is hosted outside Mauritius, then irrespectively the service provider will be compelled to provide access to the emails.</p><h2 id="the-national-cybersecurity-committee">The National Cybersecurity Committee</h2><p>The Bill introduces a National Cybersecurity Committee. This committee will be composed of fourteen members including a Chairperson that will be appointed by the Prime Minister. A person from the private sector and another from the civil society will be on this committee and both of them will be appointed by the Minister of Technology, Communication and Innovation. Both persons should have experience in the field of cybersecurity and cybercrime.</p><p><strong>All members of the committee will be remunerated.</strong></p><p>The committee may call upon people who can be of assistance but those persons won't draw any remuneration nor have any voting right at the committee's meetings.</p><p>The composition of the committee seems to be tightly controlled by the minister and the committee will operate in complete opacity, although their decisions will impact everyone who use the Internet and other technological services.</p><h2 id="the-computer-emergency-and-response-team-cert-mu">The Computer Emergency and Response Team (CERT-MU)</h2><p>The CERT-MU is mentioned in Section 38. I read and ignored. In my opinion, the CERT-MU acts like a poster for the government to say that they do cybersecurity stuff. I have plenty of un-answered emails in which I questioned CERT-MU on cybersecurity matters. I believe CERT-MU will have to up the game and be more responsive to people irrespective of their religion, caste, color, political background, bank balance, social status, etc.</p><h2 id="will-the-possession-of-certain-software-be-criminalised">Will the possession of certain software be criminalised?</h2><p>Lastly, Section 13 of the Bill states that any person who intentionally procures for use, a computer system or any other device, designed or adapted primarily for the purpose of committing an offence under the Act shall commit an offence.</p><p>Let's take a deep breath. Is this bill going to make Tor, Wireshark, tcpdump, Linux distributions, and tons of other operating systems and software, become tools likely for the purpose of committing an offence?</p><p>I quote an officer of the Cybercrime Unit who once stood in front of the magistrate and said:</p><blockquote>Investigation has also revealed that Applicant is the head or the king pin of a network, well established network [...] Applicant is himself an IT Specialist with mastery of more than three operating systems, Linux is one of them.</blockquote><p>With this kind of mentality where the knowledge of an operating system can make you a prime suspect, imagine the havoc or damage that the officers might cause if they find you in possession of network pentesting tools.</p><p>A new legislation with the same understaffed, underskilled and underpaid division will not produce results.</p>]]></content:encoded>
        </item>
        <item>
            <title>CERT-MU issues Security Alert against Netflix&#039;s Squid Game</title>
            <link>https://sysadmin-journal.com/cert-mu-issues-security-alert-against-netflix-squid-game</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/cert-mu-issues-security-alert-against-netflix-squid-game</guid>
            <pubDate>Sun, 17 Oct 2021 06:39:21 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <description>The Computer Emergency Response Team of Mauritius (CERT-MU) which operates under the patronage of the National Computer Board issued a security alert against the Netflix series Squid Game on 14 October 2021.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/10/netflix-series-squid-game.jpg" medium="image" />
            <content:encoded><![CDATA[<p>Squid Game was released on 17 September 2021. It was immediately available on the Netflix platform globally. Anyone with a Netflix subscription could watch or binge the 9-episodes series on a computer, a mobile or a smart television.</p><p>Squid Game is a Korean drama based on survival in a deadly game played by characters who are deeply in debt. Its writer and director Hwang Dong-hyuk, said that the story reflects his own economic struggles and the class disparity in South Korea.</p><p>Within its first week since launch, Squid Game became one of Netflix's most watched series crossing the bar of 100 million viewers. Its popularity even led to a surge in the network traffic in South Korea, prompting <a href="https://www.reuters.com/business/media-telecom/skorea-broadband-firm-sues-netflix-after-traffic-surge-squid-game-2021-10-01/">SK Boardband to file a lawsuit against Netflix</a> and claim monetary damages for the increased network traffic and maintenance work caused by the surge.</p><h2 id="security-alert">Security Alert</h2><figure class="kg-card kg-image-card"><img src="https://sysadmin-journal.com/content/images/2021/10/cert-mu-squid-game-1.png" class="kg-image" alt loading="lazy" width="758" height="336" srcset="/content/images/size/w600/2021/10/cert-mu-squid-game-1.png 600w, /content/images/2021/10/cert-mu-squid-game-1.png 758w" sizes="(min-width: 720px) 720px"></figure><p>The <a href="https://cert-mu.govmu.org/Communique/Security%20Alert%20-%20SQUID%20GAME.pdf">CERT-MU Security Alert</a> explains that although the series is rated 15+ it has scenes depicting excessive violence, nudity, self-harm, suicide, sexual violence, horror and torture. The amount of killing is horrific and the methods are awful. It further adds that the scenes are dangerous and can have a negative impact on children and young people.</p><p>CERT-MU warns parents to be vigilant as children and young teens may be tempted to repeat the scenes from the series. It strongly recommends to apply parental controls and to closely supervise children when they are online.</p><p>I didn't watch Squid Games and probably I won't any time soon.</p>]]></content:encoded>
        </item>
        <item>
            <title>More than 100 new COVID-19 cases in one day</title>
            <link>https://sysadmin-journal.com/more-than-100-new-covid-19-cases-in-one-day</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/more-than-100-new-covid-19-cases-in-one-day</guid>
            <pubDate>Thu, 15 Jul 2021 21:22:28 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>COVID-19</category>
            <category>Mauritius</category>
            <description>Mauritius sets new record of new COVID-19 cases. The country re-opened its borders on 15 July 2021. On the same day the number of new local cases of COVID-19 rose to an unprecedented peak and the country recorded one unfortunate COVID-19 related death.</description>
            <content:encoded><![CDATA[<p>Mauritius has recorded perhaps the highest number of new COVID-19 cases in just one day so far. The number is at 123.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2021/07/lexpress-covid-19-counter.png" class="kg-image" alt="l'express COVID-19 counter" loading="lazy" width="1219" height="139" srcset="/content/images/size/w600/2021/07/lexpress-covid-19-counter.png 600w, /content/images/size/w1000/2021/07/lexpress-covid-19-counter.png 1000w, /content/images/2021/07/lexpress-covid-19-counter.png 1219w" sizes="(min-width: 720px) 720px"><figcaption>l'express COVID-19 counter</figcaption></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2021/07/lemauricien-covid-19-counter.png" class="kg-image" alt loading="lazy" width="325" height="323"><figcaption>Le Mauricien COVID-19 counter</figcaption></figure><p>The COVID-19 counters on <a href="https://lexpress.mu">lexpress.mu</a> and <a href="lemauricien.com">lemauricien.mu</a> indicated this new record after their evening update on 15 July 2021.</p>]]></content:encoded>
        </item>
        <item>
            <title>COVID-19 vaccine Sputnik V available in Mauritius</title>
            <link>https://sysadmin-journal.com/covid-19-vaccine-sputnik-v-available-in-mauritius</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/covid-19-vaccine-sputnik-v-available-in-mauritius</guid>
            <pubDate>Wed, 14 Jul 2021 13:53:58 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>COVID-19</category>
            <category>Mauritius</category>
            <description>The Ministry of Health has started administering the first dose of the Sputnik V vaccine as part of its campaign against COVID-19 in Mauritius.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/07/Sputnik-V.jpg" medium="image" />
            <content:encoded><![CDATA[<p>Since Monday 12 July 2021, the COVID-19 vaccine Sputnik V is available in Mauritius and its first dose is being administered by the Ministry of Health officials at the Central Warehouse in Castel, between 09h00 to 15h00.</p><p>Early information about the availability of the Sputnik V seemed to be poor, which led to many people flocking to Castel, in the hope of getting vaccinated. I checked the <a href="https://gis.govmu.org/Pages/Newsroom/Covid-19.aspx">Government Information System</a> and there has not been any communique about who is eligible for the Sputnik V vaccine.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2021/07/gis-july-2021.png" class="kg-image" alt="Website of the Government Information Service" loading="lazy" width="1402" height="848" srcset="/content/images/size/w600/2021/07/gis-july-2021.png 600w, /content/images/size/w1000/2021/07/gis-july-2021.png 1000w, /content/images/2021/07/gis-july-2021.png 1402w" sizes="(min-width: 720px) 720px"><figcaption>Website of the Government Information Service</figcaption></figure><p>The last communique published by GIS dates 10 July 2021.</p><p>Meanwhile, people have been queuing up at the Central Warehouse in Castel since as early as 7:00 a.m. Later on they were by the officers that only senior citizens, front-liners and employees of certain economic sectors registered though the Economic Development Board (EDB) would get access to the vaccination centre.</p><!--kg-card-begin: html--><center>
    <blockquote class="twitter-tweet"><p lang="ht" dir="ltr">Ouiii zis 60+ avek ceki ine register avek EDB par contre ena enn tas ceki ni 60+ ni ena message EDB ine fini rentrer!! <br><br>Dimounes p extra encoler ici!!<a href="https://twitter.com/oummesakina?ref_src=twsrc%5Etfw">@oummesakina</a></p>&mdash; ✨Étoile Brillante✨🇲🇺 (@harsha1912) <a href="https://twitter.com/harsha1912/status/1415177186860961794?ref_src=twsrc%5Etfw">July 14, 2021</a></blockquote> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
</center><!--kg-card-end: html--><h2 id="update">Update</h2><ul><li>15 July 2021<br>Following a « cafouillage » at the Central Warehouse, Castel, vaccination centre, the Ministry of Health enforced the rule that only a selection of personnel from specific industries in Mauritius will be able to get vaccinated at Castel. The personnel should already be registered with the Economic Board of Development.<br>- Teaching and Non-teaching staff;<br>- Personnel of the Tourism and Travel Sector;<br>- Personnel of the ATOL / AML;<br>- Personnel of the Air Mauritius;<br>- Personnel of the Mauritius Port Authority;<br>- Personnel of the Economic Sector.<br><br>The <a href="https://www.lexpress.mu/article/396709/spoutnik-v-cafouillage-au-centre-vaccination-castel-vaccin-ne-fait-pas-au-choix">press communique </a>was issued on the 14th July 2021.</li></ul>]]></content:encoded>
        </item>
        <item>
            <title>ICTA says it will summarize the comments &amp; suggestions, can we trust?</title>
            <link>https://sysadmin-journal.com/icta-says-it-will-summarize-the-comments-suggestions-can-we-trust</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/icta-says-it-will-summarize-the-comments-suggestions-can-we-trust</guid>
            <pubDate>Mon, 31 May 2021 03:41:42 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>In its latest press communique, the Information and Communication Technologies Authority, displayed a cheap tactic of manipulating public opinion, by publishing only a selection of paragraphs from Facebook&#039;s submission to show them in the good light.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/05/lie-detector-test-1.jpg" medium="image" />
            <content:encoded><![CDATA[<p>On the 21<sup>st</sup> May 2021, the Information and and Communication Technologies Authority (ICTA) issued a <a href="https://www.icta.mu/documents/2021/ICTA_Communique.pdf">communique</a><sup>1</sup> to mark the end of the comments submission to their <a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">consultation paper</a><sup>2</sup> on proposed amendments to the ICT Act for regulating the use and addressing the abuse and misuse of Social Media in Mauritius.</p><p>In the communique, ICTA expressed satisfaction on the debate that the consultation paper generated. The Officer-in-Charge of ICTA, Jérôme Louis, is quoted as saying that ICTA will publish a document summarizing the comments and suggestions.</p><blockquote><em>Nous allons synthétiser les réponses, et publierons sous peu un document résumant les suggestions et commentaires », indique Jérôme Louis, Officer-in-Charge de l'ICTA.</em></blockquote><h2 id="what-can-go-wrong"><strong>What can go wrong?</strong></h2><p>The communique itself gives an inkling on what can go wrong. ICTA mentioned in the communique that Facebook responded to the consultation paper on the 20<sup>th</sup> of May 2021. ICTA said that if both parties come to an agreement then there will be no need for a tool to decrypt Facebook traffic.</p><p>ICTA selectively quoted three paragraphs from the Facebook’s submission, from which one may be led to believe that Facebook is commending ICTA’s efforts, welcoming the regulation and providing full support to ICTA.</p><p>It didn’t make sense to many people who read the communique that a proposal which a few days earlier Google and Mozilla were highly critical about, now Facebook is supporting the same.</p><p>I <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6768.html">wrote to Jérôme Louis</a><sup>3</sup> on the 22<sup>nd</sup> May 2021, asking him whether for transparency sake ICTA could publish the full response received from Facebook. I also copied the Manager of Communications and Consumer Affairs at ICTA, Meera Vayapooree, but none of them replied.</p><h2 id="how-did-%C2%AB-we-%C2%BB-get-the-response-from-facebook"><strong>How did « we » get the response from Facebook?</strong></h2><p>On the 20<sup>th</sup> of May, before ICTA informs the public that they received Facebook’s comments, a colleague of mine, <a href="https://twitter.com/chitteshBMsham">Chittesh Sham</a><sup>4</sup> wrote to Facebook, telling them that there has been zero response from Facebook so far and questioned them on their indifference to the local authority's attempt to break the chain of trust between Facebook and its users in Mauritius.</p><p>Chittesh <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6765.html">received a reply</a><sup>5</sup> the next morning from Kezia Anim-Addo, the Head of Communications, Facebook Sub-Saharan Africa, who looped in two of her colleagues, mentioning that they might have been already in touch. Chittesh clarified that this is his first attempt to contact Facebook and highlighted the importance again for the organization to react on this matter.</p><p>On the 25<sup>th</sup> of May 2021, Chittesh wrote to Facebook requesting them for an update, informed them about ICTA's brief publication of Facebook's submission and asked whether they could publish the comments that they sent to ICTA. Facebook replied with their <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html">submission attached</a><sup>6</sup>.</p><figure class="kg-card kg-image-card kg-width-wide"><img src="https://sysadmin-journal.com/content/images/2021/05/facebook-email-reply-chittesh-sham.png" class="kg-image" alt="Facebook's reply on the Mauritius Internet Users list" loading="lazy" width="1218" height="836" srcset="/content/images/size/w600/2021/05/facebook-email-reply-chittesh-sham.png 600w, /content/images/size/w1000/2021/05/facebook-email-reply-chittesh-sham.png 1000w, /content/images/2021/05/facebook-email-reply-chittesh-sham.png 1218w" sizes="(min-width: 1200px) 1200px"></figure><p>Thanks to the Mauritius Internet Users mailing list &amp; its public archive, we have a <a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html">record of these communications</a><sup>7</sup> for reference.</p><h2 id="conclusion"><strong>Conclusion</strong></h2><p>If Google and Mozilla or the 50 international organizations who criticized ICTA’s proposal didn’t make their statements public then ICTA could have easily led Mauritians to believe that tech companies and international organizations are agreeing with their proposal.</p><p>A cheap display of manipulating public opinion was clear in ICTA’s latest communique.</p><p>Based on these recent events and knowing the political climate, how political nominees act like dolls on boards, it is difficult to trust ICTA being capable of showing impartiality and producing a concise summary of comments &amp; suggestions that they received during the public consultation exercise.</p><p><strong>I will write a separate blog post on what Facebook meant in its 12 pages submission to ICTA.</strong></p><p><em>Cover photo by <a href="https://unsplash.com/@ashkfor121?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Ashkan Forouzani</a> on <a href="https://unsplash.com/s/photos/lie?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a>.</em></p><ol><li><a href="https://www.icta.mu/documents/2021/ICTA_Communique.pdf">https://www.icta.mu/documents/2021/ICTA_Communique.pdf</a></li><li><a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf</a></li><li><a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6768.html">http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6768.html</a></li><li><a href="https://twitter.com/chitteshBMsham">https://twitter.com/chitteshBMsham</a></li><li><a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6765.html">http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6765.html</a></li><li><a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html">http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html</a></li><li><a href="http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html">http://lists.elandnews.com/archive/mauritius/internet-users/2021/05/6773.html</a></li></ol>]]></content:encoded>
        </item>
        <item>
            <title>Proof-of-concept proxy shows user account passwords and private photos can be decrypted</title>
            <link>https://sysadmin-journal.com/proof-of-concept-proxy-shows-user-account-passwords-and-private-photos-can-be-decrypted</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/proof-of-concept-proxy-shows-user-account-passwords-and-private-photos-can-be-decrypted</guid>
            <pubDate>Wed, 19 May 2021 16:59:46 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Cybersecurity</category>
            <description>A proof-of-concept proxy using Fiddler Everywhere shows that user account passwords from websites like Twitter, LinkedIn, Gmail Hotmail and private photos from Facebook, Messenger and Instagram can be decrypted.</description>
            <content:encoded><![CDATA[<p>Since the publication of ICTA’s <a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">consultation paper</a><sup>1</sup> on proposed amendments to the ICT Act in order to regulate social media, there has been an outcry and a lot of criticism on the measures proposed. Professionals from the ICT industry have raised alarms over the security risks that the proposed technical framework will give rise to. Legal professionals and civil society activists have expressed that the measures are radically dis-proportionate to the problems stated. The proposed measures will heavily affect the individual’s privacy rights.</p><p>ICTA issued several <a href="https://www.icta.mu/mediaoffice/news2021.htm">communiques</a><sup>2</sup> in an attempt to dispel fear and doubt surrounding their proposal. However, those communiques repeatedly stressed only public posts on Facebook will be filtered and decrypted.</p><p>For example, in a recent <a href="https://www.icta.mu/ICTA_Socialmedia.mp4">video</a><sup>3</sup> published on ICTA’s website, at 2m3s, they say that ICTA won’t get user password, log in, email, private messages, bank details etc.</p><p>In this report, I explain how a proof-of-concept proxy was used to demonstrate the capabilities of the technical framework proposed in Section 11.2 of the consultation paper.</p><p><em><strong>Disclaimer:</strong></em><br><em><strong>The purpose of this report is purely educational and written to demonstrate a specific context. Any misuse of the knowledge of the software or technique described in this report cannot be held against the author, i.e Ish Sookun. If you continue to read, you acknowledge having read this disclaimer.</strong></em></p><h2 id="ictas-proposed-technical-framework">ICTA's Proposed  Technical Framework</h2><p>These three steps are the most important ones that are mentioned in Section 11.2 of the consultation paper and my proof-of-concept will focus on these steps only.</p><ol><li>install a Certification Authority (CA) root certificate in web browser,</li><li>route requests for facebook.com to a proxy server,</li><li>decrypt the HTTPS requests.</li></ol><h2 id="software-technique"><strong>Software &amp; Technique</strong></h2><p>I used <a href="https://docs.telerik.com/fiddler-everywhere/introduction">Fiddler Everywhere</a><sup>4</sup> v1.6.0, <a href="https://www.mozilla.org/en-US/firefox/88.0/releasenotes/">Mozilla Firefox</a><sup>5</sup>, <a href="https://discourse.ubuntu.com/t/hirsute-hippo-release-notes/19221">Ubuntu 21.04</a><sup>6</sup> and a My.T Internet connection.</p><p>Fiddler generated a CA Root certificate which was added to the certificate store of Firefox. Then, Firefox was configured to use the Fiddler proxy.</p><p>All web requests, i.e HTTP and HTTPS requests, were intercepted by the proxy. HTTPS requests to and from different websites were decrypted in real-time.</p><p>I used my own Facebook, Messenger, Instagram, Twitter, LinkedIn, Gmail and Hotmail accounts in this experiment.</p><h2 id="results">Results</h2><p>I sent the photo of a lazy panda to my wife on Facebook to see whether this private message will be decrypted by the proxy.</p><figure class="kg-card kg-image-card"><img src="https://sysadmin-journal.com/content/images/2021/05/facebook-message-test.png" class="kg-image" alt loading="lazy" width="433" height="460"></figure><p>Yes, the private message was decrypted by the Fiddler proxy and the photo appeared exactly as I sent.</p><figure class="kg-card kg-image-card"><img src="https://sysadmin-journal.com/content/images/2021/05/facebook-private-message-decrypted.png" class="kg-image" alt loading="lazy" width="549" height="613"></figure><p>Next, I tested messenger.com and the first thing I noted was that the proxy decrypted my login and password.</p><figure class="kg-card kg-image-card kg-width-wide"><img src="https://sysadmin-journal.com/content/images/2021/05/messenger-login-password.jpg" class="kg-image" alt loading="lazy" width="1318" height="741" srcset="/content/images/size/w600/2021/05/messenger-login-password.jpg 600w, /content/images/size/w1000/2021/05/messenger-login-password.jpg 1000w, /content/images/2021/05/messenger-login-password.jpg 1318w" sizes="(min-width: 1200px) 1200px"></figure><figure class="kg-card kg-image-card kg-width-full"><img src="https://sysadmin-journal.com/content/images/2021/05/messenger-password-cleartext.png" class="kg-image" alt loading="lazy" width="1318" height="741" srcset="/content/images/size/w600/2021/05/messenger-password-cleartext.png 600w, /content/images/size/w1000/2021/05/messenger-password-cleartext.png 1000w, /content/images/2021/05/messenger-password-cleartext.png 1318w"></figure><p>The email field contained the login. Both login and password were exactly what I typed in the login page of messenger.com. I blurred the fields in the screenshot for obvious reasons.</p><p>I tested Instagram to see whether a picture that my wife sent me would be decrypted the same way the proxy did for the Facebook private message.</p><figure class="kg-card kg-image-card kg-width-wide"><img src="https://sysadmin-journal.com/content/images/2021/05/instagram-private-message.jpg" class="kg-image" alt loading="lazy" width="1318" height="741" srcset="/content/images/size/w600/2021/05/instagram-private-message.jpg 600w, /content/images/size/w1000/2021/05/instagram-private-message.jpg 1000w, /content/images/2021/05/instagram-private-message.jpg 1318w" sizes="(min-width: 1200px) 1200px"></figure><figure class="kg-card kg-image-card kg-width-wide"><img src="https://sysadmin-journal.com/content/images/2021/05/instagram-private-message-decrypted.jpg" class="kg-image" alt loading="lazy" width="1318" height="741" srcset="/content/images/size/w600/2021/05/instagram-private-message-decrypted.jpg 600w, /content/images/size/w1000/2021/05/instagram-private-message-decrypted.jpg 1000w, /content/images/2021/05/instagram-private-message-decrypted.jpg 1318w" sizes="(min-width: 1200px) 1200px"></figure><p>Yes, the picture of the adorable Quokka was decrypted by the proxy, as you may see in the above screenshot.</p><p>I tested Twitter and I could see my login, password and direct messages in clear text.</p><figure class="kg-card kg-image-card kg-width-wide kg-card-hascaption"><img src="https://sysadmin-journal.com/content/images/2021/05/twitterl-dm-decrypted.png" class="kg-image" alt loading="lazy" width="1318" height="741" srcset="/content/images/size/w600/2021/05/twitterl-dm-decrypted.png 600w, /content/images/size/w1000/2021/05/twitterl-dm-decrypted.png 1000w, /content/images/2021/05/twitterl-dm-decrypted.png 1318w" sizes="(min-width: 1200px) 1200px"><figcaption>Twitter DM decrypted by the proxy</figcaption></figure><p>Lastly I tested Gmail, Hotmail and LinkedIn. The login and password of all three platforms appear in clear text.</p><p>You will notice that Firefox never prompted me about any untrusted connection while the proxy decrypted the HTTPS traffic.</p><figure class="kg-card kg-image-card"><img src="https://sysadmin-journal.com/content/images/2021/05/mozilla-firefox-fiddler-self-signed-certificate.jpg" class="kg-image" alt loading="lazy" width="742" height="432" srcset="/content/images/size/w600/2021/05/mozilla-firefox-fiddler-self-signed-certificate.jpg 600w, /content/images/2021/05/mozilla-firefox-fiddler-self-signed-certificate.jpg 742w" sizes="(min-width: 720px) 720px"></figure><p>See above, the padlock will give you the impression that the website is genuine and it can be trusted. However, the certificate is issued by Fiddler and signed with "DO_NOT_TRUST_BC".</p><p>Facebook.com is signed by DigiCert and not DO_NOT_TRUST_BC.</p><p>Lastly, without decryption there is no way to identify what content the user is accessing on Facebook because all traffic will appear as <code>facebook.com:443</code>.</p><figure class="kg-card kg-image-card kg-width-full"><img src="https://sysadmin-journal.com/content/images/2021/05/facebook-wo-https-decrypt-1.png" class="kg-image" alt loading="lazy" width="1318" height="741" srcset="/content/images/size/w600/2021/05/facebook-wo-https-decrypt-1.png 600w, /content/images/size/w1000/2021/05/facebook-wo-https-decrypt-1.png 1000w, /content/images/2021/05/facebook-wo-https-decrypt-1.png 1318w"></figure><p>As seen above, all Facebook traffic end with <code>:443</code> because the complete URL is encrypted. There is no means to know where does <code>facebook.com:443</code> lead to, whether it leads to <code>facebook.com/public-post</code> or <code>facebook.com/private-content</code>. To obtain the URL information, the entire Facebook traffic will have to be decrypted. This means decrypting login, passwords, public posts and private messages in the process.</p><p>Login details, passwords and content sent via private messages can be decrypted by a proxy that is trusted by the web browser. At no point the browser will notify that the website being visited is being proxied and decrypted.</p><p>Therefore, if someone starts with decrypting facebook.com today and tomorrow decides to start decrypting gmail.com, the Internet user will not know that this is happening.</p><blockquote>Credits to S. Moonesamy for mentioning a proof-of-concept proxy in his <a href="http://www.elandsys.com/~sm/slides/unsafe-web-browsing-mauritius.html">slide decks</a><sup>7</sup> on Unsafe Web Browsing in Mauritius.</blockquote><blockquote>Cover photo by <a href="https://unsplash.com/@etiennegirardet?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Etienne Girardet</a> on <a href="https://unsplash.com/s/photos/surveillance?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a>.</blockquote><ol><li><a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf</a></li><li><a href="https://www.icta.mu/mediaoffice/news2021.htm">https://www.icta.mu/mediaoffice/news2021.htm</a></li><li><a href="https://www.icta.mu/ICTA_Socialmedia.mp4">https://www.icta.mu/ICTA_Socialmedia.mp4</a></li><li><a href="https://docs.telerik.com/fiddler-everywhere/introduction">https://docs.telerik.com/fiddler-everywhere/introduction</a></li><li><a href="https://www.mozilla.org/en-US/firefox/88.0/releasenotes/">https://www.mozilla.org/en-US/firefox/88.0/releasenotes/</a></li><li><a href="https://discourse.ubuntu.com/t/hirsute-hippo-release-notes/19221">https://discourse.ubuntu.com/t/hirsute-hippo-release-notes/19221</a></li><li><a href="http://www.elandsys.com/~sm/slides/unsafe-web-browsing-mauritius.html">http://www.elandsys.com/~sm/slides/unsafe-web-browsing-mauritius.html</a></li></ol>]]></content:encoded>
        </item>
        <item>
            <title>Internet Society and Mauritius IGF react to ICTA&#039;s consultation paper</title>
            <link>https://sysadmin-journal.com/internet-society-and-mauritius-igf-react-to-icta-consultation-paper</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/internet-society-and-mauritius-igf-react-to-icta-consultation-paper</guid>
            <pubDate>Wed, 19 May 2021 06:27:33 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>Mauritius IGF and Internet Society respond to ICTA&#039;s consultation paper.</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/05/mahen-busgopaul-mauritius-igf.jpg" medium="image" />
            <content:encoded><![CDATA[<p>At last, the Internet Society and Mauritius IGF published their <a href="https://drive.google.com/file/d/1XlGmzzdV3P6wSmoBPWcBYhq4txez12ps/view?usp=sharing">response</a><sup>1</sup> to the <a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">ICTA consultation paper</a><sup>2</sup> on regulating social media. I was hoping that Mauritian NGOs would react faster and in a more collaborative way but nevertheless this response is welcomed.</p><p>It was easier for me to get in touch with Access Now, Article 19 and the Electronic Frontier Foundation and get a response from them.</p><p><em>Disclaimer: I admit I didn’t reach out to Mahen Busgopaul, whom I have met during past events. However, I <a href="https://atlarge-lists.icann.org/pipermail/afri-discuss/2021-May/007093.html">reached out</a><sup>3</sup> to Dave Kissoondoyal, who signed an email to ICANN as the President of IGF Mauritius, but I didn’t receive any response.</em></p><p>Ramblings aside, let’s come to gratitude.</p><p>The Mauritius IGF and ISOC’s response is signed jointly by Mahendranath Busgopaul, as the Director of Mauritius IGF and Olaf Kolkman as the Principal - Internet Technology, Policy and Advocacy at the Internet Society.</p><p>I am grateful to both of them for the response they submitted to the Information and Communication Technologies Authority, which they also released publicly.</p><p>In their summary, they highlighted the importance of encryption for both personal and national security. They aligned themselves with the points already raised in the <a href="https://www.accessnow.org/cms/assets/uploads/2021/05/Mauritius-ICT-Act-Submission.pdf">joint civil society statement</a><sup>4</sup> by Access Now.</p><blockquote>Cover photo, Mahen Busgopaul, Director of Mauritius IGF, photo credits to <a href="https://www.harelmallac.com/connexion/blog/the-man-behind-the-mauritius-internet-governance-forum-mahen-busgopaul">Harel Mallac</a><sup>5</sup>.</blockquote><ol><li><a href="https://drive.google.com/file/d/1XlGmzzdV3P6wSmoBPWcBYhq4txez12ps/view?usp=sharing">https://drive.google.com/file/d/1XlGmzzdV3P6wSmoBPWcBYhq4txez12ps/view?usp=sharing</a></li><li><a href="https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf">https://www.icta.mu/docs/2021/Social_Media_Public_Consultation.pdf</a></li><li><a href="https://atlarge-lists.icann.org/pipermail/afri-discuss/2021-May/007093.html">https://atlarge-lists.icann.org/pipermail/afri-discuss/2021-May/007093.html</a></li><li><a href="https://www.accessnow.org/cms/assets/uploads/2021/05/Mauritius-ICT-Act-Submission.pdf">https://www.accessnow.org/cms/assets/uploads/2021/05/Mauritius-ICT-Act-Submission.pdf</a></li><li><a href="https://www.harelmallac.com/connexion/blog/the-man-behind-the-mauritius-internet-governance-forum-mahen-busgopaul">https://www.harelmallac.com/connexion/blog/the-man-behind-the-mauritius-internet-governance-forum-mahen-busgopaul</a></li></ol>]]></content:encoded>
        </item>
        <item>
            <title>Writer Ariel Saramandi &amp; ICTA Chairman Dick Ng Sui Wa respond to BBC&#039;s journalist on ICTA&#039;s consultation paper</title>
            <link>https://sysadmin-journal.com/writer-ariel-saramandi-icta-chairman-dick-ng-sui-wa-respond</link>
            <guid isPermaLink="true">https://sysadmin-journal.com/writer-ariel-saramandi-icta-chairman-dick-ng-sui-wa-respond</guid>
            <pubDate>Sat, 15 May 2021 04:16:40 +0000</pubDate>
            <dc:creator>Ish Sookun</dc:creator>
            <category>Mauritius</category>
            <category>Legislation</category>
            <description>On Friday 14th May 2021, writer Ariel Saramandi and the ICTA Chairman, Dick Ng Sui Wa, spoke on the BBC Newsday1 programme.

They both spoke on ICTA&#039;s consultation paper on proposed amendments to the...</description>
            <media:content url="https://sysadmin-journal.com/content/images/2021/05/bbc-sounds-1.jpg" medium="image" />
            <content:encoded><![CDATA[<p>On Friday 14<sup>th</sup> May 2021, writer Ariel Saramandi and the ICTA Chairman, Dick Ng Sui Wa, spoke on the BBC Newsday<sup>1</sup> programme. </p><p>They both spoke on ICTA's consultation paper on proposed amendments to the ICT Act of Mauritius.</p><!--kg-card-begin: html--><iframe width="100%" height="166" scrolling="no" frameborder="no" allow="autoplay" src="https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/1049084731&color=%23ff5500&auto_play=false&hide_related=false&show_comments=true&show_user=true&show_reposts=false&show_teaser=true"></iframe><div style="font-size: 10px; color: #cccccc;line-break: anywhere;word-break: normal;overflow: hidden;white-space: nowrap;text-overflow: ellipsis; font-family: Interstate,Lucida Grande,Lucida Sans Unicode,Lucida Sans,Garuda,Verdana,Tahoma,sans-serif;font-weight: 100;"><a href="https://soundcloud.com/user-599603786" title="Ish Sookun" target="_blank" style="color: #cccccc; text-decoration: none;">Ish Sookun</a> · <a href="https://soundcloud.com/user-599603786/ariel-saramandi-dick-ng-sui-wa-respond-to-bbcs-journalist-on-ictas-consultation-paper" title="Ariel Saramandi &amp; Dick Ng Sui Wa respond to BBC&#x27;s journalist on ICTA&#x27;s consultation paper" target="_blank" style="color: #cccccc; text-decoration: none;">Ariel Saramandi &amp; Dick Ng Sui Wa respond to BBC&#x27;s journalist on ICTA&#x27;s consultation paper</a></div><!--kg-card-end: html--><p>I uploaded a 5m36s extract of the programme on SoundCloud. The programme content is owned by BBC. Its publication here is for solely for information purposes.</p><ol><li><a href="https://www.bbc.co.uk/sounds/play/w172xv2mgsm68vl?fbclid=IwAR0CvtL_StmwYNjj6DK4L5Oq-oIHksEU2vwk2-UffF86fbW-36fLvZ2Bzds">https://www.bbc.co.uk/sounds/play/w172xv2mgsm68vl</a></li></ol>]]></content:encoded>
        </item>
    </channel>
</rss>
