Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Pepkor builds R21-billion fintech giant - and plans to list it - Pieter Erasmus

      Pepkor builds R21-billion fintech giant – and plans to list it

      22 July 2026
      OpenAI says AI models went rogue during testing

      OpenAI says AI models went rogue during testing

      22 July 2026
      Home affairs opens visa fast lane - with tech talent a top priority

      Home affairs opens visa fast lane – with tech talent a top priority

      21 July 2026
      Skills authority to probe MICT Seta leadership crisis - Buti Manamela

      Skills authority to probe MICT Seta leadership crisis

      21 July 2026
      Mastercard bets billions on the tech that could eat its lunch - Prakriti Singh

      Mastercard bets billions on the tech that could eat its lunch

      21 July 2026
    • World
      Meta AI will now tell parents if their teen is in crisis

      Meta AI will now tell parents if their teen is in crisis

      17 July 2026
      IBM shares crash 25% as AI upends software spending - Arvind Krishna

      IBM shares crash 25% as AI upends software spending

      15 July 2026
      Jony Ive's first OpenAI device: an AI smart speaker - Jony Ive and Sam Altman

      Jony Ive’s first OpenAI device: an AI smart speaker

      15 July 2026
      Stripe, Advent in talks to buy PayPal for $53-billion

      Stripe, Advent in talks to buy PayPal for $53-billion

      15 July 2026
      Memory crisis sends smartphone market into steep decline

      Memory crisis sends smartphone market into steep decline

      13 July 2026
    • In-depth
      The plan to stop AI from breaking the world - Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
      Every plug-in hybrid on sale in South Africa, ranked by price - Lamborghini Temerario

      Every plug-in hybrid on sale in South Africa, ranked by price

      7 June 2026
      What Wi-Fi 8 will mean for wireless networks

      What Wi-Fi 8 will mean for wireless networks

      1 June 2026
    • TCS
      Watts & Wheels S1E7: 'Ferrari's EV breaks the internet'

      Watts & Wheels S1E7: ‘Ferrari’s EV breaks the internet’

      8 July 2026
      TCS+ | How Tracker is turning vehicle data into business strategy - Silvia Schollenberger

      TCS+ | How Tracker is turning vehicle data into business strategy

      1 July 2026
      TCS+ | IBM Bob: an AI-powered 'development partner' for the enterprise - David Spurway

      TCS+ | IBM Bob: an AI-powered development partner for the enterprise

      30 June 2026
      Watts & Wheels S1E6: 'A flawless Alfa and a bakkie that divides'

      Watts & Wheels S1E6: ‘A flawless Alfa and a bakkie that divides’

      17 June 2026
      Watts & Wheels S1E6: 'A flawless Alfa and a bakkie that divides'

      Watts & Wheels S1E5: ‘A Bentley of the bush and a car that swims’

      8 June 2026
    • Opinion
      Selling vapour is corporate suicide in slow motion - Jannie van Zyl

      Selling vapour is corporate suicide in slow motion

      16 July 2026
      Brazil's online gambling crackdown is a lesson for South Africa

      How Amazon outmanoeuvred Starlink in South Africa

      15 July 2026
      The Popia problem with agentic AI - Herman Haasbroek

      The Popia problem with agentic AI

      14 July 2026
      The author, Fanie van Rooyen

      South Africa can still catch the AI wave – here’s how

      7 July 2026
      The author, Fanie van Rooyen

      The AI utopia South Africa can’t afford

      1 July 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM Telecom
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » In-depth » Spooks threaten online freedoms

    Spooks threaten online freedoms

    By Jane Duncan19 June 2013
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    keyboard-640

    At a recent breakfast briefing on cybersecurity hosted by Neotel and the Mail & Guardian, information security consultant Beza Belayneh referred to cybercrime in South Africa as a “crisis”, and called on the government to make it a national security concern.

    He said the state needs to respond to cybercrime to prevent loss of life in the same way that it responded to the HIV and Aids pandemic. Cybercrime is a problem, but to equate it with HIV and Aids is inappropriate and insensitive. It has not and will not lead to loss of life at the levels caused by Aids. In fact, according to cyber warfare expert and academic Thomas Rid, no recorded cyber attack has led to loss of life, injury or damage to a building.

    Other comments made at the breakfast also require examination. Siyabonga Cwele, the minister of state security, commented on South Africa’s vulnerability to cyber terrorism and cyber warfare.

    But the main cyber security threats in South Africa are not related to national security at all: they are criminal and, more specifically, related to fraud. Phishing is the most common form of attack, with the distribution of malware such as worms being the second-biggest problem.

    So, then, why are the spooks needed to fight the worms? While there is no denying that cybercrime is a terribly serious issue, there are unexamined implications for users’ Internet rights if we simply accept that this criminal matter is so grave that it should be escalated to the level of a threat to national security, and that therefore the department of state security should become the lead agency on cyber security matters.

    The best defences against cybercrime are technical and social in nature. The fight against phishing requires the widespread use of anti-spam software and user education. This encourages users to change their behaviour and not provide sensitive information to criminals.

    Such threats can be dealt with effectively through an information policy that protects information systems from unauthorised access, use, disclosure, disruption and/or destruction, rather than through a national security policy.

    Policy framework
    Yet it appears that the problem has already been escalated to a national-security threat — the government’s cyber security policy framework has been transferred from the department of communications to that of state security. The framework is due for release in August, although no public comment has been sought on it. This should sound warning bells.

    Many of the statements made at the breakfast are typical of the sort of hyperventilation elsewhere (especially in the US) that creates public panic and paves the way for policy overreactions that securitise and militarise cyberspace.

    These overreactions often lead to emergency measures that erode civil liberties — especially privacy and rights to freedom of expression and association — and such erosions soon become normalised as permanent ways of life.

    In the words of Brunel University’s Mark Neocleous: “Whatever example we use, the pattern is the same: an ‘emergency’ occurs in which ‘security’ is threatened; existing emergency powers are exercised and new ones put into place; these are then gradually ‘stretched’ beyond their original scope; this stretching is gradually justified and legitimised, until the police and security forces are exercising the powers way beyond their original context, to the extent that they become part of the everyday functioning of the rule of law: the emergency becomes permanent, the exceptional becomes the rule, and the sun fails to set on the sunset clauses.”

    A nexus has developed in other countries between the security industry and governments. The former hypes cyber security threats to ensure larger government budgets and hence more expenditure on consultancies, while governments hype them to increase Internet controls.

    Cwele’s warnings about the country’s vulnerability to cyber terrorism overstate the threat. It is difficult to mount a cyber attack that threatens critical national infrastructure, and their outcomes remain unclear. As a result, terrorists have stuck largely to physical attacks of the analogue variety.

    In attempting to justify increasing their powers over the Internet, governments often refer to the cyber attacks on Estonia in 2007 and Georgia in 2008, when the countries’ major institutions were subjected to distributed denial-of-service attacks. The Russian government was accused of being behind the attacks, but investigations traced them to Russian “hacktivists” and criminal botnets.

    Critical services
    A scientist at the Nato Co-operative Cyber Defence Centre of Excellence has stated that the immediate impacts of the attacks were minimal to nonexistent, and that no critical services were permanently affected. Yet cyber security policies continue to be developed based on dread risks or worst-case scenarios that will probably never occur as feared, leading to misallocations of public resources.

    The one cyber attack that came closest to cyber warfare, although it didn’t fulfil all the criteria, was launched by the government that has been shouting the loudest about the threat of cyber warfare — the US.

    Soon after taking office, President Barack Obama ordered a cyber attack to disable Iran’s nuclear systems, using the Stuxnet worm developed by the US and Israel. But such attacks are highly resource-intensive, making them relatively unpopular warfare choices.

    South Africans need to be particularly vigilant when examining whether cybercrime should be securitised. National security offences are generally punished much more harshly than ordinary crimes, and the state security organs are particularly secretive, making them even more susceptible to abuse.

    Furthermore, South Africa has a broad definition of national security, drawn from human-security conceptions of national security. The evidence is that this definition has allowed intelligence agencies to become, effectively, state watchdogs over society, leading to inappropriate interventions in aspects of the country’s politics. Fears that new state powers over the Internet may be abused are not unjustified.

    It is instructive to look at the government’s previous efforts to regulate communications networks on national-security grounds.

    The 2002 Regulation of Interception of Communications and Provision of Communication-Related Information Act was one of a basket of laws passed after the 9/11 attacks on the US. It allows intelligence agencies to intercept communications, including Internet traffic, providing they have a warrant from a judge (an “interception direction”, in the language of the act).

    Communications surveillance
    Last week, however, several organisations released a set of international principles on the application of human rights to communications surveillance. The act falls short of many of these principles. For instance, it forbids the establishment of networks that are not capable of surveillance. This means that users cannot hold a single phone conversation or send a single e-mail without the expectation of it being intercepted.

    Apart from the implications for users’ rights to privacy and expression, the requirement that network operators build “backdoors” into their networks as a matter of course creates network insecurity: these backdoors can (and have) been used, not just by the state, but by criminals, to hack into networks.

    As a result, the international principles say that “in order to ensure the integrity, security and privacy of communications systems, and in recognition of the fact that compromising security for state purposes almost always compromises security more generally, states should not compel service providers or hardware or software vendors to build surveillance or monitoring capability into their systems”.

    Even more seriously, there is no provision in the act for people whose communications have been intercepted to be informed of the warrants, even after the investigations are complete: a crucial safeguard to prevent abuse, as the principles note.

    Moreover, the public is provided with too little information to be able to monitor whether the act is achieving its intended results – information such as the number of warrants that have resulted in convictions.

    A recent court case revealed how the act can be abused to threaten privacy and the right to media freedom. In 2010, crime-intelligence officers duped the designated judge into signing an order to tap the phones of Bheki Cele, then the national police commissioner, and two Sunday Times journalists who were reporting on a controversial lease deal implicating Cele.

    Cyber security is a relatively new issue for policymakers, but already it has proved susceptible to premature securitisation. Unless overstatements on cyber security are challenged, and there is a proper debate backed up by empirical evidence of the source and nature of the threats, control of the Internet will, slowly but surely, creep into the hands of the spooks. And that will be the beginning of the end for Internet freedom.

    • Professor Jane Duncan is the Highway Africa chair of Media and Information Society at Rhodes University. This piece was first published in the Mail & Guardian
    • Visit the Mail & Guardian Online, the smart news source
    • Image: RoccoAlpha/Flickr
    Follow TechCentral on Google News Add TechCentral as your preferred source on Google


    Bheki Cele Jane Duncan Mark Neocleous Siyabonga Cwele Thomas Rid
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleKenya to hand out 3,3m light bulbs
    Next Article How New Zealand became tech hotbed

    Related Posts

    How to stop the abuse of South Africa's intelligence agencies

    How to stop the abuse of South Africa’s intelligence agencies

    25 July 2024
    South Africa's proposed new spying law is deeply flawed

    South Africa’s proposed new spying law is deeply flawed

    9 February 2024

    South Africa’s new intelligence bill is open to abuse

    12 January 2024
    Company News
    Cloud adoption is done. Execution is the new frontier - Cloud on Demand

    Cloud adoption is done. Execution is the new frontier

    21 July 2026
    Data poisoning in AI models: what businesses need to know - Domains.co.za

    Data poisoning in AI models: what businesses need to know

    21 July 2026
    The AI-led industrial revolution has begun - CallMiner Bruce McMahon

    The AI-led industrial revolution has begun

    20 July 2026
    Opinion
    Selling vapour is corporate suicide in slow motion - Jannie van Zyl

    Selling vapour is corporate suicide in slow motion

    16 July 2026
    Brazil's online gambling crackdown is a lesson for South Africa

    How Amazon outmanoeuvred Starlink in South Africa

    15 July 2026
    The Popia problem with agentic AI - Herman Haasbroek

    The Popia problem with agentic AI

    14 July 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Pepkor builds R21-billion fintech giant - and plans to list it - Pieter Erasmus

    Pepkor builds R21-billion fintech giant – and plans to list it

    22 July 2026
    OpenAI says AI models went rogue during testing

    OpenAI says AI models went rogue during testing

    22 July 2026
    Home affairs opens visa fast lane - with tech talent a top priority

    Home affairs opens visa fast lane – with tech talent a top priority

    21 July 2026
    Skills authority to probe MICT Seta leadership crisis - Buti Manamela

    Skills authority to probe MICT Seta leadership crisis

    21 July 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}