320 likes | 337 Views
The submission by ISOC-ZA supports the ECT Bill, aiming to ensure certainty in the digital realm and promote growth. Areas of improvement in the Bill are addressed, including definitions, cryptography, data integrity, authentication, encryption, and domain names. Recommendations like incorporating accessibility standards for the disabled and clarifying terms to align with Internet protocols are made. Emphasis is placed on Chapter 3 of the Bill for providing essential certainty in the virtual world.
E N D
ISOC-ZA South African Chapter of the Internet Society Submission to the PPCC on the ECT Bill, no 8 of 2002
Internet Society • ISOC was founded by the people who founded the Internet, e.g.: - • Vint Cerf – co-inventor of TCP/IP • Jon Postel – RFC Editor • To this day, ISOC funds the RFC process.
The Internet • A vast collection of privately owned networks in voluntary co-operation • All member networks agree to follow the rules as specified by the RFCs • Member networks agree to interconnect and exchange traffic, according to agreed rules • Failure to follow these rules results in a loss of connection to the Internet – no-one will talk to you.
Who owns the Internet? • No one party – parts are owned and operated by many, many different organisations • Rules, protocols & procedures established by RFCs, by mutual agreement • ISOC manages RFCs • ICANN manages naming and numbering issues • Significant ICANN changes require US Dept of Commerce approval – never been refused to date
ECT Bill • ISOC-ZA supports the introduction of this Bill • Legislation is required to provide much needed certainty • Will facilitate further growth, if appropriate legislation is passed • Some sections of the Bill require improvement
Participation in ECT Bill Process • ISOC-ZA members have taken part in every stage of the process: - • E-Commerce Debate • Working Groups • E-Law Conference • Meetings with DoC
DEFINITIONS • “advanced electronic signature” is a misnomer, we propose “accredited electronic signature” • “browser” is defined as a “computer program which allows a person to read hyperlinked data messages”. This should specify “web browser” as one can have programs to browse other things, and there are programs that read web pages that are not browsers.
Cryptography • “cryptography product” and “cryptography service” need to be extensively revised • Three distinct issues here • Data integrity • Authentication • Encryption
Data Integrity • Data Integrity simply ensures that the data transmitted or stored has not been corrupted in some way. • It has nothing to do with encryption, however, cryptographic techniques are often used to achieve assurance of integrity • Integrity can be checked using checksum algorithms or similar programs
Authentication • Authentication verifies the identity of the authorship of a document • Authentication can be done in various ways including using digital certificates, passwords, etc
Encryption • Encryption scrambles a message so that it is unintelligible to anyone who does not have the key to decrypting it. • The organization that provides software for a third party to encrypt data does not have any extra advantage when trying to decrypt a message using their technology • Encryption on its own does not guarantee authenticity or data integrity
Combining these functions • There are a number of products that can do any two or all three in combination. • E.g. Microsoft Outlook, which comes standard with Microsoft Office, does all three. • You cannot include authentication and data integrity in the definition of cryptography just because some programs offer them together.
Domain Name • The use of “…assigned in respect of an electronic address on the Internet” is inaccurate • “Address” in Internet terminology can refer to email addresses or IP addresses, and neither of these is relevant to domains • Suggest: “a hierarchical alphanumerical designation that is registered or assigned in respect of a resource record on the Internet”
Electronic • What about analogue electronics? • “Intangible” is a very bad choice as there are plenty of intangible forms of data that are not electronic, e.g, air vibrations forming musical notes • We suggest: “in a form that can be stored or processed on a computer” or other electrical system.
IP Address • Internet Protocol Address • Is a number e.g. 196.22.64.195 • Is assigned to computers or network equipment connected to a network or to the Internet • “data message” should be deleted from the definition as IP addresses are attached to or give information about data messages.
World Wide Web • Suggest delete “…includes all data messages residing on all computers linked to the Internet” as this would include files that have nothing to do with the Internet, such as Word documents and password files.
Maximising Benefits • This Bill lacks any specific provisions to benefit the disabled. We suggest that reference is made to the US example of Section 508 of the Rehabilitation Act: Electronic and Information Technology Accessibility Standards. See http://www.access-board.gov/508.htm
Chapter 3 • This Chapter is the heart of the Bill, and is very welcome indeed. • It provides much needed certainty in the “virtual world”. • Chapter 3 goes a long way towards providing parity between paper-based transactions and electronic transactions
E-Government • ISOC-ZA welcomes the provisions allowing “Public Bodies” to make use of electronic transactions • ISOC-ZA is disappointed that a principle agreed at the E-Law Conference was omitted from the Bill • Should require Government Departments to implement electronic transactions within a reasonable timeframe • Would act as an important boost to E-Commerce in RSA, “kick start” the economy
Cryptography Providers • This Chapter does not seem to lead to any discernable benefit to the consumer, or to law enforcement Agencies. • Knowing the “provider” of cryptography software is of little use in decoding an encoded message
Cryptography Provider • Considerable confusion as to who is the “provider” – the inventor, manufacturer, importer, distributor, wholesaler, retailer, installer, manager or user? • If an end user (e.g. an SMME) buys and installs SSL on a web site for E-Commerce purposes, which is used by visitors to the site for secure transactions, does the web site owner become a “Cryptography Provider”?
Authentication Providers • Similarly, this Chapter is a dangerous step down the slippery slope of “crypto regulation” • All current web browsers and most operating systems include both authentication & cryptography facilities • Are we expecting every PC vendor to register as a provider?
US Example • The US Government attempted to regulate cryptography, classifying it as a “munition” • This severely damaged US credibility and US business interests • This was a direct contributing factor to Thawte Consulting being paid R3bn by Verisign, and Mark Shuttleworth being in space last week.
Consumer Protection • An important chapter, and one that meets with ISOC-ZA’s support. • Only protects individuals and not organisations – especially SMMEs • No obligation on the consumer to return the goods during the cooling off period.
Consumer Protection – cont’d • Suggest that Section 43 (f) read: - • “where the goods or services - ” • Will address cellular networks concerns about sale of airtime, as does Section 43 (d)
Domain Name Authority • Appointment of ALL board members by the Minister is a gross violation of democracy. • Provisions of Parts 1, 2 & 3 of this Chapter are in direct contradiction of Objectives (d),(i),(k),(m),(o),(p) and (q) of Section 2 – Objects of the Act.
Domain Name Authority – cont’d • ISOC-ZA supports NameSpace ZA as the best body for management of the .ZA ccTLD in the public trust • NameSpace ZA was formed as the result of an inclusive and fully democratic process • Request legislative recognition of NameSpace ZA, as per line 1, phrase 2, page 41 of the Bill, as gazetted.
Liability of ISPs • An excellent addition to the Act • We don’t understand why an ISP should have to belong to any particular Association in order to be protected – surely objective standards and adherence to a Code of Conduct would be better. • Meets with global best practice
Cyber Inspectors • The contents of this Chapter are surely a matter for the Department of Justice, not of Communications • The SAPS does have a Computer Crime Unit. Let’s rather give them adequate resources to do their job properly, rather than creating another police force or “Inspectorate”. • Where Inspectorates exist in other industries, e.g. Mining, they have specific and well defined roles to play, as laid out in Legislation & Regulation. Their function isn’t something as nebulous as “surfing the web” at the tax-payer’s expense.
Cyber Crime • We welcome the introduction of this Chapter. It’s high time that my “virtual property” was as well protected, legally, as my physical property • Section 90 (3) “ … unlawfully … possess a computer program … an offence” • E.g. Master keys in a hotel
Summary • ISOC-ZA welcomes the introduction of this Bill, and supports its objectives • Chapter 3 especially gives much needed legal ‘weight’ to electronic evidence. • Consumer protection is to be welcomed • Privacy protection does not go far enough • Cyber crime provisions much needed • Some sections – even whole chapters – are ill-conceived. • Revision of this Bill will be a valuable boost to the SA economy and will benefit its citizens.
Conclusion • ISOC-ZA is ready and willing to assist the PPCC in its deliberations, in answering questions, and in any other way we can. Thank you