Slashdot Mirror


SA Government's Crypto Registration Up And Running

orange writes "Anyone who supplies crypto products to South Africans (and the government defines crypto as almost anything) has to register with the appropriate agency and pay a ZAR2000 fee (US$200). Failure to supply South Africans without being registered means potential jail time (How they're gonna get you unless you come to South Africa is another story). A copy of the legislation can be found can be found online."

2 of 249 comments (clear)

  1. Re:How are they going to get you? by f97tosc · · Score: 4, Informative
  2. Even more terrifying... by Chastitina · · Score: 5, Informative

    ... is the additional requirement to register all "critical databases":

    "The protection of sensitive data is essential for a functioning of a modern society. As stated in the Electronic Communications and Transaction Act, the information that is of importance to the protection of the national security of the country or the economic and social well-being will be declared as critical. All critical databases will be identified and registered with the Department of Communications which includes the details of the database administrator, the location of the database and the general description of the categories or types of information stored in the critical database.The registered information will be treated as confidential. The protection, management and control of critical databases must comply with the minimum standards that might be prescribed by the Minister. The audit will be performed, from time to time either by Cyber Inspectors or an independent auditor to evaluate the compliance."

    Given such vague standards for "critical" almost *any* commercial database could be deemed "of importance to the protection of the national security of the country or the economic and social well-being." Amazon.com's database contains names and addresses of persons purchasing "how-to" books on terrorism and building bombs? It's critical! A Pr0n site has kept track of all visitors? Some of them *might* be criminals and dangerous to "social well-being."

    Yes, there's also issues with persons living in SA downloading crypto software from foreign companies that haven't registered (are they liable or not?), but most of that is easily bypassed. Just have a visitor bring the "protected" code in on a floppy and distribute it internally.

    The database restrictions have much more serious implications...