Pakistan Bans Encryption
An anonymous reader writes "After some rumors of this last month, Pakistan has now officially told all of the country's ISPs that they need to block all encrypted VPNs since content running over such services cannot be monitored by the government."
It exists. Obviously.
DRM: Terminator crops for your mind!
Try Fortune $infinity. The company I work for is no where near Fortune 500 or even 5000 and we still could not have anyone work from Pakistan now.
The new law not only imposes exciting requirements so that the gov't can monitor all communications for 120 days, but also forbids anyone but the government to "monitor, reconcile, or block any traffic" -- so the ISP, parents, schools etc. are not allowed to do that.
The encryption ban isn't all that impressive, just typical government not-thinking-things-through, and easily enough fixable -- they could add an exception for banks, permitting encryption but the bank has to store the corresponding unencrypted data. FWIW, the requirements pertaining to this may be in place (I'm not a lawyer, so I'm not sure if that's what the second statement here means, or if it's more a Room 641A thing for international comms passing through):
What's really jawdropping is requiring that every fucking byte going through every ISP or telco in Pakistan must be logged for 120 days. In other news, the middle east division of every vendor of massive storage arrays report 1000% increase in sales...
Read the law here (PDF), it's only 6 pages.
Based on my reading of the law (thanks for posting the link to the PDF, AC), you can still encrypt traffic (think banks, online retailers, etc.) as long those who employ it add additional network links to the Pakistani government, pass all traffic to the government and provide them with the appropriate keys. Said additional links and any supporting hardware and/or software to be implemented at the TLS/SSL users' expense.
AFAICT, The 120 days that the OP refers to isn't how long they have to keep the data, it's how long ISPs have to implement the environment.
N.B. IANAL
No, no, you're not thinking; you're just being logical. --Niels Bohr
Iran has been accused of jamming satellite connections in the past, as has Libya. The US apparently has the capability.
As for how it's possible, Wikipedia has a brief description of the process. Because of the satellite's distance, it's signal is relatively weak when it reaches the ground (you're familiar with the inverse-square law, right?). A terrestrial broadcast will be much stronger and can drown out the signal from the satellite.
(reposting this because I forgot to login. whoops)
The point of stenography is to write very fast in abbreviated form, using a set of glyphs that enable you to write very quickly in terrible chicken scratch that no one other than a trained secretary can read and which drives mortals straight past drink to heroin, also called shorthand. Stenograhpy also refers to typing quickly on a special keyboard, in order to capture as much spoken dialog as possible in-line. Often seen in courtrooms.
The point of steganography is to obscure data within other innocuous data. This is where you hide your secret missile codes in photos of cats you post on Flickr.
I like music
This is a complete misread of telecoms terminology, they are not banning user encryption.
The actual regulation only mentions encryption ONCE, and that is in regard to signalling information.
Signalling information is not the data. I repeat, signaling information is NOT the data.
For phone calls, signalling is the bits that tell the system where the call is go to, and who from, and other "meta" information about the call. For data, signalling is the outer part of the IP packet that carries destination information.
The encrypted part of data is in the PAYLOAD. And they don't require the payload to be decrypted. It's also the same section that requires the
info to not be compressed. Are they really going to decompress all files before sending them off? No way.
All they are requiring is that the phone call source/destination info, and Ip traffic packets are not encrypted *further* by the ISP. Customer
VPN data will continue to flow as normal.
IAANE (I am a network engineer) and I have had to deploy a government spying^Hlegal intercept platform before, and this is pretty much just
bog standard like many other countries do.
Bottom line: A non story. Pakistan wants ISPs to implement legal intercept. Big whoop, most countries have already done this.
Sparks:Gadget:Beer Maker