Showing posts with label south africa. Show all posts
Showing posts with label south africa. Show all posts

Monday, August 27, 2007

Dr Beetroot and the Stolen Records


This is my take on the whole Manto Tshabalala-Msimang vs The Sunday Times controversy.

Being an Information Security professional I am going to relate it as I see it. And the way I see it both the minister and the paper are correct.

For those of you who read this blog and are not from South Africa I'm going to put a bit of background down for you. If you are from South Africa you can safely skip the next little bit - you know this already.

Manto Tshabalala-Msimang is the Minister of Health and is also known as Dr Beetroot because of her criticized belief that AIDS is cured better through vegetables than medicine. This belief kills people every day and the opposition want her to leave the government because of it.

The Sunday Times newspaper is the most popular weekly newspaper in South Africa and they published an article that hinted very strongly that the minister was an alcoholic without actually saying it outright. They worked this out because of evidence that came from her medical records when she was in hospital and had alcohol when she was not supposed to.

The Minister has not denied the fact that she had alcohol while in hospital but has been upset that the Sunday Times had a copy of her medical records. (This is typical government spin doctoring; according to Nick Naylor from Thank You For Smoking: "That's the beauty of argument, if you argue correctly, you're never wrong". But thats not the point of this post.)

The point is that the Sunday Times did not steal the documentation. They merely happened to get a copy of it. And, once they had a copy, it is their duty to report on news they think the country should know about. And, of course, the whole country is following this very closely so the Sunday Times was right to publish.

So, where does information come from? That is the big question. In Information Security we have a saying "protect all the information that you don't want to read about in tomorrow's newspaper". The Sunday Times is a respectable, "non-tabloid" newspaper. I can't picture their staff crawling around in hospitals, looking for medical records or hacking into medical systems.

Somehow there was a leak in the hospital and this is who the minister should be going after but its a lot easier to sue a newspaper than a hospital especially for the minister of health who would like to pretend that all is well with patient records in hospitals.

The Minister is right that her private details should be kept private but once it is in the newspaper it is too late. It should have been protected from the start and the hospital is (in my humble opinion not being a lawyer) to blame.

If the Minister does take up the issue with the hospital then some questions may arise as to why she used a private hospital for an operation that could have been done at a public hospital and why the government does not protect patients (even at private hospitals) from having their records go missing, ending up at newspapers. Maybe California can help her out.

Friday, May 18, 2007

Only in Africa.... phishing is done on the street.

Today I had to do some (personal) work with the Government.

What I did is personal (so don't ask) and probably not offered in all countries but you can think of it as being similar to renewing a driver's license or getting health benefits, etc. Dealing with the Government.

The department I had to visit has moved and not done a very good job of Informing The Public. Also, unlike the Department of Home Affairs it is not a place you'd visit very often. Some people need never go there.

So... while I was in their waiting room I read a newspaper article they had stuck up on the wall about how they were being targeted by fraudsters. These are people who wait on the pavement just outside or near to the building. They can then spot people who are obviously lost and looking for the building and "help" them out.

They take the people to other buildings somewhere in the vicinity in which a little look-alike office has been set up and charge them about $20 to $100 to lodge an application.

The Government charges nothing (its covered by tax).

Even for me that amount is a lot of money but for the poor who would be most likely to use the service it can be almost half their monthly salary. They also leave in the (falsely) secure knowledge that their application has been processed and I'm not even sure if it does make its way to the Government.

And, of course, these guys also have personal details about the person and probably a photographed copy of their ID book and signature. Maybe even a copy of their last bank statement. These are all things needed to get credit.

Only 1% of Africans have access to the Internet and in the largest city built not near a major river or dam or coast phishing is done on the street.

Tuesday, March 13, 2007

Temet Nosce and the quest to put auditors where they belong

"γνῶθι σεαυτόν" "Know Thyself". As Neo found out when he went to visit the Oracle.

In an industry where "proactive" is the biggest buzzword it seems to me that we in the Information Security field are not doing so well.

From observations in the industry I have noticed a trend to allow Auditors to dictate what needs to be done (and in turn - point out what is not being done). In some companies what the auditors say should be done is all that gets done.

This is very different to how the Accounting profession works. The books get drawn up, approved by management and then only do the Auditors come through and approve them. Note the difference - here the Accountants decide what and how things should be done and the auditors just see if they are done. And management is involved.

It may be that management sees us as IT "guys". They may not think of us very highly and they may believe that the Auditors are great and all knowing. In my experience the auditors have come across as being very knowledgeable (even though I have had some good laughs at some audit findings). They usually arrive with ties and jackets and shiny shoes. And checklists and boring looking software. And they are backed by international auditing firms that have Ways Of Doing Things.

Us guys are lumped with IT. We are told what the auditors found wrong and told to fix it - that is how IT works. This is what needs to change.

Even many people involved in Information Security over emphasize the importance of Auditors. Here in South Africa and (it seems - abroad). I've noticed a number of American bloggers trying to push Information Security as a goal and compliance as a result. This fits into the same concept.

We need to be proactive and tell Auditors: this is what we do, this why. And slowly change perceptions and become guides to our organisations.

But first, we have to understand who we are and know what we do.

Temet Nosce.

Wednesday, February 21, 2007

New York - City that never sleeps.

Just a quick one - promise.

Mayor Bloomberg of NYC on the www.nyc.gov site in his "State of the city" boasts that NYC had 44 Million visitors. Thats pretty good going considering that the number of people in the whole of South Africa is 44 Million and the number of people in Australia is 25 Million.

So, essentially the whole of South Africa could have visited New York. Or the whole of Australia could- twice in one year.

Amazing.

Coincidently, the number of people living in NYC is 8.2 Million - which is roughly the number of visitors (estimated, very badly by yours truly, but probably rather accurate) to South Africa in a year.

Tuesday, February 6, 2007

We support you FNB!

Ok, this is way off topic. But it is my blog so I can do what I want with it, not?

I bank with FNB and I am proud to be a customer of theirs.

South Africans should know this story by now but overseas readers may not:

First National Bank is involved in a number of non-banking initiatives to give back to the community etc.

One of these was a petition to the Office of the President asking for more action to be taken on crime. They made thousands of little booklets that were addressed to the above Office. The plan was to send these out to the general public who would then fill in an incident of crime that had touched them. The petitions were (at the bank's expense) already stamped and addressed.

The Government got wind of the idea and (it is alleged) put pressure on the bank (who does the banking for some big government departments) and the whole plan was dropped.

FNB is a business and I understand them needing to reassess the situation and watching the bottom line first but I am very upset with the Government and the position they have taken.

It is obvious that crime is a huge deal in South Africa - even the conservative, edited, diminutive statistics that get released each year show how bad South Africa's crime levels are.

Even wikipedia has an article on crime in South Africa which begins "Crime is a major problem in South Africa. According to a survey for the period 1998-2000 compiled by the United Nations Office on Drugs and Crime, South Africa was ranked second for assault and murder (by all means) per capita, in addition to being ranked second for rape and first for rapes per capita."

(I feel that) It got to the point where normal people were sick of crime but were numb to it. The papers stopped printing stories about crime unless they were strange or terrible.

Then South Africa got interested in crime again:

  • The Minister of Safety and Security, Charles Nqakula caused outrage among South Africans in June 2006 when he responded to opposition MPs in parliament, who were not satisfied that enough was being done to counter crime, saying that MPs who complain about the country's crime rate, should stop whining and leave the country (Also from the wikipedia)
  • The 19th FIFA World Cup is scheduled to take place in South Africa. This event will bring tons of foreign capital into South Africa and promote to the entire world the idea of South Africa as a holiday destination. On the other hand - the infastructure and initial outlay is huge too. It is do-or-die. This competition has to be handled perfectly for the country to benefit. Crime is a risk to this. Possibly the most important one.
These combined with the fact that Governement does not seem to be willing/able to deal with crime has led South Africans to feel lost about this issue.

First National bank seem to be a very patriotic bank. They have loads of adverts promoting how great the 2010 FIFA World Cup will be. They are also (the main?) sponsor of http://www.homecomingrevolution.co.za/ which aims to promote South Africa to ex-patriots who may be interested in returning.

Reading a few messages on the forum there, the message is quite clear - "we would love to return home for a million reasons. and we will not for one reason - crime!"

It seems to me that FNB as a place has just, like the rest of us, had enough of the moaning about crime and wants to do something about it. They are not allowed to start their own police force and justice system so they are trying to get the attention of the people who can deal with crime.

Unfortunately instead of taking action against crime the Government have taken action against FNB.

And that...is a crime.