Thursday, August 2, 2007

Counterterrorism, Lawful Interception and Privacy

The Government of Sri Lanka (GoSL) faces a severe security threat which it has a legitimate right to mitigate. However, lack of lawful interception capability in Sri Lanka hinders forensic investigations and inadvertently assist perpetrators to escape. I have heard enough about politically motivated unlawful wiretapping in fixed telephones in Sri Lanka. In this respect, mobiles have so far remained untouched despite the fact that most terrorism and related crimes/ activities are carried out with mobile communication. Apart from script kiddies attempting to crack passwords, cyber-terrorism hasn’t caused any considerable damage to Sri Lankan infrastructure. Nonetheless, it is naive and foolish to disregard the potential risk factor lurking in Telco. The growing number of government online systems/web sites and the tremendous increase of internet users further prove the need for effective cyber-terrorism countermeasures as well as centralized lawful intercept systems.

Evolving technologies have led to a substantial increase in the use of stored communications, such as SMS/MMS messaging, instant messaging and e-mail in Sri Lanka. Therefore, the need for imposing lawful interception in order to combat terrorism/ criminal activities cannot be ignored. Arguably, privacy is no longer an absolute right in the contemporary world, and as such privacy interests must be balanced with competing public interests (national security). Nonetheless, intercepting a voice communications is just as intrusive as reading someone’s private emails or stored communications. As such, government and the judiciary should address theese challenges and attempt to achieve a balance between the thin line between privacy and national security.

The telecommunication world was a much smaller place in early 1990s when US congress passed a landmark wiretapping law. But post 9/11 brought about controversial intercept laws to western democracies under the cloak of Anti-terrorism laws. In 2002, Australian judiciary approved Telecommunications Interception Legislation Amendment Bill which specified the conditions under which it was lawful for law enforcement agencies and Australian Security Intelligence Organization (ASIO) to intercept communications under the authority of a warrant, subject to reporting and accountability mechanisms. All telecom carriers should possess lawful intercept capability for Dial, packet data and Voice and law enforcement agencies could conduct a wiretap (packet data, voice) centrally on a carrier’s network by duplicating a phone call (or packet dump) digitally by directing a copy to designated central location.

Lawful interception involves complicated processes and heavy investment in software and hardware. Every telecom carrier must employ dedicated staff with government security clearance to maintain all lawful intercept systems and frequent warrants. In Australia, those engaged in alleged criminal activities like child pornography, cyber terrorism etc shouldn’t be surprised to see Feds knocking on their door with records of all relevant past voice communications and internet access packet dumps.

In my next blog, I am hoping to focus more on prevailing issues/concerns with intercepting Internet Telephony and Intercepting Standards.

1 comment:

Anonymous said...

This should be proposed to relevant authorities in order to be implemented in Sri Lanka.