Showing posts with label internetfreedom. Show all posts
Showing posts with label internetfreedom. Show all posts

Wednesday, December 14, 2016

ETHIOPIA OFFLINE: EVIDENCE OF SOCIAL MEDIA BLOCKING AND INTERNET CENSORSHIP IN ETHIOPIA


By Amnesty International, Index number: AFR 25/5312/2016
Waves of protests against the government have taken place across various parts of Ethiopia since November 2015. These protests have consistently been quashed by Ethiopian security forces using excessive, sometimes lethal, force, which led to scores of injuries and deaths. The crackdown on protests was accompanied by increasingly severe restrictions on access to information and communications in large parts of the country by cutting off internet access, slowing down connections and blocking social media websites.

View report in English

Thursday, June 9, 2016

Ethiopia Passed Law Against Sharing Defamatory Speech Online

Ethiopia’s parliament has approved a law to imprison people who distribute defamatory speech, pornography and spam online, a move that bloggers and activists say is meant to silence dissent.

Lawmakers on Tuesday passed the law, whose most severe penalty is 10 years’ imprisonment for sharing pornography online. Sharing defamatory speech or spam gets at least three years in prison.

Ethiopia’s cybersecurity officials have said the country is subject to more than 1,000 cyberattacks per day, and the government has said the new law will enable it to prosecute such crimes more efficiently.

But rights groups have accused the East African country of restricting freedom of expression and using spyware against dissidents living overseas. An Ethiopian court last month charged an opposition activist over his Facebook posts.

Source:http://www.addisinsight.com/2016/06/07/ethiopia-passed-law-sharing-defamatory-speech-online/

Monday, May 16, 2016

Ethiopian Blogger and Activist Sentenced to Five Years and Four Months

After a long trial driven by controversy the Ethiopian Federal High Courtsentenced young Ethiopian blogger and activist Zelalem Workagegnehu to five years and four months in prison.
Zelalem is a human rights advocate and a scholar who regularly contributed to the diaspora-run website DeBirhan.
He is expected to appeal the decision.
Currently Zelalem is being held in Kilinto prison in the capital Addis Ababa.
However, his family and friends fear he will be transferred to Ziway prison, some 160 kilometers south of the Ethiopian capital.
Zolaman
Zolaman
On April 15, the Ethiopian Federal High Court acquitted two of Zelalem's co-defendants Yoantan Wolde and Bahiru Degu, who spent more than 600 days incarcerated on terrorism charges critics allege were politically motivated.
Zelalem Workagenehu, however, was found guilty of “supporting terror” for an alleged link to Ginbot 7 Movement, a pro-democracy political party founded by Professor Berhanu Nega and labelled as a “terrorist organisation” by the Ethiopian government in 2010.
He was charged with conspiring to overthrow the government (he helped facilitate a course on digital security) and disseminating false information (he wrote regularly for diaspora-run websites that remain one of the true sources of reliable information on events in Ethiopia).
The judge reportedly said he was guilty of recruiting members to start an Arab-Spring-like revolution in Ethiopia and co-facilitating a digital security course that the state prosecutor understood as “a course to terrorize Ethiopia.”
Zelalem along with nine others were accused under Ethiopia's Anti-Terror Proclamation, which was adopted in July 2009. State officials defend the law, saying it is modelled on existing legislation in countries such as the United Kingdom.
Zelalem was initially charged in October 2014, along with a group of nine other defendants that included Internet users, opposition politicians, and activists. So far, seven people in this group have been acquitted after spending more than a year in jail.
Zelalem and his co-defendants told the court that they had experienced extensive torture in detention.
While in detention, Zelalem was forced to sign confession letters. As a result of beatings and torture, Zelalem says he is now suffering from a severe eye pain.
This article was originally published by Global Voices Online and is reproduced on this website (Oximity) as part of a content sharing partnership.

Wednesday, April 27, 2016

How Ethiopia’s New Internet Crime Bill Could Stop Online Dissent

Bahirdar AIDS Resource Centre is always filled with youths usingAn Ethiopian internet cafe. Creative commons image via UNICEF
When things get a little too hot for the powers that be, a sure fire way to cool them down is a good old-fashioned social media blackout. Just ask Congo-Brazzaville, where back in October, a constitutional referendum changed the game, striking down the previous two term presidential limit, allowing 72 year-old President Denis Sassou Nguesso to run for office, yet again. Nguesso was president from 1979 to 1992, returning to his throne in 1997. Nguesso recently won yet again with a supposed 60 percent of the vote. Five more years.
The opposition in Congo-Brazzaville was not happy, crying foul amid allegations of widespread fraud and voter intimidation. A media blackout was instituted with access to social media and SMS blocked. Users were able to circumvent the ban by utilizing virtual private networks or VPNs. General Jean-Marie Mokoko, speaking to VOA’s French to Africa Service said, “When a dictatorship is installed in a country, we (call on) people, basically, to engage in legal civil disobedience to block this attempt at fraud”. Read here for more on the situation there.
In Uganda, Donald Trump doppelgänger, sort of, Yoweri Museveni, won (stole) his fifth term as President this past February. Fraud, voting irregularities, voter intimidation, and the arrest of the opposition have been reported. The state also instituted a media blackout of social media, citing security concerns. Museveni has been President since 1986. Trump has taken note.
Ethiopia, land of coffee and soon to be not land of Emails has drafted legislation that will criminalize spamming. Those found guilty will be subject to five years behind bars in Ethiopia’s state of the art prison facilities where prisoners are treated very humanely, no torture is going on there, just lots of shiro-wat and chill.
Entitled ‘Computer Crime Proclamation’ the legislation targets the mass distribution of mail that aims to sell and/or advertise goods and services and the sharing of photos and content.
A portion of the law reads, “Whosoever intentionally intimidates or threatens another person or his family with serious danger or injury by disseminating any writing, video, audio or any other image through a computer system shall be punishable, with simple imprisonment not exceeding three years or in a serious cases with rigorous imprisonment not exceeding five years.”
In addition to common sense legislation such as criminalizing the dissemination of child pornography, theft, and cyber attacks there is a clause concerning the distribution of material that incites a public disturbance aka protest that is raising some eyebrows.
Some view the new legislation to be a backhanded way of arresting journalists, bloggers, and people who utilize the web to express their opposition to government policies or just factually report news that can be seen as damaging to the Ethiopian government. The new law comes on the heels of a large protest movement that has gripped the nation.
The protests began when development plans to expand the borders of the country’s capital Addis Ababa into Oromia was announced.
Government forces have already wounded, tortured, arrested and killed hundred of protesters. People in parts of the Oromia region have reported messaging applications including Twitter, WhatsApp, and Facebook Messenger as being inactive on the country’s state owned telecommunications monopoly.
Back in March, Tanzanian civil servants were barred from using social media during working hours amid its rise in popularity and have been warned that ‘gossiping’ will lead to termination.
Social media blackouts are far from a distinctly African political feature. In 2011 the Bay Area Rapid Transit system, a public transportation train system in northern California shut down cell phone service in four stations for a few hours following anti-police brutality protests. And then there is China.
Protests in both Zimbabwe and Gambia occurred earlier this month. In Serekunda people went to the streets demanding electoral reform. Meanwhile demonstrators in Harare protested President Mugabe’s four hundred and eighteen year rule. A social media blackout can be expected in the country.

Monday, July 20, 2015

Ethiopian Arrests for Internet Security Training Undermine Right to Privacy

The simple act of taking steps to protect oneself online is enough to send a journalist to jail, according to charges issued by Ethiopian prosecutors in several cases to be heard this week. An Ethiopian court will soon hand down verdicts in a number of cases where criminal charges could be assessed for attending or applying to attend Internet security training.
Five of the Zone 9 bloggers (four of whom are in prison and one who is being tried in absentia) will face a long-awaited verdict in the case on July 29 after the court adjourned a planned hearing on July 20. Seven of the bloggers were arrested under criminal and anti-terrorism charges for acts that include participating in online security training sessions where they learned how to use encryption technologies such as Tactical Tech and Front Line Defenders’Security in a Box guide. As evidence for their alleged crimes, prosecutors submitted widely available documents including Security in a Box: Tools & Tactics in Digital Security as well as guides on secure passphrases and message encryption to make their case against the bloggers much like EFF’s own Surveillance Self-Defense.
If convicted, the mandatory sentence in Ethiopia for terrorism and incitement offenses is a minimum of eight years—however hope remains that the court will exonerate the bloggers in the absence of substantive evidence to support the charges, according to Zone 9 founding member Endalk Chala. Already five of the bloggers were released last week, which some have attributed to anticipation of a visit by President Barack Obama at the end of the month.
In another group of cases, Yonatan Wolde, Abraham Solomon, Bahiru Dego, and Zelalem Workagenhu are facing charges for applying to attend an Internet security and social media training session abroad. All four were detained on July 8, the same day the Zone 9 bloggers were released, along with six other locally-based opposition politicians, social media activists, and youths, on suspicion that they have links to the diaspora-based opposition group Ginbot 7. Zelalem, who was the co-organizer of the training session, is also charged with using social media to oust the government and sending reports that appeared on independent Ethiopian satellite service ESAT tv. They will appear in court on July 22 to hear a verdict.
The regularity of these arrests suggests a concerning trend, in which journalists are being arrested for the suspicion of what they might say or do and detained without any substantive evidence to support their crimes. The United Nations Special Rapporteur on Freedom of Expression David Kaye said in a recent report that not only do such charges “fail to meet the standards for permissible restrictions,” states like Ethiopia “…undermine the rights to privacy and freedom of expression when they penalize those who produce and distribute tools to facilitate online access for activists.”
“Encryption and anonymity, and the security concepts behind them, provide the privacy and security necessary for the exercise of the right to freedom of opinion and expression in the digital age. Such security may be essential for the exercise of other rights, including economic rights, privacy, due process, freedom of peaceful assembly and association, and the right to life and bodily integrity,” Kaye said in the report.
Encryption is indeed a powerful tool that not only enables users to communicate securely online, but fosters the kind of conditions that make freedom of expression possible. Its use should never be cause for the deprivation of freedom.     

Monday, March 9, 2015

Ethiopia: Digital Attacks Intensify

(New York) – The Ethiopian government has renewed efforts to silence independent voices abroad by using apparent foreign spyware, Human Rights Watch said today. The Ethiopian authorities should immediately cease digital attacks on journalists, while foreign surveillance technology sellers should investigate alleged abuses linked to their products.

Independent researchers at the Toronto-based research center Citizen Lab on March 9, 2015, reported new attempts by Ethiopia to hack into computers and accounts of Ethiopian Satellite Television (ESAT) employees based in the United States. The attacks bear similarities to earlier attempts to target Ethiopian journalists outside Ethiopia dating back to December 2013. ESAT is an independent, diaspora-run television and radio station.

“Ethiopia’s government has over the past year intensified its assault on media freedom by systematically trying to silence journalists,” saidCynthia Wong, senior Internet researcher at Human Rights Watch. “These digital attacks threaten journalists’ ability to protect the safety of their sources and to avoid retaliation.”

The government has repressed independent media in Ethiopia ahead of the general elections scheduled for May, Human Rights Watch said. Many privately owned print publications heavily self-censor coverage of politically sensitive issues or have shut down. In the last year, at least 22 journalists, bloggers, and publishers have been criminally charged, at least six publications have closed amid a campaign of harassment, and many journalists have fled the country.

Many Ethiopians turn to ESAT and other foreign stations to obtain news and analysis that is independent of the ruling Ethiopian People’s Revolutionary Democratic Front. However, intrusive surveillance of these news organizations undermines their ability to protect sources and further restricts the media environment ahead of the elections. Government authorities have repeatedly intimidated, harassed, and arbitrarily detained sources providing information to ESAT and other foreign stations.

Citizen Lab’s analysis suggests the attacks were carried out with spyware called Remote Control System (RCS) sold by the Italian firm Hacking Team, which sells surveillance and hacking technology. This spyware was allegedly used in previous attempts to infect computers of ESAT employees in December 2013. If successfully installed on a target’s computer, the spyware would allow a government controlling the software access to activity on a computer or phone, including email, files, passwords typed into the device, contact lists, and audio and video from the device’s microphone and camera.

Citizen Lab also found that the spyware used in the attacks against ESAT appeared to have been updated as recently as December 2014. On November 19, a security researcher, Claudio Guarnieri, along with several nongovernmental organizations, publicly released a tool called Detekt, which can be used to scan computers for Hacking Team RCS and other spyware. Citizen Lab’s testing determined that Detekt was able to successfully recognize the version of RCS used in a November attack, but not the version used in a December attack. Citizen Lab concluded that this may indicate that the software had been updated sometime between the two attempts.

These new findings, if accurate, raise serious concerns that Hacking Team has not addressed evidence of abuseof its product by the Ethiopian government and may be continuing to facilitate that abuse through updates or other support, Human Rights Watch said.

Hacking Team states that it sells exclusively to governments, particularly law enforcement and intelligence agencies. The firm told Human Rights Watch in 2014 that “we expect our clients to behave responsibly and within the law as it applies to them” and that the firm will suspend support for its technology if it believes the customer has used it “to facilitate gross human rights abuses” or “who refuse to agree to or comply with provisions in [the company’s] contracts that describe intended use of HT [Hacking Team] software.” Hacking Team has also stated that it has suspended support for their product in the past, in which case the “product soon becomes useless.”

Media reports and research by independent human rights organizations in the past year have documented serious human rights violations by the Ethiopian government that at times have been facilitated by misuse of surveillance powers. Although spyware companies market their products as “lawful intercept” solutions used to fight serious crime or counterterrorism, the Ethiopian government has abused its counterterrorism laws to prosecute bloggers and journalists who merely report on public affairs or politically sensitive issues. Ethiopian laws that authorize surveillance do not adequately protect the right to privacy, due process, and other basic rights, and are inconsistent with international human rights requirements.

Hacking Team previously told Human Rights Watch that “to maintain their confidentiality” the firm does not “confirm or deny the existence of any individual customer or their country location.” On February 25, 2015, Human Rights Watch wrote to the firm to ask whether it has investigated possible abuse of its products by the Ethiopian government to target independent media and hack into ESAT computers. In response, on March 6 a representative of the firm emailed Human Rights Watch that the company “take[s] precautions with every client to assure that they do not abuse our systems, and, we investigate when allegations of misuse arise” and that the firm is “attempting to understand the circumstances in this case.” The company also stated that “it can be quite difficult to get to actual facts particularly since we do not operate surveillance systems in the field for our clients.” Hacking Team raised unspecified questions about the evidence presented to identify the spyware used in these attacks.

Human Rights Watch also asked the company whether contractual provisions to which governmental customers agree address governments’ obligations under international human rights law to protect the right to privacy, freedom of expression, and other human rights. In a separate March 7 response from the firm’s representative, Hacking Team told Human Rights Watch that the use of its technology is “governed by the laws of the countries of our clients,” and sales of its technology are regulated by the Italian Economics Ministry under the Wassenaar Arrangement, a multilateral export controls regime for dual-use technologies. The company stated that it relies “on the International community to enforce its standards for human rights protection.”

The firm has not reported on what, if any, investigation was undertaken in response to the March 2014 Human Rights Watch report discussing how spyware that appeared to be Hacking Team’s RCS was used to target ESAT employees in 2013. In its March 7 response, the company told Human Rights Watch that it will “take appropriate action depending on what we can determine,” but they “do not report the results of our investigation to the press or other groups, because we consider this to be an internal business matter.”

Without more disclosure of how Hacking Team has addressed potential abuses linked to its business, the strength of its human rights policy will be in question, Human Rights Watch said. 
Sellers of surveillance systems have a responsibility to respect human rights, which includes preventing, mitigating, and addressing abuses linked to its business operations, regardless of whether government customers adequately protect rights.

“Hacking Team should publicly disclose what steps it has taken to avoid abuses of its product such as those alleged against the Ethiopian government,” Wong said. “The company protects the confidentiality of its customers, yet the Ethiopian government appears to use its spyware to compromise the privacy and security of journalists and their sources.” 
Source: hrw.org

Spyware vendor may have helped Ethiopia target journalists – even after it was aware of abuses, researchers say






Reuters/Kacper Pempel/Files



The Ethiopian government appears again to be using Internet spying tools to attempt to eavesdrop on journalists based in suburban Washington, said security researchers who call such high-tech intrusions a serious threat to human rights and press freedoms worldwide.
The journalists, who work for Ethiopian Satellite Television in Alexandria, Va., provide one of the few independent news sources to their homeland through regular television and radio feeds — to the irritation of the government there, which has accused journalists of "terrorism" and repeatedly jammed the signals of foreign broadcasters.
The struggle increasingly has stretched into cyberspace, where malicious software sold to governments for law enforcement purposes has been observed targeting the journalists, researchers said. The most recent documented case, from December, came several months after The Washington Post first detailed the government's apparent deployment of the Internet spying tools, which though far cruder, offer some of the same snooping capabilities enjoyed by the National Security Agency and the intelligence services of other advanced nations.
"This is the second round of coordinated attempts at installing spyware so they can monitor our systems and uncover who our sources are inside of the Ethiopia," said Neamin Zeleke, the managing director of Ethiopian Satellite Television, which is commonly known as ESAT. "This is a really tenacious attempt to crack down on freedom of expression."
Zeleke became suspicious when a message arrived in his inbox in December with an attachment claiming to have information about upcoming elections. Normally, that's the sort of information ESAT is eager to get its hands on: Ethiopia is ruled by a government notoriously unfriendly to the press — leaving much of the independent journalism on local affairs to outfits such as ESAT that operate outside of the country but rely on sources from inside Ethiopia.
But editors and reporters at ESAT have become wary of e-mails from unknown senders in recent years — and for good reason.
In 2013, the computer of one of Zeleke's colleagues was infected with malware after the colleague opened what appeared to be a Microsoft Word file. They later learned that it was probably a commercial spying tool sold to governments around the world by the Italy-based vendor Hacking Team, according to researchers at Citizen Lab at the University of Toronto's Munk School of Global Affairs.
So after receiving the recent suspicious e-mail, Zeleke said he forwarded it to the Citizen Lab researchers instead of opening the attachment.
The e-mail, along with other messages to Ethiopian journalists, show that Ethiopia appears to be continuing to wage a digital campaign against independent journalists — including some based within the United States — with the help of updated versions of Hacking Team software, according to the report's authors Bill Marczak, John Scott-Railton and Sarah McCune.
Sophisticated surveillance tools on a budget
While the debate over cyberattacks has been dominated by disclosure about National Security Agency capabilities and alleged cyberespionage campaigns of Chinese and Russian hackers, a booming commercial spyware market has put high-tech surveillance tools within the reach of governments worldwide. In the hands of repressive regimes, this can mean a wave of cyberattacks on journalists, human rights workers and political activists.
The Internet, instead of being a tool for organizing and spreading information about government abuse, can become a tool for oppression able to even reach those who have fled the physical borders of a country.
And the latest Citizen Lab report suggests that Hacking Team may continue to support its software to nations even after abuse was identified.
Hacking Team declined to comment on whether it sells its services to Ethiopia. "We do not disclose the identities of clients nor their locations as a matter of policy," company spokesperson Eric Rabe told The Post. "Obviously, clients demand confidentiality and require it in order to conduct legitimate legal surveillance of suspects in cases of crime, terrorism or other wrongdoing."
The Ethiopian government also did not directly answer questions about whether it uses Hacking Team's products. "Ethiopia acts in compliance with its own laws and with the laws of nations," Tesfaye Wolde of the Ethiopian Embassy in Washington said in a statement.
Hacking Team investigates allegations of abuse, Rabe said. "In cases where we find that an agency is misusing our technology, we can take a variety of actions up to and including suspending support for the system."
He did not say, though, whether those investigations have ever resulted in a country being cut off. "It can be quite difficult to determine facts, particularly since we do not operate surveillance systems in the field for our clients," Rabe said. "Assertions that may seem perfectly obvious to some can be extremely difficult to actually prove."
And activists are skeptical. "Hacking Team is one of the go-to companies of authoritarian regimes who absolutely need spying capabilities and don't want to develop them on their own," said Christopher Soghoian, a principal technologist at the American Civil Liberties Union.
The company's signature product is its Remote Control System (RCS), which allows governments to hack into the computers of targets and gain almost complete control. "For a few hundred thousand dollars, they will give you the software you need to take over someone's webcams, microphones, and access other sensitive information," Soghoian said.
It's this RCS malware that Citizen Lab says attackers appear to have tried to use against ESAT. "In this case, what we have is the same entity who attacked ESAT in 2013 attacking them in December of 2014 using Hacking Team's software again," Marczak, one of researchers, said. The malware linked back to the same sort of control infrastructure as the previous version, and researchers uncovered other evidence, including an encryption certificate, that tie it back to Hacking Team, according to Citizen Lab.
The malware was modified from the version used against ESAT journalists reported in February 2014 to avoid tools developed to help activists and journalists detect whether they had been infected by commercial spyware, Citizen Lab said. The modifications to the malware indicate that Hacking Team continued to provide support to the Ethiopian government even after The Post reported on the issue last year.
Rabe of Hacking Team said the company's software is regularly updated for customers who are not in violation of its customer policy, which says the company will stop providing support to a client if it believes their software has been used to "facilitate gross human rights abuses."
The use of Hacking Team software is a strong sign that the Ethiopian government was behind the attack, Marczak said.
"The software is sold exclusively to governments — and in the case of ESAT, it doesn't seem like there's anyone else who would be interested in targeting them beyond Ethiopia," he said.
But there are other signs that point to Ethiopia — including Internet addresses used by the attacker that were linked to an Ethiopian telecom provider, researchers said, as well as links uncovered between the attacker and a computer that calls itself "INSA-PC," a possible reference to the Ethiopian Information Network Security Agency, or INSA.
Ethiopia's crack down on journalists
Ethiopia has a poor track record on freedom of the press. "There's been a systematic decimation of independent media" since 2010, said Felix Horne, Africa researcher at Human Rights Watch, featuring escalating tactics including threats of jail time.
And that campaign has become more aggressive as the country approaches elections in May, with 30 some journalists fleeing the country and six publications closing down in 2014, he said.
The State Department, which declined to comment for this story, has repeatedly expressed concern about human rights abuses by the country's government against activists and journalists. But the United States maintains strong ties with Ethiopia, especially when it comes to combating Islamist extremism in neighboring Somalia. Wolde, of the Ethiopian Embassy, said that Ethiopia "has close working relations with the United States and has done nothing to jeopardize these relations."
ESAT, which was started in 2010, is largely staffed by journalists who have fled Ethiopia, sometimes while facing the threat of torture or imprisonment, Zeleke said. While independent, the group is viewed by outside observers as tied to political opposition groups within Ethiopia. And the malware campaign shows that its reporters are within the digital grasp of the Ethiopian government, even if they've escaped its physical control, Zeleke said.
But he said that he is most worried about sources who share information with the outlet, often at significant personal risk. "We have all kinds of contacts who give us information," Zeleke said. "The government wants to know who they are so they can crack down and arrest them."
News of commercial surveillance tools has had a chilling effect among those inside Ethiopia and the diaspora, Horne said. "A lot of Ethiopians have become afraid to talk on tech that they previously considered secure like Skype or e-mail."
Hacking Team is not the only company selling this type of technology. The Electronic Frontier Federation is currently suing Ethiopia on behalf of a U.S. citizen whose computer was allegedly infected in 2013 by FinSpy, another form of commercial spyware available to foreign governments.
Attempting to hack someone located in the United States with spyware is illegal, said Nate Cardozo, a lawyer with the EFF, unless done in partnership with domestic law enforcement agencies. "It's absolutely a violation of U.S. law, probably both the Computer Fraud and Abuse Act and the Wiretap Act," he said.
Many companies that market their tools to foreign governments have made it a point to stay outside the range of U.S. courts, he said, and they often argue they cannot be held responsible for what a country does once it buys the products. "The industry turns a blind eye to the abuses of their products, and they have from the very beginning," Cardozo said.
Rabe said that Hacking Team works to "prevent abuse in ways that no other company in our business comes close to." Last month, the company announced it is complying with a European Union agreement that controls the export of its type of software. The company has previously committed not to sell to countries on various International blacklists.
But the latest Citizen Lab report could make it harder for the industry to insist they are ignorant of abuses, researchers said.
"This is the first case we've been able to identify where abuses have continued, Marczak said. "It's very much a retort to the defenses we hear from this industry."


Source: washingtonpost