Meant to protect us...
The preamble of the draft bill reads:
The purpose of this draft bill is to grant Military Intelligence a new remit consisting of ensuring the cyber defence of the Czech Republic. For this purpose, the amendment to the Military Intelligence Act will allow it to use technical means of cyber defence and will set out the rules for their use.
So what's actually in the proposal?
First, some context:
Military Intelligence is obliged, under the conditions set by this Act, to avert or reduce the effects of a threat to the sovereignty, territorial integrity, democratic foundations of the Czech Republic, or to an extensive threat to life and health, property values or the environment (hereinafter "important state interests") identified by it in cyberspace, if doing so is necessary given its intensity to be carried out immediately upon detection, or if the armed forces or armed security corps lack the necessary forces or means to stop or avert it.
Avert and reduce the effects of threats — nothing specific about cybersecurity, right?
Military Intelligence assesses threats to important state interests in cyberspace on the basis of
a) information gathering, collection and evaluation (hereinafter "information provision") carried out in the performance of its tasks as the unified armed intelligence service of the Czech Republic, or
b) monitoring of public communications networks and electronic communications services (hereinafter "cyberspace monitoring") pursuant to Section 16b(2).
This is better — monitoring public communications networks and electronic communications services. So there'll be a probe somewhere? Yes, in Section 16 we find:
(3) For cyberspace monitoring, Military Intelligence uses probes pursuant to the Electronic Communications Act placed in electronic communications networks under the conditions laid down by this Act.
And what will that probe be able to do? Just L3/L4? Or some L7 information as well? Could it capture all traffic, i.e. PCAP? Section 16 is fairly generous with meaningless information:
(2) Cyberspace monitoring means the continuous evaluation of non-addressed data in cyberspace ensuring early detection of security threats to important state interests, assessment of their intensity, severity of their consequences and the manner of stopping or averting them in cyberspace. Cyberspace monitoring does not include the processing of personal data or interception and recording pursuant to the Electronic Communications Act; cyberspace monitoring must not violate the confidentiality of message content and may only be carried out in a manner that excludes interference with private or family life.
What is non-addressed data? Let me put it differently — I understand addressed data as data that can be used for identification: i.e. an IP address, data from an HTTP certificate, user agent data, etc. So what's left? The port number — though even that combined with other data can often reveal a lot. Then there are traffic volume characteristics, and that's about it.
I'd venture to say that with volume characteristics alone they can do nothing useful. Why? Because they'll want to monitor traffic at a point where the volume is enormous. At best they'll catch a DoS/DDoS. ISPs handle this better and on their own — it threatens their business directly.
I'm not sure whether to feel reassured that this is what passes for an adequate level of cyber defence... to me it looks like another money pit with no real benefit.
Somewhat sad is the fact that only these institutions may submit comments: BIS, ČNB, ČTÚ, the Presidential Office, KML, KOM, MPO, MSP, MV, MZV, NBÚ, NÚKIB, ÚZSI. The expert public is nowhere to be seen...
More about the document titled: Draft Act amending Act No. 289/2005 Coll., on Military Intelligence, as amended, and certain other acts in the ODok portal.