Showing posts with label IT ACT 2000. Show all posts
Showing posts with label IT ACT 2000. Show all posts

Sunday, January 15, 2012

How Would Google, Facebook, Microsoft And Yahoo Approach Delhi High Court?

Recently the Indian government granted its approval to criminally prosecute companies like Google, Facebook, Microsoft and Yahoo for posting objectionable contents on their websites. Indian government claims that despite repetitive requests being made to these websites, they failed to remove the objectionable contents from their websites.

Before that companies like Google and Facebook approached the Delhi High Court to quash the complaint against them. However, the Delhi High Court refused to do so and this cleared the way for continuance of the complaint against these companies. With the granting of sanction by central government under section 196 of the Code of Criminal Procedure (CrPC), 1973, the criminal trial against these companies can now be started for diverse offenses under Indian laws.

The trial court has adjourned the matter till March 13, 2012. The trial court has also directed the external affairs ministry to serve the summons issued to foreign-based social networking and other websites. With this the excuse of being an Indian subsidiary is also gone and now parent companies would have to face the heat and their executives have to appear personally before the trial court. Now the Delhi Police can also prosecute these parent companies after the sanction has been received.

The representatives of companies may or may not appear before the trial court. If they appear, they have to face the trial and prove their innocence as per Indian laws. If they do not appear, this may have serious ramifications that these companies cannot afford to face.

On 16th January 2012 the Delhi High Court would hear further arguments of these companies. However, it seems the matter would not be settled easily and lightly by Delhi High Court. Techno legal experts like Praveen Dalal have been warning against unconstitutional cyber laws in India. He was the only cyber law expert of India who protested against the information technology amendment act 2008 (IT Act 2008) in its present form that is root of all present cyber law related distortions in India.

According to Praveen Dalal, the cyber law of India should be repealed. There is no second opinion about the fact that the cyber law of India needs urgent reforms if not a repeal. However, the companies like Google, Facebook, Microsoft, Yahoo, etc cannot complain now when they did not complain earlier at the time of IT Act 2008, opines Praveen Dalal. Now the IT Act 2000, as amended by the IT Act 2008, is the law of the land and these companies must follow the same, suggests Dalal.

It seems these companies are in hot water as they have not complied with Indian cyber laws requirements and now they cannot turn back and question the very same cyber law that they silently endorsed earlier.

Tuesday, June 21, 2011

Natgrid And NIA Became More Obscure And Unconstitutional

Accountability and transparency are two words that do not apply to Indian law enforcement and intelligence agencies. India has chosen to stick to the British legacy of non transparency. Whether it is laws like official secrets act, Indian telegraph act or the accountability of Indian law enforcement and intelligence agencies, Indian government has even surpassed the Britishers in this regard.

Instead of strengthening the transparency and Parliamentary scrutiny, India is further making these agencies more unaccountable and lawless. The right to information act 2005 (RTI Act 2005) is the sole transparency law of India that needs further amendments and strengthening. However, the proposed right to information rules 2010 instead of strengthening the RTI Act, 2005 took steps that are retrograde in nature.

Firstly, India amended the cyber law of India through the draconian information technology amendment act 2008 that empowered Indian government and its agencies with unconstitutional e-surveillance, internet censorship and website blocking powers. Subsequently, it made the RTI Act 2005 weaker and redundant.

Now Indian government has announced that Central Bureau of Investigation (CBI), national investigation authority of India (NIA) and national intelligence grid (Natgrid) would be exempted from the applicability of RTI Act, 2005. The constitutional validity of national investigation agency act, 2008 (NIA 2008) is still doubtful and CBI and Natgrid are not governed by any law at all. Even the proposed central monitoring system of India is without any parliamentary oversight.

Whether it is CBI or Intelligence Agencies of India, none of them are presently Accountable to Parliament of India, informs Praveen Dalal, managing partner of New Delhi based ICT law firm Perry4Law and CEO of exclusive Human Rights Protection Centre for Cyberspace in India. This casts a doubt about the Impartiality and Transparency of these Agencies, suggests Dalal. Exempting these Agencies without any parallel “Parliamentary Oversight” is against the provisions of Indian Constitution, informs Dalal.

In these days the role of Indian Parliament has been reduced to almost nothing. Important laws are never passed and existing laws like the cyber law of India have been made e-surveillance instrumentality for Indian government and its agencies. The Parliament of India needs to take its legislative role seriously, at least now.

Friday, June 3, 2011

Techno-Legal Measures To Prevent ATM Frauds In India

Reserve Bank of India (RBI) has recently released the report of its working group on securing card present transaction that covers ATM security as well. RBI has also prescribed cyber security due diligence for banks of India. Despites these pro active steps, ATM frauds are increasing in India.

ATM frauds are executed by techniques like wire tapping, replicating the digital signature of the card, getting authentic personal data at fake data call centres, tampering ATM slots by rigging, phishing through e-mail accounts and fixing hidden cameras at vantage points inside ATM installations to steal the secret PIN number of the customers. Fraudsters use special devices like skimmers, duplicate ATMs, to withdraw stacks of money from ATMs.

In this interview of Praveen Dalal, Managing Partner of New Delhi based ICT Law Firm Perry4Law and leading Techno Legal Expert of India, he has shared the techno legal methods to prevent ATM Frauds in India. ATM frauds can be tackled by using techno legal measures alone.

Q-1 Apart from the spamming and phishing, what are the various kinds of ATM frauds? Please specify the ones that take place at the ATM machine or at the counter.

A.1 ATM frauds happen when someone leaves his/her credit card unattended in a vehicle or changing room or allows anyone else to use the card or looses the card that is misused by others or discloses the Personal Identification Number (PIN) to others, etc. These mistakes allow the offender to withdraw money by using the stolen information. Fraudsters are using special devices, skimmers, duplicate ATMs, etc to withdraw money from ATMs. Sometimes such frauds are an insider job with the collusion of the employees of the company issuing those cards.

Q-2 Out of all the techniques, which one is the most common?

A.2 The misuse of disclosed PIN for withdrawing money is the most common techniques used for committing ATM Frauds.

Q. 3 What the individual can do to avoid their money from being siphoned off due to ATM fraud?

A.3 Some basic precautions by the card holders can be very effective in preventing ATM frauds. For instance, never leave your credit card unattended in a vehicle or changing room, never allow anyone else to use your card, always retain sales/charge slips to compare with the amount specified on the billing statement, do not disclose your PIN to anyone, etc.

Q. 4 Is any new technology available to handle ATM frauds? If yes, please elaborate.

A.4 The technological mechanisms like Designated time, Microchip technology, Biometric tokens, Enhanced security, ATM Monitoring, Customised softwares, Customer motivation, Alerts, etc can be used to minimise and prevent ATM frauds in India.

Q.5 What is the scenario abroad? Are ATM frauds more rampant outside?

A.5 The culture of e-banking is more prevalent in foreign countries. Obviously, the menace of ATM frauds is more in those countries. However the problem of ATM frauds is global in nature and its ramifications have been felt in India as well. Information and Communication Technology (ICT) is forcing Indian legal system to adapt itself as per its requirements. Presently, there is a lack of legal enablement of ICT systems in India and we need good laws in this regard.

Q. 6 What does IT Act 2000 say about ATM frauds?

A.6 The IT Act, 2000 does not contain any specific provisions regarding the same and the traditional law of IPC, 1860 also cannot be relied solely and independently to tackle this problem. We need a better law for this purpose and Perry4Law has already provided its suggestions and recommendations in this regard and other ICT related matters to the Government of India, Department of Information Technology, Department of Science and Technology, Prime Minister’s Office, etc. Till we have suitable and apt laws, we must apply existing laws in a purposive and updating manner.

Tuesday, May 10, 2011

India Has Become An E-Police State

This is the updated version of my previous article on similar topic. Cyber law of India is incorporated in the information technology act, 2000 (IT Act 2000) that was drastically amended through the information technology amendment act 2008 (IT Act 2008). The cyber law of India has become so offensive and useless that it requires an urgent repeal. Instead of following the right path, India has chosen to become an e-police state.

Suggestions have been given in the past that United Nations (UN) must protect human rights in cyberspace as well. However, UN is not serious about protecting human rights in cyberspace. Countries like India are taking advantage of this void created by inaction on the part of UN.

Human Rights in Cyberspace are outlawed in India, says Praveen Dalal, managing partner of New Delhi based ICT law firm Perry4Law and leading techno legal expert of India. In fact, the IT Act, 2008 has made the sole Cyber Law of India susceptible to the attacks of “Unconstitutionality” as it is now openly and blatantly violating various Fundamental Rights as incorporated in the Constitution of India, informs Dalal.

Cyber law of India has been doomed to its detriment and civil liberties of Indian citizens have been at their nadir. All this has happened due to lack of insight and capabilities of Indian legislation makers. The vested interests have overshadowed public interest and the sole cyber law of India has become an instrumentality for mass deprivation and grave suppression of cyber rights of Indians. E-surveillance in India has come as a death knell for privacy rights in India.

Despite the assurances of the law minister Mr. Veerappa Molly regarding further amendments in the IT Act 2008, the same has been notified. This has officially given India the status of a chronic e-surveillance State. The unreasonable and unconstitutional e-surveillance and draconic police state powers conferred by the IT Act 2008 have become the law of the land.

Indians have ceased to hold some of the basic human rights in cyberspace and the omnipresent state powers have doomed the Indian cyber sphere. The accountability is missing and the reasonableness deliberately scrapped off from the provisions contained in the IT Act 2008. Even basic level encryption that is absolutely essential for safe and secure cyber space transactions has been under scrutiny. We have neither encryption standards in India nor encryption laws and regulations in India.

It is ironic that the Ministry of Law, Government of India and Mr. Molly finally gave away the freedom and security of India netizens in the hands of otherwise incompetent and inexperienced officials. How the Law Ministry allowed these unconstitutional provisions to be passed is still a bigger mystery?

The IT Act 2008 is a dark moment for the Indians wherein their rights have been curtailed on the one hand and the law has been made impotent on the other. Most of the offences have been made bailable and the deterrent has been lost forever. The misuse of the unbridled powers is very likely to happen as there are no safeguards and reasonable procedures that can prevent the same.

What would be the next step? Perhaps we would not be allowed to write articles like these in future as well if we keep on sleeping like we have been doing in the past. Alternatively, we must use self defence in cyberspace to defeat unconstitutional and illegal e-surveillance and Internet censorship exercises of Indian government and its agencies.

Friday, April 29, 2011

Cyber Crime Investigation Capabilities in India

India has a single law on cyber crimes. The cyber law of India is named as information technology act, 2000 (IT Act, 2000) and it is the sole cyber law of India. IT Act 2000 is also the sole law that deals with cyber crimes.

Cyber crimes in India have increased unchecked and dramatically partly due to the weak cyber law of India and partly due to poor cyber law knowledge among the police officers. This results in many cyber crimes remaining undetected and unsolved. Further, lawyers and judges are also not aware of cyber law of India and its fine details. This is the chief reason that in India we have very few cyber crime convictions.

Even on the front of cyber security India is not well situated. India is facing serious Cyber Threats and it needs good Techno Legal Skill Development Initiatives to have skilled manpower to meet such challenges, suggests Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and CEO of Perry4Law Techno Legal Base (PTLB).

It seems India has also realised that in the absence of adequate skills it cannot meet the challenges to its internal security. This is the reason why public private partnership (PPP) has been proposed for even internal security matters of India. World renowned techno legal institutions like PTLB can greatly help Indian government in maters like cyber law, cyber security, telecom issues, cyber forensics, digital evidencing, e-courts, e-discovery, cyber crimes investigations, etc.

In fact, the first techno legal cyber crime investigation manual of India would be released shortly by PTLB. PTLB is also providing exclusive courses on techno legal cyber law skill development in India. There are other techno legal skill development courses as well that are provided by PTLB.

The cyber crime investigation capabilities of India need to be enhanced. Police officers, lawyers and judges must be given suitable techno legal trainings so that cyber criminals can be nabbed and punished. Even the cyber law of India need to be repealed and a new and strong cyber law must be enacted. The sooner this is done the better it would be for the larger interest of India.

Monday, April 18, 2011

Home Ministry Mulls Lawful Interception Law Of India

Lawful Interception is a process that “Reconciles” the National Security requirements and Civil Liberties of a Nation. In the Indian context, we have no Lawful Interception Law in India. By Lawful Interception Law I mean a “Constitutionally Sound” Lawful Interception Law and not just any “Self Serving Law”- Praveen Dalal.

World over civil liberties are infringed using information and communication technology (ICT). In the past, Indian telecom companies have used private individuals to do phone tapping. Experts like Praveen Dalal have been suggesting enactment of a “constitutionally sound” lawful interception law in India. Till now we do not have a constitutionally sound lawful interception law in India and the same is urgently required.

On the top of it we have projects like central monitoring system (CMS), national intelligence grid (Natgrid), Aadhar, crime and criminal tracking network and systems (CCTNS), etc that are not governed by any legal framework and procedural safeguards.

We also do not have any encryption laws in India nor do we have any encryption standards in India. Further, India has a poorly drafted and decayed cyber law in the form of information technology act, 2000 that needs urgent repeal, inadequate cyber security, missing cyber forensics capabilities, inadequate critical infrastructure protection and so on.

In this background, the home ministry has asked the departments of telecommunication (DoT) and department of information technology (DIT) to examine the existing legal framework and recommend appropriate amendments of the laws to ensure smooth access to services like BlackBerry and Skype.

The home ministry has asked DoT and DIT to examine the Indian Telegraph Act 1885, Information Technology (Amendment Act), 2008, rules under the Telegraph and IT Act and provisions in the licence agreements and recommend appropriate amendments so that requirements, to the extent possible, are incorporated in the Act itself. However, India needs a dedicated lawful interception law and not just few amendments in the present outdated laws.

According to Praveen Dalal, managing partner of New Delhi base law firm Perry4Law and leading techno legal expert of India, India is the only country of the World where Phone Tapping and Interceptions are done without a Court Warrant and by Executive Branch of the Constitution of India. Phone Tapping in India is “Unconstitutional” and the Parliament of India has not thought it fit to enact a “Constitutionally Sound Law” for Phone Tappings and Lawful Interceptions. Even the Supreme Court’s directions in PUCL case have proved futile and presently the Court is dealing with the issue once more, informs Dalal.

The present action of home ministry seems to be in response to these developments that are “unconstitutional” in nature. These activities of Indian government and its agencies can be challenged in Indian higher courts as unconstitutional as violative of fundamental rights of Indians. Let us hope the Parliament of India would soon come up with a constitutionally sound lawful interception law of India.

Wednesday, March 16, 2011

CMS As The Internet Kill Switch Of India

Internet censorship in India has increased tremendously and that also without a constitutionally sound lawful interception law in India. Internet censorship requires a good balance between civil liberties and law and order and national security requirements. Presently, the approach of Indian government is leaning heavily towards e-surveillance and Internet censorship without much regard to civil liberties of Indians in cyberspace.

Take the example of Internet kill switch (IKS) that has been in limelight these days. Lots of people are talking about IKS without knowing where it exists and how it can be used. The Indian equivalent of IKS can be found in the form of central monitoring system (CMS), which is a centralised mechanism that can assist in lawful interception of communications from landline, mobile and Internet. Although it can be used only if there is a lawful interception law in India yet it seems to have been tested recently without any lawful interception law in India at place.

According to Praveen Dalal, leading techno legal expert of India and managing partner of New Delhi based law firm Perry4Law, the present Cyber Law of India is incorporated in the Information Technology Act, 2000 (IT Act 2000), as amended by the Information Technology Amendment Act 2008 (IT Act 2008). It also carries provisions regarding Internet Censorship and Website Blocking but without any “Procedural Safeguards and Guidelines”. This amounts to taking away “Fundamental Rights” of Indians without Reasonable Restrictions and without prescribing any “Procedural Safeguards” to prevent use of this abusive power, says Dalal.

Recently the Blogspot domain (hosted services) and sub domain (free blogs) were systematically blocked by many of the internet service providers (ISPs) of India. Even Google did not give any reason as to the cause of this outage. Google had enough time to analyse the traffic reports and respond back yet it preferred to keep a mum due to commercial interests it has in Indian market.

This outage may be an “experimental blockage” that took place at the point where Internet traffic enters and exits India. This exercise may have different names. Some may call it an Internet kill switch whereas others may call it a centralised monitoring system. At this stage it is not the nomenclature that is important but the need to put measures and safeguards to prevent its abuse in India.

So next time when we discuss about Internet kill switch of India, we must keep in mind the central monitoring system project of Indian government. If Indian government is not committed to safeguard our civil liberties, we must use self defence measures to protect our civil liberties in cyberspace.