Sunday, January 17, 2010

India Caught On The Wrong Foot Of Cyber Anarchy

This work is analysing the strategic and policy lacunas of Indian Government in the fields of Cyber Law, Cyber Security, Cyber Forensics, etc. As a result India has not only become a safe heaven for cyber criminals but also a “soft target” for hackers and cyber war criminals worldwide. A dominant majority of work, suggestions and recommendations in these crucial directions have been done/provided by Mr. Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India. This work is summarising his suggestions and recommendations (with his approval) and we hope the Government of India in general and the Prime Minister Mr. Manmohan Singh in particular would consider and act upon these suggestions.

Cyber law enforcement and regulation passing through a bad phase in India. It is evident from the recent attack by the Chinese Hackers to the computers in the Prime Minister's Office (PMO). The sinister attempt was made around December 15 last year. Investigators are still coming to terms with the depth of the damage. There is hardly any conviction of cyber criminals in India. On the one hand India has bad and weak cyber law whereas on the other hand law enforcement is hardly aware about the basics of cyber law and cyber forensics. India has become a safe heaven for cyber criminals. The hackers had aimed high - their targets were the cream of India's national security set-up: National Security Advisor M.K. Narayanan, Cabinet Secretary K.M. Chandrashekhar, PM's Special Envoy Shyam Saran and Deputy National Security Advisor Shekhar Dutt. The four and up to 26 others were squarely in the crosshairs of the hacking attempt.

A top PMO official, whose e-mail account was cracked by the Chinese hackers, confirmed the espionage bid, saying: These kind of hacking attempts are made. To think they are not made is wrong. The internet or intranet is not used for official purposes. As per the India Today, According to Bharat Karnad, a strategic affairs analyst, "China wants war by all means. It doesn't believe in peacetime. For China, it's always rivals, always competition." R.S.N. Singh, a former RAW officer, says: "China wants to dominate and control this space. This cyber army has soldiers not in uniform but anybody and everybody, maybe college students. It's very serious as cyber warfare can bring a country to a crippling halt."

The timing of the espionage attempt has investigators suspecting that the Chinese hackers were desperately trying to access any data on India's position at the Copenhagen Climate Summit. Until Prime Minister Manmohan Singh arrived in Copenhagen on December 17, Environment Minister Jairam Ramesh and PM's Special Envoy Shyam Saran were singing different tunes. While Ramesh was in favour of scrapping the Kyoto Protocol, Saran was against the move. On December 15 when India's final stand was still shrouded in mystery, the Chinese hackers targeted the PMO computers.

But what has disturbed investigators the most is that the Chinese hackers quite likely had inside help. The possibility of a mole within the Indian establishment helping a foreign adversary is staring investigators in the face. And the technology being used is preoccupying the Indian sleuths no end. The espionage attempt was highly evolved and well-researched. The mail was routed through several multi-proxy servers thus obliterating the trail. The hacking spyware itself was embedded in a PDF document. And the trojan was programmed to carry out an array of functions, including downloading files, accessing emails and passwords and also accessing the desktop from a remote location.

The police officers, lawyers and judges must be trained in cyber law aspects so that cyber criminals may be suitably punished. In the absence of proper training, there is almost no conviction of cyber criminals in India. To fight the cyber crimes the Crime and Criminal Tracking Network & Systems (CCTNS) Project has been approved by the Cabinet Committee on Economic Affairs Govt. of India. It has a financial cushion of Rs.2000 Crores as per the 11th Five Year Plan. The Project would be initiated by the Ministry of Home Affairs and implemented by the National Crime Records Bureau. The CCTNS project is to be implemented in a manner where the major role would lie with the State Governments in order to bring in the requisite stakes, ownership and commitment, and only certain core components would be in the hands of the Central Government, apart from the required review and monitoring of project implementation on a continuing basis.

The broad objectives of the CCTNS project are streamlining investigation and prosecution processes, strengthening of intelligence gathering machinery, improved public delivery system and citizen-friendly interface, nationwide sharing of information across on crime and criminals and improving efficiency and effectiveness of police functioning. The Project aims to fulfill various specified objectives over a period of three years. cases registered at Police Stations; obtaining copies of FIRs, post-mortem reports and other permissible documents etc. An indicative list of e-services expected from CCTNS to citizens would be filing of complaints / information to concerned Police Station; obtaining status of complaints.

The information technology is a double edge sword, which can be used for destructive as well as constructive work. For instance, a malicious intention forwarded in the form of hacking, data theft, virus attack, etc can bring only destructive results unless and until these methods have been used for checking the authenticity, safety and security of the technological device which has been primarily relied upon and trusted for providing the security to a particular organisation.

In fact, a society without protection in the form of "self help" cannot be visualised in the present electronic era. Thus, we must concentrate upon securing our ICT and e-governance bases before we start encashing their benefits. The same can be effectively achieved if we give due importance to this fact while discussing, drafting and adopting policies decisions pertaining to ICT in general and e-governance in particular. The same is also important for an effective e-commerce base and an insecure and unsafe ICT base can be the biggest discouraging factor for a flourishing e-commerce business. The factors relevant for this situation are too numerous to be discussed in a single work. Thus, it would be better if we concentrate on each factor in a separate but coherent and holistic manner. The need of the hour is to set priority for a secure and safe electronic environment so that its benefits can be reaped to the maximum possible extent.

The ubiquitous use of computers and other electronic devices is creating a rapidly rising wave of new and stored digital information. The massive proliferation of data creates ever-expanding digital information risks for organizations and individuals. Electronic information is easy to create, inexpensive to store, and virtually effortless to replicate. As a result, increasingly vast quantities of digital information reside on mass storage devices located within and without corporate information systems. Information risks associated with this data are many. For example, electronic data can often show — with a high degree of reliability — who said, knew, took, shared, had and did what, and who else might be involved in the saying, knowing, taking, sharing, having, and doing. For the corporation, the free flow of digital information means that the backdoor is potentially always open to loss.

It is best to state up-front that the emphasis in any cyber forensic examination must be on the forensic element, and it is vital to understand that forensic computing, cyber forensics, or computer forensics is not solely about computers. It is about rules of evidence, legal processes, the integrity and continuity of evidence, the clear and concise reporting of factual information to a court of law, and the provision of expert opinion concerning the provenance of that evidence: Companies are very concerned about the notion that anything they write electronically can be used again at any time. If you have to discipline yourself to think, "can this be misconstrued?" that greatly hampers your ability to communicate and introduces a huge level of inefficiency.

One such improvement that is urgently required to be adopted, implemented and inculcated by the Judges of District Courts, High Courts and Supreme Court of India pertains to Techno-Legal acumen and knowledge. Techno-Legal acumen is difficult to acquire as it requires a sound working and practical knowledge of both technical as well as legal aspect of the Information and Communication Technology (ICT) related aspects. Issues like Cyber Law, International Telecommunications Laws, Cyber Forensics, Digital Evidencing, Cyber Security, etc pose difficult and sometimes non-understandable legal issues before the Courts. The Judges in India must fill in this much needed and unnoticed legal gap that has not yet been explored by them.

The establishment of E-Courts in India requires certain prerequisites. These are: E-Courts Policy, Data Keeping, and Payment Gateway. Simplicity And User Friendly Connectivity, Scope, Authentication, Integrity, Security. However, if the courts have to keep in step and play their part in restoring public confidence in the legal system then they must find new ways to improve the efficiency and effectiveness of their operations. Information and Communication technology (ICT) can be a panacea for the dying judicial system of India. We can effectively use ICT for establishment of E-Courts in India so that E-Judiciary in India can be a reality. However, the task is really difficult to achieve because of lack of expertise and absence of time bound performance. Every year in the month of February, the tenure of E-Courts Committee is extended for another year. This shows there is a lack of Political Will to achieve the task as merely extending time for another year without performance report and accountability is just a pretext to avoid the ultimate accomplishment, i.e. establishment of E-Courts in India.

The fact remains that despite all glamorous conferences and public announcements, we do not have even a single E-Court in India and there is not even a single case that has been filed, contested and finally adjudicated through an E-Court System in India. Where those claimed E-Courts are and what cases they had adjudicated is still a big mystery. It seems India is just making press statements years after years and courts after courts about establishment of E-Courts in India without actually establishing and operationalising them. The task of their establishment and operationalising cannot be accomplished till we honestly and dedicatedly try to achieve the same. Till now India is just adopting the half hearted efforts and evasive approach.

The Cyber Forensics has given new dimensions to the Criminal laws, especially the Evidence law. Electronic evidence and their collection and presentation have posed a challenge to the investigation agencies, prosecution agencies and judiciary. The scope of Cyber Forensics is no more confined to the investigation regime only but is expanding to other segments of justice administration system as well. The justice delivery system cannot afford to take the IT revolution lightly. The significance of cyber forensics emanates from this interface of justice delivery system with the Information Technology.

Evidence must be gathered by law enforcement in accordance with court guidelines governing search and seizure. The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but on probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized. Computer crime is escalating.

The growing use of IT has posed certain challenges before the justice delivery system that have to be met keeping in mind the contemporary IT revolution. The contemporary need of Cyber Forensics is essential for the following reasons: The traditional methods are inadequate: The law may be categorised as substantive and procedural. The substantive law fixes the liability whereas the procedural law provides the means and methods by which the substantive liability has to contended, analysed and proved. The procedural aspects providing for the guilt establishment provisions were always there but their interface with the IT has almost created a deadlock in investigative and adjudicative mechanisms. The challenges posed by IT are peculiar to contemporary society and so must be their solution. The traditional procedural mechanisms, including forensic science methods, are neither applicable nor appropriate for this situation. Thus, "cyber forensics" is the need of the hour. India is the 12th country in the world that has its own "Cyber law" (IT Act, 2000). However, most of the people of India, including lawyers, judges, professors, etc, are not aware about its existence and use. The traditional forensic methods like finger impressions, DNA testing, blood and other tests, etc play a limited role in this arena.

The changing face of crimes and criminals: The use of Internet has changed the entire platform of crime, criminal and their prosecution. This process involves crimes like hacking, pornography, privacy violations, spamming, phishing, pharming, identity theft, cyber terrorisms, etc. The modus operendi is different that makes it very difficult to trace the culprits. This is because of the anonymous nature of Internet. Besides, certain sites are available that provides sufficient technological measures to maintain secrecy. Similarly, various sites openly provide hacking and other tools to assist commission of various cyber crimes. The Internet is boundary less and that makes the investigation and punishment very difficult. These objects of criminal law will become a distant reality till we have cyber forensics to tackle them.

There is a dire need to compare the traditional crimes and criminals with the crimes and criminal in the IT environment. More specifically, the following must be the parameters of this comparison: Nature of the crime; Manner/Methods of commission of the crime; Purpose of the crime; Players involves in these crimes, etc.

Thus, Cyber Forensics is required to be used by the following players of criminal justice system: Investigation machinery- Statutory as well as non-statutory; Prosecution machinery, and; Adjudication machinery- Judicial, quasi-judicial or administrative; Jurisdictional dilemma: The Internet is not subject to any territorial limits and none can claim any jurisdiction over a particular incidence. Thus, at times there is conflict of laws. The best way is to use the tool of Cyber Forensics as a "preventive measure" rather than using it for "curative purposes.

Cyber Forensics is different from E-Discovery, Digital Recovery or other synonymous terms. Cyber Forensics primarily caters the "Legal Requirements" whereas E-Discovery meets the requirements of private individuals and organizations.

The management of the organisation decides to trace the origin of this breach. After proper analysis they come to know about the source of that breach. Till this stage it is only an E-Discovery. The management can take whatever preventive or remedial measure as it may deem fit.

If the management decides to take a "Legal Action" against the offender, it has to prove the acquired digital evidence before the Court of Law. Mere E-Discovery may not be enough to prove the guilt of the accused as legal requirements regarding evidence and procedural laws must also be complied with. When the E-Discovery is "Law Compliant" it becomes "Cyber Forensics".

Similarly, there are certain laws that require individuals and organisation to exercise "Due Diligence" and "Statutory Compliances". These requirements may fall either in the category of E-Discovery or Cyber Forensics as per the facts and circumstances of each case. The contemporary practice is to perform live analysis to get useful volatile data that is lost the moment a computer is turned off or after the pulling of the plug.

Computer Forensics deals with the preservation, identification, extraction, and documentation of computer evidence. The field is relatively new to the private sector but it has been the mainstay of technology-related investigations and intelligence gathering in law enforcement and military agencies since the mid- 1980s. Like any other forensic science, computer forensics involves the use of sophisticated technology tools and procedures that must be followed to guarantee the accuracy of the preservation of evidence and the accuracy of results concerning computer evidence processing.

It is extremely important to realize that evidence must have been gathered and that computer-generated evidence is considered "hearsay" with some exclusion. Depending on your role or responsibility in the computer forensics investigation, you may be subject to differing sets of rules and regulations. Internal investigators. Typically, computer forensic tools exist in the form of computer software.

Computer forensic specialists guarantee accuracy of evidence processing results through the use of time-tested evidence processing procedures and through the use of multiple software tools, developed by separate and independent developers. The use of different tools that have been developed independently to validate results is important to avoid inaccuracies introduced by potential software design flaws and software bugs. The introduction of the personal computer in 1981 and the resulting popularity came with a mixed blessing. Society in general benefited, but so did criminals using personal computers in the commission of crimes. Today, personal computers are used in every facet of society to create and share messages, compute financial results, transfer funds, purchase stocks, make airline reservations, and access bank accounts and a wealth of worldwide information on essentially any topic. Computer forensics is used to identify evidence when personal computers are used in the commission of crimes or in the abuse of company policies. Computer forensic tools and procedures are also used to identify computer security weaknesses and the leakage of sensitive computer data. In the past, documentary evidence was typically stored on paper and copies were made with carbon paper or photocopy machines.

Most documents are now stored on computer hard disk drives, floppy diskettes, Zip disks, and other forms of removable computer storage media. Computer forensics deals with finding, extracting, and documenting this form of "electronic" documentary evidence. Along the way, prior to formally pursuing a cyber forensics investigation, several important and critical questions must be asked:

The growing use of ICT for administration of all the spheres of our daily life cannot be ignored. Further, we also cannot ignore the need to secure the ICT infrastructures used for meeting these social functions. The threat from "malware" is not only apparent but also very worrisome. There cannot be a single solution to counter such threats. We need a techno-legal "harmonised law". Neither pure law nor pure technology will be of any use. Firstly, a good combination of law and technology must be established and then an effort must be made to harmonise the laws of various countries keeping in mind common security standards. In the era of e-governance and e-commerce a lack of common security standards can create havoc for the global trade in goods and services. The tool of Cyber Forensics, which is not only preventive but also curative, can help a lot in establishing a much needed judicial administration system and security base.

Referred Works

1. Praveen Dalal, Cyber Security In India: An Ignored World

2. Praveen Dalal,
Cybercrime and cyberterrorism: Preventive defense for cyberspace violations

3. Praveen Dalal,
Cyber Forensics In India

4. Shayam Prasad,
Law Enforcement In India Needs Techno-Legal Training

5. Techtalk,
Home Ministry Of India Is Taking Wrong Cyber Security Measures

6. Techtalk,
Crime and Criminal Tracking Network And Systems Of India

7. Praveen Dalal,
TECHNO-LEGAL SUPPORT AND TRAINING FOR CRIME AND CRIMINAL TRACKING NETWORK AND SYSTEMS (CCTNS) PROJECT OF INDIA

8. Praveen Dalal,
TECHNO-LEGAL JUDICIAL TRAINING IN INDIA

9. Praveen Dalal,
E-COURTS IN INDIA: AN ESSENTIAL JUDICIAL REFORM

10. University of California at Berkeley, School of Information Management and Systems, October 2000,
http://www.sims.berkeley.edu/how-much-info/.

11. Designing a Document Strategy: Documents…Technology…People. Craine, K., MC2 Books, 2000.

12.
http://www.cyber-forensic-analysis.com/CyberForensicsIndex.pdf

13 Praveen Dalal, "Securing cyberspace by private defence",

14. Praveen Dalal, "ICT strategy in India: The need of rejuvenation.

15
http://indiatoday.intoday.in/site/Story/79215/India/Chinese+hackers+target+PMO+computers+.html

16. Tabrez Ahmad, Lessons for India in the Backdrop of Chinese Hackers Attack on PMO

Saturday, January 16, 2010

The Irrational Cyber Laws Of The World

The Google’s episode regarding China’s censorship shows the growing hunger of various nations for Internet censorship and e-surveillance. India is no different from China when it comes to “Internet Censorship” and “E-Surveillance”, though the extent and degree may be somewhat lesser. The Information Technology Act 2000 (IT Act 2000) is the sole cyber law of India that was amended by the Information Technology Act 2008 (IT Act 2008). From here starts the real problem.

According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “The IT Act 2008 made India a “Safe Heaven” for cyber criminals on the one hand and an “Endemic E-Surveillance Society” and “Internet Censorship State” on the other hand. It seems the main aim of the proposed IT Act 2008 was to strengthen the “Internet Censorship” and “E-Surveillance Capabilities” of India.

With the passage of IT Act 2008 India has now officially become an endemic e-surveillance society. The amendments have provided unregulated, unconstitutional and arbitrary e-surveillance and Internet censorship powers to Government of India and its agencies and instrumentalities, says Praveen Dalal. The fact is that India has become an E-Police State, states the ICT Trends of India 2009.

Surprisingly, Minister of State for Communication Sachin Pilot believes that Indian cyber law is strong enough to meet the challenges posed by technology-assisted terrorism and cyber-terrorism. It seems he has not gone through the present IT Act 2000 after its 2008 amendments.

Some observers in India have rejoiced the exit of Google from China believing that it may be a good opportunity for India. However, they fail to understand the “ground reality” that India is no different from China when it comes to Internet Censorship and E-Surveillance. If India does not abdicate its alliance to Internet censorship and e-surveillance similar incidence may happen in India as well.

Cyber Security Initiatives Of Home Ministry Of India Are Insufficient

Cyber security in India has always remained an “ignored world” and the same must be strengthened as soon as possible. India is also suffering from the menaces of cyber war and cyber terrorism. Nobody cares about any of these threats in India. In April 2008, Indian intelligence agencies detected Chinese hackers breaking into the computer network of the Ministry of External Affairs. Similarly, for about 3 months the e-mail communications from PMO got affected as the e-mail system was affected by a virus program. With the highest offices of India being so indifferent and adopting wrong cyber security strategies not much can be expected in this crucial direction in future as well.

Recently it was reported that the Chinese intelligence agencies may have planted computer malware and broken into the headquarters of 33 Corps, the army formation looking after most of the north-eastern border with China. The break-in included the planting of trojan viruses which may have given Chinese operatives remote access to the computer network at the 33 Corps headquarters in Sukhna, near Siliguri, West Bengal.

The Union Home Ministry is considering the option to ban the use of Internet by the lower rank staff up to section officers. Many computers of the Home Ministry were found infected with different kinds of computer viruses. However, does this step increase the cyber security of Indian offices?

According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “Home Ministry is barking the wrong tree as security through obscurity and non-access in itself and without further steps is a bad choice. The Government of India must concentrate upon “Capacity Development” of not only its employees but also its core Departments and Offices”.

Another crucial aspect related to a secure and strong cyber security in India pertains to critical ICT infrastructure protection in India. Critical infrastructure is becoming increasingly dependent upon ICT these days. If we are unable to secure an ICT system we are also risking critical ICT infrastructure as well, says Praveen Dalal.

Indian government must concentrate upon many crucial aspects of cyber security. The task is difficult and time consuming hence it must start seeking the help of the right and capable manpower as soon as possible.

SOURCE: ITVOIR

Friday, January 15, 2010

Indian National Security Needs Information Warfare Capabilities

Information Warfare and Cyber Terrorism are issues that cannot be taken lightly by any country. From these threats emerge the necessity of having a robust cyber security for defense forces in India. These issues are important as they strike at the very root of the critical ICT infrastructure protection in India. However, India is not doing the needful in this regard. Cyber War Capabilities should be an Integral Part of Indian National Defense and Security says India’s leading Techno-Legal Expert Praveen Dalal.

Today countries all over the World are actively engaged in some form or other of Cyber war/Information warfare. For instance, the US Air Force has had Information Warfare Squadrons since the 1980s. In fact, the official mission of the US Air Force is now, "To provide sovereign options for the defense of the United States and its global interests. To fly and fight in Air, Space, and Cyberspace", with the latter referring to its Information Warfare role.

As the Air Force often risks aircraft and aircrews to attack strategic enemy communications targets, remotely disabling such targets using software and other means can provide a safer alternative. In addition, disabling such networks electronically (instead of explosively) also allows them to be quickly re-enabled after the enemy territory is occupied. Similarly, counter information warfare units are employed to deny such capability to the enemy. The first application of these techniques was used against Iraqi communications networks in the first Gulf War.

Also during the 1991 Gulf War, Dutch hackers stole information about U.S. troop movements from U.S. Defense Department computers and tried to sell it to the Iraqis, who thought it was a hoax and turned it down. In January 1999, U.S. Air Intelligence computers were hit by a coordinated attack, part of which appeared to come from Israeli and French hacking. These are some of the examples how Internet is becoming an essential part of modern warfare.

According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “India needs a sophisticated and robust technological command centre to defend its global network of computer systems. It must develop both offensive and defensive capabilities under one roof. Strategic information and tactical inputs are essential part of modern warfare that can be lost or gained through Cyber war methods”.

There is no doubt that India needs good cyber war capabilities to meet the growing threats of information warfare. It would be a good idea to have a “Centralised ICT Command Center” in this regard as suggested by Perry4Law for intelligence agencies of India.

SOURCE: ITVOIR

India Needs Good Cyber War Capabilities

Cyber War and Cyber Terrorism are matters of grave concern to all countries. Equally important are the issue pertaining to cyber security of defense forces in India. These issues are important as they strike at the very root of the critical ICT infrastructure protection in India. While countries like US and Russia are negotiating to limit the impact of cyber wars, India is not doing the needful in this regard. Cyber War Capabilities should be an Integral Part of Indian National Defense and Security says India’s leading Techno-Legal Expert Praveen Dalal.

The military version of cyber war has the potential to be as serious as a nuclear war in terms of creating chaos. It could crash power and water supplies, as well as trashing the global financial systems and information systems. Russia is in favour of an internet disarmament treaty, but the practical aspects are tougher than nukes ever were.

Malware are posing significant threat to India yet there is no attention towards cyber security in India. For instance, we need express provisions and specified procedures to deal with issues like denial of service (DOS), distributed denial of services (DDOS), bot, botnets, trojans, backdoors, viruses and worms, sniffers, SQL injections, buffer overflows etc. Till now India has done nothing in this crucial direction.

India is also suffering from the menaces of cyber war and cyber terrorism. Nobody cares about any these threats in India. Media reports claim that China’s intensified cyber warfare against India is becoming a serious threat to national security. In October 2007, Chinese hackers defaced over 143 Indian websites.

In April 2008, Indian intelligence agencies detected Chinese hackers breaking into the computer network of the Ministry of External Affairs forcing the government to think about devising a new strategy to fortify the system.

As a countermeasure, the Indian armed forces are trying to enhance their C4ISR capabilities, so that the country can launch its own cyber offensive if the need arises.

Similarly, Pakistan is taking steps to intensify its cyber war propaganda against India with the help of its intelligence outfit, the ISI by carrying reports of alleged communal fissures taking place on the Indian side of Kashmir. Issues like these have to be resolved as well.

India must immediately start working upon the issues like cyber war, cyber terrorism, critical infrastructure protection, etc in the larger national interest and national security.

SOURCE: MYNEWS

Thursday, January 14, 2010

Supreme Court Of India Must Be More Transparent And Fair

The Supreme Court is Supreme not because it is right but it is right because it is Supreme, says Praveen Dalal. According to him there are very few occasions when the trust and respect for the Indian Judiciary were at its nadir. During the infamous emergency imposition by the Center in the late 70s such public outrage was shown. Presently as well with the corruption in judiciary, slow speed of disposal of cases and adoption of double standards by the judiciary in matters like transparency and right to information, public trust and respect for judiciary has been on the lower side once again. However, the Delhi High Court has shown a great “Judicial Courage” by upholding the values of Constitution of India. It would be ironic if the Supreme Court becomes a “Judge of its own Cause” and negates the entire “Constitutional Philosophy” and “Administrative Law” of India, says Praveen Dalal.

Of late the Delhi High Court has shown tremendous judicial capabilities and strength by upholding the values of Constitution of India (COI). One after another it gave landmark judgments that were expected from the Supreme Court of India. At a time when the trust in the judicial system of India is falling to the lowest level this attitude of the Delhi High Court has emerged as a ray off hope in the dark clouds of judicial incapabilities.

While the District level courts are working more than good Delhi High Court has also joined this race and has become the sentinel of constitutional rights of Indian citizens. However, it cannot substitute the Supreme Court for many reasons. Although Delhi High Court is a court of law and a constitutional court, it has a major limitation. Its jurisdiction is confined to the limits of Delhi alone. On the other hand the Supreme Court of India is a “National Court” having wider powers and supreme authority.

The recent judgement of the Delhi High Court regarding declaration of assets by the Supreme Court is one of the best judgments it has ever given. Unfortunately, the same must have come from the Supreme Court itself. Having failed to do so, the Supreme Court must not now challenge the decision of Delhi High Court to itself in the Supreme Court. It would only undermine the dignity and trust of Supreme Court further. Instead the Supreme Court must now concentrate more upon damage recovery than further aggravating the situation, opined Praveen Dalal.

Time has come when the Supreme Court must change its mindset and attitude and gain more respect and dignity in the eyes of Indians. After all, it must remove the general perception prevalent among the Indian masses that the “Supreme Court is Supreme not because it is right but it is right because it is Supreme”.

SOURCE: ITVOIR

Tuesday, January 12, 2010

Judicial Standards Are Rising Again In India

There are very few occasions when the trust and respect for the Indian Judiciary were at its nadir. During the infamous emergency imposition by the Center such public outrage was shown. Presently as well with the corruption in judiciary, slow speed of disposal of cases and adoption of double standards by the judiciary in matters like transparency and right to information, public trust and respect for judiciary has been on the lower side once again. However, the Delhi High Court has shown a great “Judicial Courage” by upholding the values of Constitution of India, says Praveen Dalal.

In a landmark verdict against the Supreme Court, the Delhi High Court today held that the office of the Chief Justice of India comes within the ambit of the Right to Information (RTI) law, saying judicial independence is not a judge’s privilege but a responsibility cast upon him.

The 88-page judgement is being seen as a personal setback to CJI K. G. Balakrishnan, who has been opposed to disclosure of information relating to judges under the RTI Act.

A three-judge bench comprising Chief Justice A. P. Shah and Justices Vikramjeet Sen and S. Muralidhar dismissed a plea of the Supreme Court which contended that bringing the CJI’s office within the RTI Act would “hamper” judicial independence.

“The judicial independence is not a privilege to a judge but a responsibility,” the High Court said, adding that the CJI cannot be said to have fiduciary relationship (between a trustee and a beneficiary) with other judges.

Taking a step further to bring transparency in judiciary, the bench while pronouncing the verdict in a packed courtroom, said its judges will be making their assets public within a week.

The CJI has consistently been maintaining that his office does not come within the ambit of the RTI Act and the information including the declaration of assets of its judges cannot be made public under it.

SOURCE: HINDU

Monday, January 11, 2010

Is UIDAI A Privacy Violation And E-Surveillance Instrumentality?

The security and privacy issues of UIDAI have been raised times and again. The real problem seems to be that neither UIDAI nor its functions are legally valid and constitutionally sound. In its present form they are violative of not only the sacrosanct Human Rights but also the Fundamental Rights conferred by the Constitution of India (COI), says Praveen Dalal.

The first and foremost evil of UIDAI without a proper legal framework is that it would violate the “Right to Privacy” as conferred under Article 21 of the Constitution. This is not expressly mentioned in it but the same has been enunciated by way of judicial interpretation by the Supreme Court of India. India is a signatory to the International covenant on civil and political rights, 1966. Article 17 thereof provides for the “right of privacy”. Article 17 of the international covenant does not go contrary to any part of our municipal law. Article 21 has, therefore, to be interpreted in conformity with the international law.

Even the “Data Protection” requirements would pose big challenge before India. The amount of data collected for by UIDAI would be tremendous. Presently, India does not have either a legal framework or technical capabilities to accommodate the demands of the proposed functions of UIDAI.

The main aim of the proposed project by UID Project seems to be to strengthen the “E-Surveillance Capabilities” of India. With the passage of IT Act 2008 India has now officially become an endemic e-surveillance society. The amendments have provided unregulated, unconstitutional and arbitrary e-surveillance powers to Government of India and its agencies and instrumentalities. The fact is that India has become an E-Police State, states the ICT Trends of India 2009.

Privacy rights are valuable and must not be violated by the government under the garb of national security. An important question that has been raised in the past is whether the citizens have a right to self-defense against the State if the latter is violating their rights illegally? Private or self defense is a Human Right, Constitutional Rights as well as Statutory Right. The Indian citizens have a right to exercise self defense even against the State. This is more so in the sphere of ICT where there are least possibilities of human injuries. However the same can be exercised by law abiding citizens alone and criminals cannot claim this Constitutional Protection. The UIDAI Project must keep all these aspects in mind before being finally implemented in India.

SOURCE: ITVOIR

Wordpress Must Change Its Policy Regarding Copyright Violations

A recent copyright violation of an article on E-Courts in India by a person named Tabrez Ahmad has resulted in the analysis of copyright protection policy of Wordpress. Similar copyright violation was also notified to Google that duly removed the infringed material from respective Blogs of the infringer. However, Wordpress/ Automattic have failed to do the needful as per the Indian laws like Indian Copyright Act, 1957 and Information Technology Act 2000. This may raise serious legal issues in the near future vis-à-vis copyright violation issues in the cyberspace in India.

Wordpress is a fantastic blogging community. It has, however, a serious problem when it comes to preventing copyright violation of other users. The main problem lies with its “Policy” to deal with such copyright violation notices. Wordpress deals with copyright violation notices through its Digital Millennium Copyright Act Notice (DMCA Notice) page. It requires sending an emailed notice (“Infringement Notice”) providing the information described at the DMCA Notice page.

If Automattic takes action in response to an Infringement Notice, it will make a good faith attempt to contact the party that made such content available by means of the most recent email address, if any, provided by such party to Automattic. The Infringement Notice may also be forwarded to the party that made the content available or to third parties such as ChillingEffects.org.

All Infringement Notices need to be sent to prescribed e-mail as plain text emails without attachments (email attachments are discarded) and include the following or they will be deemed invalid:

(a) An electronic signature of the copyright owner or a person authorised to act on their behalf,

(b) An identification of the copyright claimed to have been infringed,

(c) A description of the nature and exact location of the infringing content,

(d) The name, address, telephone number and email address of the complainer,

(e) A statement by the complainer that he believe in good faith that the use of the content that he claims to infringe his copyright is not authorised by law or by the copyright owner or such owner’s agent and under penalty of perjury, that all of the information contained in his Infringement Notice is accurate, and that the complainer is either the copyright owner or a person authorised to act on his behalf.

If a DMCA notice is valid, Wordpress/ Automattic is required by law to respond to it by disabling access to the allegedly infringing content. What is frustrating is to know that Wordpress would not do anything even if it is a clear and obvious case of copyright violation. Wordpress must not force the entire population of the World to comply with the conditions of DMCA even if these provisions may not be applicable in a totally different jurisdiction. As per the amended Cyber law of India (through Information Technology Act 2008), an intermediary like Wordpress is liable for due diligence and other cyber crimes/copyright violations if it has actual knowledge. A simple notice is the only requirement under the Indian laws to invoke the jurisdiction of Indian courts.

Since the copyright violator is residing in Indian jurisdiction, Indian courts have jurisdiction to try issues arising out of violation of copyright as well as cyber law of India. There is no need for the Wordpress/ Automattic to insist upon fulfilling DMCA requirements in a very clear and apparent case of copyright violation. It would be interesting to observe how things would develop from this stage.

SOURCE: ITVOIR

Police In India Needs Techno-Legal Training

Cyber law enforcement is passing through a bad phase in India. There is hardly any conviction of cyber criminals in India. On the one hand India has bad and weak cyber law whereas on the other hand law enforcement is hardly aware about the basics of cyber law and cyber forensics.

The cyber forensics knowledge level of the police officers in India is much below the required level. On many occasions when the police teams have been asked to confiscate the computer found at the crime scene, they have ended up bringing the monitor only with them. Even they are not aware in which part of the computer does information resides. The police officers of cyber cells of various State police departments are not aware of the basics of computers. During a training session discussing Internet and other basics one of the constables enquired where the Internet building is located.

Recently Director-General of Police (Criminal Investigation Department and Training) D.V. Guruprasad confessed that the police have no clue how to handle cyber crime. In a marketing fraud case, the police had dumped desktops and laptops of the accused in a storeroom without realising they did not have the hard disks in them. When the head constable was asked about the hard disks, he did not know what they were. If this is the situation, there can be no cyber crimes conviction in India. With a weak cyber law, India has already become a safe heaven for cyber criminals, say experts.

According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “The police officers, lawyers and judges must be trained in “Techno-Legal” aspects so that cyber criminals may be suitably punished. In the absence of proper training, there is almost no conviction of cyber criminals in India”.

Time has come to take help of good techno-legal experts who can train the police officers, lawyers, judges, etc in this regard. Also the Information Technology Act 2000 must be suitable updated to so that it may cease to be a “criminal friendly legislation”.

SOURCE: MERINEWS

Sunday, January 10, 2010

Online Exams In India In Legal Tussles

Educational reforms in India are urgently required. However, the progress in this regard is far from satisfactory despite the best efforts of Ministry of Human Resource Development through Union Minister Mr. Kapil Sibal. The position is worst when it comes to online education in India. The educational reforms in India are victim of “Political Nepotism”, say experts like Praveen Dalal. Unless Government of India adopts an open mind approach and utilise the expertise of knowledgeable people, Indian educational reforms would always remain in doldrums.

Educational reforms in India are urgently required to maintain quality of education in India. The use of Information and Communication Technology (ICT) can achieve this arduous task provided we acquire the expertise to use the same.

Online education requires both state of the art technologies as well as effective laws. Even if we have all the favorable condition still there may be technical glitches or legal wrangles. But what would happen if we have inadequate technical capabilities coupled with criminal friendly cyber laws? The net result would be a demise of the e-learning and online education capabilities. The same is happening in India due to myopic insight and criminal friendly nature of government of India. Even the ICT Trends In India 2009 gave a negative report in this regard.

Indian online education system is very bad in shape. On the one hand we lack technical capabilities whereas on the other hand cyber criminals are on a ride without any deterrent law to desist them from attacking the server and other computer resources of educational institutions providing online education and exams facilities. The natural outcome was very obvious, i.e. legal disputes.

A CAT candidate has filed a writ petition in the Karnataka High Court, asking for the cancellation of the online CAT 2009 and re-introduce the paper-and-pencil format of the exam. The petition states that even though the method of computerised test is claimed to be foolproof, there were several cases of cheating, mismanagement, leaks, rampant reboots, viruses and general all-round mismanagement.

If the GOI still does not wake up, it must forget about attracting foreign universities and their opening of campuses in India. In fact, such foreign universities must not open any centre in India till India is ready, both technically as well as legally.

SOURCE: ITVOIR

Saturday, January 9, 2010

Law Enforcement And Cyber Forensics Training In India

The cyber forensics knowledge level of the police officers in India is much below the required level. On many occasions when the police teams have been asked to confiscate the computer found at the crime scene, they have ended up bringing the monitor only with them. Even they are not aware in which part of the computer does information resides. The police officers of cyber cells of various State police departments are not aware of the basics of computers. During a training session discussing Internet and other basics one of the constables enquired where the Internet building is located.

Recently Director-General of Police (Criminal Investigation Department and Training) D.V. Guruprasad confessed that the police have no clue how to handle cyber crime. In a marketing fraud case, the police had dumped desktops and laptops of the accused in a storeroom without realising they did not have the hard disks in them. When the head constable was asked about the hard disks, he did not know what they were. If this is the situation, there can be no cyber crimes conviction in India. With a weak cyber law, India has already become a safe heaven for cyber criminals, say experts.

According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “The police officers, lawyers and judges must be trained in “Techno-Legal” aspects so that cyber criminals may be suitably punished. In the absence of proper training, there is almost no conviction of cyber criminals in India”.

Time has come to take help of good techno-legal experts who can train the police officers, lawyers, judges, etc in this regard. Also the Information Technology Act 2000 must be suitable updated to so that it may cease to be a “criminal friendly legislation”.

SOURCE: MYNEWS

Friday, January 8, 2010

Security And Privacy Issues Of The Unique Identity Number Project Of India

The Unique Identification Authority of India (UIDAI) is not a legally constituted authority. In the absence of just and reasonable law(s) to support the same, it would violate the Human Rights and Fundamental Rights of the citizens of India, say techno-legal experts like Praveen Dalal. The interaction of Information and Communication Technology (ICT) with Human Rights is no more a science fiction and India must keep in mind the mandates of Human Rights Protection in Cyberspace while implementing projects that have no legal sanction and backing. The below mentioned opinion has raised some pertinent security and privacy violation issues in this regard.

The air is thick with schemes that will enable the state, and its agencies, to identify every resident, and to track what they are doing. The UIDAI, in its working paper, says that enrolment will not be mandatory, but acknowledges that in practice it is expected not to be voluntary. The ‘Registrars’, who will enroll people on to the data base, will be both private operators and government agencies, and they will be encouraged to insist that they will entertain only those who are willing to enroll. Over a short time, only those with UID numbers may find themselves able to access services.

That is the effort. Just on its own, it could even seem benign. There are two phenomena that take the innocence out of the exercise.

The first is ‘convergence’. ‘Convergence’ is about combining information. There are presently various pieces of information available separately, and held in discrete ‘silos’. We give information to a range of agencies; as much as is necessary for them to do their job. The passport agencies do not need to know how many bank accounts you have, or whether you drive a car. The telephone company need not know how you have insured your house. The police do not need to know how often you travel, not unless you are a suspect anyway. It is this that makes some privacy possible in a world where there are so many reasons why, and locations where, we give information about ourselves. The ease with which technology has whittled down the notion of the private has to be contained, not expanded. The UID, in contrast, will act as a bridge between these silos of information, and it will take the control away from the individual about what information we want to share, and with whom.

This is poised to completely change norms of privacy, confidentiality and security of personal information. The terms ‘security’ and ‘privacy’ seem to be under threat, where technological possibility is dislocating many traditional concerns.

The second phenomenon is ‘tracking’. Once the UID is in place, and convergence becomes commonplace, the movement of people, their monies, their activities can be brought together, especially since transactions from buying rice in a PDS shop to receiving wages to bank withdrawals to travel could begin to require the number. There is a difference between people tracking a state, and the state, and the ‘market’ tracking people. The UID is clearly not what it is presented as being: it is not benign, nor a mere number which will give an identity to those who the state had missed so far.

Interestingly, the working paper of the UIDAI starts with a claim that the UID will bring down barriers that prevents the poor from accessing services and subsidies by providing an identity, but soon goes on to clarify that the “UID number will only guarantee identity, not rights, benefits or entitlements”. Given that it is the powerlessness of the poor, inefficiency, the perception of the poor as not deserving of support, sympathy or rights, and the status of illegality foisted on them that stops them from getting what is due to them, and given that corruption and leakages in the system mutate and persist, this quick stepping back is wise indeed.

In the excitement about technology being deployed to do something that has not been done anywhere in the world, the importance of privacy and protection from misuse of personal information is getting eclipsed.

It is significant that the UIDAI working paper makes no mention of national security concerns, and the surveillance, and profiling, possibilities it will create. Yet, the UID is not a project in isolation. The NATGRID, which the UID will facilitate, places the whole population under surveillance; and the home minister is talking about a DNA bank.

Fallibility, the difficulties inherent in reaching those in extreme poverty, the choiceless existence on a database and the possibility of undesirable others getting hold of information only add to the scariness of the scenario that we seem to have accepted without discussion, challenge or debate. And, once accomplished, we would have reached a point of no return.

The writer is an independent law researcher.

SOURCE: INDIAN EXPRESS


India Needs Techno-Legal Capacity Development Says Praveen Dalal

Technical issues pertaining to cyber law, cyber security and cyber forensics have always haunted the law enforcement, lawyers and judges in India. As a result not much has been achieved either legally or judicially in this regard. Even the basic legal enablement of ICT systems in India is missing. Whether it is establishment of e-courts in India or cyber law and cyber forensics training of police officers, lawyers and judges in India, nothing is happening at the appropriate time and in the right direction. The results are very obvious. India is in emergent need of legal and judicial reform to sustain faith and trust in the law enforcement, legal and judicial system.

The problem gets further complicated when technical issues are merged with the complex legal problems. A “Techno-Legal Combination” of technical knowledge and legal acumen becomes an inevitable necessity in these circumstances. According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “The situation is really alarming as India is ignoring the seriousness of cyber crimes and technology related issues. There is almost no conviction of cyber criminals in India. To make the matter worst, the Information Technology Act 2008 made almost all the cyber crimes “bailable”. This means that the technically advanced cyber criminals have neither a technical nor a legal fear to prevent them from committing various cyber crimes. Even the law enforcement, lawyers and judges need techno-legal training so that the menace of cyber crimes can be tackled with an iron hand in India”.

Recently Director-General of Police (Criminal Investigation Department and Training) D.V. Guruprasad confessed that the police have no clue how to handle cyber crime. In a marketing fraud case, the police had dumped desktops and laptops of the accused in a storeroom without realising they did not have the hard disks in them. When the head constable was asked about the hard disks, he did not know what they were. If this is the situation, there can be no cyber crimes conviction in India, say experts. Cyber crime labs/cells/police stations are on no use when the cyber criminals cannot be convicted. In the absence of governmental efforts in this regard, world renowned techno-legal firms like Perry4Law can be really helpful in fighting cyber crimes in India.

Issues pertaining to hacking, data thefts, data security, cyber terrorism, financial frauds, privacy violations, etc must not be taken as lightly as has been done by India. There is an emergent need of making proper amendments in the Information Technology Act 2000 of India. Time has come to abdicate targets achieved on “papers only” and do some constructive and actual grounds work in the techno-legal field.

SOURCE: GROUND REPORT

Methods To Stop Terrorism And Important Learned Lessons

In this wonderful piece of work, Muhammad Bilal Iftikhar Khan has analysed the common mistakes that are committed while dealing with terrorism. He has also mentioned some great lessons that have been learnt in the past by taking wrong policy decisions to tackle terrorism. This is a worth piece to consider by Indian government that is presently engaged in a fight against terrorism.

Observation I

You cannot destroy liquid. Stab a knife in glass of water and water will give way to knife. Then after some time the rusting process will start and ultimately solid knife will rust. But if you put fire under the glass, the water will start evaporating but will only change form. Soon glass will be empty but water will still remain same but in other form.

Lessons

You cannot defeat a liquid force by just utilizing power of muscle. The strategy of use of force is counterproductive. If you want to defeat a liquid force you need to break it at atomic and molecular level.

Al Qaeda and Taliban cannot be defeated by sheer use of Force. Lessons of Operation Khanjer have clearly taught that troop surge will be waste of time. Use of force will only help extremists. With every innocent dead they will get more support.

They are liquid force, they will give way but this giving way is not victory because soon the rusting process will start on those who fight them. It’s exactly what happened to Soviet forces

To break this extremist force you need to break it on atomic and molecular level. This means stop use of force which cause collateral damage. It also means eliminate the conditions which help extremist forces. It also means to reckon demographic and ground realities and correct the mistakes committed. It also means winning hearts and minds of Muslims by adopting just policies in Palestine and Kashmir and Muslim Ummah in which they don’t feel losers. It also means to respect Muslims and their choices. Don’t force dictators on masses by supporting them.

And most importantly don’t fight extremism with extremism. When a civilized person becomes extremist, he become idiot and commits stupid mistakes. When US president has announced troops surge in Afghanistan, reports are coming that al Qaeda is shifting to Yemen and Somalia.

Al Qaeda is showing better strategic thinking. They are widening the battle field and exploiting the effects of American policies. More battle fields means US and NATO to stretch more. This means dispersion of force and resources. Extremists have advantage of flexibility, where as this advantage is not enjoyed by other side. Fights against these extremists according to their own wishes have already brought global economic recession. People of our world are crushing between civilized extremists and religious extremists.

To defeat religious extremists first of all stop fighting war according to their wishes. Please throw pre conceive ideas about each other. The amount of Islam phobic people in west and Europhobic/ west phobic people in Islamic world are the reason rationality is getting defeated and extremism weather Islamic or Western is winning. West should forget its colonial thinking pattern. They must see non western people as equivalent. Their thinking pattern is causing their double standards which are adding fire to already tense situation.

Leaders of west have greater responsibility because they owe their wealth and advancement to East which they exploited fully when they were colonial masters. They should give a small amount of riches back by investing in their old colonies for development. Remember empty stomach and poverty forces people to crime and incubate the extremist ideologies.

Observation Number II

Water always flows from high ground towards low Ground. According to Law of Nature water will not flow back to mountains. From seas and rivers will get evaporated, form clouds and winds will push it towards mountains.

Lessons

Extremism starts from the advance nations. Palestine issue is one big example. Colonial era and treatment of people of colonies is also another example. Then western support of dictators and those disliked by their people is another example.

Recent example of Prophet’s cartoons on which Majority of west exhibited more extremism the third world extremists is another big example. In west denying Holocaust is crime but to degrade a person who have billions followers is freedom of speech. Like Bulleh Shah, the Famous Sufi Poet said

میری بکل دے ÙˆÚ† چور “Thief is in my clock”

West should understand that a real extremist lies in their ranks. Its only third law of motion which becomes a reality in many cases.

Observation Number III

A capitalist do everything for the love of capital. Money is cold and non living that’s why those who love money become cold.

Lessons

I agree that Human are selfish by nature. In East and West ideologies are sold not for betterment of people but to achieve interests. Here Mullah sells religion. They have big Madrassas big cars etc etc.

In west those who advocate war and advocate extremism versus extremism, have big commercial interests. Some want to sell their arms and ammunition, other have their eyes on resources.

In east we have religious extremists and in west we have economic extremists. Both exploit common man. These vulture control media and information outlets. They motivate common man to become fodder of their selfish interests. A common man in East, like his human brother in west wants an honest life with food and security and a good life. He doesn’t want war or insecurity. His leaders on other hand, weather economic, political/ religious or military, know if conflict ends how will he earn?

It’s surprising to see how thinking pattern of OBL, Ayman Al Zawahiri, Billy Graham, and Garry Fall well, GW Bush, Tony Blair, and BAL Thackeray etc is the same and on other side thinking pattern of a common man living in East or in West matches.

It’s really tough to create but very easy to destroy. Our leaders both in East and in West like to destroy not to build

Observation Number IV

If you have to walk a thousand mile or just 10 steps, 1st step counts the most.

Lessons

I am not socialist, but I agree with socialists on couple of Points. We, the citizens of World should understand how we all are being exploited by our religious, economic and political elite.

We must understand, Our God, call him Allah, God, El, Baghwan … honored us by making us humans. If we cannot become humans we can never become Muslims, Hindus or Christians. Becoming a human is best way to thank creator.

Secondly if my neighbor is not happy, I cannot become happy. We live in globalize world where world has become a global village. If there is suffering in Palestine, I cannot run away from its effects. I know my leaders will never like conflicts and real politics to end because that’s how they earn and become rich but as human it’s my duty to elect humans not cold capitalist, and force them to formulate policies which will bring peace and prosperity not only for me but my other brethren with whom I share common ancestry and world.

For Feed Back write to mbik14@gmail.com

SOURCE: GROUND REPORT

Thursday, January 7, 2010

Cyber Crime Police Stations Of India In Bad Shape

The ICT Trends of India 2009 have proved that India has failed to enact a strong and stringent Cyber Law in India. On the contrary, the Information Technology Act 2008 (IT Act 2008) has made India a “safe heaven” for cyber criminals, say cyber law experts of India.

India has a very poor cyber crime conviction rate. As per DG of Corps of Detectives (CoD) D V Guruprasad the reason behind this is the officers themselves are clueless about cyber crime. It is of no use setting up cyber crime labs when the cyber criminals cannot be convicted. As for training judiciary and prosecutors this process should have initiated a long time back when the cyber-law was passed. The cyber crime police stations/cells/labs established by NASSCOM have absolutely failed to make any difference in this regard.

According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “This was bound to happen as the government of India is not at all serious about tackling the menace of cyber crimes in India. Rather than strengthening the cyber law of India, it has diluted the same and made it criminal friendly through the Information Technology Act 2008”.

In the absence of a stringent cyber law of India and lack of proper techno-legal training of lawyers, judges and police officers not much can be expected from Indian legal and judicial system of India. A special emphasis must be given to the training of police officers, lawyers and judges in the field of cyber forensics.

India must engage in good capacity development initiatives rather than merely opening cyber crimes cells and achieving cyber crimes tackling capacities on papers alone. The first step must be to strengthen cyber law of India and then steps must be taken to provide adequate training to the players involved in dealing with cyber crimes in India, says Praveen Dalal.