Friday, November 25, 2011

Police In India Is Not Comfortable With Cyber Crimes

Cyber crimes in India are increasing at a rapid rate. However, the cyber law of India is not strong enough to deter these cyber crimes and common man has to suffer the results of this weak cyber law of India.

Further, the law enforcement agencies of India are not well trained to deal with cyber crimes. If a person whishes to lodge a first information report (FIR) with the police for a cyber crime, he is discouraged by police in every possible manner.

If you seek an explanation from the police officers for this behaviour they would candidly tell you that they lack the necessary expertise to deal with cyber crimes. If police force is not at all aware of cyber law there is no chance that it can solve many sophisticated cyber crimes.

Cyber crimes investigation in India is not satisfactory at all. Police forces lack cyber crimes investigation capabilities in India. Cyber skills development in India for police forces is need of the hour. Even the cyber crimes cells of India are not effective in successfully investigating and solving various cyber crimes.

The position has become so worst that now complainants of cyber crimes have to knock at the doors of high courts to get proper relief. Recently a Criminal Miscellaneous Writ Petition has been filed in Lucknow Bench of Allahabad High Court for transferring a cyber criminal cases against Facebook to Special Task Force (STF) or some other specialised agency of UP Police.

The petitioner a social activist Nutan Thakur approached the court after the local police failed to take any action in FIRs filed by her against Facebook over alleged use of criminally abusive language. The local police reported that they have no expertise in computers so they cannot proceed ahead.

Blaming the police force of India for this lack of expertise is not good. It is the duty of Indian government to suitably train the police force of India. Modernisation of police force of India is urgently required. Police force must be provided cyber crimes investigation courses and trainings in India.

Perry4Law Techno Legal Base (PTLB) is providing techno legal cyber law trainings for police agencies and various stakeholders. PTLB e-learning virtual campus manages various techno legal courses for stakeholders from around the world. Indian police force must get suitable trainings in the field like cyber law and cyber forensics from institutions like PTLB.

Tuesday, November 22, 2011

Skills Development In India Is Required

India has one of the largest educated workforces of the world. However, a majority of these educated students are not suitable for employment purposes. This is because employment requires skills and practical trainings that our academic educational system does not provide.

Indian government is aware of this limitation of Indian educational system and is working in the direction of skills development, practical trainings and vocational education. Even suitable legal framework to streamline educational sector in India is in pipeline.

Skills development in India is an area that requires top priority of Indian government. Further, technical education skill development in India also needs to be taken care of. Virtual campuses can be a big help in streamlining professional, vocational and skills development in India.

Even the legal education in India needs great reforms. PhDs in India are dying and higher legal education in India needs urgent reforms. In particular, continuing professional legal education in India needs to be developed. Further, public legal awareness training in India also needs to be strengthened.

India is providing many Information Technology related services. However, other countries, especially China, have now started giving competition to India. A cyber skilled workforce of India needs to be developed. Even cyber law skills developments in India are required to meet growing cyber crimes.

The cyber crime investigation capabilities in India need to be upgraded as cyber crimes are far exceeding the cyber capabilities of law enforcement agencies of India. Cyber crime investigation training in India as well as cyber fraud detection training in India is needed to tackle cyber crimes, white color crimes and organised crimes.

To solve these high tech and organised crimes, we also need to develop cyber forensics capabilities in India. Cyber forensics training in India can help in detection and prosecution of these crimes. Perry4Law Techno Legal Base (PTLB) is managing the exclusive techno legal online cyber forensics training centre of India that is developing cyber forensics skills of various stakeholders.

Since India is facing growing cyber attacks, cyber warfare, cyber terrorism, cyber espionage, etc, we also need to ensure cyber security skills development in India. Ethical hacking training and courses in India can be really helpful.

PTLB skills development initiative is providing techno legal trainings in the fields like cyber law, cyber security, cyber forensics, offensive and defensive cyber capabilities, etc. Interested individuals, organisations and stakeholders can enroll for these courses to develop their skills.

Saturday, November 19, 2011

Ethical Hacking Skills Development In India

Skills development in India is an area that requires top priority. Even among various skills, cyber skills development in India requires a special treatment. Skills development in India for technical education is missing as Indian educational institutions are paying more attention to academic nature rather than practical and vocational requirements.

Cyber crimes in India are increasing at an alarming rate. Similarly cyber attacks against India are increasing at fast pace. However, neither cyber crime investigation training in India nor cyber security training has been undertaken so far to a satisfactory level.

For instance, very few institutions are providing ethical hacking training, courses and education in India. Further there is a single ethical hacking software and tools repository in India managed by Perry4Law Techno Legal Base (PTLB).

Cyber security skills development in India is the need of hour. Cyber forensics skills development in India is another area that requires urgent attention of various stakeholders.

PTLB e-learning platform is providing various techno legal e-learning trainings, education and courses. Interested stakeholders may contact PTLB in this regard.

To sum up, ethical hacking skills development in India are urgently required to take care of cyber crimes and cyber attacks that are playing havoc with Indian critical infrastructure. The sooner it is done the better it would be for the national interest of India.

Friday, November 18, 2011

Cyber Security Courses In India

Indian defense and security against cyber warfare is not upto the mark. A major reason for this lack of cyber capabilities is that India has very few institutions that can provide good and qualitative techno legal skills development, education, courses and trainings in the field of cyber security.

Thus, cyber security skills development in India is directly related to good and qualitative cyber security courses in India. There are many essentials of cyber security courses in India that must be taken care of before trained and skilled cyber workforce can be produced in India.

Perry4Law is managing many qualitative and world class techno legal education and training institutions and centers. For instance, Perry4Law Techno Legal Base (PTLB) provides good and qualitative techno legal cyber law, cyber security, cyber forensics and many more techno legal courses and trainings.

Similarly, Perry4Law Techno Legal ICT Training Centre (PTLITC) provides domain specific and highly specilaised cyber law, cyber security, cyber forensics and many more techno legal courses, trainings and educations.

PTLB e-learning platform is providing courses on cyber law, cyber forensics, cyber security and many more techno legal fields. Stakeholders and learners from around the world can be enrolled there for these courses. These virtual campuses can fill the cyber security education gap that is prevailing in India.

Cyber security courses in India must not be mere academic degrees or diplomas. They must be practical and vocational in nature. Technical education and skill development in India still needs to be developed. Kapil Sibal is doing a good work in the field of education and very soon cyber security courses may also be taught in India in a qualitative manner.

Wednesday, November 16, 2011

Law Enforcement Agencies Need Cyber Law Training

World over it is a common belief that law enforcement agencies are well behind the cyber criminals and they cannot meet the growing challenges of cyber law and cyberspace. Even the law enforcement agencies are also of the opinion that their expertise is well behind the expertise of cyber criminals and crackers.

A well organised police cell for dealing with cyber crimes is still a distant dream. However, the least law enforcement agencies can do is to get the basic level computer and cyber law trainings. Till now even this basic level awareness and training is missing for law enforcement agencies.

Further, these trainings must be techno legal in nature to be effective. Perry4Law Techno Legal Base (PTLB) is providing world class techno legal trainings for law enforcement officials. It is also managing a techno legal cyber law, cyber forensics and ICT training centre for police force in India.

The best part is that PTLB is also managing the exclusive Techno legal e-learning centre in India. Any law enforcement agency of the world can enroll its officer for the great techno legal cyber law, cyber forensics and other courses of PTLB. All these courses can be undertaken in an online mode and from any location of the world.

The need for such trainings in India is very apparent. Cyber crimes investigation in India is a tedious and difficult task for the police force of India. A trained cyber police force of India is needed so that the growing cyber crime cases in India can be effectively tackled. Indian Police needs cyber law training so that cyber crimes victims in India may get appropriate remedy and justice.

PTLB is providing various courses on investigation of cyber crime cases in India and world wide. Further, PTLB is also providing cyber crimes investigation training in India.

Interested stakeholders may visit the PTLB e-learning site and follow the procedure mentioned therein. Once the enrollment to PTLB courses is successfully undertaken, these stakeholders can enrich themselves with the world class techno legal trainings of PTLB.

Sunday, November 13, 2011

Counter Terrorism Capabilities Of India Are Not Sufficient

Of late, the terrorist activities in India have increased significantly. Unfortunately, Indian government has not been able to deal with terrorism nuisance effectively. In the war against terrorism, India has miserably lost the same despite many efforts in this regard.

There are many shortcomings of Indian counter terrorism initiatives. The most important shortcoming is that Indian national security policy is missing. Even the counter terrorism capabilities of India are not satisfactory. To make the situation worst, the turf war in India is compromising the national security in India. This is the main reason why the national counter terrorism centre of India has also been downsized.

Even in the cyberspace Indian capabilities to deal with cyber terrorism are limited. Cyber security in India is not up to the mark and we must seriously consider developing cyber warfare capabilities in India and anti cyber terrorism capabilities in India. Questions about cyber security of Indian nuclear facilities and centers have also been raised.

It is high time for Indian government to seriously consider developing anti terrorism capabilities and anti cyber terrorism capabilities. Mere assurances and verbal achievements would do more harm to India at this stage.

Tuesday, November 8, 2011

Interpol Helped India In Tracking Child Porn Surfers

Protecting children in cyberspace has become a daunting task. As the Internet is not confined with any boundary, fighting online child pornography requires an internationally coordinated effort.

This is exactly what happened in a recent episode of surfing child pornography in India. In this case the Interpol coordinated with the Central Bureau of Investigation (CBI) to unearth the guilty surfers. After the details of the accused were made available to the local police, the state cyber police registered a case against 20 Keralites for trawling child porn websites.

The list was prepared by the Interpol after closely tracking the users for the past couple of months. The list contains the name, IP address and full postal address of persons from various parts of the state.

Police has also started cross-checking the details of these surfers. As per the cyber law of India, incorporated in the information technology act 2000, browsing child porn sites is a non-bailable offence. However, action against the offenders will be decided after thorough discussions with higher-ups.

According to police sources there has been considerable increase in child porn surfing in Kerala. The Interpol prepared the list after getting in touch with various internet service providers. At times, they even host fake websites to check how many surfers are visiting it. It is a basically a covert operation of the Interpol to hunt down such surfers. The list of offenders is prepared after multiple-level of surveillance and filtering.

Friday, September 16, 2011

Software Vulnerabilities And Their Exploitation

Some sort of vulnerability is common in any security infrastructure and software is no exception to the same. Software vulnerability may occur due to insufficient testing, lack of audit trail, use of publicly available codes, programming errors, etc. A programmer while making a software may assume that all user input is safe. Programs that do not check user input can allow unintended direct execution of commands or SQL statements like buffer overflows, SQL injection or other non-validated inputs.

Although various set of coding guidelines have been developed and a large number of static code analysers has been used to verify that the code follows the guidelines yet coding errors are common in a majority of software. A coding error gives rise to vulnerability in software that can be exploited by a malicious user.

An exploit may be a piece of software, a chunk of data, or sequence of commands that takes advantage of vulnerability in order to cause unintended or unanticipated behavior to occur on software.

There are several methods of classifying exploits. The most common is by how the exploit contacts the vulnerable software. A “remote exploit” works over a network and exploits the security vulnerability without any prior access to the vulnerable system. A “local exploit” requires prior access to the vulnerable system and usually increases the privileges of the person running the exploit past those granted by the system administrator.

Exploits against client applications also exist, usually consisting of modified servers that send an exploit if accessed with client application. Exploits against client applications may also require some interaction with the user and thus may be used in combination with social engineering method. This is the hacker way of getting into computers and websites for stealing data.

Often, when an exploit is published, the vulnerability is fixed through a patch and the exploit becomes obsolete for newer versions of the software. This is the reason why some blackhat hackers do not publish their exploits but keep them private to themselves or other hackers. Such exploits are referred to as “zero day exploits”.

As far as legality of exploiting software is considered, it is considered to be a cyber crime or offence in many jurisdictions. Even circumventing an access control mechanism is punishable under laws like digital millennium copyright act (DMCA). However, it is cracking of software that is punishable and not hacking as is popularly misunderstood in the media circles.

Software vulnerability and their exploitation need to be taken care of by a techno legal framework that combines both technological and legal issues. However, this techno legal framework is still missing in most of the jurisdictions of the world.

Monday, August 29, 2011

Proposed Jan Lokpal Law Must Be Techno Legal

The drafting of final Jan Lokpal Bill of India is pending before the Parliament Standing Committee (PSC). The task before the PSC is enormous as it has to analyse the inputs of various stakeholders and experts while suggesting the final Jan Lokpal Bill.

There are many drafts of Jan Lokpal bills that have been in circulation. Besides, there are many good suggestions from techno legal experts of India that have shown the necessity to make the proposed Jan Lokpal law techno legal in nature.

According to Praveen Dalal, managing partner of New Delhi based techno legal ICT law firm Perry4Law and leading techno legal expert of India, the proposed Jan Lokpal Law of India must be Techno Legal and Technology Driven in nature.

The issues like E-Procurement, E-Banking, E-Delivery of Services, etc would bring their own share of Scams and Corrupt Practices and the same cannot be dealt with by the Jan Lokpal Law unless it is Techno Legal in nature, suggests Dalal.

So far the proposed drafts of Jan Lokpal have failed to address these crucial issues. Fortunately, the PSC on Jan Lokpal can consider the suggestions of techno legal experts of India while suggesting final bill in this regard.

Sunday, August 28, 2011

Should Media Be Brought Under Lokpal Scanner?

Jan Lokpal has raised many debates. Some are constitutional while others are ethical and those pertaining to the efficacy of Jan Lokpal itself. One issue that has been sternly opposed by the Indian media is whether media should be brought under the purview of proposed Jan Lokpal law of India?

Some experts have opined that the idea of bringing the media within the ambit of the Lokpal is "bad and mischievous". They have argued that media falls under the category of “private individuals” and the basic objective of the proposed Jan Lokpal law is to target governmental irregularities and corruptions.

Though experts agreed there were problems in the media like paid news, they felt the media would have to deal with the issue itself. They argue that while involvement of a politician in paid news would come under the Election Commission of India norms, in case a newspaper took cash for publishing such news, it would violate the tax laws. The experts mentioned there are quasi-judicial watchdogs like the Press Council of India to look into the complaints against media.

However, demanding that media cannot and should not be brought under the ambit of Jan Lokpal in all circumstances is ignoring the ground realities and the influence making powers of media. If media is involved in corrupt practices, it can validly be brought under the ambit of Jan Lokpal.

There is no reason why media should be excluded from the ambit of Jan Lokpal and there are many factors and reasons that may justify this inclusion. The parliamentary standing committee must consider this aspect as well while formulating the ultimate Jan Lokpal Bill for India.

Tuesday, August 23, 2011

Trained Cyber Police Force Of India Is Needed

Modernisation of police force of India is an issue that has not received much attention of Indian government in general and ministry of home affairs of India in particular. Even the so called cyber crime cells of India lack expertise in fields like cyber law and cyber crimes. The truth is that police in India needs urgent cyber law training.

Perry4Law Techno Legal Base (PTLB) of Perry4Law has been providing techno legal cyber law and cyber forensics trainings for law enforcement, lawyers, judges, corporate CEOs, etc. PTLB is the exclusive techno legal training institution of India that provides a combination of technical and legal trainings to various stakeholders.

Cyber crimes in India are increasing and victims of such cyber crimes have virtually no redress. Neither the police officials nor the courts are well trained to deal with high tech crimes in India.

Merely opening few cyber crime cells in some states would not serve the purpose. Even opening of such cyber crime cells in all parts of the country would not serve any purpose. What is the purpose of opening such cells if they cannot investigate cyber crimes and book the cyber criminals for various cyber crimes?

Till now the sole techno legal cyber forensics research, training and educational centre of India is managed by PTLB and Perry4Law. This cyber forensics centre of India has been providing cyber forensics best practices in India and is also disseminating techno legal information regarding cyber law, cyber security, cyber forensics, cyber espionage, cyber terrorism, human rights in cyberspace, etc at national and international level.

We need more training institutions on the lines of PTLB/Perry4Law. Further, it is high time for Indian government to work on a public private partnership model that can include techno legal institutions/firms like PTLB/Perry4Law.

Sunday, August 21, 2011

Privacy And Data Protection Law Firms In India

Of late, privacy and data protection issues have assumed importance from the commercial and legal point of views. Commercially privacy and data protection are required to be protected to retain strategic advantage. Legally privacy and data protection are required to be protected under the laws of various jurisdictions.

Privacy is a concept that is unknown to Indian culture. However, slowly and steadily it has started gaining importance. When i talk about privacy, it not only includes the traditional privacy requirements but the more demanding requirements of our present times as well.

In the age of Internet and social networking, privacy has assumed a totally different meaning. There are many privacy violations in cyberspace and the role of good techno legal lawyers and law firms is very apparent in punishing the offenders.

According to B.S.Dalal, partner at New Delhi based ICT and IP law firm Perry4Law and a techno legal expert, “Techno legal privacy protection, data protection and data security lawyers and law firms are limited in nature. As far as India is concerned, we have no dedicated privacy, data protection and data security law. This is a serious limitation that is resulting in poor privacy, data protection and data security legal practice in India”.

However, sooner or later regulatory framework for privacy and data protection in India would be required. Further, disputes regarding privacy and data protection would also increase in future. This would require techno legal expertise on the part of lawyers and law firms.

The outsourcing industry must pay a special attention to the techno legal requirements of privacy, data protection and data security issues. Perry4Law and Perry4Law Techno Legal Base (PTLB) have strongly recommended formulating and adopting best practices by stakeholders in this regard.

The Search Engine Quality Of Google Is Deteriorating

Up to some time before, Google was considered synonymous with search engine results. However, the picture is fast changing now when competitors are fast catching up with the quality of Google and are challenging its market share.

Have you noticed that the search results in Google search engine do not reflect the correct and true picture? If you are a blogger and using the blogspot platform, you must have also realised that your posts are appearing only after a period of 2/3 days.

Further, in the past there are clear cut examples of Google censoring and filtering news and search results, at least in India. Further, Google has also been messing up with search placements whether by default or otherwise.

Now consider the search engines like Yahoo, Bing and DuckDuckGo. They have acquired a good reputation and goodwill among the users due to their consistency and lack of censorship activities.

I analysed the four search engines with a common search query and was surprised to find how Google simply does not index the blog posts that were immediately picked up by other search engines.

I also checked the webmaster tool of Google but there were no indexing errors or errors of other type that could have resulted in non indexing or poor indexing of blog posts. Naturally, either Google’s algorithm has been deteriorated to a level that would ultimately affect it reputation and usage or it is deliberately censoring and manipulating the results.

Either way this is too much for users like me who prefer to shift to other search engines for getting legitimate, genuine and good results. My personal ranking for search engines, for the time being, is Yahoo, DuckDuckGo, Bing and Google.

Cyber Security Law Firms In India

Technology has brought its own share of legal challenges for both law makers and lawyers. For law makers, technology has posed a challenge of enacting suitable laws that can meet the challenges of misuse of technology. For lawyers, technology has come as an unexplored area that they have to understand, apply and argue in courts and corporate environment.

Take the example of India. There are very few cyber law firms in India or cyber law lawyers in India who can understand and apply the same. Even the cyber law consultants in India are handfuls that are serving the corporate entities.

One area that has recently interested the legal community pertains to cyber security. Although cyber security as a legal field has started gaining attention of foreign lawyers and law firms yet cyber security law firms in India or cyber security lawyers in India are still missing.

Of course, exception in the form of Perry4Law and Perry4Law Techno Legal Base (PTLB) can be found in India. Perry4Law is the exclusive techno legal ICT and IP law firm of India that has acquired international reputation in the fields like cyber law, cyber security, cyber forensics, etc.

B.S.Dalal, partner at Perry4Law opines, “One positive development that I have recently noted about these techno legal fields is that lawyers and law firms have started exploring the areas like cyber law, cyber security, cyber forensics, etc. Although the number of such lawyers/law firms is negligible yet the growing interest in the techno legal fields would increase such numbers in future”.

Further, techno legal issues would also change the way traditional businesses and transactions would be carried out in future. For instance concepts like cyber insurance, online dispute resolution, e-courts, digital evidencing and e-discovery, media forensics, cyber forensics, etc would be very much used in future, says B.S.Dalal.

Indian legal fraternity must start exploring techno legal fields that would take tremendous time, energy and efforts to understand and apply. The sooner it is done the better it is for the legal fraternity of India.

Want Better Search Results Try DuckDuckGo and Yahoo

Of late the search results of Google India have messed up badly. If you are a blogger who is blogging for years, you must have already noticed poor placement of your blog posts at Google’s search engine.

As a matter of fact other search engines like DuckDuckGo, Yahoo and Bing are producing much better results. There can be many reasons for this poor listing of blog posts at Google.

These include censorship on behalf of Google under government pressure, manipulation by rouge employees at Google, spam blog posts by a particular blogger, discrimination in favour of commercial entities by Google, poor search engine optimisation (SEO) by concerned blogger, non qualitative and repetitive contents, etc.

Initially it was content farming and splogs that caused trouble for Google, now its poor search algorithm is bringing bad name for it. Google must pay special attention to its Indian operations as they are not up to the mark and are not meeting the Google’s philosophy and corporate policy.

In these circumstances it would be a better option for SEO companies and bloggers to target other search engines like DuckDuckGo, Yahoo, Bing, etc as presently they are providing more relevant, unbiased and specific search results than Google.

Sunday, July 24, 2011

Serious Fraud Investigation Office (SFIO) Of India Would Get More Powers

Serious fraud investigation office (SFIO) is a corporate fraud investigating body under the ministry of corporate affairs (MCA), India. SFIO has been seeking broader powers to carry out investigations abroad. Now the MCA is considering this proposal of SFIO that would allow it to trail funds abroad.

Lack of such powers has also been hampering SFIO’s investigations into the multi-crore Satyam fraud as the company has operations in other countries also. Set up in 2003, the government plans to give the SFIO more teeth in the new Companies Bill, which was tabled in Parliament last August.

A permanent cadre for the SFIO is also under consideration to ensure more stability to the body. Diversion of funds is a Companies Act violation, but when funds are hived off abroad it becomes a hawala transaction, and falls under the ambit of the Enforcement Directorate.

The proposals to give SFIO more teeth for investigation are mostly based on the recommendations of the V Vepa Kamesam Committee. Giving the SFIO powers to trail illegal money stashed away abroad is, however, not part of the committee's suggestions.

The eight-member committee had suggested that the SFIO be given exclusive jurisdiction to probe and prosecute entities involved in financial frauds, besides also probing cases related erring entities/individuals like chartered accountants and company secretaries.

The committee is of the opinion that power of search and seizure, and attachment should be entrusted with the SFIO as available with the Income Tax authorities, Customs, Enforcement Directorate etc.

It has also suggested that the SFIO be empowered to take up a case suo moto and even on a source-based information if a fraud has been committed. The committee has also called for the SFIO having flexibility to outsource the services of experts like chartered accountants, legal experts etc and officers joining the investigating agency on deputation be ensured protection of their existing pay and allowances.

Saturday, July 9, 2011

UIDAI Served With Legal Notices Challenging Its Constitutionality

Aadhar project of India is managed by Nandan Nilekani led unique identification authority of India (UIDAI). It has always remained in controversies since it has been launched.

Neither Aadhar project nor UIDAI are governed by any legal framework and parliamentary oversight. Aadhar project and UIDAI are purely executive projects with no constitutional sanctity. In fact Aadhar project and UIDAI are operating in an “unconstitutional manner”. Even the Prime Minister of India, Dr. Manmohan Singh, has not given a serious thought to the Aadhar project and UIDAI.

Now legal notices have been served upon UIDAI questioning its credentials and constitutionality. The notices have asked the legal sanctity behind the process of acquiring biometric data of people to provide them the 12-digit UID number even before a law on UID comes into force.

The two legal notices issued to UIDAI chairman Nandan Nilekani on July 5 and July 6 also raise concerns over UID numbers invading the privacy of individuals as these are for multi-utility service use, and would force individuals to leave trails, allowing invasion of their privacy.

Mathew Thomas, general secretary, Citizens’ Action Forum, and V K Somashekhar, founder patron, Coordinated Action of Consumer and Voluntary Organisations of Karnataka (CACVOK), have separately issued legal notices to Nilekani on Tuesday and Wednesday through their respective advocates.

Tuesday, July 5, 2011

US Legal Workforce Act Of 2011 And E-Verification

The Legal Workforce Act of 2011 of US has been doing rounds these days. However, it has also raised many privacy and identity theft concerns as well. Privacy groups of US have been opposing the same as undesirable and a problematic law.

These privacy groups believe that storing highly sensitive information, including the biometric details, of the employee would cause many cyber security and identity theft issues.

The proposed Bill would force the employers to use the federal E-Verify system to vet new employees and to verify that new hires and current employees can legally work in the US.

All employers would be required to compare information supplied by current and prospective employees with information contained in Department of Homeland Security (DHS) and the Social Security Administration (SSA) databases. As part of the verification process, the Social Security number provided by new hires would be compared with the name on record.

The Bill also proposes a pilot biometric authentication program that would let employers fingerprint employees as part of the vetting process. The Bill calls for penalties of up to $25,000 per violation and imprisonment of at least one year for employers who refuse to use E-Verify.

In India as well the Aadhar project managed by unique identification authority of India (UIDAI) is facing similar problems. There is neither a legal framework supporting the Aadhar project of India nor Aadhar project is secure from physical thefts and cyber attacks.

Sunday, July 3, 2011

Are International Cyber Security Initiatives Enough?

While going through a good article on cyber security, I was thinking is the cyber security initiatives at national and international levels enough?

The article has contended that cyber security at the international level is not upto the mark and there is an urgent need of bringing international harmonisation in this regard.

Even there is no international cyber law treaty and different countries are governed by different cyber laws. This at times creates jurisdictional problems.

Even at the national and international cyber security events no consensus has reached for formulating an international cyber security convention.

As far India is concerned, we have no cyber security policy in India and even the cyber security laws in India are missing.

I believe it is high time for India and international community to consider cyber security seriously. The sooner we adopt sound cyber security in India the better it would be for the larger interest of India.

Thursday, June 30, 2011

CBI Exemption From RTI Act 2005 Challenged In Delhi High Court

Indian government exempted the central bureau of investigation (CBI), national investigation agency (NIA) of India and national intelligence grid (Natgrid) from the applicability of right to information act 2005 (RTI Act 2005).

Despite sever protests from civil liberty activists and legal experts, Indian government took this controversial step. Of course, it is against the constitution of India as per leading techno legal experts of India.

Naturally, this decision was also liable to be challenged in the constitutional courts of India. Now it has been reported that this decision of Indian government has been challenged in the Delhi High Court by petitioner Sitab Ali Chaudhary.

The Delhi High Court admitted public interest litigation and posted the hearing on it on July 6th. The petitioner claimed that hiding information sought under the RTI Act is unconstitutional.

The petitioner has contended a very limited argument as there are many more grounds available that can make the government’s decision illegal and unconstitutional. Hopefully, the same would be covered during the hearing of the PIL.

Wednesday, June 22, 2011

Committee Of Secretaries (COS) Considers Right to Privacy

Right to privacy is a very important law that is missing from the list of Indian laws. For decades the right to privacy has been ignored by Indian government. However, a stage has reached where many crucial projects of Indian government have become “unconstitutional” as these are violating the crucial right to privacy as declared by the Supreme Court of India.

Now Indian government is considering enacting a privacy law for India. A Right to Privacy Bill 2011 has been proposed by Indian government in this regard. However, it has not been made public by Indian government till now and this raised a question upon the commitment of Indian government in this regard.

Meanwhile media reports have claimed that the proposed privacy law may cover all individuals in India irrespective of whether they are citizens of the country or not. This means foreigners who work in India and tourists from abroad will enjoy the same privacy rights as Indian citizens. This is a good provision if finally incorporated in the proposed privacy law.

The decision was taken at a meeting of the committee of secretaries (COS) called by the cabinet secretariat a few weeks ago. The COS members said just as every person living in India had a right to life and liberty, the right to privacy should cover every individual in India.

The COS also decided to exempt journalistic publications. It also suggested a few exemptions related to protection of sensitive personal data. It proposed that insurance companies be allowed to access the health data of individuals and employers the banking and financial data of their employees. It also agreed on strong provisions to check unsolicited commercial communication. This will curb spam emails that fraudsters use to get financial information from individuals.

The COS also wanted a list of agencies that could intercept phone calls. The circumstances under which a communication can be intercepted and the authorities that can order such interception should also be detailed, according to the COS.

However, the Prime Minister’s Office has made it clear that surveillance by intelligence agencies for national security should not be hampered. The members pointed out that intelligence gathering for security purposes would be exempted. However, intelligence work should not be an excuse for non accountability and non transparency.

The COS suggested that while there should be a provision on CCTV coverage and other methods of surveillance, the right to privacy should not apply to images captured in a public place as the individual concerned is well aware that he is at such a place. The members also wanted more clarity on sharing of information among government departments.

The COS also decided to set up a council to advise the government on data privacy issues. It was also agreed that the cyber tribunal set up under the Information Technology Act 2000 should be designated as the appellate tribunal for the purpose of this Bill. A data protection authority with powers to punish offenders was also proposed.

Some of these proposals are really good whereas others require more detailed analysis and discussion. Further, there are many more issues that have not yet been covered by the proposed Bill and they also need to be incorporated in the same.

Attorney General Bats For CBI Exclusion From RTI Act 2005

Central Bureau of Investigation (CBI) is the premier investigating authority of India. It is, however, not at all an intelligence agency though it may be handling few intelligence related aspects or cases. Intelligence work was the main excuse that was given by Indian government to exempt CBI from the applicability of right to information act 2005 (RTI Act 2005).

Indian government also exempted national investigation agency of India (NIA) and national intelligence grid (Natgrid) from the applicability of RTI Act 2005. Interestingly, the constitutional validity of national investigation agency act, 2008 (NIA 2008) is still doubtful and CBI and Natgrid are not governed by any legal framework.

Attorney General of India Goolam Vahanvati has opined that the exclusion of CBI from the purview of RTI Act 2005 is justified on the ground that CBI was also involved in intelligence-gathering as well as safeguarding the country’s economic security. He, however, failed to understand that national security and fundamental rights must be reconciled and primacy of one over another without reconciliation attempts would itself violate the constitutional provisions.

Further, Natgrid, CBI and Intelligence Agencies of India are presently not “Accountable” to Parliament of India, informs Praveen Dalal, leading techno legal expert of India and CEO of Human Rights Protection Centre in Cyberspace of India. Human Rights are regularly targeted by Indian Government and its Agencies without “Constitutional Laws”. Without Parliamentary Scrutiny and Judicial Review these Agencies cannot be considered to be “Constitutional”. If these Agencies are themselves “Unconstitutional” their functioning is also “Unconstitutional”, suggests Dalal.

Vahanvati justifies the stand of Indian government by saying that while the “main purpose of intelligence gathering and assessment is prevention and occurrence of activities which would endanger the security of the country, it cannot be restricted only to gathering of intelligence prior to happening of an event but should extend to post-event intelligence gathered which falls under investigation.

While this is a sound proposition but it does not mean that intelligence work should be an excuse for non accountability and non transparency. If Indian Government wishes to make the functioning of Intelligence Agencies “secret” there must a “Mechanism” to ensure that “Parliamentary Oversight” of these agencies does exists, opines Dalal. Presently there is no Parliamentary Oversight of these Agencies, informs Dalal.

In these circumstances, the decision of Indian Government to exempt CBI and Natgrid is not based upon “National Interest” and “National Security” but upon “Extraneous Considerations” and it deserves to be set aside by our Constitutional Courts, suggests Dalal. Let us see how things develop in this regard in India.

Tuesday, June 21, 2011

Cyber Defence Research Centre For Ranchi Stalled

Police in India is not very much comfortable with issues pertaining to cyber law and cyber security. Even if cyber crimes cells have been opened all over India they have not proved to be successful in the absence of adequate expertise.

India has also a very poor cyber crime conviction rate. The reason behind this is the police officers, lawyers and judges themselves are clueless about cyber crime.

Even if police force of India tries to make itself tech savvy, red tape and other governmental hurdles do not allow them to do so. For instance, the cyber defence research centre (CDRC), once proposed by the state of Jharkhand, seems to be the need of the hour with the government's official website being hacked twice in the past and recent successful cloning incidents of ATM cards at fuel pumps. In spite of alarms raised in the past by cyber experts in the capital and senior police officers, the proposal for CDRC constitution is yet to receive final nod of the government. The proposal for constitution of CDRC was sent to the state government for approval in March 2010.

The CDRC would constitute one chief technological officer (CTO) and two senior advisers from IT sector besides three cyber security professionals to be appointed from among civilians. The rest of the positions would be filled up by policemen trained in cyber security.

Special Branch IG S N Pradhan said once the CDRC was in place, Jharkhand would be one among the main centres of cyber security in India. Pradhan added that the centre would not only check cyber crime in state but also conduct high end research on cyber security and carry out cyber forensic tests to extend assistance to the security professionals at national level.

Till now, Perry4Law and Perry4Law Techno Legal Base (PTLB) are managing the exclusive techno legal cyber security research, education and training centre of India (CSRTCI). Perry4Law and PTLB are also managing the exclusive techno legal cyber forensics research and training centre of India.

Despite various efforts, the law enforcement and intelligence agencies in India seem to be helpless in front of modern technological crimes like cyber crimes in India, terrorism and cyber-terrorism. India needs to tackle this problem as soon as possible.

Friday, June 10, 2011

Legal Empowerment Of Indian ICT

Legal empowerment of Indian information and communication technology (ICT) regime is still missing. We have no legal enablement of ICT systems in India in true sense.

Legal enablement of ICT presupposes adoption of a legal framework that can take care of various dealings in the cyberspace.

Cyberspace is very vast and borders less. It is very difficult to regulated cyberspace but national and international laws are required to bring some sort of discipline in the otherwise chaosed cyber world.

Cyber law of India is weak and experts have been suggesting it should be repealed. We have no data protection and privacy laws in India. Even cyber security and cyber forensics laws are missing in India.

On the policy front as well India is lagging far behind. We do not have policies regarding critical ICT infrastructure protection, cyber warfare, cyber security, etc.

India has to do a lot in order to legally empower the ICT usage in India. The sooner it is done the better it would be for India in general and Indian citizens in particular.

Sunday, June 5, 2011

Jan Lokpal Bill Of India 2011

The efforts to have the Jan Lokpal Act of India 2011 are in full progress. However, till now they are at the stage of drafting a Bill for that purpose.

Even a final draft Bill has not yet been prepared. In all probability it may not be prepared till the deadline of 30th June 2011.

Meanwhile, Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India has explained what an ideal Jan Lokpal Bill must have. He has also sent these suggestions to the government of India.

He has also introduced the element of information and communication technology (ICT) for effective applicability of the proposed law.

The present Drafts proposed by both Indian government and civil liberty activists do not cover the points suggested by Praveen Dalal.

Since he has also sent these suggestions to Indian government, they may be considered while drafting the final draft.

Till now Indian government has not shown any serious efforts to make the proposed Jan Lokpal Bill strong and effective.

The suggestions given by Praveen Dalal, if incorporated, can make the final draft strong and effective.