Showing posts with label ENCRYPTION LAWS IN INDIA. Show all posts
Showing posts with label ENCRYPTION LAWS IN INDIA. Show all posts

Friday, 8 April 2011

Encryption Policy Of India

Use of encryption has many benefits. From ensuring the security and integrity of electronic transactions, encryption also helps in avoiding illegal cell phone tapping and e-surveillance by private persons that is rampant in India.

There are no privacy laws in India and data protection laws in India. This means that sensitive and personal data is open for all sorts of abuses. For example, telemarketing woes in India are well known where privacy is openly and blatantly violated by telemarketing companies.

Similarly, data stealing through cyber espionage is well known in India. With a cyber criminal friendly cyber law of India, it is very difficult to punish the cyber criminals who engage in trans border cyber espionage.

Encryption has also become essential to defeat the illegal and unconstitutional electronic sniffing and e-surveillance approach of India. We have no lawful interception law in India and telephone tapping in India is done in an unconstitutional manner.

Indian government is pressuring companies like Skype, Google/Gmail, Research in Motion (RIM) Blackberry, etc for practically using no encryption services for their communications. For instance, India is pressurising Blackberry for providing unencrypted e-mail and telecom communications in India. By threatening to ban Blackberry services in India, the government has already obtained access to Blackberry’s messenger services. Now India is forcing the telecom service providers of India to drop Blackberry’s services if it does not provide free and unencrypted access to its services in India.

Encryption policy is also important for ensuring strong and effective telecom policy of India. However, encryption is an unresolved enigma in India. We have no encryption laws in India and despite the suggestions of many experts’ encryption laws and regulations in India are still missing.

India is compromising the Mobile Security of India and Mobile Governance in India by insisting upon a Weak Encryption Infrastructure, says Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India. Mobile Cyber Security in India is not upto the mark and unencrypted communication would further increase the risks, claims Dalal. New Telecom Policy of India 2011 is in pipeline and it would be a good idea if Mobile Security Policy of India is also made a part of the same, suggests Dalal. The proposed Telecom Security Council of India can take this issue when constituted, suggests Dalal.

Let us hope that Indian government would consider and accept the suggestions of experts and would come up with a sound and effective encryption policy of India.

Monday, 21 March 2011

Mobile Security In India

Mobile phones have reached every nook and area of India. Even in remote villages of India, mobile phone services are available. Further, services like micro financing and payments, online bill payments, internet banking, etc have also extended the use of mobile phone for business, personal and professional purposes.

This growth of mobile usage has also given rise to increasing cyber crimes and mobile phone related crimes. We have a poor track record of mobile security in India. Further, India is also not very enthusiastic about use of encryption and other security measures as well.

Mobile viruses and worms have further created problem for mobile users in India. The biggest hurdles before the mobile related uses in India pertain to use of weak encryption standards and non use of mobile cyber security mechanisms in India, informs Praveen Dalal, managing partner of New Delhi based law firm Perry4Law. Absence of encryption laws in India has further made the mobile security very weak in India, says Dalal.

The advent of 3G and smart phone has further added to the woes of mobile users in India. With Internet connection and downloading facilities, many viruses and worms are accidentally downloaded upon mobiles. With a low mobile security culture in India, these mobile sets remain compromised.

Cyber criminals have now started exploring mobile phones for committing various cyber crimes. Even Nigerian scams have been successfully committed by using mobile phone in India, informs Dalal. In fact, cyber criminals are specifically developing tools and codes that can exploit vulnerabilities in mobile phones, says Dalal.

There is an urgent need to spread awareness among mobile users of India regarding mobile security, mobile viruses, mobile worms and trojans. Similarly, India must also consider effective utilisation of encryption technology to safeguard mobile communications.

Thursday, 10 March 2011

Encryption Laws And Regulations In India

Encryption is an important aspect of cyber security and data security. Though India has a cyber law in the form of information technology act 2000 (IT Act 2000) yet it does not contain any effective and robust encryption provisions. Till now encryption is an unresolved enigma in India.

For some strange reasons, encryption is a feared technology in India. Government of India in general and intelligence and security agencies in particular are very nervous regarding use of encryption in India. Till now there are no clear and definite encryption standards in India

India is increasingly looking forward for concepts like e-governance, e-commerce, m-commerce, mobile governance, mobile banking, cloud computing, etc. However, we do not have legal enablement of ICT systems in India. Further, we do not have a cyber security policy of India.

In this background, absence of encryption laws, regulations and standards is a death knell of online dealings of Indian citizens. There are no safeguards against possible loss of sensitive information and money due to insecure online transactions.

Governments of most developed countries allow the usage of strong encryption standards ranging from 128 bits to 256 bits or more to ensure the security of sensitive information exchanged via Internet and other networks. However, India is still clinging to 40 bits encryption standards for the simple reason that intelligence and security agencies of India are not capable enough to break strong encryptions.

Instead of strengthening its cyber security capabilities, Indian government and security agencies are concentrating more upon e-surveillance. However, e-surveillance is not a substitute for effective cyber skills, especially the ability to break high quality encrypted communications.

The Information Technology Amendment Act 2008 (IT Act 2008) incorporated a single provision in the form of Section 84A for Encryption Purposes, informs Praveen Dalal, leading techno legal expert of India and Managing Partner of Perry4Law. Although the provision became applicable since 27th October 2009 yet Indian Government has slept over the issue, says Dalal. Indian Government must urgently formulate a Dedicated Encryption Policy of India, suggests Dalal.

Presently, Indian government has taken a wrong decision by enforcing encryption standards through Internet service provider’s (ISPs) license. The same strategy has been adopted by Indian government to force Research in Motion (RIM) to surrender Blackberry’s encryption keys. It is indirectly forcing Blackberry to succumb to its demand by forcing the telecom service providers of India to drop services of Blackberry if e-surveillance of Blackberry is not possible.

This is not the right strategy and Indian government must take a pro active and positive approach regarding encryption issues.

Friday, 25 February 2011

Encryption: An Unresolved Enigma In India

Encryption is a technology that is always feared by India. Despite the benefits of encryption for a robust cyber security, safe and secure e-commerce, meaningful e-governance and many such benefits, use of encryption has always been suppressed in India.

India has no rules, regulations and laws regarding use of encryption. Some vague rules are scattered in the telecom related affairs of governmental departments and their agencies but no clear and legally sustainable norms are present in India till now.

According to Praveen Dalal, managing partner of Perry4Law and the leading Techno-Legal Expert of India, India must ensure that encryption standards are suitably regulated through a good and strong cyber law and other laws so that security and law enforcement requirements can be reconciled.

Presently, encryption standards are biased in favour of security agencies requirements that need to be addressed by Parliament of India, opines Praveen Dalal.

For example, the directions to Research in Motion’s (RIM) Blackberry, Gmail, Skype, etc by Indian government for providing encryption keys are hegemony manifestations and not genuine security concerns. If the Indian government is serious about its claims, it must produce factual and documentary proofs of the possible and actual threats form the Chinese telecom gears and the questioned Internet services and utilities.

However, any concrete laws and regulations regarding encryption standards in India are very unlikely as the same may go against the endemic e-surveillance practices of Indian government and its agencies.