Friday, 30 November 2012

Indian Crisis Management Plan For Cyber Attacks And Cyber Terrorism

The threats of cyber attacks, cyber espionage and cyber terrorism are looming large at India. India needs to understand the seriousness of cyber attacks upon its critical infrastructures and cyberspace. To start with, India must formulate a crisis management plan to tackle cyber attacks, cyber terrorism and cyber espionage attempts.

Crisis management plan (CMP) is a measure of readiness to meet uncertainties and future risks and accidents. If we have a good crisis management plan at place, we can minimise the damage and harm to maximum possible extent.

CMP pertaining to information and communication technology (ICT) is an essential part of national ICT policy of India. The other parts of national ICT policy of India are cyber security policy of India, critical infrastructure protection policy of India, critical national infrastructure protection policy of India from cyber attacks, national security policy of India, etc.

Similarly, we must also formulate a cyber security policy for India. With more and more networks and computers are now connected with public utilities and essential public services, cyber security assumes great significance these days. India is also looking forward for mandatory electronic delivery of services. This would increase the risks of cyber attacks upon crucial public delivery systems of India.

The government of India has issues certain guidelines to safeguard Indian cyberspace. According to these guidelines no sensitive information is to be stored on the systems that are connected to Internet. The Government has also claimed to have formulated Crisis Management Plan for countering cyber attacks and cyber terrorism for implementation by all Ministries/ Departments of Central Government, State Governments and their organizations and critical sectors.

The organisations operating critical information infrastructure have been advised to implement information security management practices based on International Standard ISO 27001. Ministries and Departments have been further advised to carry out their IT systems audit regularly to ensure robustness of their systems. Ministry of External Affairs has also issued a comprehensive set of IT security instructions for all users of MEA and periodically updates them on vulnerabilities.

Although the steps taken by Indian government are praiseworthy, they are not sufficient to ward off the sophisticated cyber attacks. The practical implementation of the crisis management plan of India is still missing. With a beginning already taken place, it needs a political will to give it a final shape and help it to reach its final destination.

Unconstitutional And Illegal Biometrics Collection Laws And Practices In India

India is passing through one of the “Most Dangerous Periods” for Civil Liberties and Human Rights Protections. No time in the past Indian Citizens were so “Vulnerable” to Human Rights Violations and blatant violation of their Fundamental Rights.

The Constitution of India has conferred many Fundamental Rights upon Indian Citizens and Persons. However, Indian Government is acting in clear “Derogation” of these Fundamental Rights and Human Rights.

Article 21 of Indian Constitution confers Privacy Rights in India to all. Similarly, Article 21 also confers Right to Life and Liberty to all that cannot be taken away except by “Due Process of Law”. Articles 14, 19 and 21 collectively protect against “Arbitrary and Unconstitutional State Actions”.

Despite all these “Protections and Rights” we have Authorities like Unique Identification Authority of India (UIDAI) that is not governed by any Law whatsoever. Similarly, we have provisions pertaining to National Population Register (NPR) of India that are clearly “Unconstitutional”.

We have no dedicated Data Protection Laws in India, Data Security Laws in India, Cyber Security Laws in India, etc. Even the Cyber Law of India, incorporated in the Information Technology Act, 2000 (IT Act 2000), is an “Endemic E-Surveillance Enabling Law” that requires urgent “Repeal”.
Cyber Security in India is also in bad shape and even the Supreme Court of India has chided Indian Government to boost up its Cyber Security to protect National Security of India. National Security and Right to Information in India are on “Crossroads” where the “National Security Card” is very frequently played by Indian Government to deny “Legitimate and Eligible Information” to Indian Citizens.

In all this “Political and Legislative Mess” we have a “Bonus” for Indian Government as well. The Parliamentary Oversight of Intelligence Agencies of India is missing and they are “Not Accountable” to any “Legislative and Parliamentary Scrutiny”.  Intelligence related Projects like National Intelligence Grid (NATGRID), Central Monitoring System (CMS) of India, proposed National Counter Terrorism Centre (NCTC) of India, etc have no Parliamentary Approval and Oversight.  

There is no second opinion that collection of “Highly Sensitive Biometric Details” by any Governmental Agency or Authority in such circumstances is not only “Unconstitutional” but is also “Highly Risky” for Life and Liberty of Indian Citizens/Persons. In fact, collection of Biometric Details by UIDAI and NPR are clearly “Unconstitutional and Illegal” and Indian Citizens and Residents can “Refuse” to provide the same no matter what these Authorities and Laws say.

Human Rights Protection in India is at its nadir. Similarly, Civil Liberties Protection in Indian Cyberspace is in doldrums. If we keep on succumbing to the “Pressure Tactics” of Indian Government, the day would be not far when Indian Government would have complete control over our “Body and Soul”.

Thursday, 29 November 2012

The Extra Steps That TOR Users Must Take

The “Decloaking Engine” invented by HD Moore was one of the most effective ways of showing how exit nodes of TOR system can sniff the unencrypted, plain text and insecure information and data passing through it. A malicious or e-surveillance capable exit node is the weakest link of the privacy and security chain of a TOR user. However, the problem is not with the TOR’s system as this is the way TOR works. The real problem lies with the end user’s perception regarding TOR’s use in general and anonymity and privacy in particular.

There are various media reports that suggest that Wikileaks acquired its whistle blowing ammunition by sniffing or intercepting the traffic flowing through TOR networks. Whether this is true or not is not the real question here. The real question is what TOR is actually offering to the end users?

Interestingly, TOR is very clearly and openly explaining the scope of anonymity and privacy offered by it to the end users. Actually TOR is great for anonymity but average at privacy protection and poor at data security. This is because although the entry node encrypts the data and forwards it to the next node, the exit node sees it in clear text and unencrypted form. This means that although the ultimate site that you wish to access would see the IP address of the exit node and not your original IP address yet the exit node itself is very sure about the data you are sending to the website.

Think about a malicious exit node as a man-in-the middle attacker (MITM).that can sniff your traffic that you are sending to the ultimate website. It may include confidential information like bank accounts, passwords, governmental secret documents, etc. All of these travel in a plain text form and can be sniffed easily by the exit node. To some extent a malicious exit node is also a form of “Extended MITM” attack as the normal MITM attack occurs either at the local network or local wireless network/access point. But in case of MITM attack occurring at the exit node of TOR system, this is happening at a place far beyond your network(s) and jurisdiction. This scary fact must be kept in mind while sending unencrypted and unprotected data across TOR network.

The real problem is that an average TOR user cannot differentiate between a trusted and untrusted exit node. This differentiation is not within his direct control. But he has something great that can reduce his risks of exit node attacks. The TOR users must use great services like OpenSSH or PuTTY while sending confidential information. They may also use their own preferred end to end encryption software and systems but the main idea remains the same. TOR provides the anonymity and a secured connection provides additional privacy and security.

Using Firefox after disabling Add-ons, Active X Controls, Java Scripts, Cookies, etc can also bring additional anonymity and privacy. If you need all these functionalities, you can use two different browsers with different setting i.e. Firefox for TOR and other browser for your other tasks. These steps may not make you absolutely anonymous but would definitely solve the problem of malicious exit nodes sniffing to a great extent.

Source PTLB Blog.

Wednesday, 28 November 2012

Techno Legal Thoughts

I have started a new blog titled Techno Legal Thoughts that would discuss issues like cyber law, cyber forensics, cyber security, trainings and education, cyber threats and cyber attacks, etc.

The purpose of this blog is to share short and contemporary techno legal issues from around the globe. I am also expecting that my colleagues from other platforms would also join me in this endeavour.

Kindly visit Techno Legal Thoughts for more details.

Google Is Rightly Held Liable For Defamatory Contents By Australian Court

In a recent case filed by Milorad Trkulja against search engine Google, the Australian court has held Google liable for defamatory images that were reflected in its search results.

The jury in this case concluded that the search engine was the publisher of images of Trkjulja and related information which suggested he was involved in crime. Google naturally took the defence of being an online service provider (OSP) not liable for defamatory images.

However, Google failed to realise that the safe harbour protection available to it ceases to exist the moment it is put to notice of the defamatory or any copyright infringing material and it fails to take any action upon the same.

If even after being aware of such offending material a search engine like Google does not take action, it is certainly liable for the consequences as the safe harbour protection is not available to it.

Of late Google has also been defying both Indian and US laws that pertains to copyright protection, trademarks protection and offensive contents removal laws. In fact, Google has been deleting the original and copyright protected articles and is supporting copyright infringers by not removing the copyright violating results from the search results.

A dedicated website titled websites, blogs and news censorship by Google and India and a corresponding discussion group has also been started by Perry4Law’s Techno Legal Base (PTLB) to demarcate the legal liabilities of Google for engaging in many forms of search results censorships and not taking appropriate legal action after receiving a valid content removal request.

We must ascertain is Google playing stupid or is it actually stupid? Google has been ignoring in many cases the applicable laws for removal of copyright violating material and offending contents. And merely because it is an intermediary or OSP does not protect it from civil and criminal liabilities especially when it is aware of the offending contents.

Monday, 26 November 2012

Indian National Cyber Security Database

This post talks about the latest techno legal cyber security initiative by Perry4Law Techno Legal Base (PTLB). The initiative is known as National Cyber Security Database of India (NCSDI) and it is a unique techno legal cyber security initiative.


See Cyber Security Issues In India for more details.

Cyber Crimes Investigation Centre Of India

Research and development plays a major role in developing cyber security capabilities. It is also crucial to develop methods to fight against cyber crimes and cyber attacks. Private initiatives like cyber security research centre of India (CSRCI), cyber forensics research and development centre of India (CFRDCI), cyber and hi-tech crimes investigation and training centre (CHCIT) of India, cyber security research and development centre of India (CSRDCI), etc are crucial in this regard.

At Perry4Law and Perry4Law Techno Legal Base (PTLB) we are managing the exclusive techno legal cyber crime and high tech investigation and training centre of India.

See Cyber Crimes Investigation Centre Of India for more details.