Tuesday, May 3, 2016

RBI ACKNOWLEDGES FINANCIAL ILL- LITERACY AND LACK OF AWARENESS



                 The Reserve Bank of India has recently come up with Notification dated 21 April 2016 vide ref. no.RBI/2015-16/378 DBR No.Leg.BC.93/09.07.005/2015-16 regarding Publicity in Bank branches cautioning public against placing deposits in dubious schemes.
                The Circular says that RBI has noticed that customers receive telephone calls relating to winning of lotteries/prizes etc. or various dubious schemes have been floated where returns are higher than offered by banks on deposits. The customer believing such messages/schemes remit the required amount apart from divulging details of their accounts to the fraudsters.
               Then circular adds that absence of financial literacy and lack of alertness to fraudulent schemes/calls are the main reasons behind innocent depositors falling prey to such schemes.
               There after circular states that all Scheduled Commercial Banks including Regional rural Banks and Local Area Banks may in their own interest and as customer education effort in interest of public consider designing suitable posters or pamphlets and notices consisting messages of awareness.
                Cyber Awareness Organisation suggests some additional measures which should be implemented on priority basis for prevention of such frauds and protecting public’s hard earned money.
1)    RBI itself is sitting on huge fund known as Depositors Education and Awareness Fund since last two years and should consider releasing same for benefit of customer education and awareness as per old saying CHARITY BEGINS AT HOME!!!!
2)    RBI should mandate all the banks to carry out Customer Cyber Awareness and Education program in each branch on bi-monthly basis to impart security trainings to customers.
3)    RBI should create central helpline for speedy reporting and data analysis of such frauds so as to act faster.
4)    RBI should monitor AML reporting on weekly basis and more consistently.
5)    There has to be synchronization of LEA, RBI AND TSP’s in investigations.
6)    The payments gateways should be properly regulated.
7)    There must be some cooling time for all transactions except few where additional security or authentication measures are followed with prior approval of the customer.
8)    All payment gateways must be compliant with section 43A of I T Act.
9)    RBI should monitor KYC implementation more strictly and illiterate customers should not be provided with any type of Credit/Debit cards.    
                There are many more such suggestions like encouraging talk shows/power point presentations for creating cyber awareness among users etc.

                 We congratulate RBI for the issuance of this circular which is first step towards creating Cyber Awareness and CYBER AWARENESS ORGANISATION feels proud that its cause is at least endorsed by the Apex bank of India.


Monday, April 18, 2016

Information Technology Civil Judicial System, Is it working?



All of us know that online transactions have gained the momentum it desired and many people are finding benefits of it. There are few black sheep’s in this business also and to take action agonist them Information Technology Act was introduced as Special Act by Parliament of India. There are sections 43 and 43A which specifically deals with Civil Liability and for appealing under these sections Adjudicators have been prescribed under Information Technology Act. These Adjudicators are Information Technology Secretary of respective State governments.
To appeal against decisions of these Adjudicators, the Cyber appellate Tribunal has been constituted under said act.
So we presume that the set up is very fine and must be in order.
But reality is very different. The most progressive state Maharashtra, which was in many ways a trend setter in I T Adjudication till Mr. Rajesh Aggrawal was Adjudicator, has conducted only two hearings in last two years.
Amazing!!!!! A state with 47 cases registered in 2014, 59 cases in 2015 and 18 cases till March 2016 could conduct only one hearing in entire Year speaks itself about the way government is looking towards I T Civil Litigation's.
And it’s no good to speak about CYBER APPELLATE TRIBUNAL which is yet to see new Chairperson since last many years.
The Information Technology Department Maharashtra neither is bothered about updating its website in relation to I T Act cases nor interested in ascertaining how much Court fees is paid to it towards such litigation's.
It has to be mentioned very sadly that A country whose Prime Minister is encouraging use of Technology in every possible manner is unaware about I T Civil Judicial System.
Its no good for a country where cyber criminals are targeting innocent people who are left remediless by such Judicial apathy.  

Friday, April 1, 2016

Regulators needed for PAYMENT GATEWAYS!!!!!



Last fortnight a leading Mobile Payment gateway from India unveiled its projections to 5,00,000 online seller base by March 2017 as compared to current seller base of 1,70,000.This portal alone facilitates 300 million payment transactions per day and has set a target of 1 billion by 2020.
As I presume this ONLINE BUSINESS IS HIGH VOLUME AND LOW MARGIN BUSINESS.
When margins are low there are possibilities of compromises with the security or quality of the services customers receive. As these online companies can not compromise with bandwidth and high resolution servers they are most likely to save by compromising on security measures. These companies are for profit and not for charity and scrutinizing their business module it looks more probable that they might be compromising on security.
Section 43A of Information Technology Act mandates these service providers to follow reasonable security practices and guidelines to protect sensitive personal data and information of the users.
Another point of worry about these payment gateways, which have mushroomed recently, is very few legal or technical compliance required from government end. In a rush towards fulfilling its well deserved mission of Start up India government seems to be neglecting inherent threats in cyberspace. The cyberspace is used by entrepreneurs, end users who are techno illiterate and simultaneously by cyber criminals who are highly comfortable with technology and rather are highly techno savvy.
All are cohabiting in same cyberspace and when these payment gateways are carrying out almost a billion transactions per day collectively, the cyber criminals are bound to found out vulnerabilities in the same and exploit them for their financial gain. The biggest losers in this scenario presently are the innocent online payment gateway users and more interestingly people who don’t even opt for these payment gateways for their any transaction.
Shocked????
How people who don’t even opt for online payment gateways can be falling prey to such frauds???

The modus operandi noticed is very simple. These fraudsters obtain credit/debit card details and cvv code from such innocent people and utilise same for fraudulent transactions through these payment gateways. Payment gateways are least bothered about origin of payment or destination of beneficiary. What they are bothered about is their transaction fees and nothing else.
There are many cases where payment gateways are unable to provide complete authenticated details of beneficiaries. This is alarming situation and currently cyber criminals are exploiting it very effectively. The amount of such frauds can not be estimated with limited information available with my organisation but I am sure its figure will be unimaginable by anybody. If you prefer to guess you are welcome.

It’s high time that Payment Gateways must be brought under some sort of Regulatory mechanism!!!
This regulator will be entrusted to look into all such matters where Payment Gateways are found to be involved in some sort of fraudulent activities. For want of such regulatory mechanism, unnecessarily Good Payment Gateways are also being tarnished.
To avoid this situation and make people believe in this online payment mechanism the formation of such regulator is NEED OF HOUR.

Tuesday, January 26, 2016

Need of hour to strengthen Cyber Judiciary regime in India.



India is fastest developing economy in world and under vibrant leadership of Hon.PM Narendra Modiji it is set to instigate many projects through e-governance activities. It will also be a booster to various e-commerce activities in India. Mission Digital India with its expected and anticipated targets will make many more citizens use online services and yield its benefits.
With more and more focus on digitalisation of activities and era of Internet of Things, citizens are left with no option but to become digital knowledgeable. While many e-commerce activities are getting impetus like online shopping, online ticket booking, online complaint reporting mechanisms etc., the focus of government is bound to promote growth of more and more digitalisation.
The digitalisation of services provides various benefits like transparency, efficiency and jurisdiction and hence are becoming more and more attractive.
But there is other side of this digitalisation which is neither noticed yet nor thought for. This other side is allied to disputes in e-commerce activities. Due to growth of e-commerce activities there are various issues which need to be answered but till date very meager efforts are put into resolving them.
Indeed I am highlighting Internet Frauds and Cyber crimes and its reporting mechanism. When in country like India which has larger geographical territory among many countries in world, it’s very convenient for cyber criminals to commit crimes from far off location even within country and with petty amount involved and get away with it. The reason behind is for meager amount local police won’t register crime or owing to location of actual happening of incident the police will display their inability to register crimes due to jurisdiction issue.
And even if some victims are able to register the offenses then there is another stumbling block known as judiciary. When in a country like India where normal judiciary is neglected less should be said about Cyber Judicial process. In Supreme Courts and High Courts almost 50 percent vacancies exists in posts of Judges till date and hence cases are piling up by every passing day. It’s better not to say anything about lower courts vacancies and case pending ratio.
But in this era of digitalisation many people believe that cyber adjudication must be different from traditional judicial process and there must be faster relief to the victims. But this can be said as mere wishful thinking and nothing else. If we strictly go by Information Technology Act, a special act passed by Indian Parliament to regularise e-commerce activities in India, it certainly provides for time bound adjudication. The desired duration for completion of adjudication is specified as Six months and which is very welcome one.
But if we scrutinize reality it’s totally catastrophic. For example the apex body for cyber adjudication known as Cyber Appellate Tribunal is without any head and hence almost defunct since last 4-5 years. There are about 67 appeals pending from across India since 2011 and no real efforts seems to be taken to provide relief to these 67 applicants. It is said that justice delayed is justice denied but I think time has come to redefine the word “Delay”. In this digitalised word every second is significant because by every passing second I P Address can change so can location of criminal and so also the cyber crime victim. So in this digitalisation era there is magnanimous importance to time bound activities and hence Timing is very crucial in Cyber Adjudication Matters also.
Even if we observe the lower level of Cyber Adjudication, which is termed as Adjudicator and Information Technology Secretary of each state, is designated as Adjudicating Officer, there is even more pathetic situation. Most of the I T Secretaries even today have not entertained a single case till date i.e. even after passage of 15 years, since when they were supposed to act in such capacity.
Even if we consider one of the most progressive states i.e. Maharashtra, there have been no significant hearings since last one year. It’s better not to comment about performance of rest of the Adjudicating Officers in other Indian States.
So in this situation where police are unenthusiastic to register cyber crime complaints and cyber judiciary is practically non- functional, what the ordinary citizen should do if he is cyber crime victim?
The growth in cyber crimes is imminent as more and more financial transactions are carried on using online medium and also confirmed by recent NCRB statistics.
The present cyber judicial situation needs to be revamped drastically. Cyber Judiciary should be seen as priority sector so that cyber criminals can be penalized and deterred and which can be one of the factors to bring down cyber crimes. If we go by financial frauds reported through credit or debit cards or through dubious online portals its need of hour to reinforce our Cyber Judiciary regime.
Hope that some wisdom will prevail and steps will be taken in this direction.

Monday, June 15, 2015

Investigative Journalism and Cyberspace

From yesterday onwards Times Now is claiming to have exploded e-mail scandals of correspondances between Sushma Swarajji,Lalit Modi and Keith Waz, the British MP wherein Sushmaji has supposedly asked for favor for her kin from Lalit Modi.
As a numero uno channel with so claimed highest proprietory to Active journalism,I feel this channel has exceeded its limit in the name of investigative journalism. If the channel claims to have in its custody the emails exchanged between the trio, the natural question comes to my mind is How third party got access with the pesonal e-mails of these persons. Has Times Now engaged hacers to hack e-mail accounts or either of three willingly gave access to TIME NOW for accessing the said mails?
Secondly probability seems to be improbable and hence certainity about first possibility is obvious.

Information Technology Act under section 43 (a) says that if any person without permisssion of owner or any other person who is incharge of such computer,computer network or computer system accesses or secures access to such system then he shall be liable to pay damages. And if this act in section 43a is done with dishonest or fraudulent intention then he shall be punished with imprisonment or fine or with both.

Now keeping the political issue apart from this act of Times Now,the question remains How they accessed the e-mails without prior permisssion. Mr.Waz has made it clear that this act of Times Now in punishable under British Laws and Indian laws have similar provisions.

Does investigative journalism gives immunity for acts forbidden under law? If not then why legal action under section 66a should not be initiated?

Under RTI act also you can not seek someons personal information and in many matters even court has upheld privacy of the individual supreme. Even our Fundamental Rights does not compell someone to testify against himself so all persons have inherrent immunity against depositions about themselves.

Considering these logic ,the source of emails must be explained by Times Now and if they fail to disclose there souce then legal action should be initiated immedialtely against them.

Also when contacted with senior editor Mr.Praveen Bardapurkar,he opinioned that Nobody has given free run to invade anyone’s privacy and this act of Times Now has exceeded all the limits of investigative journalism.

I T Act also has provision to punish who assists in such criminal act and hence even Times Now have not hired the Hackers they should be punished under this provison of act.

The bigger issue is Can anybody’s privacy in Cyberspace is so fragile? And if yes then its an eye-opner for MISSION DIGITAL INDIA. Today its emails between politicians and tomorrow it could be emails between officials and day after it could be conversations between head of state.
Its high time to rethink about security in Cyberspace and laws and its implementation must be strengthened to such extent that cyber criminals will think twice before committing such misadventures.
There has to be a nation-wide debate amongst Law Enforcement Agencies, Politicians, Academicians, Legal Professionals and Telecom Service Providers on this issue, which is concerned with safety and security of the Nation as well as future of this Young India

Wednesday, May 27, 2015

MY VIEWS ON TCS's BIGGEST ANNUAL SURVEY ON DIGITAL LIFESTYLES OF URBAN TEENS .

Recently a survey called as “The biggest Annual survey on Digital Lifestyles of Urban Indian Teens” was conducted by one of the leading I T Company in India i.e. TCS.

The survey can be studied and inferences can be drawn by various angles and Cyber Awareness Organisation wishes to express its own supposition about the survey. 

Let’s first see what salient features of the survey are.

1)    The survey was conducted in Metros like Mumbai, Delhi, Chennai and Kolkata and also emerging metros like Nagpur, Pune, Ahmadabad and Indore etc. In all14 cities with 1739 schools and 12365 high school students between age group of 12 to 18 years were the participants of this survey.
2)    72 % students own Smartphone and 85% use social media which they think as essential for keeping in touch with friends and knowing current affairs. Whatsapp, a free messenger platform, is used by almost 58% students without understanding inherent dangers of freeware.
3)    67% have shopped online and survey is silent about whether they used credit/debit card or Cash on delivery option. About 76% students spent 60 minutes per day on SNS.30% post daily on SNS while another 33% posts thrice a week 52% students opinioned that SNS helps in increasing friends whereas 23% feel that SNS helps them in studies. More than half respondents have stated that their parents monitor their online activity.
4)    In Nagpur 21% students follow their teachers on Twitter whereas in India 14% students follow their teachers. Surprisingly Pune, which is considered as bastion of Education, only 9% students follow their Teachers on Twitter.

CAO see’s the increasing pattern of using Smartphone and Social media as a cause of concern for these teens. It has been proved by various studies that increased reliance on electronic gadgets is disturbing feature in retention capacity of the students. So it can be inferred that young Digital Generation will be having very short memories and will rely more on electronic gadgets.

In other words, where most of the life of Digital Generation will be more electronically driven in coming years, all the required passwords/mail passwords/ banking passwords will also be remembered by the gadgets and if gadget is lost or stolen entire privacy of this generation can be exposed to various dangers.

When free apps are used more often for communication, the security is certainly liable to be compromised. It has been proven time and again that all these freeware applications are primarily crated for data collection and currently there are no legal regulations for governing such applications.
The non-regulatory mechanism either on ground of fundamental right of free speech and expression or non-understanding of potential dangers of data collection is really a cause of serious concern and CAO wishes to highlight this issue again on backdrop of this survey.

There has to be a nation-wide debate amongst Law Enforcement Agencies, Politicians, Academicians, Legal Professionals and Telecom Service Providers on this issue, which is concerned with safety and security of the Nation as well as future of this Young India. Can we imagine such India, which will be Youngest Democracy in coming years, wherein its citizen’s entire personal data would be in hands of some company which is located out of India and which could be able to dance the citizens of free India on its own tunes, owing to sensitive personal information held by it?  

Another disturbing trend is shopping online which is exhibited by 67% students. Normal principles of purchasing decision making authority lying IN HANDS OF Money Earner seems to be changing from money earner to technology user, because these students we don’t expect to earn on their own and thereby spending the hard earned money by their parents. This pattern is really disturbing because these students have not earned on their own still they have option of decision making on how it should be spent online and here the entire decision making expertise of their parents is making way to these inexperienced and immature generation which is best opportunity for trickster and fraudsters to promote various products through various fake online shopping portals. Unfortunately, presently, there are hardly any rules and regulations governing these online shopping portals. Nor people know about any remedial mechanism, set up by government, to report such frauds.

In such sorry situation, if online purchasing trend is increasing then again it’s a cause of concern.

 Encouraging results of survey are 50% parents monitoring their wards online activity as well as @ 25% students sharing their passwords with parents. It indicates that half the parents are aware about online threats and take interest in monitoring wards online behavior also.

In our views survey should have asked questions about Cyber Bullying and Awareness level of Cyber Security issues.

Cyber Awareness Organisation is NGO which helps to victims of cyber crimes to come forward and avail civil/criminal remedy provided under I T Act. Many times due to ignorance of available remedies cyber crime victims are left with no option than to curse themselves. To make such cyber crime victims more informed and aware about the remedy CAO has appealed them to call on CYBER CRIME HELPLINE 09225109900 or mail to info@cyberorgindia.com.