Monday, April 18, 2016

Information Technology Civil Judicial System, Is it working?



All of us know that online transactions have gained the momentum it desired and many people are finding benefits of it. There are few black sheep’s in this business also and to take action agonist them Information Technology Act was introduced as Special Act by Parliament of India. There are sections 43 and 43A which specifically deals with Civil Liability and for appealing under these sections Adjudicators have been prescribed under Information Technology Act. These Adjudicators are Information Technology Secretary of respective State governments.
To appeal against decisions of these Adjudicators, the Cyber appellate Tribunal has been constituted under said act.
So we presume that the set up is very fine and must be in order.
But reality is very different. The most progressive state Maharashtra, which was in many ways a trend setter in I T Adjudication till Mr. Rajesh Aggrawal was Adjudicator, has conducted only two hearings in last two years.
Amazing!!!!! A state with 47 cases registered in 2014, 59 cases in 2015 and 18 cases till March 2016 could conduct only one hearing in entire Year speaks itself about the way government is looking towards I T Civil Litigation's.
And it’s no good to speak about CYBER APPELLATE TRIBUNAL which is yet to see new Chairperson since last many years.
The Information Technology Department Maharashtra neither is bothered about updating its website in relation to I T Act cases nor interested in ascertaining how much Court fees is paid to it towards such litigation's.
It has to be mentioned very sadly that A country whose Prime Minister is encouraging use of Technology in every possible manner is unaware about I T Civil Judicial System.
Its no good for a country where cyber criminals are targeting innocent people who are left remediless by such Judicial apathy.  

Friday, April 1, 2016

Regulators needed for PAYMENT GATEWAYS!!!!!



Last fortnight a leading Mobile Payment gateway from India unveiled its projections to 5,00,000 online seller base by March 2017 as compared to current seller base of 1,70,000.This portal alone facilitates 300 million payment transactions per day and has set a target of 1 billion by 2020.
As I presume this ONLINE BUSINESS IS HIGH VOLUME AND LOW MARGIN BUSINESS.
When margins are low there are possibilities of compromises with the security or quality of the services customers receive. As these online companies can not compromise with bandwidth and high resolution servers they are most likely to save by compromising on security measures. These companies are for profit and not for charity and scrutinizing their business module it looks more probable that they might be compromising on security.
Section 43A of Information Technology Act mandates these service providers to follow reasonable security practices and guidelines to protect sensitive personal data and information of the users.
Another point of worry about these payment gateways, which have mushroomed recently, is very few legal or technical compliance required from government end. In a rush towards fulfilling its well deserved mission of Start up India government seems to be neglecting inherent threats in cyberspace. The cyberspace is used by entrepreneurs, end users who are techno illiterate and simultaneously by cyber criminals who are highly comfortable with technology and rather are highly techno savvy.
All are cohabiting in same cyberspace and when these payment gateways are carrying out almost a billion transactions per day collectively, the cyber criminals are bound to found out vulnerabilities in the same and exploit them for their financial gain. The biggest losers in this scenario presently are the innocent online payment gateway users and more interestingly people who don’t even opt for these payment gateways for their any transaction.
Shocked????
How people who don’t even opt for online payment gateways can be falling prey to such frauds???

The modus operandi noticed is very simple. These fraudsters obtain credit/debit card details and cvv code from such innocent people and utilise same for fraudulent transactions through these payment gateways. Payment gateways are least bothered about origin of payment or destination of beneficiary. What they are bothered about is their transaction fees and nothing else.
There are many cases where payment gateways are unable to provide complete authenticated details of beneficiaries. This is alarming situation and currently cyber criminals are exploiting it very effectively. The amount of such frauds can not be estimated with limited information available with my organisation but I am sure its figure will be unimaginable by anybody. If you prefer to guess you are welcome.

It’s high time that Payment Gateways must be brought under some sort of Regulatory mechanism!!!
This regulator will be entrusted to look into all such matters where Payment Gateways are found to be involved in some sort of fraudulent activities. For want of such regulatory mechanism, unnecessarily Good Payment Gateways are also being tarnished.
To avoid this situation and make people believe in this online payment mechanism the formation of such regulator is NEED OF HOUR.

Tuesday, January 26, 2016

Need of hour to strengthen Cyber Judiciary regime in India.



India is fastest developing economy in world and under vibrant leadership of Hon.PM Narendra Modiji it is set to instigate many projects through e-governance activities. It will also be a booster to various e-commerce activities in India. Mission Digital India with its expected and anticipated targets will make many more citizens use online services and yield its benefits.
With more and more focus on digitalisation of activities and era of Internet of Things, citizens are left with no option but to become digital knowledgeable. While many e-commerce activities are getting impetus like online shopping, online ticket booking, online complaint reporting mechanisms etc., the focus of government is bound to promote growth of more and more digitalisation.
The digitalisation of services provides various benefits like transparency, efficiency and jurisdiction and hence are becoming more and more attractive.
But there is other side of this digitalisation which is neither noticed yet nor thought for. This other side is allied to disputes in e-commerce activities. Due to growth of e-commerce activities there are various issues which need to be answered but till date very meager efforts are put into resolving them.
Indeed I am highlighting Internet Frauds and Cyber crimes and its reporting mechanism. When in country like India which has larger geographical territory among many countries in world, it’s very convenient for cyber criminals to commit crimes from far off location even within country and with petty amount involved and get away with it. The reason behind is for meager amount local police won’t register crime or owing to location of actual happening of incident the police will display their inability to register crimes due to jurisdiction issue.
And even if some victims are able to register the offenses then there is another stumbling block known as judiciary. When in a country like India where normal judiciary is neglected less should be said about Cyber Judicial process. In Supreme Courts and High Courts almost 50 percent vacancies exists in posts of Judges till date and hence cases are piling up by every passing day. It’s better not to say anything about lower courts vacancies and case pending ratio.
But in this era of digitalisation many people believe that cyber adjudication must be different from traditional judicial process and there must be faster relief to the victims. But this can be said as mere wishful thinking and nothing else. If we strictly go by Information Technology Act, a special act passed by Indian Parliament to regularise e-commerce activities in India, it certainly provides for time bound adjudication. The desired duration for completion of adjudication is specified as Six months and which is very welcome one.
But if we scrutinize reality it’s totally catastrophic. For example the apex body for cyber adjudication known as Cyber Appellate Tribunal is without any head and hence almost defunct since last 4-5 years. There are about 67 appeals pending from across India since 2011 and no real efforts seems to be taken to provide relief to these 67 applicants. It is said that justice delayed is justice denied but I think time has come to redefine the word “Delay”. In this digitalised word every second is significant because by every passing second I P Address can change so can location of criminal and so also the cyber crime victim. So in this digitalisation era there is magnanimous importance to time bound activities and hence Timing is very crucial in Cyber Adjudication Matters also.
Even if we observe the lower level of Cyber Adjudication, which is termed as Adjudicator and Information Technology Secretary of each state, is designated as Adjudicating Officer, there is even more pathetic situation. Most of the I T Secretaries even today have not entertained a single case till date i.e. even after passage of 15 years, since when they were supposed to act in such capacity.
Even if we consider one of the most progressive states i.e. Maharashtra, there have been no significant hearings since last one year. It’s better not to comment about performance of rest of the Adjudicating Officers in other Indian States.
So in this situation where police are unenthusiastic to register cyber crime complaints and cyber judiciary is practically non- functional, what the ordinary citizen should do if he is cyber crime victim?
The growth in cyber crimes is imminent as more and more financial transactions are carried on using online medium and also confirmed by recent NCRB statistics.
The present cyber judicial situation needs to be revamped drastically. Cyber Judiciary should be seen as priority sector so that cyber criminals can be penalized and deterred and which can be one of the factors to bring down cyber crimes. If we go by financial frauds reported through credit or debit cards or through dubious online portals its need of hour to reinforce our Cyber Judiciary regime.
Hope that some wisdom will prevail and steps will be taken in this direction.

Monday, June 15, 2015

Investigative Journalism and Cyberspace

From yesterday onwards Times Now is claiming to have exploded e-mail scandals of correspondances between Sushma Swarajji,Lalit Modi and Keith Waz, the British MP wherein Sushmaji has supposedly asked for favor for her kin from Lalit Modi.
As a numero uno channel with so claimed highest proprietory to Active journalism,I feel this channel has exceeded its limit in the name of investigative journalism. If the channel claims to have in its custody the emails exchanged between the trio, the natural question comes to my mind is How third party got access with the pesonal e-mails of these persons. Has Times Now engaged hacers to hack e-mail accounts or either of three willingly gave access to TIME NOW for accessing the said mails?
Secondly probability seems to be improbable and hence certainity about first possibility is obvious.

Information Technology Act under section 43 (a) says that if any person without permisssion of owner or any other person who is incharge of such computer,computer network or computer system accesses or secures access to such system then he shall be liable to pay damages. And if this act in section 43a is done with dishonest or fraudulent intention then he shall be punished with imprisonment or fine or with both.

Now keeping the political issue apart from this act of Times Now,the question remains How they accessed the e-mails without prior permisssion. Mr.Waz has made it clear that this act of Times Now in punishable under British Laws and Indian laws have similar provisions.

Does investigative journalism gives immunity for acts forbidden under law? If not then why legal action under section 66a should not be initiated?

Under RTI act also you can not seek someons personal information and in many matters even court has upheld privacy of the individual supreme. Even our Fundamental Rights does not compell someone to testify against himself so all persons have inherrent immunity against depositions about themselves.

Considering these logic ,the source of emails must be explained by Times Now and if they fail to disclose there souce then legal action should be initiated immedialtely against them.

Also when contacted with senior editor Mr.Praveen Bardapurkar,he opinioned that Nobody has given free run to invade anyone’s privacy and this act of Times Now has exceeded all the limits of investigative journalism.

I T Act also has provision to punish who assists in such criminal act and hence even Times Now have not hired the Hackers they should be punished under this provison of act.

The bigger issue is Can anybody’s privacy in Cyberspace is so fragile? And if yes then its an eye-opner for MISSION DIGITAL INDIA. Today its emails between politicians and tomorrow it could be emails between officials and day after it could be conversations between head of state.
Its high time to rethink about security in Cyberspace and laws and its implementation must be strengthened to such extent that cyber criminals will think twice before committing such misadventures.
There has to be a nation-wide debate amongst Law Enforcement Agencies, Politicians, Academicians, Legal Professionals and Telecom Service Providers on this issue, which is concerned with safety and security of the Nation as well as future of this Young India

Wednesday, May 27, 2015

MY VIEWS ON TCS's BIGGEST ANNUAL SURVEY ON DIGITAL LIFESTYLES OF URBAN TEENS .

Recently a survey called as “The biggest Annual survey on Digital Lifestyles of Urban Indian Teens” was conducted by one of the leading I T Company in India i.e. TCS.

The survey can be studied and inferences can be drawn by various angles and Cyber Awareness Organisation wishes to express its own supposition about the survey. 

Let’s first see what salient features of the survey are.

1)    The survey was conducted in Metros like Mumbai, Delhi, Chennai and Kolkata and also emerging metros like Nagpur, Pune, Ahmadabad and Indore etc. In all14 cities with 1739 schools and 12365 high school students between age group of 12 to 18 years were the participants of this survey.
2)    72 % students own Smartphone and 85% use social media which they think as essential for keeping in touch with friends and knowing current affairs. Whatsapp, a free messenger platform, is used by almost 58% students without understanding inherent dangers of freeware.
3)    67% have shopped online and survey is silent about whether they used credit/debit card or Cash on delivery option. About 76% students spent 60 minutes per day on SNS.30% post daily on SNS while another 33% posts thrice a week 52% students opinioned that SNS helps in increasing friends whereas 23% feel that SNS helps them in studies. More than half respondents have stated that their parents monitor their online activity.
4)    In Nagpur 21% students follow their teachers on Twitter whereas in India 14% students follow their teachers. Surprisingly Pune, which is considered as bastion of Education, only 9% students follow their Teachers on Twitter.

CAO see’s the increasing pattern of using Smartphone and Social media as a cause of concern for these teens. It has been proved by various studies that increased reliance on electronic gadgets is disturbing feature in retention capacity of the students. So it can be inferred that young Digital Generation will be having very short memories and will rely more on electronic gadgets.

In other words, where most of the life of Digital Generation will be more electronically driven in coming years, all the required passwords/mail passwords/ banking passwords will also be remembered by the gadgets and if gadget is lost or stolen entire privacy of this generation can be exposed to various dangers.

When free apps are used more often for communication, the security is certainly liable to be compromised. It has been proven time and again that all these freeware applications are primarily crated for data collection and currently there are no legal regulations for governing such applications.
The non-regulatory mechanism either on ground of fundamental right of free speech and expression or non-understanding of potential dangers of data collection is really a cause of serious concern and CAO wishes to highlight this issue again on backdrop of this survey.

There has to be a nation-wide debate amongst Law Enforcement Agencies, Politicians, Academicians, Legal Professionals and Telecom Service Providers on this issue, which is concerned with safety and security of the Nation as well as future of this Young India. Can we imagine such India, which will be Youngest Democracy in coming years, wherein its citizen’s entire personal data would be in hands of some company which is located out of India and which could be able to dance the citizens of free India on its own tunes, owing to sensitive personal information held by it?  

Another disturbing trend is shopping online which is exhibited by 67% students. Normal principles of purchasing decision making authority lying IN HANDS OF Money Earner seems to be changing from money earner to technology user, because these students we don’t expect to earn on their own and thereby spending the hard earned money by their parents. This pattern is really disturbing because these students have not earned on their own still they have option of decision making on how it should be spent online and here the entire decision making expertise of their parents is making way to these inexperienced and immature generation which is best opportunity for trickster and fraudsters to promote various products through various fake online shopping portals. Unfortunately, presently, there are hardly any rules and regulations governing these online shopping portals. Nor people know about any remedial mechanism, set up by government, to report such frauds.

In such sorry situation, if online purchasing trend is increasing then again it’s a cause of concern.

 Encouraging results of survey are 50% parents monitoring their wards online activity as well as @ 25% students sharing their passwords with parents. It indicates that half the parents are aware about online threats and take interest in monitoring wards online behavior also.

In our views survey should have asked questions about Cyber Bullying and Awareness level of Cyber Security issues.

Cyber Awareness Organisation is NGO which helps to victims of cyber crimes to come forward and avail civil/criminal remedy provided under I T Act. Many times due to ignorance of available remedies cyber crime victims are left with no option than to curse themselves. To make such cyber crime victims more informed and aware about the remedy CAO has appealed them to call on CYBER CRIME HELPLINE 09225109900 or mail to info@cyberorgindia.com.


Sunday, May 17, 2015

Does Equality really exists in India, while reporting CYBER CRIMES??????

A day before there was a news about "CM Fadnavis' personal secretary cheated by cyber fraudsters" in many newspapers mostly published from Mumbai.

There was a huge shock in store when on very next day it was reported that " E-fraudester's a/c frozen in a day after Maharashtra CM aide loses Rs.64,000/".

Its not clear to me whether I should appreciate the commendable work of investigation carried out by Mumbai Police or think rationally about the fundamental right guaranteed under Indian Constitution which speaks about All are Equal before Law and All will have Equal Protection of Law.

I must clarify about this dilemma.

Does police take similar prompt action if person involved is not soms one as influential as PA of Hon. C M of Maharashtra?

The normal questions asked by police would be "Why you compromised your password?"," When you yourself disclosed the information,why ask police to investigate?","First go to bank and report the matter and they will do the needful?,"From where money is withdrawn,the location is not in our jurisdiction.Pl file FIR in Kolkota","You won't get your money back and hence don't waste your as well as our time".

And many more such questions would have been asked by police and FIR would have been reported only if the complainant would have been successful in answering all the questions. And you yourself can guess the numbers.

But look in this matter.On very next day of filing FIR police have even frozen the beneficiary account where money was credited.

It very clearly shows that if Police wish to crack cyber crimes like Credit Cards Frauds ,as in above case, they can crack the same within hours.

So why many such victims complain that their FIR is even not registered?

And here I am sad to say that Does Equality really exists in India???

If and only if you are some influential person then only you are assured of Justice otherwise you are left on your own destiny.

Compare present case scenario which is almost similar to thousands of other cases,wherein people have lost corers of Rupees, but since Equality is not practiced those victims are denied their due share of Justice.
Is it not shameful for all of us???

The number of such incidents received by me indicates that Police are still evasive about filing FIR though all offenses under Information Technology Act are cognizable. And this prevents me from applauding commendable investigation carried out by police in above referred matter.

I can only prey that Police follow the same principles when it comes to reporting of Cyber Crimes.



Tuesday, April 14, 2015

My head hangs in shame!!!!!

                                                    
Cyber Security is very much hot topic for discussions these days. There are numerous online banking frauds, online shopping portal frauds and online job frauds and so on and so forth. The real issue today is everyone has accepted the benefits on online transaction from their own views and neglecting the security issues to be taken care of by others.
Like in an old story of Elephant being described by seven blind men, everyone thought his description of elephant perfect, as it was based on that part of elephant which that blind person got hold of. So naturally the person touching the leg thought it to be very strong and the person catching hold of trunk of elephant certainly described it at very thin and weak.
Cyber security scenario is similar to this description by seven blind persons, the only difference is, here people look from their own perspective and firmly disbelieve the views of others.
The recent example of issuing warning to CM’s Official Facebook page being vulnerable to hacking is such small example which shows what is the concern for security?
It is sorrow state of situation wherein the page with more than 1.3 million following is at the mercy of good will of Hackers!!!! I am really and deeply concerned about the same.
The owners of the page are not aware about the possible consequences of any such attack from unwanted elements and ignoring the security signals and warnings provided to them, time and again. This is very disturbing and worrying signal as they even don’t have that acumen to understand what is written between the lines.
Were they ever thought of what could be possible fallout of losing control of such a powerful Facebook page? Can they foresee what will happen if the control of this Facebook page is snatched by some unscrupulous element?
And that’s why my Head hangs in shame!!!
Why we are doing this thankless job of intimating and advising about issues concerning Cyber Security?
When Cyber Security is nobody’s baby who we are to look after and take care for the same????
If people are so fascinated and charmed by Cyberspace and ready to come forward only to celebrate every time the reasonable restrictions are removed but not coming forward to have some self regulation which will take us in direction of more safe and secured Cyberspace God alone can save the netizens!!!!


With such visionary at the helm of affairs of such responsible social media pages REALLY MY HEAD HANGS IN SHAME!!!!!!!