[Commons-Law] [india-gii] IT Act Draft Rules and Encryption
Pranesh Prakash
pranesh at cis-india.org
Fri Feb 25 19:50:21 IST 2011
The link says:
"Draft Rules under Section 43A & Section 79 of IT Act - Public Comments
Invited by February 25, 2011"
while the text on the page says "28.02.2011"
Hence the confusion.
On Friday 25 February 2011 07:26 PM, Pranesh Prakash wrote:
> Dear Tarun and all,
> Thanks so much for pointing out the final date is 28th, and not as I'd
> mentioned. We don't have to work overtime tonight to wrap up our
> comments. :)
>
> I would strongly urge everyone go through all three of these and send in
> comments.
>
> One general idea you might all want to keep in mind is to see if there
> is a nexus between each sub-rule and the parent section. For instance,
> most of the cybercafe regulations and a lot of the gen. intermediary
> guidelines regulation has nothing to do at all with whether they should
> or should not be held liable for user actions (which is what s.79(2),
> under which they are made is about).
>
> Regards,
> Pranesh
>
> On Friday 25 February 2011 06:35 PM, Tarun Dua wrote:
>> Draft Rules under Section 43A& Section 79 of IT Act for public comments
>>
>> * The Draft rule under section 43A- Reasonable security practices
>> and procedures and sensitive personal information
>> * The Draft rule under section 79-Due diligence observed by
>> intermediaries guidelines
>> * The Draft rule under section 79-Guidelines for Cyber Cafe
>>
>> Comments are invited till 28.02.2011 which can be sent by email to:
>> grai AT mit.gov.in
>>
>> From the website.
>>
>> The intermediaries guidelines are especially worrisome. Having dealth
>> first hand with the bureaucracy at CERT. It has implications for the
>> nascent webhosting/hosted datacenter industry of which we are a part.
>>
>> -Tarun
>>
>> On Fri, Feb 25, 2011 at 1:06 PM, Pranesh
>> Prakash<pranesh at cis-india.org> wrote:
>>> Dear all,
>>> Today is the last date for comments on:
>>>
>>> The draft rule under s.43A : Reasonable security practices and
>>> procedures and sensitive personal information
>>> The draft rule under s.79 : Due diligence observed by intermediaries
>>> guidelines
>>> The draft rule under s.79 : Guidelines for cybercafes
>>>
>>> They are all very worrisome and disturbing. Importantly, there is a good
>>> case to say that they exceed the authority granted by the IT Act.
>>> Many of
>>> the provisions in the rules on intermediaries and cybercafes, for
>>> instance,
>>> have no nexus with s.79(2) under which they are drafted.
>>>
>>> They text of the draft rules be downloaded from the DIT website:
>>> http://goo.gl/qWZ8L
>>>
>>> Comments need to be sent to Gulshan Rai: grai at mit.gov.in
>>>
>>> And there's this op-ed in today's Hindu:
>>>
>>> http://goo.gl/Yp9pu
>>>
>>> The battle lines over encryption
>>>
>>> APARNA VISWANATHAN
>>>
>>> The draft Information Technology Rules provide the key to the back door
>>> sought by the government, and leave no doubt that security concerns will
>>> prevail over privacy.
>>>
>>> The draft “Information Technology (Due Diligence observed by
>>> intermediaries
>>> guidelines) Rules, 2011 circulated by the Ministry of Communications and
>>> Information Technology on February 10, 2011, address the issue of the
>>> liability of internet service providers (ISPs) and other
>>> intermediaries, an
>>> issue which achieved public notoriety through the Baazee.com case in
>>> 2004.
>>> In one master stroke, the Draft Rules settle the dispute raging over the
>>> last year, regarding the use of encryption techniques by the
>>> customers of
>>> BlackBerry, Google, Skype and MSN. Yet, while doing so, the Draft
>>> Rules also
>>> reveal the fundamental shortcomings of the IT Act even after the 2008
>>> amendments.
>>>
>>> The case, Avnish Bajaj v State arose out of the sale of a video clip
>>> on the
>>> website of Baazee.com, shot on a mobile phone in MMS form, depicting two
>>> schoolchildren indulging in an explicit sexual act. Although the
>>> Bazee.com
>>> case was ultimately decided under the provisions of the Indian Penal
>>> Code,
>>> the critical legal issue in civil law is to what extent ISPs can be held
>>> liable for the content transmitted through their network. The question,
>>> which was initially addressed by California courts in the mid-1990s, was
>>> whether ISPs should be treated in the same manner as newspapers or
>>> magazines
>>> publishing content and, therefore, made potentially liable for copyright
>>> infringement, defamation, obscenity and other civil/criminal
>>> liability, or
>>> as telephone companies which are not liable for the content of the
>>> communications they transmit.
>>>
>>> Since the seminal 1995 judgment of the District Court of Northern
>>> California
>>> in the Netcom case, the view in the U.S. has been that an ISP is a
>>> passive
>>> service provider much like a telephone company and cannot be held
>>> liable for
>>> the content transmitted through its server. This legal position
>>> changed in
>>> the U.S. with the passage of the Digital Millenium Copyright Act (DMCA),
>>> which provided a “safe harbour” for ISPs, conferring exemption from
>>> copyright liability. However, the exemption is subject to the ISP
>>> meeting
>>> certain conditions. The ISP must not have the actual knowledge that the
>>> material is infringing, must not be aware of the facts and circumstances
>>> from which the infringing activity is apparent and, in the event of
>>> having
>>> such knowledge, must act expeditiously to disable such material. In
>>> order to
>>> avail himself of the exemption from liability, the service provider must
>>> also not receive a financial benefit directly attributable to the
>>> infringing
>>> activity.
>>>
>>> The legal position in India is similar to the DMCA in that the exemption
>>> from liability is not absolute but is subject to meeting certain
>>> conditions.
>>> Following the 2008 amendments, Section 79 of the IT Act, 2000
>>> provides that
>>> an intermediary will not be held liable for any third party information,
>>> data or communication link made available or hosted by him. However,
>>> this
>>> exemption will apply only if the following conditions are met.
>>>
>>> First, the function of the intermediary must be limited to providing
>>> access
>>> to a communication system over which information made available by third
>>> parties is transmitted or temporarily stored or hosted. Second, the
>>> intermediary does not initiate the transmission, select the receiver or
>>> select/modify the information contained in the transmission. In other
>>> words,
>>> the ISP acts like a telephone company and not like a newspaper editor
>>> who
>>> can select or edit the information provided. The exemption will also
>>> not be
>>> applicable if the ISP has conspired, aided, abetted or induced the
>>> commission of the unlawful act; or upon receiving actual knowledge
>>> that any
>>> information, data or communication link residing in or connected to a
>>> computer resource controlled by the intermediary is being used to
>>> commit the
>>> unlawful act, the intermediary fails to expeditiously remove or disable
>>> access to that material. The last two conditions are similar to those
>>> imposed under the DMCA in the U.S.
>>>
>>> Furthermore, in order to avail himself of the exemption under Section
>>> 79,
>>> the intermediary must “observe due diligence” while discharging his
>>> duties
>>> under the IT Act, 2000 and also observe other guidelines which the
>>> Central
>>> government may prescribe in this behalf. For the first time, since
>>> the 2008
>>> amendments came into force, on February 10, 2011, the Ministry of
>>> Communications and Information Technology circulated draft rules
>>> regarding
>>> due diligence by intermediaries (the “Draft Rules”).
>>>
>>> Sub-rule (2) of the Draft Rules lists the types of infringing
>>> information
>>> which should not be transmitted by the intermediary, including
>>> information
>>> which is 1) abusive, blasphemous, obscene, vulgar etc., 2) infringing of
>>> IPRs, 3) sensitive personal information, and 4) information which
>>> threatens
>>> the unity, security or sovereignty of India. However, sub-rule (2) then
>>> tries to add in the offences which are the instruments of modern cyber
>>> crime. The list includes any information which impersonates another
>>> person,
>>> that is, identity theft and deceiving or misleading the addressee
>>> about the
>>> origin of electronic messages more commonly known as phishing.
>>> However, this
>>> list comprising identity theft and phishing is entirely inadequate as
>>> these
>>> are only a few methods of modern cyber crime/war. The list ignores, for
>>> example, the installation of a program which allows an attacker to
>>> remotely
>>> control the targeted computer otherwise known as “BOTNETS.” Another
>>> common
>>> tool of cyber crime is the use of a software program or a device
>>> designed to
>>> secretly monitor and log all keystrokes otherwise known as “keyloggers.”
>>> However, neither the remote access of a computer nor the secret
>>> monitoring
>>> of a computer resource is mentioned in sub-rule (2).
>>>
>>> The Draft Rules also introduce a definition of “cyber security
>>> incident” as
>>> any real or suspected adverse event in relation to cyber security that
>>> violates an explicitly or implicitly applicable security policy
>>> resulting in
>>> unauthorised access, denial of service or disruption, unauthorised
>>> use of a
>>> computer resource for processing or storage of information or changes to
>>> data, information without authorisation. In fact, the need to include
>>> the
>>> concepts of modern cyber crime and a definition as basic and critical as
>>> “cyber security incident” in Draft Rules on due diligence by
>>> intermediaries
>>> shows that there is a fundamental lacuna in the IT Act itself,
>>> namely, that
>>> it ignores the concepts of modern cyber war altogether and is limited
>>> to the
>>> outdated concerns of theft of software code through hacking.
>>>
>>> The partial attempt to bring in the concepts of modern cyber crime
>>> under the
>>> purview of the IT Act distracts attention from what is perhaps the main
>>> objective of the Draft Rules, that is, to codify the government's
>>> position
>>> towards service providers such as BlackBerry, Google, Skype, and MSN
>>> Hotmail
>>> which has recently attracted much attention. Research in Motion
>>> (RIM), the
>>> Canadian company, which operates BlackBerry, provides its customers with
>>> their own encryption key and does not possess a master key. According to
>>> RIM, in its system, there is no “back door” through which either RIM
>>> or any
>>> third party can gain access to the key or the customer's data.
>>>
>>> However, the Indian government was concerned that this level of
>>> encryption
>>> makes it impossible to monitor BlackBerry messages for national security
>>> purposes and that BlackBerrry's strong encryption technology could be
>>> used
>>> for terrorist or criminal activity. As per newspaper reports, on
>>> August 31,
>>> 2010, the Government of India accepted RIM's proposal for “lawful
>>> access by
>>> law enforcement agencies” of encrypted BlackBerry data. In December
>>> 2010,
>>> RIM reportedly provided the government a cloud computing-based system
>>> which
>>> would enable security agencies to lawfully intercept BlackBerry
>>> Messenger
>>> (BBM) messages in a comprehensible format but not BlackBerry Enterprise
>>> Service, that is, corporate emails.
>>>
>>> The Draft Rules incorporate the government's stand vis-à-vis
>>> BlackBerry into
>>> law because they require an intermediary to provide information to
>>> government agencies, which are lawfully authorised for investigative,
>>> protective, cyber security or intelligence activity. In sum, the
>>> Draft Rules
>>> provide the key to the back door long sought after by the government and
>>> leave no doubt that security concerns will prevail in law over the
>>> interest
>>> in privacy through use of encryption by civil society.
>>>
>>> --
>>> Pranesh Prakash
>>> Programme Manager
>>> Centre for Internet and Society
>>> W: http://cis-india.org | T: +91 80 40926283
>>>
>>>
>
--
Pranesh Prakash
Programme Manager
Centre for Internet and Society
W: http://cis-india.org | T: +91 80 40926283
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 262 bytes
Desc: OpenPGP digital signature
URL: <http://mail.sarai.net/pipermail/commons-law/attachments/20110225/456367b1/attachment-0001.bin>
More information about the commons-law
mailing list