<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/internet-governance/blog/online-anonymity/search_rss">
  <title>We are anonymous, we are legion</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 1821 to 1835.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/indian-express-january-11-2018-"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/hakon-2016"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/hacking-without-borders-the-future-of-artificial-intelligence-and-surveillance"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/economic-times-jayadevan-pk-neha-alawadhi-february-25-2015-hacking-of-sim-card-by-spy-agencies-raises-fears-of-sensitive-documents-being-leaked"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/hackers-take-protest-to-indian-streets-and-cyberspace"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-times-of-india-may-19-2017-kim-arora-and-digbijay-mishra-hacker-steals-17-million-zomato-users-data-briefly-puts-it-on-dark-web"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/hacking-cis"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-may-19-2017-hack-exposes-zomatos-weak-protection-of-customer-data-say-cyber-experts"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/habeas-data-in-india"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/repeat-remix-remediate-summer-school-2013"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/guidelines-for-protection-of-national-critical-information-infrastructure"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/gsma-research-outputs"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/the-india-chronicles"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/ground-zero-summit-2014"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/ground-zero-summit"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/news/indian-express-january-11-2018-">
    <title>Hammered government offers Virtual ID firewall to protect your Aadhaar</title>
    <link>https://cis-india.org/internet-governance/news/indian-express-january-11-2018-</link>
    <description>
        &lt;b&gt;Days after reports surfaced claiming security breaches, the Unique Identification Authority of India (UIDAI) on Wednesday announced the implementation of a new security protocol that would remove the need to divulge Aadhaar numbers during authentication processes and limit third-party access to KYC details.&lt;/b&gt;
        &lt;p&gt;The article was published in &lt;a class="external-link" href="http://www.newindianexpress.com/nation/2018/jan/11/hammered-government-offers-virtual-id-firewall-to-protect-your-aadhaar-1750466.html"&gt;New Indian Express&lt;/a&gt; on January 11, 2018.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Admitting that the “collection and storage of Aadhaar numbers by various entities has heightened privacy concerns”, the UIDAI circular said Authentication User Agencies (AUAs) providing Aadhaar services have to be ready to implement the protocol from March 1, 2018. From June 1 use of Virtual ID for authentication would be mandatory.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The linchpin of the new protocol will be the virtual ID (VID) — a “temporary, revocable 16-digit random number” that can be used instead of Aadhaar to verify or link services. VIDs will have a limited validity and can be generated only by the Aadhaar holder. “UIDAI will provide various options to generate, retrieve and replace VIDs… these will be made available via UIDAI’s resident portal, Aadhaar Enrolment Centre, mAadhaar mobile application, etc.,” it said. While only one VID per Aadhaar number will be valid at a time, users can revoke and generate new VIDs as many times as desired.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;UIDAI will also limit KYC details accessible by AUAs by classifying them as Global AUAs, which are required to use Aadhaar e-KYC by law, and Local AUAs. Only the former will have full access to e-KYC details and can store Aadhaar numbers. Local AUAs will only have access to limited KYC details and be prohibited from storing Aadhaar numbers. UIDAI will also generate UID tokens which will be used to identify customers within agencies’ systems, but these will not be usable by other AUAs.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, cybersecurity experts say that even if the new “patch” is effective, verification processes will have to be redone to prevent misuse of already-leaked Aadhaar numbers. “The concept is attractive, but the devil is in the details,” observed Pavan Duggal, cyberlaw expert, adding that the new system does not address those who have already gained unauthorised access to Aadhaar numbers. Sunil Abraham, executive director, Centre for Internet and Society, was more categorical. “If it has to be effective, they will have to redo (Aadhaar-KYC) from scratch.”&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/indian-express-january-11-2018-'&gt;https://cis-india.org/internet-governance/news/indian-express-january-11-2018-&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-01-16T23:34:12Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/hakon-2016">
    <title>Hakon 2016</title>
    <link>https://cis-india.org/internet-governance/news/hakon-2016</link>
    <description>
        &lt;b&gt; Udbhav Tiwari attended attended Hakon 2016, a conference held between September 30 and October 2, 2016 at Indore, Madhya Pradesh, India,on behalf of CIS under the Hewlett Cyber Security Project. &lt;/b&gt;
        &lt;p dir="ltr" style="text-align: justify; "&gt;Hakon 2016 was the third edition of the conference which  has been organised by Ninja Information Security Systems, an ISO  27001:2013 &amp;amp; 9001:2008 certified training organisation and the  primary sponsor of the conference from Indore. The conference was  efficiently organised, had about 150 to  200 people attending overall  and provided an unique window into the non-tech hub/big city ethical  hacker ecosystem and their place within the cyber security setup in  India. The agenda of this year's conference was the Underground Digital  Black Market &amp;amp; Digital Terrorism, with a fair mix of participants  from the industry, academia and the government. The conference website  can be looked up at &lt;a href="http://www.hakonindia.org/"&gt;http://www.hakonindia.org/&lt;/a&gt; for further details, including a look at past editions of the conference.&lt;/p&gt;
&lt;p dir="ltr" style="text-align: justify; "&gt;The technical workshops held during the first two days of the conference were well organised and networking with the teachers during and mostly at the end of the conference was very helpful in understanding a practitioners perspective on cutting edge aspects of cyber security. This was particularly true for &lt;a class="external-link" href="http://www.chuckeasttom.com/"&gt;Chuck Easttom Williams&lt;/a&gt;, an accomplished cyber security expert from the USA who regularly trains government agencies and in a fairly reputed industry veteran who has been an invited speaker at DEFCON and even has a couple of patents to his name.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/hakon-2016'&gt;https://cis-india.org/internet-governance/news/hakon-2016&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2016-10-15T10:04:41Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/hacking-without-borders-the-future-of-artificial-intelligence-and-surveillance">
    <title>Hacking without borders: The future of artificial intelligence and surveillance</title>
    <link>https://cis-india.org/internet-governance/blog/hacking-without-borders-the-future-of-artificial-intelligence-and-surveillance</link>
    <description>
        &lt;b&gt;In this post, Maria Xynou looks at some of DARPA´s artificial intelligence surveillance technologies in regards to the right to privacy and their potential future use in India. &lt;/b&gt;
        &lt;hr /&gt;
&lt;p&gt;&lt;i&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC&lt;/i&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;p class="Normal1"&gt;Robots or computer systems controlling our thoughts is way beyond anything I have seen in science fiction; yet something of the kind may be a reality in the future. The US Defence Advanced Research Projects Agency (DARPA) is currently funding several artificial intelligence projects which could potentially equip governments with the most powerful weapon possible: mind control.&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Combat Zones That See (CTS)&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;b&gt;&lt;img src="http://farm5.staticflickr.com/4137/4749564682_9ab88cb4d1.jpg" /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="Normal1"&gt;Source: &lt;span&gt; &lt;/span&gt;&lt;a href="http://www.flickr.com/photos/swanksalot/"&gt;swanksalot&lt;/a&gt; on flickr&lt;/p&gt;
&lt;p class="Normal1"&gt;Ten years ago DARPA started funding the&lt;a href="http://www.freerepublic.com/focus/f-news/939608/posts"&gt; Combat Zones That See (CTS)&lt;/a&gt; project, which aims to ´track everything that moves´ within a city through a massive network of surveillance cameras linked to a centralized computer system. Groundbreaking artificial intelligence software is being used in the project to identify and track all movement within cities, which constitutes Big Brother as a reality. The computer software supporting the CTS is capable of automatically identifying vehicles and provides instant alerts after detecting a vehicle with a license plate on a watch list. The software is also able to analyze the video footage and to distinguish ´normal´ from ´abnormal´ behavior, as well as to discover links between ´places, subjects and times of activity´ and to identify patterns. With the use of this software, the CTS constitute the world´s first multi-camera surveillance system which is capable of automatically analyzing video footage.&lt;/p&gt;
&lt;p class="Normal1"&gt;Although the CTS project was initially intended to be used for solely military purposes, its use for civil purposes, such as combating crime, remains a possibility. In 2003 DARPA stated that&lt;span&gt; &lt;a class="external-link" href="http://www.wired.com/politics/law/news/2003/07/59471"&gt;40 million surveillance cameras were already in use around the &lt;/a&gt;&lt;/span&gt;&lt;a class="external-link" href="http://www.wired.com/politics/law/news/2003/07/59471"&gt;world &lt;/a&gt;by law enforcement agencies to combat crime and terrorism, with 300 million expected by 2005. &lt;a href="http://www.wired.com/politics/law/news/2003/07/59471"&gt;Police&lt;/a&gt; in the U.S. have stated that buying new technology which may potentially aid their work is an integral part of the 9/11 mentality. Considering the fact that literally millions of CCTV cameras are installed by law enforcement agencies around the world and that DARPA has developed the software that has the capability of automatically analyzing data gathered by CCTV cameras, it is very possible that law enforcement agencies are participating in the CTS network.&lt;/p&gt;
&lt;p class="Normal1"&gt;However if such a project was used for non-military level purposes, it could raise concerns in regards to data protection, privacy and human rights. As a massive network of surveillance cameras, the CTS ultimately could enable the sharing of footage between private parties and law enforcement agencies without individuals´ knowledge or consent. Databases around the world could be potentially linked to each other and it remains unclear what laws would regulate the access, use and retention of such databases by law enforcement agencies of multiple countries. Furthermore, there is no universal definition for ´normal´ and ´abnormal´ behaviour, thus if the software is used for its original purpose, to distinguish between “abnormal” and “normal” behaviour, and used beyond military purposes, then there is a potential for abuse, as the criteria for being monitored, and possibly arrested, would not be clearly set out.&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Mind´s Eye&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;b&gt;&lt;img src="http://farm9.staticflickr.com/8425/7775805386_8260b7836c.jpg" /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="Normal1"&gt;Source: &lt;span&gt; &lt;/span&gt;&lt;a href="http://www.flickr.com/photos/58687716@N05/"&gt;watchingfrogsboil&lt;/a&gt; on flickr&lt;/p&gt;
&lt;p class="Normal1"&gt;A camera today which is only capable of recording visual footage appears futile in comparison to what DARPA´s creating: a &lt;a href="http://www.wired.com/dangerroom/2011/01/beyond-surveillance-darpa-wants-a-thinking-camera/"&gt;thinking camera&lt;/a&gt;. The Mind´s Eye project was launched in the U.S. in early 2011 and is currently developing smart cameras endowed with &lt;a href="http://www.darpa.mil/Our_Work/I2O/Programs/Minds_Eye.aspx"&gt;´visual intelligence´&lt;/a&gt;. This ultimately means that artificial intelligence surveillance cameras can not only record visual footage, but also automatically detect ´abnormal´ behavior, alert officials and analyze data in such a way that they are able to &lt;a href="http://phys.org/news/2012-10-surveillance-tech-carnegie-mellon.html"&gt;predict future human activities and situations&lt;/a&gt;.&lt;/p&gt;
&lt;p class="Normal1"&gt;Mainstream surveillance cameras already have visual-intelligence algorithms, but none of them are able to automatically analyze the data they collect. Data analysts are usually hired for analyzing the footage on a per instance basis, and only if a policeman detects ´something suspicious´ in the footage. Those days are over. &lt;a href="http://www.wired.com/dangerroom/2011/01/beyond-surveillance-darpa-wants-a-thinking-camera/"&gt;General&lt;/a&gt;&lt;a href="http://www.wired.com/dangerroom/2011/01/beyond-surveillance-darpa-wants-a-thinking-camera/"&gt; &lt;/a&gt;&lt;a href="http://www.wired.com/dangerroom/2011/01/beyond-surveillance-darpa-wants-a-thinking-camera/"&gt;James Cartwright&lt;/a&gt;, the vice chairman of the Joint Chiefs of Staff, stated in an intelligence conference that “Star[ing] at Death TV for hours on end trying to find the single target or see something move is just a waste of manpower.” Today, the Mind´s Eye project is developing smart cameras equipped with artificial intelligence software capable of identifying &lt;a href="http://www.darpa.mil/Our_Work/I2O/Programs/Minds_Eye.aspx"&gt;operationally significant activity&lt;/a&gt; and predicting outcomes.&lt;/p&gt;
&lt;p class="Normal1"&gt;Mounting these &lt;a href="http://www.dailygalaxy.com/my_weblog/2011/01/minds-eye-darpas-new-thinking-camera-will-transform-the-world-of-surveillance.html"&gt;smart cameras on drones&lt;/a&gt; is the initial plan; and while that would enable military operations, many ethical concerns have arisen in regards to whether such technologies should be used for ´civil purposes.´ Will law enforcement agencies in India be equipped with such cameras over the next years? If so, how will their use be regulated?&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;SyNAPSE&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;b&gt;&lt;img src="http://farm9.staticflickr.com/8230/8384110298_da510e0347.jpg" /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="Normal1"&gt;Source: &lt;span&gt; &lt;/span&gt;&lt;a href="http://www.flickr.com/photos/healthblog/"&gt;A Health Blog&lt;/a&gt; on flickr&lt;/p&gt;
&lt;p class="Normal1"&gt;The &lt;i&gt;Terminator &lt;/i&gt;could be more than just science fiction if current robots had artificial brains with similar form, function and architecture to the mammalian brain. DARPA is attempting this by funding HRL Laboratories, Hewlett-Packard and IBM Research to carry out this task through the &lt;a href="http://www.artificialbrains.com/darpa-synapse-program"&gt;Systems of Neuromorphic Adaptive Plastic Scalable Electronics (SyNAPSE)&lt;/a&gt; programme.  Is DARPA funding the creation of the &lt;i&gt;Terminator&lt;/i&gt;? No. Such artificial brains would be used to build robots whose intelligence matches that of mice and cats...for now.&lt;/p&gt;
&lt;p class="Normal1"&gt;SyNAPSE is a programme which aims to develop &lt;a href="http://celest.bu.edu/outreach-and-impacts/the-synapse-project"&gt;electronic neuromorphic machine technology&lt;/a&gt; which scales to biological levels. It started in the U.S. in 2008 and is scheduled to run until around 2016, while having received&lt;a href="http://www.artificialbrains.com/darpa-synapse-program"&gt; $102.6 million&lt;/a&gt; in funding as of January 2013. The ultimate aim is to build an electronic microprocessor system that matches a mammalian brain in power consumption, function and size. As current programmable machines are limited by their computational capacity, which requires human-derived algorithms to describe and process information, SyNAPSE´s objective is to create &lt;a href="http://www.darpa.mil/Our_Work/DSO/Programs/Systems_of_Neuromorphic_Adaptive_Plastic_Scalable_Electronics_(SYNAPSE).aspx"&gt;biological neural systems &lt;/a&gt;which can autonomously process information in complex environments. Like the mammalian brain, SyNAPSE´s &lt;a href="http://www.ibm.com/smarterplanet/us/en/business_analytics/article/cognitive_computing.html"&gt;cognitive computers&lt;/a&gt; would be capable of automatically learning relevant and probabilistically stable features and associations, as well as of finding correlations, creating hypotheses and generally remembering and learning through experiences.&lt;/p&gt;
&lt;p class="Normal1"&gt;Although this original type of computational device could be beneficial to &lt;a href="http://www.ibm.com/smarterplanet/us/en/business_analytics/article/cognitive_computing.html"&gt;predict natural disasters&lt;/a&gt; and other threats to security based on its cognitive abilities, human rights questions arise if it were to be used in general for surveillance purposes. Imagine surveillance technologies with the capacity of a human brain. Imagine surveillance technologies capable of remembering your activity, analyzing it, correlating it to other facts and/or activities, and of predicting outcomes; and now imagine such technology used to spy on us. That might be a possibility in the future.&lt;/p&gt;
&lt;p class="Normal1"&gt;Such cognitive technology is still in an experimental phase and although it could be used to tackle threats to security, it could also potentially be used to monitor populations more efficiently. No such technology currently exists in India, but it could only be a matter of time before Indian law enforcement agencies start using such artificial intelligence surveillance technology to supposedly enhance our security and protect us.&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Brain-Computer Interface (BCI)&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;iframe frameborder="0" height="360" src="http://www.youtube.com/embed/qCSSBEXBCbY?feature=player_embedded" width="640"&gt;&lt;/iframe&gt;&lt;/p&gt;
&lt;p class="Normal1"&gt;Remember Orwell's ´&lt;i&gt;Thought Police&lt;/i&gt;´? Was Orwell exaggerating just to get his point across? Well, the future appears to be much scarier than Orwell's vision depicted in &lt;i&gt;1984&lt;/i&gt;. Unlike the ´&lt;i&gt;Thought Police&lt;/i&gt;´ which merely arrested individuals who openly expressed ideas or thoughts which contradicted the Party´s dogma, today, technologies are being developed which can &lt;i&gt;literally &lt;/i&gt;read our thoughts.&lt;/p&gt;
&lt;p class="Normal1"&gt;Once again, DARPA appears to be funding one of the world´s most innovative projects: the &lt;a href="http://www.wired.com/opinion/2012/12/the-next-warfare-domain-is-your-brain/"&gt;Brain-Computer Interface (BCI)&lt;/a&gt;. The human brain is far better at pattern matching than any computer, whilst computers have greater analytical speed than human brains. The BCI is an attempt to merge the two together, and to enable the human brain to control robotic devices and other machines. In particular, the BCI is comprised of a headset (an electroencephalograph -&lt;a href="http://www.extremetech.com/wp-content/uploads/2012/08/brain-hacking-accuracy-chart.jpg"&gt; an EEG&lt;/a&gt;) with sensors that rest on the human scalp, as well as of software which processes brain activity. This enables the human brain to be linked to a computer and for an individual to control technologies without moving a finger, but by merely &lt;i&gt;thinking &lt;/i&gt;of the action.&lt;/p&gt;
&lt;p class="Normal1"&gt;Ten years ago it was reported that the brains of &lt;a href="http://www.newscientist.com/article/dn2237"&gt;rats&lt;/a&gt; and &lt;a href="http://news.bbc.co.uk/2/hi/health/3186850.stm"&gt;monkeys&lt;/a&gt; could control robot arms through the use of such technologies. A few years later&lt;a href="http://www.newscientist.com/article/dn4540"&gt; brainstem implants&lt;/a&gt; were developed to tackle deafness. Today, brain-computer interface technologies are able to directly link the human brain to computers, thus enabling paralyzed people to conduct computer activity by merely thinking of the actions, as well as&lt;a href="http://www.cyborgdb.org/mckeever.htm"&gt; to control robotic limbs with their thoughts&lt;/a&gt;. BCIs appear to open up a new gateway for disabled persons, as all previously unthinkable actions, such as typing on a computer or browsing through websites, can now be undertaken by literally &lt;i&gt;thinking &lt;/i&gt;about them, while using a BCI.&lt;/p&gt;
&lt;p class="Normal1"&gt;Brain-controlled robotic limbs could change the lives of disabled persons, but&lt;a href="http://www.guardian.co.uk/science/2007/feb/09/neuroscience.ethicsofscience"&gt; ethical concerns&lt;/a&gt; have arisen in regards to the BCI´s mind-reading ability.  If the brain can be used to control computers and other technologies, does that ultimately mean that computers can also be used to control the human brain?  Researchers from the University of Oxford and Geneva, and the University of California, Berkley, have created a custom programme that was specially designed with the sole purpose of finding out &lt;a href="http://www.extremetech.com/extreme/134682-hackers-backdoor-the-human-brain-successfully-extract-sensitive-data"&gt;sensitive data&lt;/a&gt;, such as an individuals´ home location, credit card PIN and date of birth. Volunteers participated in this programme and it had up to 40% success in obtaining useful information. To extract such information, researchers rely on the &lt;i&gt;P300 response&lt;/i&gt;, which is a very specific brainwave pattern that occurs when a human brain recognizes something that is meaningful, whether that is personal information, such as credit card details, or an enemy in a battlefield. According to &lt;a href="http://www.digitaltrends.com/cool-tech/this-is-your-brain-on-silicon/"&gt;DARPA&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote class="italized"&gt;&lt;i&gt;´When a human wearing the EEG cap was introduced, the number of false alarms dropped to only five per hour, out of a total of 2,304 target events per hour, and a 91 percent successful target recognition rate was introduced.´&lt;/i&gt;&lt;/blockquote&gt;
&lt;p class="Normal1"&gt;This constitutes the human brain as&lt;a class="external-link" href="http://www.wired.com/opinion/2012/12/the-next-warfare-domain-is-your-brain/"&gt; a &lt;span&gt;new warfighting &lt;/span&gt;domain&lt;/a&gt; of the twenty-first century, as experiments have proven that the brain can control and maneuver quadcopter drones and other military technologies. Enhanced threat detection through BCI´s scan for P300 responses and the literal control of military operations through the brain, definitely appear to be changing the future of warfare. Along with this change, the possibility of manipulating a soldier´s BCI during conflict is real and could lead to absolute chaos and destruction.&lt;/p&gt;
&lt;p class="Normal1"&gt;Security expert, Barnaby Jack, of IOActive demonstrated the &lt;a href="http://www.computerworld.com/s/article/9232477/Pacemaker_hack_can_deliver_deadly_830_volt_jolt"&gt;vulnerability of biotechnological systems&lt;/a&gt;, which raises concerns that BCI technologies may also potentially be vulnerable and expose an individual's´ brain to hacking, manipulation and control by third parties. If the brain can control computer systems and computer systems are able to detect and distinguish brain patterns, then this ultimately means that the human brain can potentially be controlled by computer software.&lt;/p&gt;
&lt;p class="Normal1"&gt;Will BCI be used in the future to&lt;a href="http://www.guardian.co.uk/science/2007/feb/09/neuroscience.ethicsofscience"&gt; interrogate terrorists and suspects&lt;/a&gt;? What would that mean for the future of our human rights? Can we have human rights if authorities can literally hack our brain in the name of national security? How can we be protected from abuse by those in power, if the most precious thing we have - our &lt;i&gt;thoughts&lt;/i&gt; - can potentially be hacked? Human rights are essential because they protect us from those in power; but the &lt;i&gt;privacy of our thoughts&lt;/i&gt; is even more important, because without it, we can have no human rights, no individuality.&lt;/p&gt;
&lt;p class="Normal1"&gt;Sure, the BCI is a very impressive technological accomplishment and can potentially improve the lives of millions. But it can also potentially destroy the most unique quality of human beings: their personal thoughts. Mind control is a vicious game to play and may constitute some of the scariest political novels as a comedy of the past. Nuclear weapons, bombs and all other powerful technologies seem childish compared to the BCI which can literally control our mind! Therefore strict regulations should be enacted which would restrict the use of BCI technologies to visually impaired or handicapped individuals.  Though these technologies currently are not being used in India, explicit laws on the use of artificial intelligence surveillance technologies should be enacted in India, to help ensure that they do not infringe upon the right to privacy and other human rights.&lt;/p&gt;
&lt;p class="Normal1"&gt;Apparently, anyone can&lt;a href="http://www.extremetech.com/extreme/134682-hackers-backdoor-the-human-brain-successfully-extract-sensitive-data"&gt; buy Emotiv or Neurosky BCI online&lt;/a&gt; to mind control their computer with only $200-$300. If the use of BCI was imposed in a top-down manner, then maybe there would be some hope that people would oppose its use for surveillance purposes; but if the idea of mind control is being socially integrated...the future of privacy seems bleak.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/hacking-without-borders-the-future-of-artificial-intelligence-and-surveillance'&gt;https://cis-india.org/internet-governance/blog/hacking-without-borders-the-future-of-artificial-intelligence-and-surveillance&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-12T15:30:27Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/economic-times-jayadevan-pk-neha-alawadhi-february-25-2015-hacking-of-sim-card-by-spy-agencies-raises-fears-of-sensitive-documents-being-leaked">
    <title>Hacking of SIM card by spy agencies raises fears of sensitive documents being leaked</title>
    <link>https://cis-india.org/internet-governance/news/economic-times-jayadevan-pk-neha-alawadhi-february-25-2015-hacking-of-sim-card-by-spy-agencies-raises-fears-of-sensitive-documents-being-leaked</link>
    <description>
        &lt;b&gt;The hacking of SIM-card and digital security services provider Gemalto by American and British spy agencies has raised fears that sensitive communications, by the Indian government and hundreds of domestic companies, may have been at the risk of being spied on.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by PK Jayadevan and Neha Alawadhi was &lt;a class="external-link" href="http://articles.economictimes.indiatimes.com/2015-02-25/news/59499696_1_gemalto-encryption-keys-security-solutions"&gt;published in the Economic Times&lt;/a&gt; on February 25, 2015. Pranesh Prakash and Sunil Abraham were quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The Netherlands-based Gemalto was jointly hacked by the &lt;a href="http://economictimes.indiatimes.com/topic/US%20National%20Security%20Agency"&gt;US National Security Agency&lt;/a&gt; and Britain's Government Communications Headquarters, and encryption  keys were stolen to monitor mobile communications, according to a news  report published last week.&lt;/p&gt;
&lt;div class="mod-articletext mod-economictimesarticletext mod-economictimesarticletextwithadcpc" id="mod-a-body-after-first-para" style="text-align: justify; "&gt;
&lt;p&gt;India's largest telecom vendors including Airtel, Vodafone and &lt;a href="http://economictimes.indiatimes.com/topic/Idea%20Cellular"&gt;Idea Cellular&lt;/a&gt; use SIM cards supplied by Gemalto, the world's biggest maker of  mobile-phone chips and provider of secure devices such as smart cards  and tokens. &lt;a href="http://economictimes.indiatimes.com/topic/Online%20publisher"&gt;Online publisher&lt;/a&gt; The Intercept in its report named Idea Cellular as one of the networks from which the spy agencies accessed encryption keys.&lt;/p&gt;
&lt;p&gt;"Phone calls and text messages by military, government, diplomats, spy  corporations and by ordinary citizen of India - all of those get  affected by this hack," said Pranesh Prakash, Policy Director at  research and advocacy firm &lt;a href="http://economictimes.indiatimes.com/topic/Centre%20for%20Internet"&gt;Centre for Internet&lt;/a&gt; and Society.&lt;/p&gt;
&lt;p&gt;The Intercept, which accessed top secret documents provided by NSA whistleblower &lt;a href="http://economictimes.indiatimes.com/topic/Edward%20Snowden"&gt;Edward Snowden&lt;/a&gt;,  said American and British spies dug into the private communications of  Gemalto engineers and other employees to steal encryption keys.&lt;/p&gt;
&lt;p&gt;Gemalto provides security services such as two-factor authentication and  access management, and has hundreds of clients in India. The company in  2012 said it provided 25 million e-driver's licences and vehicle  registration certificates in India that let the government "consolidate  driver and vehicle registration information across the population in a  central repository".&lt;/p&gt;
&lt;p&gt;"We believe that the biggest risk stands for  the large number of Vodafone users in the country as the company has  deployed Gemalto's Near Field Communication services solutions to  provide secure and convenient 'wave and pay' contactless transactions  via mobile phone," said Sanchit Vir Gogia, Chief Analyst and Group CEO,  Greyhound Research.&lt;/p&gt;
&lt;p&gt;"We have no further details of these  allegations, which are industry-wide in nature and are not focused on  any one mobile operator. We will support industry bodies and Gemalto in  their investigations," said a Vodafone spokesperson in an email  response.&lt;/p&gt;
&lt;p&gt;Emails to Idea and &lt;a href="http://economictimes.indiatimes.com/topic/Airtel"&gt;Airtel&lt;/a&gt; were unanswered till the time of going to Press.&lt;/p&gt;
&lt;p&gt;"Indian operators typically go for cheaper Chinese vendors that are  anyway low on security. Among the European SIM vendors, Gemalto has the  largest share in India," said a senior mobile services executive,  requesting anonymity.&lt;/p&gt;
&lt;p&gt;The report on the hack comes at a time when Gemalto was looking to tap the &lt;a href="http://economictimes.indiatimes.com/topic/Indian%20market"&gt;Indian market&lt;/a&gt;,  including e-governance initiatives. The company in a recent email to ET  said it had plans to expand its center of excellence in India to  develop multiple products, offer tech support and provide security  solutions for the domestic market.&lt;/p&gt;
&lt;p&gt;"We take this (breach) very  seriously and will devote all resources necessary to fully investigate  and understand the scope of such highly sophisticated attacks to obtain  SIM card data," a Gemalto spokesperson said. "The target was not  Gemalto, per se - it was an attempt to try and cast the widest net  possible to reach as many mobile phones as possible."&lt;/p&gt;
&lt;p&gt;Initial  investigations indicate that SIM products as well as banking cards,  passports and other products and platforms are secure, the company said.  Gemalto is expected to announce the results of its investigation on  Wednesday. British and US spy agencies have been under fire for hacking  and spying on citizens after Snowden in mid-2013 began leaking documents  that revealed massive surveillance programmes by the two governments.  At the time, the Indian government said the NSA was only collecting  meta-data and had no access to the actual contents of phone calls or  text messages.&lt;/p&gt;
&lt;div class="mod-articletext mod-economictimesarticletext mod-economictimesarticletextwithadcpc" id="mod-a-body-after-second-para"&gt;
&lt;p&gt;Experts suggest a multinational consensus or treaty that strikes a balance between national security concerns and privacy.&lt;/p&gt;
&lt;p&gt;"Governments will have to debate this in the United Nations and some  kind of rules for surveillance, maybe treaties, are relevant in the  future," said Kamlesh Bajaj, Chief Executive at Data Security Council of  India. "They shall have to have some kind of a limit to surveillance.  They can't be vacuuming all data in the name of finding a needle in the  haystack."&lt;/p&gt;
&lt;p&gt;Sunil Abraham, Executive Director at Center for  Internet and Society, suggested the Indian government should replace  proprietary operating systems and Android on phones with pure free  software projects, use of virtual private network on phones to  carry voice and data traffic, and encrypt voice and data payloads  separately.&lt;/p&gt;
&lt;p&gt;"When it comes to all the other services provided by  Gemalto, the India government should insist that they will do key  management on their own. This will also mitigate the compromise of  Gemalto's enterprise networks by the NSA," he said.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/economic-times-jayadevan-pk-neha-alawadhi-february-25-2015-hacking-of-sim-card-by-spy-agencies-raises-fears-of-sensitive-documents-being-leaked'&gt;https://cis-india.org/internet-governance/news/economic-times-jayadevan-pk-neha-alawadhi-february-25-2015-hacking-of-sim-card-by-spy-agencies-raises-fears-of-sensitive-documents-being-leaked&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2015-03-09T01:31:39Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/hackers-take-protest-to-indian-streets-and-cyberspace">
    <title>Hackers Take Protest to Indian Streets and Cyberspace</title>
    <link>https://cis-india.org/news/hackers-take-protest-to-indian-streets-and-cyberspace</link>
    <description>
        &lt;b&gt;First there was self-styled Gandhian activist Anna Hazare who took to the streets to protest corruption. Now a group agitating against censorship on the Internet has arrived in India.&lt;/b&gt;
        
&lt;p&gt;&lt;a class="external-link" href="http://blogs.wsj.com/indiarealtime/2012/06/08/hackers-take-protest-to-indian-streets-and-cyberspace/"&gt;This article by Shreya Shah was published in the Wall Street Journal on June 8, 2012&amp;nbsp; &lt;/a&gt;Pranesh Prakash is quoted in this article.&lt;/p&gt;
&lt;p&gt;Only this time, the location is cyberspace and their modus operandi hacking.&lt;/p&gt;
&lt;p&gt;In the last few months, Anonymous –a group of hackers, or hacktivists as they like to call themselves –has gone after Web sites of political parties, government sites and Internet service providers, &lt;a class="external-link" href="http://www.thehindu.com/sci-tech/article3496968.ece"&gt;the latest being MTNL&lt;/a&gt;, to protest censorship on the Internet.&lt;/p&gt;
&lt;p&gt;The group says they are opposing laws including the 2008 Information Technology (Amendment) Act and the Information Technology (Intermediaries Guidelines) Rules of 2011, which they say unfairly restrict Internet freedom.&lt;/p&gt;
&lt;p&gt;On Saturday, the hackers will take their protest to the streets, with an Occupy Wall Street-style march called ”Operation Occupy India” planned in 17 cities including Mumbai, Delhi, Indore in Madhya Pradesh, Nagpur in Maharashtra and Kundapur in Karnataka. The group has requested all protestors to wear Guy Fawkes masks, the symbol of Anonymous.&lt;/p&gt;
&lt;p&gt;“This time the common man wants to help us,” an “anon,” which is what members of the group call themselves, told India Real Time.&lt;/p&gt;
&lt;p&gt;Anonymous, which has a global presence, catapulted to fame with its &lt;a class="external-link" href="http://online.wsj.com/article/SB10001424052748704457604576011873881591338.html"&gt;attacks on Visa, Mastercard and Paypal&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This is how the group attacks Web sites: It overwhelms them with thousands of requests from different computer systems simultaneously. The Web site is unable to handle the load and crashes.&lt;/p&gt;
&lt;p&gt;The group intensified its attacks after Internet Service Providers like Reliance, MTNL and Airtel temporarily &lt;a class="external-link" href="http://blogs.wsj.com/indiarealtime/2012/05/18/vimeo-ban-more-web-censorship/"&gt;blocked file sharing sites like Vimeo&lt;/a&gt;, Dailymotion, Patebin and Pirate bay, citing a Court order.&lt;/p&gt;
&lt;p&gt;But many question the method used by Anonymous.&lt;/p&gt;
&lt;p&gt;“I don’t believe in defacing or hacking government Web sites to prove a point,” says Ankit Fadia, a cyber security expert. “You can’t hold the government ransom,” he adds.&lt;/p&gt;
&lt;p&gt;In an &lt;a class="external-link" href="http://opindia.posterous.com/open-letter-from-anonymous-to-government-of-i"&gt;open letter&lt;/a&gt; to the government, Anonymous India defended its actions. It wrote that traditional ways of protesting are losing meaning and this is a new method to pressure the politicians.&lt;/p&gt;
&lt;p&gt;Members of the group say that like a regular protest on the street, they too block the infrastructure of their opponents. Except in this case, the infrastructure is located in cyberspace.&lt;/p&gt;
&lt;p&gt;This is a “geek method of attacking,” said the anon who spoke to India Real Time. The group does not plan to attacks sites like that of the Indian railways, for instance, which is used by the masses, he explained.&lt;/p&gt;
&lt;p&gt;But not everyone is convinced.&lt;/p&gt;
&lt;p&gt;The group attacked the Web site of India’s Supreme Court even when it says it does not attack Web sites used by the common man, says Pranesh Prakash, Program Director of the Center for Internet and Society.&lt;/p&gt;
&lt;p&gt;The IT Act is another reason Anonymous is protesting. The Act gives the government the power to remove content it finds offensive. The government can also restrict public access to a Web site.&lt;/p&gt;
&lt;p&gt;Anonymous is also protesting the &lt;a class="external-link" href="http://www.mit.gov.in/sites/upload_files/dit/files/GSR314E_10511%281%29.pdf"&gt;Intermediary Guidelines of 2011&lt;/a&gt;. According to this Act, a site that hosts offensive content will have to remove it within 36 hours of a complaint against it.&lt;/p&gt;
&lt;p&gt;As a result, Web sites like Google and Facebook are &lt;a class="external-link" href="http://online.wsj.com/article/SB10001424052702304746604577381791461076660.html%20%20%E2%80%9CThis%20government%20does%20not%20stand%20for%20censorship;%20this%20government%20does%20not%20stand%20for%20infringement%20of%20fr"&gt;facing criminal cases&lt;/a&gt; for hosting objectionable content on their site.&lt;/p&gt;
&lt;p&gt;“This government does not stand for censorship; this government does not stand for infringement of free speech. Indeed, this government does not stand for regulation of free speech,” Kapil Sibal, the Communications and Information Technology Minister told the Rajya Sabha, or the upper house of the Indian Parliament, last month.&lt;/p&gt;
&lt;p&gt;Pranesh Prakash, of the Center for Internet and Society told India Real Time that he does not believe that Anonymous will influence policy makers. He says that the main aim of a protest is to get media attention, and in turn get the attention of the people.&lt;/p&gt;
&lt;p&gt;But he agrees that India’s cyber laws are “hopelessly flawed” and create a framework by which not only the government but &lt;a class="external-link" href="http://kafila.org/2012/01/11/invisible-censorship-how-the-government-censors-without-being-seen-pranesh-prakash/"&gt;everyone can censor&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;He adds, “The laws are a greater threat than Anonymous.”&lt;/p&gt;
&lt;p&gt;Photo Source: Joel Saget/Agence France-Presse/Getty Images&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/hackers-take-protest-to-indian-streets-and-cyberspace'&gt;https://cis-india.org/news/hackers-take-protest-to-indian-streets-and-cyberspace&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Freedom of Speech and Expression</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Censorship</dc:subject>
    

   <dc:date>2012-06-18T04:02:21Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-times-of-india-may-19-2017-kim-arora-and-digbijay-mishra-hacker-steals-17-million-zomato-users-data-briefly-puts-it-on-dark-web">
    <title>Hacker steals 17 million Zomato users’ data, briefly puts it on dark web</title>
    <link>https://cis-india.org/internet-governance/news/the-times-of-india-may-19-2017-kim-arora-and-digbijay-mishra-hacker-steals-17-million-zomato-users-data-briefly-puts-it-on-dark-web</link>
    <description>
        &lt;b&gt;Records of 17 million users were stolen from online restaurant search platform Zomato, the company said in a blog post on Thursday.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Kim Arora and Digbijay Mishra with inputs from Ranjani Ayyar in Chenna was &lt;a class="external-link" href="http://timesofindia.indiatimes.com/india/hacker-steals-17-million-zomato-users-data-briefly-puts-it-on-dark-web/articleshow/58742129.cms"&gt;published in the Times of India&lt;/a&gt; on May 19, 2017. Pranesh Prakash was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;According to information security blog and news website &lt;a class="key_underline" href="http://timesofindia.indiatimes.com/topic/HackRead"&gt;HackRead&lt;/a&gt;,  the data was being peddled online on the "dark web" for about $1,000.  The company, also a food delivery platform, advised users to change  passwords. However, late on Thursday night, &lt;a class="key_underline" href="http://timesofindia.indiatimes.com/topic/Zomato"&gt;Zomato&lt;/a&gt; claimed it had contacted the hacker and persuaded him/her to not only  destroy all copies of the data, but also to take the database off the  dark web marketplace. The company said it will post an update on how the  breach happened once they "close the loopholes".&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In an official blog updated with this information, Zomato said, "The hacker has been very cooperative with us. He/she wanted us to acknowledge security vulnerabilities in our system and work with the ethical hacker community to plug the gaps. His/her key request was that we run a healthy bug bounty program for security researchers." Bug bounties are a standard program among tech companies, where they reward outsiders to highlight bugs and flaws in their software systems.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The number of user accounts compromised was pegged at 17 million earlier in the day. In the late night update, Zomato said password hashes (passwords in a scrambled, encrypted form) of 6.6 million users was compromised. It wasn't immediately clear whether this 6.6 million was part of the 17 million records stolen.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Zomato tried assuring users that payment information was safe. "Please note that only 5 data points were exposed - user IDs, names, usernames, email addresses, and password hashes with salt- that is, passwords that were encrypted and would be unintelligible. No other information was exposed to anyone (we have a copy of the 'leaked' database with us). Your payment information is absolutely safe, and there's no need to panic," said the late night update.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, the information security community raised concerns over the technique used for "hashing" or encrypting the passwords. A screenshot of the vendor's sale page for stolen data posted on HackRead identifies the hashing algorithm as "MD5", which experts say is "outdated" and "insecure". The research team at infySEC -- a cyber security company from Chennai -- tried to access user information in Zomato's database, as part of its bug bounty program. "We were able to access user names, email IDs, addresses and history of transactions. We highlighted this to Zomato but we have not heard from them," said Karthick Vigneshwar, director, infySEC.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Zomato joins a long list of tech-enabled businesses that have recently had user data stolen. Such data can ostensibly be used by malicious actors to send phishing mails, or even by hackers to carry out cyber attacks. In February 2017, content delivery network CloudFlare's customer data was leaked. The data leaked had not just password hashes, but even customers' IP addresses and private messages. In June 2015, online password management service LastPass was hacked and had its data leaked online.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"We hash passwords with a one-way hashing algorithm, with multiple hashing iterations and individual salt per password. This means your password cannot be easily converted back to plain text. We, however, strongly advise you to change your password for any other services where you are using the same password," Zomato's chief technology officer Gunjan Patidar said in the blog which was updated twice through the day. Affected users have been logged out of the website and the app.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Password "hashing" is an encryption technique usually used for large online user databases. The strength of the encryption depends on the algorithm employed to do the same. "Salting" is the addition of a string of characters to the passwords when stored on such a database, which adds another layer of difficulty in cracking them.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In an email to TOI, a company spokesperson said, "Over the next couple of days, we'll be actively working to improve our security systems — we'll be further enhancing security measures for all user information stored within our database, and will also add a layer of authorisation for internal teams having access to this data to avoid any human breach."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;HackRead, a security blog and news website, found the stolen Zomato database of 17 million users for sale on what is called the "dark web". This can be described as a portion of the content available on the World Wide Web, away from the public internet. This content is not indexed on search engines like Google, and can only be accessed using software that can route around the public internet to get there.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to the screenshots of the sale posted on HackRead, the Zomato database used a hashing technique called "MD5", which security experts say is inappropriate for encrypting passwords. "If MD5 was used, it shows bad security practices were in place. It isn't industry standard to use this algorithm for password hashing. Algorithms like bcrypt, scrypt, are more secure," says Pranesh Prakash, policy director at Bengaluru's Centre for Internet and Society.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What if a user does not use an exclusive Zomato account to sign into the service, but signs in through a Google or Facebook account? "In that case, just to be safe, you can delink your Zomato from the account you use to sign in, although your password will not be at risk," says Prakash. Zomato says, 60% of its users use such third party authorisation, and they are at "zero risk."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Would Zomato be liable to compensate end users for loss of sensitive data? Supreme Court advocate Pavan Duggal says, "Such players, referred to as intermediaries under the IT Act hold sensitive data and are expected to have reasonable security protocols in place. Should an end user face any loss/damage due to a data breach, they can sue Zomato and seek compensation." While most players have end user agreements and disclaimers in place, Duggal adds that the IT Act will prevail over any other law or contract to the extent it is inconsistent.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-times-of-india-may-19-2017-kim-arora-and-digbijay-mishra-hacker-steals-17-million-zomato-users-data-briefly-puts-it-on-dark-web'&gt;https://cis-india.org/internet-governance/news/the-times-of-india-may-19-2017-kim-arora-and-digbijay-mishra-hacker-steals-17-million-zomato-users-data-briefly-puts-it-on-dark-web&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Hacking</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T05:57:14Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/hacking-cis">
    <title>Hack Night in CIS ― A Meeting of Java Script Hackers</title>
    <link>https://cis-india.org/internet-governance/hacking-cis</link>
    <description>
        &lt;b&gt;CIS hosted a hack night in conjunction with the tech-event organizers HasGeek at its office on 24 September 2011. The event brought together local java script hackers on a common platform. Tom Dane and Kiran Jonnalagadda participated in the event. &lt;/b&gt;
        
&lt;p&gt;The idea behind hosting the event was to have fun building cool stuff. The participants met in the afternoon to decide on projects and group into teams, and then&amp;nbsp;&lt;a class="external-link" href="http://twitter.com/#!/sudarmuthu"&gt;Sudar Muthu&lt;/a&gt;&amp;nbsp;gave an&amp;nbsp;&lt;a href="http://www.youtube.com/watch?v=t8BVYn6vS5g&amp;amp;feature=related" target="_blank"&gt;explanation of node.js&lt;/a&gt;&amp;nbsp;and its usage for the hack. There were also some very cool free t-shirts.&amp;nbsp;Much code was written and caffeine shared until the morning when the projects were uploaded online.&lt;/p&gt;
&lt;p&gt;&lt;span class="Apple-style-span"&gt;One project was a game allowing players to pass a ball between computers. The source code is available&amp;nbsp;&lt;a href="https://github.com/sudar/pass-the-ball" target="_blank"&gt;here&lt;/a&gt;&amp;nbsp;on GitHub.&amp;nbsp;&lt;a class="external-link" href="http://twitter.com/#!/netroy"&gt;Aditya Yadav&lt;/a&gt;&amp;nbsp;also worked on the beautiful&amp;nbsp;&lt;a href="http://jsfoo.hasgeek.com/" target="_blank"&gt;jsFoo website&lt;/a&gt;&amp;nbsp;during the night.&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span"&gt;Our friends from&amp;nbsp;HasGeek made a short video showing a snippet of the event:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;div&gt;
&lt;div style="text-align: center;"&gt;&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;&lt;iframe src="http://www.youtube.com/embed/D6p3K8XgTzQ" frameborder="0" scrolling="auto" height="315" width="560"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;span class="Apple-style-span"&gt; &lt;/span&gt;
&lt;div&gt;Below is the full list of participants:&lt;br /&gt;&amp;nbsp;&lt;/div&gt;
&lt;blockquote class="webkit-indent-blockquote"&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="external-link" href="https://github.com/jace"&gt;Kiran&lt;/a&gt;&amp;nbsp;&lt;a class="external-link" href="http://twitter.com/#!/jackerhack"&gt;Jonnalagadda&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="https://github.com/netroy"&gt;Aditya&lt;/a&gt;&amp;nbsp;&lt;a class="external-link" href="http://twitter.com/#!/netroy"&gt;Yadav&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="https://github.com/ritehs85"&gt;Ritesh Kadmawala&lt;/a&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="https://github.com/prakash122"&gt;MS Prakas Kumar Chakka&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Amarjit Singh&lt;/li&gt;&lt;li&gt;Arun Kumar&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="https://github.com/sudar"&gt;Sudar&lt;/a&gt;&amp;nbsp;&lt;a class="external-link" href="https://twitter.com/#!/sudarmuthu"&gt;Muthu&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="https://github.com/aravindavk"&gt;Aravinda&lt;/a&gt;&amp;nbsp;&lt;a class="external-link" href="http://twitter.com/#!/aravindvk"&gt;VK&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="https://github.com/ciju"&gt;Ciju&lt;/a&gt;&amp;nbsp;&lt;a class="external-link" href="http://twitter.com/#!/ciju"&gt;Cherian&lt;/a&gt;&amp;nbsp;and&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="https://github.com/caulagi"&gt;Pradip&lt;/a&gt;&amp;nbsp;&lt;a class="external-link" href="http://twitter.com/#!/caulagi"&gt;Caulagi&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;br /&gt;If you feel sad missing an event like this, be excited because HasGeek is hosting&amp;nbsp;&lt;a class="external-link" href="http://droidcon.in/"&gt;Droidcon&lt;/a&gt;&amp;nbsp;&lt;a class="external-link" href="http://funnel.hasgeek.com/droidcon/"&gt;India&lt;/a&gt;&lt;a href="http://droidcon.in/" target="_blank"&gt;&amp;nbsp;&lt;/a&gt;next month.&lt;span class="Apple-style-span"&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;blockquote class="webkit-indent-blockquote"&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;pre&gt;About Hasgeek&lt;/pre&gt;
&lt;div&gt;HasGeek is a developer-led initiative, and has been un-organising the unconference scene since 2010. HasGeek is an attempt to solve the problem of insipid conferences organised around buzzwords by uninterested, soulless corporate entities who pitch them as company training events or as places for companies to pick up hot developers.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;ul&gt;&lt;li&gt;For more info on Hasgeek, &lt;a class="external-link" href="http://jsfoo.hasgeek.com/2011-pune/#about-hasgeek"&gt;click here&lt;/a&gt;&lt;/li&gt;&lt;li&gt;For info on jsFoo, &lt;a class="external-link" href="http://jsfoo.hasgeek.com/2011-pune/#about-event"&gt;click here&lt;/a&gt;&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a class="external-link" href="http://jsfoo.hasgeek.com/2011-pune/#about-event"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/hacking-cis'&gt;https://cis-india.org/internet-governance/hacking-cis&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Tom Dane</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2011-10-27T11:36:26Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-may-19-2017-hack-exposes-zomatos-weak-protection-of-customer-data-say-cyber-experts">
    <title>Hack exposes Zomato's weak protection of customer data, say Cyber experts </title>
    <link>https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-may-19-2017-hack-exposes-zomatos-weak-protection-of-customer-data-say-cyber-experts</link>
    <description>
        &lt;b&gt;Online restaurant aggregator says it will beef up security after 17 million user details were stolen.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by &lt;span&gt;&lt;a href="http://www.business-standard.com/author/search/keyword/alnoor-peermohamed" target="_blank"&gt;Alnoor Peermohamed&lt;/a&gt; was published in the Business Standard on May 19, 2017. Pranesh Prakash was quoted.&lt;/span&gt;&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;&lt;span class="p-content"&gt;After details of over 17 million users was stolen and sold online, restaurants discovery and food ordering service &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;has vowed to beef up security measures, including adding a layer of authentication for its own employees to access user data. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span class="p-content"&gt;
&lt;p&gt;The company in a blog post claimed that the leak appeared to be an  internal (human) security breach with an employee's development account  getting compromised.&lt;/p&gt;
&lt;p&gt;However, &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Cyber+Security" target="_blank"&gt;cyber security &lt;/a&gt;experts pointed out that &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;was clearly lacking in its technique to protect customer data from unwanted elements .&lt;/p&gt;
&lt;div class="article-middle-banner" id="div-gpt-ad-1490771277198-0"&gt;&lt;/div&gt;
&lt;p&gt;Sajal Thomas, a &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Cyber+Security" target="_blank"&gt;cyber security &lt;/a&gt;consultant, claimed on Twitter that he verified the sample data being sold on the dark web and found that &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;had  used MD5 to hash passwords. MD5 is neither encryption nor encoding, and  was known to be easily cracked by attacks and suffered from major  vulnerabilities.&lt;/p&gt;
&lt;p&gt;Further, he said &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;had  not used salting, a technique where random data was used as additional  input to make cracking a hashed password much harder. Thomas said that  it took just a few seconds to crack the hashed passwords to turn them  into plain text.&lt;/p&gt;
&lt;p&gt;&lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;in  its blog post, however, claimed that it protected "passwords with a  one-way hashing algorithm, with multiple hashing iterations and  individual salt per password."&lt;/p&gt;
&lt;p&gt;It said that this was to ensure that passwords could not be easily  converted back to plain text. The firm claimed no credit or debit card  information of users were leaked.&lt;/p&gt;
&lt;p&gt;While &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;says it has reset passwords of all the affected accounts, experts say that users whose data were leaked are still under threat.&lt;/p&gt;
&lt;p&gt;"If you had a password for &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;that  you used elsewhere (on facebook or email), immediately change that  password across all those accounts," tweeted Pranesh Prakash, policy  director at the Centre for Internet and Society.&lt;/p&gt;
&lt;blockquote class="twitter-tweet"&gt;
&lt;p dir="ltr"&gt;If you had a password for &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;that you used elsewhere, then IMMEDIATELY change that password across ALL those accounts. Use a pw manager! &lt;a href="https://t.co/CbhtxCwlnD"&gt;https://t.co/CbhtxCwlnD&lt;/a&gt;&lt;/p&gt;
— Pranesh Prakash (@pranesh) &lt;a href="https://twitter.com/pranesh/status/865136966190288896"&gt;May 18, 2017&lt;/a&gt;&lt;/blockquote&gt;
According to Prakash, a statement by &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;misled people on how serious the security breach was by providing a false sense of security.&lt;br /&gt; &lt;br /&gt; Subsequently, the company reworded its blog post to prompt users to  change passwords of other services where they might have used the same  password as their &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;account.
&lt;p&gt;The leak was first detected by security blog &lt;i&gt;HackRead&lt;/i&gt; when it  came across an online handle going by the name of "nclay" claiming to  have hacked Zomato's database and selling its data on the dark web. Upon  testing some of the data made public by the hacker, &lt;i&gt;HackRead&lt;/i&gt; found that each account actually existed on &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;"The database includes emails and password hashes of registered &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;users  while the price set for the whole package is $1,001.43 (BTC 0.5587).  The vendor also shared a trove of sample data to prove that the data is  legit," &lt;i&gt;HackRead &lt;/i&gt;wrote in its post.&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-may-19-2017-hack-exposes-zomatos-weak-protection-of-customer-data-say-cyber-experts'&gt;https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-may-19-2017-hack-exposes-zomatos-weak-protection-of-customer-data-say-cyber-experts&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-19T09:11:40Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/habeas-data-in-india">
    <title>Habeas Data in India</title>
    <link>https://cis-india.org/internet-governance/blog/habeas-data-in-india</link>
    <description>
        &lt;b&gt;Habeas Data is a latin word which can be loosely translated to mean “have the data”. The right has been primarily conceptualized, designed, ratified, and implemented by various  nation-states in the background of a shared common history of decades of torture, terror, and other repressive practices under military juntas and other fascist regimes.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;a class="external-link" href="http://cis-india.org/internet-governance/files/habeas-data-india.pdf/view"&gt;&lt;b&gt;Download the Paper&lt;/b&gt;&lt;/a&gt; (PDF)&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;h3 style="text-align: justify; "&gt;Introduction&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The writ of habeas data was a distinct response to these recent histories which provided individuals with basic rights to access personal information collected by the state (and sometimes byprivate agencies of a public nature) and to challenge and correct such data, requiring the state to safeguard the privacy and accuracy of people's personal data.&lt;a href="#fn1" name="fr1"&gt;[1] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The origins of Habeas Data are traced back, unsurprisingly, to the European legal regime since Europe is considered as the fountainhead of modern data protection laws. The inspiration for Habeas Data is often considered to be the Council of Europe's 108th Convention on Data Protection of 1981.&lt;a href="#fn2" name="fr2"&gt;[2] &lt;/a&gt;The purpose of the Convention was to secure the privacy of individuals regarding the automated processing of personal data. For this purpose, individuals were granted several rights including a right to access their personal data held in an automated database.&lt;a href="#fn3" name="fr3"&gt;[3] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Another source or inspiration behind Habeas Data is considered to be the German legal system where a constitutional right to information self-determination was created by the German Constitutional Tribunal by interpretation of the existing rights of human dignity and personality. This is a right to know what type of data is stored on manual and automatic databases about an individual, and it implies that there must be transparency on the gathering and processing of such data.&lt;a href="#fn4" name="fr4"&gt;[4] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Habeas Data is essentially a right or mechanism for an individual complaint presented to a constitutional court, to protect the image, privacy, honour, information self-determination and freedom of information of a person. &lt;a href="#fn5" name="fr5"&gt;[5] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A Habeas Data complaint can be filed by any citizen against any register to find out what information is held about his or her person. That person can request the rectification, update or even the destruction of the personal data held, it does not matter most of the times if the register is private or public.&lt;a href="#fn6" name="fr6"&gt;[6] &lt;/a&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Habeas Data in different jurisdictions&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Habeas Data does not have any one specific definition and has different characteristics in different jurisdictions. Therefore, in order to better understand the right, it will be useful to describe the scope of Habeas Data as it has been incorporated in certain jurisdictions in order to better understand what the right entails:&lt;a href="#fn7" name="fr7"&gt;[7] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Brazil&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Constitution of Brazil grants its citizens the right to get a habeas data “a. to assure knowledge of personal information about the petitioner contained in records or data banks of government agencies or entities of a public character; b. to correct data whenever the petitioner prefers not to do so through confidential judicial or administrative proceedings;&lt;a href="#fn8" name="fr8"&gt;[8] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The place or tribunal where the Habeas Data action is to be filed changes depending on who is it presented against, which creates a complicated system of venues. Both the Brazilian constitution and the 1997 law stipulate that the court will be:&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt;The Superior Federal Tribunal for actions against the President, both chambers of Congress and itself;&lt;/li&gt;
&lt;li&gt;The Superior Justice Tribunal for actions against Ministers or itself;&lt;/li&gt;
&lt;li&gt;The regional federal judges for actions against federal authorities;&lt;/li&gt;
&lt;li&gt;State tribunals according to each state law;&lt;/li&gt;
&lt;li&gt;State judges for all other cases.&lt;a href="#fn9" name="fr9"&gt;[9] &lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Paraguay&lt;/b&gt;&lt;br /&gt;The Constitution of Paraguay grants a similar right of habeas data in its constitution which states:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"All persons may access the information and the data that about themselves, or about their assets, [that] is [obren] in official or private registries of a public character, as well as to know the use made of the same and of their end. [All persons] may request before the competent magistrate the updating, the rectification or the destruction of these, if they were wrong or illegitimately affected their rights."&lt;a href="#fn10" name="fr10"&gt;[10] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Compared to the right granted in Brazil, the text of the Paraguay Constitution specifically recognises that the citizen also has the right to know the use his/her data is being put to.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Argentina&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Article 43 of the Constitution of Argentina grants the right of habeas data, though it has been included under the action of “amparo”,&lt;a href="#fn11" name="fr11"&gt;[11] &lt;/a&gt;the relevant portion of Article 43 states as follows:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"Any person may file an amparo action to find out and to learn the purpose of data about him which is on record in public registries or data banks, or in any private [registers or data banks] whose purpose is to provide information, and in case of falsity or discrimination, to demand the suppression, rectification, confidentiality, or updating of the same. The secrecy of journalistic information sources shall not be affected."&lt;a href="#fn12" name="fr12"&gt;[12] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The version of Habeas Data recognised in Argentina includes most of the protections seen in Brazil and Paraguay, such as the right to access the data, rectify it, update it or destroy it, etc. Nevertheless, the Argentinean constitution also includes certain other features such as the fact that it incorporates the Peruvian idea of confidentiality of data, being interpreted as the prohibition to broadcast or transmit incorrect or false information. Another feature of the Argentinean law is that it specifically excludes the press from the action, which may be considered as reasonable or unreasonable depending upon the context and country in which it is applied.&lt;a href="#fn13" name="fr13"&gt;[13] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Venezuela&lt;/b&gt;&lt;br /&gt;Article 28 of the Constitution of Venezuela established the writ of habeas data, which expressly permits access to information stored in official and private registries. It states as follows:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"All individuals have a right to access information and data about themselves and about their property stored in official as well as private registries. Secondly, they are entitled to know the purpose of and the policy behind these registries. Thirdly, they have a right to request, before a competent tribunal, the updating, rectification, or destruction of any database that is inaccurate or that undermines their entitlements. The law shall establish exceptions to these principles. By the same token, any person shall have access to information that is of interest to communities and groups. The secrecy of the sources of newspapers-and of other entities or individuals as defined by law-shall be preserved."&lt;a href="#fn14" name="fr14"&gt;[14] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Venezuelan writ of habeas data expressly provides that individuals "are entitled to know the purpose of and the policy behind these registries." Also, it expresses a right to "updating, rectification, or destruction of any database that is inaccurate or that undermines their entitlements." Article 28 also declares that the “secrecy of the sources of newspapers and of other entities or individuals as defined by law-shall be preserved."&lt;a href="#fn15" name="fr15"&gt;[15] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Philippines&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It is not as if the remedy of Habeas Data is available only in Latin American jurisdictions, but even in Asia the writ of Habeas Data has been specifically granted by the Supreme Court of the Philippines vide its resolution dated January 22, 2008 which provides that “The writ of habeas data is a remedy available to any person whose right to privacy in life, liberty or security is violated or threatened by an unlawful act or omission of a public official or employee, or of a private individual or entity engaged in the gathering, collecting or storing of data or information regarding the person, family, home and correspondence of the aggrieved party.” According to the Rule on Writ of Habeas Data, the petition is to be filed with the Regional Trial Court where the petitioner or respondent resides, or which has jurisdiction over the place where the data or information is gathered, collected or stored, at the option of the petitioner. The petition may also be filed with the Supreme Court or the Court of Appeals or the Sandiganbayan when the action concerns public data files of government offices.&lt;a href="#fn16" name="fr16"&gt;[16] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Two major distinctions are immediately visible between the Philippine right and that in the latin jurisdictions discussed above. One is the fact that in countries such as Bazil, Argentina and Paraguay, there does not appear to be a prerequisite to filing such an action asking for the information, whereas in Philippines it seems that such a petition can only be filed only if an individual’s “right to privacy in life, liberty or security is violated or threatened by an unlawful act or omission”. This means that the Philippine concept of habeas data is much more limited in its scope and is available to the citizens only under certain specific conditions. On the other hand the scope of the Philippine right of Habeas Data is much wider in its applicability in the sense that this right is available even against private individual and entities who are “engaged in the gathering, collecting or storing of data or information regarding the person, family, home and correspondence”. In the Latin American jurisdictions discussed above, this writ appears to be available only against either public institutions or private institutions having some public character.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Main features of Habeas Data&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Thus from the discussion above, the main features of the writ of habeas data, as it is applied in various jurisdictions can be culled out as follows: &lt;a href="#fn17" name="fr17"&gt;[17] &lt;/a&gt;&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt;It is a right to the individual or citizen to ask for his/her information contained with any data registry;&lt;/li&gt;
&lt;li&gt;It is available only against public (government) entities or employees; or private entities having a public character;&lt;a href="#fn18" name="fr18"&gt;[18] &lt;/a&gt; &lt;/li&gt;
&lt;li&gt;Usually it also gives the individuals the right to correct any wrong information contained in the data registry;&lt;/li&gt;
&lt;li&gt;It is a remedy that is usually available by approaching any single judicial forum.&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="text-align: justify; "&gt;Since the writ of Habeas Data has been established and evolved primarily in Latin American countries, there is not too much literature on it available freely in the English language and that is a serious hurdle in researching this area. For example, this author did not find many article mentioning the scope of the writ of habeas data, for example whether it is an absolute right and on what grounds can it be denied. The Constitution of Venezuela, for example, specifies that the law shall establish exceptions to these principles and infact mentions the secrecy of sources for newspapers as an exception to this rule.&lt;a href="#fn19" name="fr19"&gt;[19] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Similarly in Argentina, there exists a public interest exception to the issuance of the writ of Habeas Data.&lt;a href="#fn20" name="fr20"&gt;[20] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;That said, although little literature on the specific exceptions to habeas data is freely available in English, references can still be found to exceptions such as state security (Brazil), secrecy of newspaper sources (Argentina and Venezuela), or other entities defined by law (Venezuela).&lt;a href="#fn21" name="fr21"&gt;[21] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This suggests that the, as would be expected, the right to ask for the writ of habeas data is not an absolute right but would also be subject to certain exceptions and balanced against other needs such as state security and police investigations.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Habeas Data in the context of Privacy&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Data protection legislation and mechanisms protect people against misuse of personal information by data controllers. Habeas Data, being a figure for use only by certain countries, gives the individuals the right to access, correct, and object to the processing of their information.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In general, privacy is the genus and data protection is the species, data protection is a right to personal privacy that people have against the possible use of their personal data by data controllers in an unauthorized manner or against the requirements of force. Habeas Data is an action that is brought before the courts to allow the protection of the individual’s image, privacy, honour, self-determination of information and freedom of information of a person. In that sense, the right of Habeas Data can be found within the broader ambit of data protection. It does not require data processors to ensure the protection of personal data processed but is a legal action requiring the person aggrieved, after filing a complaint with the courts of justice, the access and/or rectification to any personal data which may jeopardize their right to privacy.&lt;a href="#fn22" name="fr22"&gt;[22] &lt;/a&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Habeas Data in the Indian Context&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Although a number of judgments of the Apex Court in India have recognised the existence of a right to privacy by interpreting the fundamental rights to life and free movement in the Constitution of India,&lt;a href="#fn23" name="fr23"&gt;[23] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;the writ of habeas data has no legal recognition under Indian law. However, as is evident from the discussion above, a writ of habeas data is very useful in protecting the right to privacy of individuals and it would be a very useful tool to have in the hands of the citizens. The fact that India has a fairly robust right to information legislation means that atleast some facets of the right of habeas data are available under Indian law. We shall now examine the Indian Right to Information Act, 2005 (RTI Act) to see what facets of habeas data are already available under this Act and what aspects are left wanting. As mentioned above, the writ of habeas data has the following main features:&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt;It is a right to the individual or citizen to ask for his/her information contained with any data registry;&lt;/li&gt;
&lt;li&gt;It is available only against public (government) entities or employees; or private entities having a public character;&lt;a href="#fn24" name="fr24"&gt;[24] &lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Usually it also gives the individuals the right to correct any wrong information contained in the data registry;&lt;/li&gt;
&lt;li&gt;It is a remedy that is usually available by approaching any single judicial forum.&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="text-align: justify; "&gt;We shall now take each of these features and analyse whether the RTI Act provides any similar rights and how they differ from each other.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Right to seek his/her information contained with a data registry&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Habeas data enables the individual to seek his or her information contained in any data registry. The RTI Act allows citizens to seek “information” which is under the control of or held by any public authority. The term information has been defined under the RTI Act to mean “any material in any form, including records, documents, memos, e-mails, opinions, advices, press releases, circulars, orders, logbooks, contracts, reports, papers, samples, models, data material held in any electronic form and information relating to any private body which can be accessed by a public authority under any other law for the time being in force”.&lt;a href="#fn25" name="fr25"&gt;[25] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Further, the term “record” has been defined to include “(a) any document, manuscript and file; (b) any microfilm, microfiche and facsimile copy of a document; (c) any reproduction of image or images embodied in such microfilm (whether enlarged or not); and (d) any other material produced by a computer or any other device”. It is quite apparent that the meaning given to the term information is quite wide and can include various types of information within its fold. The term “information” as defined in the RTI Act has been further elaborated by the Supreme Court in the case of Central Board of Secondary Education v. Aditya Bandopadhyay,&lt;a href="#fn26" name="fr26"&gt;[26] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;where the Court has held that a person’s evaluated answer sheet for the board exams held by the CBSE would come under the ambit of “information” and should be accessible to the person under the RTI Act.&lt;a href="#fn27" name="fr27"&gt;[27] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;An illustrative list of items that have been considered to be “information” under the RTI Act would be helpful in further understanding the concept:&lt;/p&gt;
&lt;ol style="text-align: justify; "&gt;
&lt;li&gt;Asset declarations by Judges;&lt;a href="#fn28" name="fr28"&gt;[28]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Copy of inspection report prepared by the Reserve Bank of India about a Co-operative Bank;&lt;a href="#fn29" name="fr29"&gt;[29] &lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Information on the status of an enquiry;&lt;a href="#fn30" name="fr30"&gt;[30] &lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Information regarding cancellation of an appointment letter;&lt;a href="#fn31" name="fr31"&gt;[31] &lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Information regarding transfer of services;&lt;a href="#fn32" name="fr32"&gt;[32] &lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Information regarding donations given by the President of India out of public funds.&lt;a href="#fn33" name="fr33"&gt;[33] &lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify; "&gt;The above list would indicate that any personal information relation to an individual that is available in a government registry would in all likelihood be considered as “information” under the RTI Act.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, just because the information asked for is considered to come within the ambit of section 2(h) does not mean that the person will be granted access to such information if it falls under any of the exceptions listed in section 8 of the RTI Act. Section 8 provides that if the information asked falls into any of the categories specified below then such information shall not be released in an application under the RTI Act, the categories are:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"(a) information, disclosure of which would prejudicially affect the sovereignty and integrity of India, the security, strategic, scientific or economic interests of the State, relation with foreign State or lead to incitement of an offence; &lt;br /&gt;(b) information which has been expressly forbidden to be published by any court of law or tribunal or the disclosure of which may constitute contempt of court; &lt;br /&gt;(c) information, the disclosure of which would cause a breach of privilege of Parliament or the State Legislature; &lt;br /&gt;(d) information including commercial confidence, trade secrets or intellectual property, the disclosure of which would harm the competitive position of a third party, unless the competent authority is satisfied that larger public interest warrants the disclosure of such information; &lt;br /&gt;(e) information available to a person in his fiduciary relationship, unless the competent authority is satisfied that the larger public interest warrants the disclosure of such information; &lt;br /&gt;(f) information received in confidence from foreign Government; &lt;br /&gt;(g) information, the disclosure of which would endanger the life or physical safety of any person or identify the source of information or assistance given in confidence for law enforcement or security purposes; &lt;br /&gt;(h) information which would impede the process of investigation or apprehension or prosecution of offenders; &lt;br /&gt;(i) cabinet papers including records of deliberations of the Council of Ministers, Secretaries and other officers: &lt;br /&gt;Provided that the decisions of Council of Ministers, the reasons thereof, and the material on the basis of which the decisions were taken shall be made public after the decision has been taken, and the matter is complete, or over: &lt;br /&gt;Provided further that those matters which come under the exemptions specified in this section shall not be disclosed; &lt;br /&gt;(j) information which relates to personal information the disclosure of which has no relationship to any public activity or interest, or which would cause unwarranted invasion of the privacy of the individual unless the Central Public Information Officer or the State Public Information Officer or the appellate authority, as the case may be, is satisfied that the larger public interest justifies the disclosure of such information: &lt;br /&gt;Provided that the information which cannot be denied to the Parliament or a State Legislature shall not be denied to any person."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The above mentioned exceptions seem fairly reasonable and infact are important since public records may contain information of a private nature which the data subject would not want revealed, and that is exactly why personal information is a specific exception mentioned under the RTI Act. When comparing this list to the recognised exceptions under habeas data, it must be remembered that a number of the exceptions listed above would not be relevant in a habeas data petition such as commercial secrets, personal information, etc. The exceptions which could be relevant for both the RTI Act as well as a habeas data writ would be (a) national security or sovereignty, (b) prohibition on publication by a court, (c) endangering the physical safety of a person, (d) hindrance in investigation of a crime. It is difficult to imagine a court (especially in India) granting a habeas data writ in violation of these four exceptions.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Certain other exceptions that may be relevant in a habeas data context but are not mentioned in the common list above are (a) information received in a fiduciary relationship; (b) breach of legislative privilege, (c) cabinet papers; and (d) information received in confidence from a foreign government. These four exceptions are not as immediately appealing as the others listed above because there are obviously competing interests involved here and different jurisdictions may take different points of view on these competing interests.&lt;a href="#fn34" name="fr34"&gt;[34] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Available only against public (government) entities or entities having public character.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A habeas corpus writ is maintainable in a court to ask for information relating to the petitioner held by either a public entity or a private entity having a public character. In India, the right to information as defined in the RTI Act means the right to information accessible under the Act held by or under the control of any public authority. The term "public authority" has been defined under the Act to mean “any authority or body or institution of self-government established or constituted—&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(a) by or under the Constitution;&lt;br /&gt;(b) by any other law made by Parliament;&lt;br /&gt;(c) by any other law made by State Legislature;&lt;br /&gt;(d) by notification issued or order made by the appropriate Government, and includes any— (i) body owned, controlled or substantially financed; (ii) non-Government organisation substantially financed, directly or indirectly by funds provided by the appropriate Government;"&lt;a href="#fn35" name="fr35"&gt;[35] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Therefore most government departments as well as statutory as well as government controlled corporations would come under the purview of the term "public authority". For the purposes of the RTI Act, either control or substantial financing by the government would be enough to bring an entity under the definition of public authority.&lt;a href="#fn36" name="fr36"&gt;[36]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The above interpretation is further bolstered by the fact that the preamble of the RTI Act contains the term “governments and their instrumentalities".&lt;a href="#fn37" name="fr37"&gt;[37] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Right to correct wrong information&lt;/b&gt; &lt;br /&gt;While certain sectoral legislations such as the Representation of the People Act and the Collection of Statistics Act, etc. may provide for correction of inaccurate information, the RTI Act does not have any such provisions. This stands to reason because the RTI Act is not geared towards providing people with information about themselves but is instead a transparency law which is geared at dissemination of information, which may or may not relate to an individual.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Available upon approaching a single judicial forum&lt;br /&gt;&lt;/b&gt;While the right of habeas data is available only upon approaching a judicial forum, the right to information under the RTI Act is realised entirely through the bureaucratic machinery. This also means that the individuals have to approach different entities in order to get the information that they need instead of approaching just one centralised entity.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Conclusion&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;There is no doubt that habeas data, by itself cannot end massive electronic surveillance of the kind that is being carried out by various governments in this day and age and the excessive collection of data by private sector companies, but providing the citizenry with the right to ask for such a writ would provide a critical check on such policies and practices of vast surveillance.&lt;a href="#fn38" name="fr38"&gt;[38] &lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;An informed citizenry, armed with a right such as habeas data, would be better able to learn about the information being collected and kept on them under the garb of law and governance, to access such information, and to demand its correction or deletion when its retention by the government is not justified.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As we have discussed in this paper, under Indian law the RTI Act gives the citizens certain aspects of this right but with a few notable exceptions. Therefore, if a writ such as habeas data is to be effectuated in India, it might perhaps be a better idea to approach it by amending/tweaking the existing structure of the RTI Act to grant individuals the right to correct mistakes in the data along with creating a separate department/mechanism so that the applications demanding access to one’s own data do not have to be submitted in different departments but can be submitted at one central place. This approach may be more pragmatic rather than asking for a change in the Constitution to grant to the citizens the right to ask for a writ in the nature of habeas data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There may be calls to also include private data processors within the ambit of the right to habeas data, but it could be challenging to enforce this right. This is because it is still feasible to assume that the government can put in place machinery to ensure that it can find out whether information about a particular individual is available with any of the government’s myriad departments and corporations, however it would be almost impossible for the government to track every single private database and then scan those databases to find out how many of them contain information about any specific individual. This also throws up the question whether a right such as habeas data, which originated in a specific context of government surveillance, is appropriate to protect the privacy of individuals in the private sector. Since under Indian law section 43A and the Rules thereunder, which regulate data protection, already provide for consent and notice as major bulwarks against unauthorised data collection, and limit the purpose for which such data can be utilised, privacy concerns in this context can perhaps be better addressed by strengthening these provisions rather than trying to extend the concept of habeas data to the private sector.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr1" name="fn1"&gt;1&lt;/a&gt;]. González, Marc-Tizoc, ‘Habeas Data: Comparative Constitutional Interventions from Latin America Against Neoliberal States of Insecurity and Surveillance’, (2015). Chicago-Kent Law Review, Vol. 90, No. 2, 2015; St. Thomas University School of Law (Florida) Research Paper No. 2015-06. Available at SSRN:&lt;a href="http://ssrn.com/abstract=2694803"&gt;http://ssrn.com/abstract=2694803&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr2" name="fn2"&gt;2&lt;/a&gt;]. Article 8 of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, 1981, available at &lt;a href="https://www.coe.int/en/web/conventions/full-list/-/conventions/rms/0900001680078b37"&gt;https://www.coe.int/en/web/conventions/full-list/-/conventions/rms/0900001680078b37&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr3" name="fn3"&gt;3&lt;/a&gt;]. Guadamuz A, 'Habeas Data: The Latin-American Response to Data Protection',&lt;a href="https://www2.warwick.ac.uk/fac/soc/law/elj/jilt/"&gt;2000 (2)&lt;/a&gt; &lt;i&gt;The Journal of Information, Law and Technology (JILT)&lt;/i&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr4" name="fn4"&gt;4&lt;/a&gt;]. &lt;i&gt;Id.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr5" name="fn5"&gt;5&lt;/a&gt;]. Speech by Chief Justice Reynato Puno, Supreme Court of Philippines delivered at the &lt;i&gt;UNESCO Policy Forum and Organizational Meeting of the Information for all Program (IFAP), Philippine National Committee&lt;/i&gt;, on November 19, 2007, available at &lt;a href="http://jlp-law.com/blog/writ-of-habeas-data-by-chief-justice-reynato-puno/"&gt;http://jlp-law.com/blog/writ-of-habeas-data-by-chief-justice-reynato-puno/&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr6" name="fn6"&gt;6&lt;/a&gt;]. Guadamuz A, 'Habeas Data: The Latin-American Response to Data Protection',&lt;a href="https://www2.warwick.ac.uk/fac/soc/law/elj/jilt/"&gt;2000 (2)&lt;/a&gt; &lt;i&gt;The Journal of Information, Law and Technology (JILT)&lt;/i&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr7" name="fn7"&gt;7&lt;/a&gt;]. The author does not purport to be an expert on the laws of these jurisdictions and the analysis in this paper has been based on a reading of the actual text or interpretations given in the papers that have been cited as the sources. The views in this paper should be viewed keeping this context in mind.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr8" name="fn8"&gt;8&lt;/a&gt;]. Article 5, LXXII of the Constitution of Brazil, available at &lt;a href="https://www.constituteproject.org/constitution/Brazil_2014.pdf"&gt;https://www.constituteproject.org/constitution/Brazil_2014.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr9" name="fn9"&gt;9&lt;/a&gt;]. Guadamuz A, 'Habeas Data vs the European Data Protection Directive', Refereed article, &lt;a href="https://www2.warwick.ac.uk/fac/soc/law/elj/jilt/"&gt;2001 (3)&lt;/a&gt; &lt;i&gt;The Journal of Information, Law and Technology (JILT)&lt;/i&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr10" name="fn10"&gt;10&lt;/a&gt;]. Article 135 of the Constitution of Paraguay, available at &lt;a href="https://www.constituteproject.org/constitution/Paraguay_2011.pdf?lang=en"&gt;https://www.constituteproject.org/constitution/Paraguay_2011.pdf?lang=en&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr11" name="fn11"&gt;11&lt;/a&gt;]. The petition for a writ of amparo is a remedy available to any person whose right to life, liberty and security is violated or threatened with violation by an unlawful act or omission of a public official or employee, or of a private individual or entity.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr12" name="fn12"&gt;12&lt;/a&gt;]. Article 43 of the Constitution of Argentina, available at &lt;a href="https://www.constituteproject.org/constitution/Argentina_1994.pdf?lang=en"&gt;https://www.constituteproject.org/constitution/Argentina_1994.pdf?lang=en&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr13" name="fn13"&gt;13&lt;/a&gt;].&lt;a class="external-link" href="https://www2.warwick.ac.uk/fac/soc/law/elj/jilt/2001_3/guadamuz/"&gt; https://www2.warwick.ac.uk/fac/soc/law/elj/jilt/2001_3/guadamuz/&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr14" name="fn14"&gt;14&lt;/a&gt;]. Article 28 of the Venezuelan Constitution, available at &lt;a href="http://www.venezuelaemb.or.kr/english/ConstitutionoftheBolivarianingles.pdf"&gt;http://www.venezuelaemb.or.kr/english/ConstitutionoftheBolivarianingles.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr15" name="fn15"&gt;15&lt;/a&gt;]. González, Marc-Tizoc, ‘Habeas Data: Comparative Constitutional Interventions from Latin America Against Neoliberal States of Insecurity and Surveillance’, (2015). Chicago-Kent Law Review, Vol. 90, No. 2, 2015; St. Thomas University School of Law (Florida) Research Paper No. 2015-06. Available at SSRN:&lt;a href="http://ssrn.com/abstract=2694803"&gt;http://ssrn.com/abstract=2694803&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr16" name="fn16"&gt;16&lt;/a&gt;]. Rule on the Writ of Habeas Data Resolution, available at &lt;a class="external-link" href="http://hrlibrary.umn.edu/research/Philippines/Rule%20on%20Habeas%20Data.pdf"&gt;http://hrlibrary.umn.edu/research/Philippines/Rule%20on%20Habeas%20Data.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr17" name="fn17"&gt;17&lt;/a&gt;]. The characteristics of habeas data culled out in this paper are by no means exhaustive and based only on the analysis of the jurisdictions discussed in this paper. This author does not claim to have done an exhaustive analysis of every jurisdiction where Habeas Data is available and the views in this paper should be viewed in that context.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr18" name="fn18"&gt;18&lt;/a&gt;]. Except in the case of the Philippines and Venezeula. This paper has not done an analysis of the writ of habeas data in every jurisdiction where it is available and there may be jurisdictions other than the Philippines which also give this right against private entities.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr19" name="fn19"&gt;19&lt;/a&gt;]. González, Marc-Tizoc, ‘Habeas Data: Comparative Constitutional Interventions from Latin America Against Neoliberal States of Insecurity and Surveillance’, (2015). Chicago-Kent Law Review, Vol. 90, No. 2, 2015; St. Thomas University School of Law (Florida) Research Paper No. 2015-06. Available at SSRN:&lt;a href="http://ssrn.com/abstract=2694803"&gt;http://ssrn.com/abstract=2694803&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr20" name="fn20"&gt;20&lt;/a&gt;]. The case of &lt;i&gt;Ganora v. Estado Nacional&lt;/i&gt;,  Supreme Court of Argentina, September 16, 1999, &lt;i&gt;cf.&lt;/i&gt;&lt;a href="http://www.worldlii.org/int/journals/EPICPrivHR/2006/PHR2006-Argentin.html"&gt;http://www.worldlii.org/int/journals/EPICPrivHR/2006/PHR2006-Argentin.html&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr21" name="fn21"&gt;21&lt;/a&gt;]. González, Marc-Tizoc, ‘Habeas Data: Comparative Constitutional Interventions from Latin America Against Neoliberal States of Insecurity and Surveillance’, (2015). Chicago-Kent Law Review, Vol. 90, No. 2, 2015; St. Thomas University School of Law (Florida) Research Paper No. 2015-06. Available at SSRN:&lt;a href="http://ssrn.com/abstract=2694803"&gt;http://ssrn.com/abstract=2694803&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr22" name="fn22"&gt;22&lt;/a&gt;].&lt;a href="http://www.oas.org/dil/data_protection_privacy_habeas_data.htm"&gt; http://www.oas.org/dil/data_protection_privacy_habeas_data.htm&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr23" name="fn23"&gt;23&lt;/a&gt;]. Even the scope of the right to privacy is currently under review in the Supreme Court of India. See “Right to Privacy in Peril”, &lt;a href="http://cis-india.org/internet-governance/blog/right-to-privacy-in-peril"&gt;http://cis-india.org/internet-governance/blog/right-to-privacy-in-peril&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr24" name="fn24"&gt;24&lt;/a&gt;]. Except in the case of the Philippines. This paper has not done an analysis of the writ of habeas data in every jurisdiction where it is available and there may be jurisdictions other than the Philippines which also give this right against private entities.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr25" name="fn25"&gt;25&lt;/a&gt;]. Section 2(f) of the Right to Information Act, 2005.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr26" name="fn26"&gt;26&lt;/a&gt;]. 2011 (106) AIC 187 (SC), also available at &lt;a href="http://judis.nic.in/supremecourt/imgst.aspx?filename=38344"&gt;http://judis.nic.in/supremecourt/imgst.aspx?filename=38344&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr27" name="fn27"&gt;27&lt;/a&gt;]. The exact words of the Court were: “The definition of `information' in section 2(f) of the RTI Act refers to any material in any form which includes records, documents, opinions, papers among several other enumerated items. The term `record' is defined in section 2(i) of the said Act as including any document, manuscript or file among others. When a candidate participates in an examination and writes his answers in an answer-book and submits it to the examining body for evaluation and declaration of the result, the answer-book is a document or record. When the answer-book is evaluated by an examiner appointed by the examining body, the evaluated answer-book becomes a record containing the `opinion' of the examiner. Therefore the evaluated answer-book is also an `information' under the RTI Act.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr28" name="fn28"&gt;28&lt;/a&gt;]. &lt;i&gt;Secretary General, Supreme Court of India&lt;/i&gt; v. &lt;i&gt;Subhash Chandra Agarwal&lt;/i&gt;, AIR 2010 Del 159, available at &lt;a href="https://indiankanoon.org/doc/1342199/"&gt;https://indiankanoon.org/doc/1342199/&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr29" name="fn29"&gt;29&lt;/a&gt;].&lt;i&gt; Ravi Ronchodlal Patel&lt;/i&gt; v. &lt;i&gt;Reserve Bank of India&lt;/i&gt;, Central Information Commission, dated 6-9-2006.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr30" name="fn30"&gt;30&lt;/a&gt;].&lt;i&gt; Anurag Mittal&lt;/i&gt; v. &lt;i&gt;National Institute of Health and Family Welfare&lt;/i&gt;, Central Information Commission, dated 29-6-2006.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr31" name="fn31"&gt;31&lt;/a&gt;].&lt;i&gt; Sandeep Bansal&lt;/i&gt; v. &lt;i&gt;Army Headquarters, Ministry of Defence&lt;/i&gt;, Central Information Commission, dated 10-11-2008.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr32" name="fn32"&gt;32&lt;/a&gt;].&lt;i&gt; M.M. Kalra&lt;/i&gt; v. &lt;i&gt;DDA&lt;/i&gt;, Central Information Commission, dated 20-11-2008.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr33" name="fn33"&gt;33&lt;/a&gt;].&lt;i&gt; Nitesh Kumar Tripathi&lt;/i&gt; v. &lt;i&gt;CPIO&lt;/i&gt;, Central Information Commission, dated 4-5-2012.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr34" name="fn34"&gt;34&lt;/a&gt;]. A similar logic may apply to the exceptions of (i) cabinet papers, and (ii) parliamentary privilege.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr35" name="fn35"&gt;35&lt;/a&gt;]. Section 2 (h) of the Right to Information Act, 2005.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr36" name="fn36"&gt;36&lt;/a&gt;].&lt;i&gt; M.P. Verghese&lt;/i&gt; v. &lt;i&gt;Mahatma Gandhi University&lt;/i&gt;, 2007 (58) AIC 663 (Ker), available at &lt;a href="https://indiankanoon.org/doc/1189278/"&gt;https://indiankanoon.org/doc/1189278/&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr37" name="fn37"&gt;37&lt;/a&gt;].&lt;i&gt; Principal, M.D. Sanatan Dharam Girls College, Ambala City&lt;/i&gt; v. &lt;i&gt;State Information Commissioner&lt;/i&gt;, AIR 2008 P&amp;amp;H 101, available at &lt;a href="https://indiankanoon.org/doc/1672120/"&gt;https://indiankanoon.org/doc/1672120/&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr38" name="fn38"&gt;38&lt;/a&gt;]. González, Marc-Tizoc, ‘Habeas Data: Comparative Constitutional Interventions from Latin America Against Neoliberal States of Insecurity and Surveillance’, (2015). Chicago-Kent Law Review, Vol. 90, No. 2, 2015; St. Thomas University School of Law (Florida) Research Paper No. 2015-06. Available at SSRN:&lt;a href="http://ssrn.com/abstract=2694803"&gt;http://ssrn.com/abstract=2694803&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/habeas-data-in-india'&gt;https://cis-india.org/internet-governance/blog/habeas-data-in-india&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Vipul Kharbanda and edited by Elonnai Hickok</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Featured</dc:subject>
    
    
        <dc:subject>Habeas Data</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2016-12-10T04:01:40Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/repeat-remix-remediate-summer-school-2013">
    <title>Guilty until Proven Innocent: Pirates, Pornographers, Terrorists and the IT Act  in India</title>
    <link>https://cis-india.org/news/repeat-remix-remediate-summer-school-2013</link>
    <description>
        &lt;b&gt;The Research Center of Media and Communication at the University of Hamburg organized the Summer School 2013 at Hamburg, Germany from July 29 to August 2, 2013. Dr. Nishant Shah was a panelist in the session on "Guilty until Proven Innocent: Pirates, Pornographers, Terrorists and the IT Act  in India".&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The Summer School Book of Abstracts/Information brochure can be &lt;a class="external-link" href="http://repeatremixremediate.files.wordpress.com/2013/06/rrremediate_brochure_web.pdf"&gt;downloaded here&lt;/a&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;This year’s Summer School offered by the Research Center of Media and  Communication at the University of Hamburg picked up upon a crucial  issue for current media development – a topic relevant to academia,  media practice and media policy. In the age of digitisation, the  landscape of media and communications is being increasingly influenced  by phenomena that can be viewed as reappropriations of previously  published media communications. The Summer School pursued central  questions about the kinds of reappropriated media communications that were being developed and the relationship between ‘old’ and ‘new’ shaping  them. This repurposing was analysed from four different  perspectives: repurposing as recombination, as reactualisation, as  piracy and as plagiarism.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/repeat-remix-remediate-summer-school-2013'&gt;https://cis-india.org/news/repeat-remix-remediate-summer-school-2013&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>IT Act</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2013-08-28T10:19:23Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/guidelines-for-protection-of-national-critical-information-infrastructure">
    <title>Guidelines for the Protection of National Critical Information Infrastructure: How Much Regulation?</title>
    <link>https://cis-india.org/internet-governance/blog/guidelines-for-protection-of-national-critical-information-infrastructure</link>
    <description>
        &lt;b&gt;July has been a busy month for cyber security in India. Beginning with the release of the country’s first National Cyber Security Policy on July 2 and followed just this past week by a set of guidelines for the protection of national critical information infrastructure (CII) developed under the direction of the National Technical Research Organization (NTRO), India has made respectable progress in its thinking on national cyber security.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;Yet the National Cyber Security Policy, taken together with what little is known of the as-yet restricted guidelines for CII protection, raises troubling questions, particularly regarding the regulation of cyber security practices in the private sector. Whereas the current Policy suggests the imposition of certain preferential acquisition policies, India would be best advised to maintain technology neutrality to ensure maximum security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to Section 70(1) of the Information Technology Act, Critical Information Infrastructure (CII) is defined as a “computer resource, the incapacitation or destruction of which, shall have debilitating impact on national security, economy, public health or safety.” In one of the 2008 amendments to the IT Act, the Central Government granted itself the authority to “prescribe the information security practices and procedures for such protected system[s].” These two paragraphs form the legal basis for the regulation of cyber security within the private sector.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Such basis notwithstanding, private cyber security remains almost completely unregulated. According to the &lt;a href="http://deity.gov.in/sites/upload_files/dit/files/GSR314E_10511%281%29.pdf"&gt;Intermediary Guidelines&lt;/a&gt; [pdf], intermediaries are required to report cyber security incidents to India’s national-level computer emergency response team (CERT-In). Other than this relatively small stipulation, the only regulation in place for CII exists at the sector level. Last year the Reserve Bank of India &lt;a href="http://perry4law.org/blog/?p=93"&gt;mandated&lt;/a&gt; that each bank in India appoint a chief information officer (CIO) and a steering committee on information security. The finance sector is also the only sector of the four designated “critical” by the Department of Electronics and Information Technology (DEIT) &lt;a href="http://deity.gov.in/content/strategic-approach"&gt;Cyber Security Strategy&lt;/a&gt; to have established a sector-level CERT, which released a set of non-compulsory &lt;a href="http://www.idrbt.ac.in/PDFs/ISG_Booklet_Nov_2011.pdf"&gt;guidelines&lt;/a&gt; [pdf] for information security governance in late 201&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The new guidelines for CII protection seek to reorganize the government’s approach to CII. According to a &lt;a href="http://articles.timesofindia.indiatimes.com/2013-07-20/india/40694913_1_cyber-attacks-ntro-guidelines"&gt;Times of India article&lt;/a&gt; on the new guidelines, the NTRO will outline a total of &lt;i&gt;eight&lt;/i&gt; sectors (including energy, aviation, telecom and National Stock Exchange) of CII and then “monitor if they are following the guidelines.” Such language, though vague and certainly unsubstantiated, suggests the NTRO may ultimately be responsible for enforcing the “[mandated] security practices related to the design, acquisition, development, use and operation of information resources” described in the Cyber Security Policy. If so, operators of systems deemed critical by the NTRO or by other authorized government agencies may soon be subject to cyber security regulation—with teeth.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;To be sure, some degree of cyber security regulation is necessary. After all, large swaths of the country’s CII are operated by private industry, and poor security practices on the part of one operator can easily undermine the security of the rest. To quote security expert &lt;a href="http://www.schneier.com/blog/archives/2012/10/stoking_cyber_f.html"&gt;Bruce Schneier&lt;/a&gt;, “the externalities in cybersecurity are so great that even the freest free market would fail.” In less academic terms, networks are only as secure as their weakest links. While it is true that many larger enterprises take cyber security quite seriously, small and medium-sized businesses either lack immediate incentives to invest in security (e.g. no shareholders to answer to) or more often lack the basic resources to do so. Some form of government transfer for cyber security related investments could thus go a long way toward shoring up the country’s overall security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Yet regulation may well extend beyond the simple “fiscal schemes and incentives” outlined in section IV of the Policy and “provide for procurement of indigenously manufactured ICT products that have security implications.” Such, at least, was the aim of the Preferential Market Access (PMA) Policy recently &lt;a href="http://articles.economictimes.indiatimes.com/2013-07-08/news/40443725_1_pma-policy-preferential-market-access-policy-private-sector"&gt;put on hold&lt;/a&gt; by the Prime Minister’s Office (PMO). Under pressure from international industry groups, the government has promised to review the PMA Policy, with the PMO indicating it may strike out clauses “regarding preference to domestic manufacturer[s] on security related products that are to be used by private sector.” If the government’s aim is indeed to ensure maximum security (rather than to grow an &lt;a href="http://en.wikipedia.org/wiki/Infant_industry_argument"&gt;infant industry&lt;/a&gt;), it would be well advised to extend this approach to the Cyber Security Policy and the new guidelines for CII protection.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Although there is a national security argument to be made in favor of such policies—namely that imported ICT products may contain “backdoors” or other nefarious flaws—there are equally valid arguments to be made &lt;i&gt;against&lt;/i&gt; preferential acquisition policies, at least for the private sector. First and foremost, it is unlikely that India’s nascent cyber security institutions will be able to regulate procurement in such a rapidly evolving market. Indeed, U.S. authorities have been &lt;a href="http://blog.heritage.org/2013/05/10/cybersecurity-government-regulations-cant-keep-up/"&gt;at pains&lt;/a&gt; to set cyber security standards, especially in the past several years. Secondly, by mandating the procurement of indigenously manufactured products, the government may force private industry to forgo higher quality products. Absent access to source code or the ability to effectively reverse engineer imported products, buyers should make decisions based on the products’ performance records, not geo-economic considerations like country of origin. Finally, limiting procurement to a specific subset of ICT products likewise restricts the set of security vulnerabilities available to hackers. Rather than improve security, however, a smaller, more distinct set of vulnerabilities may simply make networks &lt;a href="http://csis.org/blog/diffusion-and-discrimination-global-it-marketplace"&gt;easier targets&lt;/a&gt; for the sorts of “debilitating” attacks the Policy aims to avert.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As India broaches the difficult task of regulating cyber security in the private sector, it must emphasize flexibility above all. On one hand, the government should avoid preferential acquisition policies which risk a) overwhelming limited regulatory resources, b) saddling CII operators with subpar products, and/or c) differentiating the country’s &lt;a href="http://www.sans.edu/research/security-laboratory/article/did-attack-surface"&gt;attack surface&lt;/a&gt;. On the other hand, the government should encourage certain performance standards through precisely the sort of “fiscal schemes and incentives” alluded to in the Cyber Security Policy. Regulation should focus on what technology does and does not do, not who made it or what rival government might have had their hands in its design. Ultimately, India should adopt a policy of technology neutrality, backed by the simple principle of &lt;i&gt;trust but verify&lt;/i&gt;. Only then can it be truly secure.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/guidelines-for-protection-of-national-critical-information-infrastructure'&gt;https://cis-india.org/internet-governance/blog/guidelines-for-protection-of-national-critical-information-infrastructure&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>jon</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-08-01T04:48:01Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/gsma-research-outputs">
    <title>GSMA Research Outputs</title>
    <link>https://cis-india.org/internet-governance/blog/gsma-research-outputs</link>
    <description>
        &lt;b&gt;This is a collection of research under our GSMA project that we have undertaken in collaboration with Privacy International. The research has sought to understand different legal and regulatory aspects of security and surveillance in India and consists of blog entries and reports. Any feedback or comment is welcome. &lt;/b&gt;
        &lt;h3&gt;Indian Law and the Necessary Proportionate Principles&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The presentation shows that there are no comprehensive provisions for the principles of legitimate aim, competent judicial authority, proportionality, transparency, etc. whereas these are partially present for the principles of legality, necessity, adequacy, public oversight, safeguards for international cooperation, etc. The presentation also looks at the Indian intelligence agencies and shows us that there are nine agencies authorized to intercept communications along with at least eleven additional agencies. It further dwelves into the establishment and structure of Indian intelligence agencies and whom they report to, the sharing of information internationally as well as nationally. It shows us that India has MLAT agreements with 36 countries and request to CBI can be initiated informally or formally through court order. It then lists out the various regulatory and important bodies responsible for national security. Some cases of unlawful interception / leaks have been discussed along with examples of arrests based on digital evidence. The various government schemes, the telecommunication companies in India, telecom licenses requirements, government developed security and surveillance solutions, private security companies, security expos, export, import and selling of security and surveillance equipment, and the way forward are also discussed.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indian-law-and-necessary-proportionate-principles.pdf" class="external-link"&gt;Click to download the PDF&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Security, Surveillance and Data Sharing Schemes and Bodies in India&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Following the 2008 Mumbai terrorist attacks, India had implemented a wide range of data sharing and surveillance schemes. Though developed under different governments the purpose of these schemes has been to increase public safety and security by tackling crime and terrorism. As such, two data sharing schemes have been proposed - the National Intelligence Grid (NATGRID) and the Crime and Criminal Tracking Network &amp;amp; Systems (CCTNS), as well as several surveillance systems, such as the Lawful Intercept and Monitoring (LIM) system, the Network Traffic Analysis system (NETRA), state Internet Monitoring Systems and the Central Monitoring System (CMS). This chapter details the various schemes and provides policy recommendations for their improvement, with regards to the protection of the right to privacy and other human rights.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/security-surveillance-and-data-sharing.pdf" class="external-link"&gt;Click to download the PDF&lt;/a&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Export and Import of Security Technologies in India: QA&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The write-up examines in question-answer format the standards regulating the export of technologies that can be used for surveillance purposes, the department and legislation that governs exports and imports of security technologies in India, the procedure for obtaining an export licence for the export of SCOMET items, what is ITC (HS) and why is it important, and examples of ITC codes for technologies that can facilitate security or surveillance. The research finds answers to all these queries.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/export-and-import-of-security-technologies-in-india.pdf" class="external-link"&gt;Click to download the PDF&lt;/a&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Regulation of CCTV’s in India&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;In light of the increasing use and installation of CCTV’s in cities across India, and the role that CCTVs play in the Home Ministry's plans for implementing "Mega Policing Cities", this blog seeks to review various attempts to regulate the use of CCTV's in India, review international best practices, and provide preliminary recommendations for the regulation of CCTV's in India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/regulation-of-cctvs-in-india.pdf" class="external-link"&gt;Click to download the PDF&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Mutual Legal Assistance Treaties (MLATs) and Cross Border Sharing of Information in India&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;It is unclear the exact process that intelligence agencies in India share information with other agencies internationally. India is a member of Interpol and the Central Bureau of Investigation, which is a Federal/Central investigating agency functioning under the Central Government, Department of Personnel &amp;amp; Training is designated as the National Central Bureau of India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/mlats-and-cross-border-sharing-of-information-in-india.pdf" class="external-link"&gt;Click to download the PDF&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Composition of Service Providers in India&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Telecom, at present, is one of the fastest-growing industries in India. As of January 2014, according to the Telecom Regulatory Authority of India (TRAI) there are 922 million wireless and over the wire subscribers in India, and 56.90 million broadband subscribers including wired, wireless and wimax subscribers. India’s overall wireless teledensity was quoted as having 893.31million subscribers, with a 0.79% (7.02 million) monthly addition.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/composition-of-service-providers-in-india.pdf" class="external-link"&gt;Click to download the PDF&lt;/a&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;The Surveillance and Security Industry in India - An Analysis of Indian Security Expos&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The ‘Spy Files’, a series of documents released by whistleblower website WikiLeaks over the last few years, exposed the tremendous growth of the private surveillance industry across the world – a multi-billion dollar industry thriving on increasing governmental and private capabilities for mass surveillance of individuals. These documents showed how mass surveillance is increasingly made possible through new technologies developed by private players, often exploiting the framework of nascent but burgeoning information and communication technologies like the internet and communication satellites.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/surveillance-and-security-industry-in-india.pdf" class="external-link"&gt;Click to download the PDF&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;An Analysis of News Items and Cases on Surveillance and Digital Evidence in India&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;In a technologically advanced era, with preponderance of electronic communications in both professional and social interactions and the ability to store such information in digital form, digital evidence has gained significance in civil as well as criminal litigation in India. In order to match the pace with the progressive technology, the Indian Courts have embarked on placing more and more reliance on the digital evidence and a portion of such digital evidence is obtained through electronic surveillance.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/analysis-of-news-items-and-cases-on-surveillance-and-digital-evidence-in-india.pdf" class="external-link"&gt;Click to download the PDF&lt;/a&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Policy Recommendations for Surveillance Law in India and an Analysis of  Legal Provisions on Surveillance in India and the Necessary &amp;amp;  Proportionate Principles&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The Government of India has created a legal framework which supports the carrying out of surveillance by authorities through its various laws and license agreements for service providers. The Centre for Internet and Society (CIS) acknowledges that lawful, warranted, targeted surveillance can potentially be a useful tool in aiding law enforcement agencies in tackling crime and terrorism. However, current Indian laws and license agreements appear to overextend the Government's surveillance capabilities in certain cases, while inadequately safeguarding individuals' right to privacy and data protection.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/policy-recommendations-for-surveillance-law-in-india-and-analysis-of-legal-provisions-on-surveillance-in-india-and-the-necessary-and-proportionate-principles.pdf" class="external-link"&gt;Click to download the PDF&lt;/a&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;The Surveillance Industry in India&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;India has the world's second largest population, an expanding middle class and undoubtedly a huge market which attracts international investors. Some of the world's largest corporations have offices in India, such as Google Incorporated and BlackBerry Limited. In the Information Age, the market revolves around data and companies which produce technologies capable of mining such data are on the rise. Simultaneously, companies selling surveillance technologies appear to be on the peak too, especially since the global War on Terror requires law enforcement agencies around the world to be equipped with the latest surveillance gear.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/surveillance-industry-india.pdf" class="external-link"&gt;Click to download the PDF&lt;/a&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;State of Cyber Security and Surveillance in India: A Review of the Legal Landscape&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;&lt;br /&gt;The issue of cyber security and surveillance, especially unauthorised surveillance, though traditionally unprioritised, has recently gained much traction due to the increasing number of news reports regarding various instances of unauthorised surveillance and cyber crimes. In the case of unauthorised surveillance, more than the frequency of the instances, it is their sheer magnitude that has shocked civil society and especially civil rights groups. In the background of this ever increasing concern regarding surveillance as well as increasing concerns regarding cyber security due to the increased pervasiveness of technology in our society, this paper tries to discuss the legal and regulatory landscape regarding surveillance as well as cyber security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/state-of-cyber-security-and-surveillance-in-india.pdf" class="external-link"&gt;Click to download the PDF&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/gsma-research-outputs'&gt;https://cis-india.org/internet-governance/blog/gsma-research-outputs&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>GSMA Research</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2015-04-06T14:18:18Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/the-india-chronicles">
    <title>Growing Wikipedia: The India Chronicles</title>
    <link>https://cis-india.org/news/the-india-chronicles</link>
    <description>
        &lt;b&gt;&lt;/b&gt;
        
&lt;p&gt;Tory Read, a professional researcher, writer and journalist was commissioned by the Wikimedia Foundation to create a vivid description of its work in India. This was done in the interest of transparency and to ensure that it captured lessons from this new approach. Tory travelled for a couple of weeks across Mumbai, Pune, Bangalore and some towns in Kerala — attending community meet-ups speaking with a host of individual community members in these cities. Tory has given a journalistic account and analysis, based on document review, interviews and observations conducted between November 2010 and June 2011, including 16 days in India in June 2011.The views expressed herein are his own and do not necessarily reflect the views of Wikimedia Foundation.&lt;/p&gt;
&lt;p&gt;Sunil Abraham, Executive Director of the Centre for Internet and Society has been quoted in this report. The following are some direct quotes extracted out from this report:&lt;/p&gt;
&lt;blockquote class="webkit-indent-blockquote"&gt;
&lt;p&gt;"Feuding and flaming is an integral part of free software culture.” “You can’t imagine a mailing list without flaming." [The Chapter and the Community Tangle, page 16]&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote class="webkit-indent-blockquote"&gt;
&lt;p&gt;"The crisis on the mailing list was ultimately a great thing.” “There was conflict, dozens of offline conversations, private and public negotiation and airing of views and doubts, followed by a public commitment to work together for a shared purpose." [Necessity Breeds Collaboration, page 19]&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote class="webkit-indent-blockquote"&gt;
&lt;p&gt;"The Foundation’s job is having meetings and growing and holding the consensus." "It should&amp;nbsp;be creating situations in which trust is gained, and you do this through radical transparency and participation. The point of the Foundation’s work is to build the community." [For the Foundation, page 24]&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Download the entire report &lt;a href="https://cis-india.org/internet-governance/india-chronicles.pdf" class="internal-link" title="The India Chronicles"&gt;here&lt;/a&gt;&amp;nbsp;[PDF, 2.9 MB]&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/the-india-chronicles'&gt;https://cis-india.org/news/the-india-chronicles&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2011-10-14T09:17:08Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/ground-zero-summit-2014">
    <title>Ground Zero Summit 2014</title>
    <link>https://cis-india.org/internet-governance/news/ground-zero-summit-2014</link>
    <description>
        &lt;b&gt;Geeta Hariharan participated in this event organized by India Infosec Consortium on November 13 and 14, 2014 in New Delhi.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;Living from the successes of last year and our recent conference in Colombo, Ground Zero Summit 2014, in its second year promises to be Asia's largest information security gathering and proposes to be the ultimate platform for showcasing researches and sharing knowledge in the field of cyber security. The event will feature a panel discussion on cyber diplomacy.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://cis-india.org/internet-governance/blog/ground-zero.pdf" class="external-link"&gt;Click to read more about the event&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/ground-zero-summit-2014'&gt;https://cis-india.org/internet-governance/news/ground-zero-summit-2014&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2014-12-05T00:42:17Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/ground-zero-summit">
    <title>Ground Zero Summit</title>
    <link>https://cis-india.org/internet-governance/blog/ground-zero-summit</link>
    <description>
        &lt;b&gt;The Ground Zero Summit which claims to be the largest collaborative platform in Asia for cyber-security was held in New Delhi from 5th to 8th November. The conference was organised by the Indian Infosec Consortium (IIC), a not for profit organisation backed by the Government of India. Cyber security experts, hackers, senior officials from the government and defence establishments, senior professionals from the industry and policymakers attended the event. &lt;/b&gt;
        &lt;h3 style="text-align: justify; "&gt;Keynote Address&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The Union Home Minister, Mr. Rajnath Singh, inaugurated the conference. Mr Singh described cyber-barriers that impact the issues that governments face in ensuring cyber-security. Calling the cyberspace as the fifth dimension of security in addition to land, air, water and space, Mr Singh emphasised the need to curb cyber-crimes in India, which have grown by 70% in 2014 since 2013. He highlighted the fact that changes in location, jurisdiction and language made cybercrime particularly difficult to address. Continuing in the same vein, Mr. Rajnath Singh also mentioned cyber-terrorism as one the big dangers in the time to come. With a number of government initiatives like Digital India, Smart Cities and Make in India leveraging technology, the Home Minister said that the success of these projects would be dependent on having robust cyber-security systems in place.&lt;br /&gt;&lt;br /&gt;The Home Minister outlined some initiatives that Government of India is planning to take in order to address concerns around cyber security - such as plans to finalize a new national cyber policy. Significantly, he referred to a committee headed by Dr. Gulshan Rai, the National Cyber Security Coordinator mandated to suggest a roadmap for effectively tackling cybercrime in India. This committee has recommended the setting up of Indian Cyber Crime Coordination Centre (I-4C). This centre is meant to engage in capacity building with key stakeholders to enable them to address cyber crimes, and work with law enforcement agencies. Earlier reports about the recommendation suggest that the I-4C will likely be placed under the National Crime Records Bureau and align with the state police departments through the Crime and Criminal Tracking and Network Systems (CCTNS). I-4C is supposed to be comprised of high quality technical and R&amp;amp;D experts who would be engaged in developing cyber investigation tools. &lt;br /&gt;&lt;br /&gt;Other keynote speakers included Alok Joshi, Chairman, NTRO; Dr Gulshan Rai, National Cyber Security Coordinator; Dr. Arvind Gupta, Head of IT Cell, BJP and Air Marshal S B Dep, Chief of the Western Air Command.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Technical Speakers&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;There were a number of technical speakers who presented on an array of subjects. The first session was by Jiten Jain, a cyber security analyst who spoke on cyber espionage conducted by actors in Pakistan to target defence personnel in India. Jiten Jain talked about how the Indian Infosec Consortium had discovered these attacks in 2014. Most of these websites and mobile apps posed as defence news and carried malware and viruses. An investigation conducted by IIC revealed the domains to be registered in Pakistan. In another session Shesh Sarangdhar, the CEO of Seclabs, an application security company, spoke about the Darknet and ways to break anonymity on it. Sarangdhar mentioned that anonymity on Darknet is dependent on all determinants of the equation in the communication maintaining a specific state. He discussed techniques like using audio files, cross domain on tor, siebel attacks as methods of deanonymization. Dr. Triveni Singh. Assistant Superintendent of Police, Special Task Force, UP Police made a presentation on the trends in cyber crime. Dr. Singh emphasised the amount of uncertainty with regard to the purpose of a computer intrusion. He discussed real life case studies such as data theft, credit card fraud, share trading fraud from the perspective of law enforcement agencies.&lt;br /&gt;&lt;br /&gt;Anirudh Anand, CTO of Infosec Labs discussed how web applications are heavily reliant on filters or escaping methods. His talk focused on XSS (cross site scripting) and bypassing regular expression filters. He also announced the release of XSS labs, an XSS test bed for security professionals and developers that includes filter evasion techniques like b-services, weak cryptographic design and cross site request forgery. Jan Siedl, an authority on SCADA presented on TOR tricks which may be used by bots, shells and other tools to better use the TOR network and I2P. His presentation dealt with using obfuscated bridges, Hidden Services based HTTP, multiple C&amp;amp;C addresses and use of OTP. Aneesha, an intern with the Kerala Police spoke about elliptical curve cryptography, its features such as low processing overheads. As this requires elliptic curve paths, efficient Encoding and Decoding techniques need to be developed. Aneesha spoke about an algorithm called Generator-Inverse for encoding and decoding a message using a Single Sign-on mechanism. Other subjects presented included vulnerabilities that remained despite using TLS/SSL, deception technology and cyber kill-chain, credit card frauds, Post-quantum crypto-systems and popular android malware.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Panels&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;There were also two panels organised at the conference. Samir Saran, Vice President of Observer Research Foundation, moderated the first panel on Cyber Arms Control. The panel included participants like Lt. General A K Sahni from the South Western Air Command; Lt. General A S Lamba, Retired Vice Chief Indian Army, Alok Vijayant, Director of Cyber Security Operation of NTRO and Captain Raghuraman from Reliance Industries. The panel debated the virtues of cyber arms control treaties. It was acknowledged by the panel that there was a need to frame rules and create a governance mechanism for wars in cyberspace. However, this would be effective only if the governments are the primary actors with the capability for building cyber-warfare know-how and tools. The reality was that most kinds of cyber weapons involved non state actors from the hacker community. In light of this, the cyber control treaties would lose most of their effectiveness. &lt;br /&gt;&lt;br /&gt;The second panel was on the Make for India’ initiatives. Dinesh Bareja, the CEO of Open Security Alliance and Pyramid Cyber Security was the moderator for this panel which also included Nandakumar Saravade, CEO of Data Security Council of India; Sachin Burman, Director of NCIIPC; Dr. B J Srinath, Director General of ICERT and Amit Sharma, Joint Director of DRDO. The focus of this session was on ‘Make in India’ opportunities in the domain of cyber security. The panelist discussed the role the government and industry could play in creating an ecosystem that supports entrepreneurs in skill development. Among the approaches discussed were: involving actors in knowledge sharing and mentoring chapters which could be backed by organisations like NASSCOM and bringing together industry and government experts in events like the Ground Zero Summit to provide knowledge and training on cyber-security issues.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Exhibitions&lt;/h3&gt;
&lt;p class="Normal1" style="text-align: justify; "&gt;The conference was accompanied by a exhibitions showcasing indigenous cybersecurity products. The exhibitors included Smokescreen Technologies, Sempersol Consultancy, Ninja Hackon, Octogence Technologies, Secfence, Amity, Cisco Academy, Robotics Embedded Education Services Pvt. Ltd., Defence Research and Development Organisation (DRDO), Skin Angel, Aksit, Alqimi, Seclabs and Systems, Forensic Guru, Esecforte Technologies, Gade Autonomous Systems, National Critical Information Infrastructure Protection Centre (NCIIPC), Indian Infosec Consortium (IIC), INNEFU, Forensic Guru, Event Social, Esecforte Technologies, National Internet Exchange of India (NIXI) and Robotic Zone.&lt;/p&gt;
&lt;p class="Normal1" style="text-align: justify; "&gt;The conference also witnessed events such Drone Wars, in which selected participants had to navigate a drone, a Hacker Fashion Show and the official launch of the Ground Zero’s Music Album.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/ground-zero-summit'&gt;https://cis-india.org/internet-governance/blog/ground-zero-summit&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Amber Sinha</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2016-01-03T06:06:56Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>




</rdf:RDF>
