<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 1 to 7.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/the-ministry-and-the-trace-subverting-end-to-end-encryption"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/regulating-the-internet-the-government-of-india-standards-development-at-the-ietf"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/openness/pre-budget-consultation-2016-submission-to-the-ministry-of-finance"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/the-short-lived-adventure-of-india2019s-encryption-policy"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/first-post-naina-khedekar-september-23-2015-online-outcry-forces-government-to-withdraw-draft-encryption-policy"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/asian-age-september-27-2015-s-raghotham-and-mayukh-mukherjee-by-weakening-our-security-govt-is-putting-us-at-risk-of-espionage"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/hindustan-times-september-22-2015-bowing-to-public-pressure-govt-withdraws-draft-encryption-policy"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/blog/the-ministry-and-the-trace-subverting-end-to-end-encryption">
    <title>The Ministry And The Trace: Subverting End-To-End Encryption</title>
    <link>https://cis-india.org/internet-governance/blog/the-ministry-and-the-trace-subverting-end-to-end-encryption</link>
    <description>
        &lt;b&gt;A legal and technical analysis of the 'traceability' rule and its impact on messaging privacy.&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The paper was published in the &lt;a class="external-link" href="http://nujslawreview.org/2021/07/09/the-ministry-and-the-trace-subverting-end-to-end-encryption/"&gt;NUJS Law Review Volume 14 Issue 2 (2021)&lt;/a&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;Abstract&lt;/h2&gt;
&lt;div class="justify"&gt;
&lt;div class="pbs-main-wrapper"&gt;
&lt;p&gt;End-to-end
 encrypted messaging allows individuals to hold confidential 
conversations free from the interference of states and private 
corporations. To aid surveillance and prosecution of crimes, the Indian 
Government has mandated online messaging providers to enable 
identification of originators of messages that traverse their platforms.
 This paper establishes how the different ways in which this 
‘traceability’ mandate can be implemented (dropping end-to-end 
encryption, hashing messages, and attaching originator information to 
messages) come with serious costs to usability, security and privacy. 
Through a legal and constitutional analysis, we contend that 
traceability exceeds the scope of delegated legislation under the 
Information Technology Act, and is at odds with the fundamental right to
 privacy.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Click here to read the &lt;a class="external-link" href="http://nujslawreview.org/2021/07/09/the-ministry-and-the-trace-subverting-end-to-end-encryption/"&gt;full paper&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/the-ministry-and-the-trace-subverting-end-to-end-encryption'&gt;https://cis-india.org/internet-governance/blog/the-ministry-and-the-trace-subverting-end-to-end-encryption&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Gurshabad Grover, Tanaya Rajwade and Divyank Katira</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cryptography</dc:subject>
    
    
        <dc:subject>Intermediary Liability</dc:subject>
    
    
        <dc:subject>Constitutional Law</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Messaging</dc:subject>
    
    
        <dc:subject>Encryption Policy</dc:subject>
    

   <dc:date>2021-07-12T08:18:18Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/regulating-the-internet-the-government-of-india-standards-development-at-the-ietf">
    <title>Regulating the Internet: The Government of India &amp; Standards Development at the IETF</title>
    <link>https://cis-india.org/internet-governance/blog/regulating-the-internet-the-government-of-india-standards-development-at-the-ietf</link>
    <description>
        &lt;b&gt;The institution of open standards has been described as a formidable regulatory regime governing the Internet. Given the regulatory and domestic policy implications that technical standards can have, there is a need for Indian governmental agencies to focus adequate resources geared towards achieving favourable outcomes at standards development fora.&lt;/b&gt;
        
&lt;p&gt;This brief was authored by Aayush Rathi, Gurshabad Grover and Sunil Abraham. Click &lt;a class="external-link" href="http://cis-india.org/internet-governance/files/regulating-the-internet"&gt;here&lt;/a&gt; to download the policy brief.&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;Executive Summary&lt;/h2&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;p style="text-align: justify;"&gt;The institution of open standards has been described as a formidable regulatory regime governing the Internet. As the Internet has moved to facilitate commerce and communication, governments and corporations find greater incentives to participate and influence the decisions of independent standards development organisations.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;While most such bodies have attempted to systematise fair and transparent processes, this brief highlights how they may still be susceptible to compromise. Documented instances of large private companies like Microsoft, and governmental instrumentalities like the US National Security Agency (NSA) exerting disproportionate influence over certain technical standards further the case for increased Indian participation.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The debate around Transport Layer Security (TLS) 1.3 at the Internet Engineering Task Force (IETF) forms an important case for studying how a standards body responded to political developments, and how the Government of India participated in the ensuing discussions. Lasting four years, the debate ended in favour of greater communications security. One of the security improvements in TLS 1.3 over its predecessor is that is makes less information available to networking middleboxes. Considering that Indian intelligence agencies and government departments have expressed fears of foreign-manufactured networking equipment being used by foreign intelligence to eavesdrop on Indian networks, the development is potentially favourable for the security of Indian communication in general, and the security of military and intelligence systems in particular.&amp;nbsp; India has historically procured most networking equipment from foreign manufacturers. While there have been calls for indigenised production of such equipment, achieving these objectives will necessarily be a gradual process. Participating in technical standards can, then, be an effective interim method for intelligence agencies, defence wings and law enforcement for establishing trust in critical networking infrastructure sourced from foreign enterprises.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;Outlining some of the existing measures the Indian government has put in place to build capacity for and participate in standard setting, this brief highlights that while these are useful starting points, they need to be harmonised and strengthened to be more fruitful. Given the regulatory and domestic policy implications that technical standards can have, there is a need for Indian governmental agencies to focus adequate resources geared towards achieving favourable outcomes at standards development fora.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Click &lt;a class="external-link" href="http://cis-india.org/internet-governance/files/regulating-the-internet"&gt;here&lt;/a&gt; to download the policy brief.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;Note: The recommendations in the brief were updated on 17 December 2018 to reflect the relevance of technical standard-setting in the recent discussions around Indian intelligence concerns about foreign-manufactured networking equipment.&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/regulating-the-internet-the-government-of-india-standards-development-at-the-ietf'&gt;https://cis-india.org/internet-governance/blog/regulating-the-internet-the-government-of-india-standards-development-at-the-ietf&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Aayush Rathi, Gurshabad Grover and Sunil Abraham</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Open Standards</dc:subject>
    
    
        <dc:subject>Cryptography</dc:subject>
    
    
        <dc:subject>Cybersecurity</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Surveillance</dc:subject>
    
    
        <dc:subject>IETF</dc:subject>
    
    
        <dc:subject>Encryption Policy</dc:subject>
    

   <dc:date>2019-01-22T07:29:39Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/openness/pre-budget-consultation-2016-submission-to-the-ministry-of-finance">
    <title>Pre-Budget Consultation 2016 - Submission to the IT Group of the Ministry of Finance</title>
    <link>https://cis-india.org/openness/pre-budget-consultation-2016-submission-to-the-ministry-of-finance</link>
    <description>
        &lt;b&gt;The Ministry of Finance has recently held pre-budget consultations with different stakeholder groups in connection with the Union Budget 2016-17. We were invited to take part in the consultation for the IT (hardware and software) group organised on January 07, 2016, and submit a suggestion note. We are sharing the note below. It was prepared and presented by Sumandro Chattapadhyay, with contributions from Rohini Lakshané, Anubha Sinha, and other members of CIS.&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;It is our distinct honour to be invited to submit this note for consideration by the IT Group of the Ministry of Finance, Government of India, as part of the pre-budget consultation for 2016-17.&lt;/p&gt;
&lt;p&gt;The Centre for Internet and Society is (CIS) is a non-profit organisation that undertakes interdisciplinary research on internet and digital technologies from policy and academic perspectives. The areas of focus include digital accessibility for persons with diverse abilities, access to knowledge, intellectual property rights, openness (including open data, free and open source software, open standards, open access, open educational resources, and open video), internet governance, telecommunication reform, digital privacy, and cyber-security. We receive financial support from Kusuma Trust, Wikimedia Foundation, MacArthur Foundation, IDRC, and other donors.&lt;/p&gt;
&lt;p&gt;We have divided our suggestions into the different topics that our organisation has been researching in the recent years.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;Free/Libre and Open Source Software (FLOSS) is the Basis for Digital India&lt;/h3&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;We congratulate the policies introduced by the government to promote use of free/libre and open source software and that of open APIs for all e-governance projects and systems. This is not only crucial for the government to avoid vendor lock-in when it comes to critical software systems for governance, but also to ensure that the source code of such systems is available for public scrutiny and do not contain any security flaws.&lt;/p&gt;
&lt;p&gt;We request the government to empower the implementation of these policies by making open sharing of source code a necessity for all software vendors hired by government agencies a necessary condition for awarding of tenders. The 2016-17 budget should include special support to make all government agencies aware and capable of implementing these policies, as well as to build and operate agency-level software repositories (with version controlling system) to host the source codes. These repositories may function to manage the development and maintenance of software used in e-governance projects, as well as to seek comments from the public regarding the quality of the software.&lt;/p&gt;
&lt;p&gt;Use of FLOSS is not only important from the security or the cost-saving perspectives, it is also crucial to develop a robust industry of software development firms that specialise in FLOSS-based solutions, as opposed to being restricted to doing local implementation of global software vendors. A holistic support for FLOSS, especially with the government functioning as the dominant client, will immensely help creation of domestic jobs in the software industry, as well as encouraging Indian programmers to contribute to development of FLOSS projects.&lt;/p&gt;
&lt;p&gt;An effective compliance monitoring and enforcement system needs to be created to ensure that all government agencies are  Strong enforcement of the 2011 policy to use open source software in governance, including an enforcement task force that checks whether government departments have complied with this or not.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;Open Data is a Key Instrument for Transparent Decision Making&lt;/h3&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;With a wider set of governance activities being carried out using information systems, the government is increasingly acquiring a substantial amount of data about governance processes and status of projects that needs to be effectively fed back into the decision making process for the same projects. Opening up such data not only allows for public transparency, but also for easier sharing of data across government agencies, which reduces process delays and possibilities of duplication of data collection efforts.&lt;/p&gt;
&lt;p&gt;We request the 2016-17 budget to foreground the National Data Sharing and Accessibility Policy and the Open Government Data Platform of India as two key enablers of the Digital India agenda, and accordingly budget for modernisation and reconfiguration of data collection and management processes across government agencies, so that those processes are made automatic and open-by-default. Automatic data management processes minimise the possibility of data loss by directly archiving the collected data, which is increasingly becoming digital in nature. Open-by-default processes of data management means that all data collected by an agency, once pre-recognised as shareable data (that is non-sensitive and anonymised), will be proactively disclosed as a rule.&lt;/p&gt;
&lt;p&gt;Implementation of the National Data Sharing and Accessibility Policy has been hindered, so far, by the lack of preparation of a public inventory of data assets, along  with the information of their collection cycles, modes of collection and storage, etc., by each union government agency. Specific budgetary allocation to develop these inventories will be crucial not only for the implementation of the Policy, but also for the government to get an extensive sense of data collected and maintained currently by various government agencies. Decisions to proactively publish, or otherwise, such data can then be taken based on established rules.&lt;/p&gt;
&lt;p&gt;Availability of such open data, as mentioned above, creates a wider possibility for the public to know, learn, and understand the activities of the government, and is a cornerstone of transparent governance in the digital era. But making this a reality requires a systemic implementation of open government data practices, and various agencies would require targeted budget to undertake the required capacity development and work process re-engineering. Expenditure of such kind should not be seen as producing government data as a product, but as producing data as an infrastructure, which will be of continuous value for the years to come.&lt;/p&gt;
&lt;p&gt;As being discussed globally, open government data has the potential to kickstart a vast market of data derivatives, analytics companies, and data-driven innovation. Encouraging civic innovations, empowered by open government data - from climate data to transport data - can also be one of the unique initiatives of budget 2016-17.&lt;/p&gt;
&lt;p&gt;For maximising impact of opened up government data, we request the government to publish data that either has a high demand already (such as, geospatial data, and transport data), or is related to high-net-worth activities of the government (such as, data related to monitoring of major programmes, and budget and expenditure data for union and state governments).&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;Promotion of Start-ups and MSMEs in Electronics and IT Hardware Manufacturing&lt;/h3&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In line with the Make in India and Digital India initiatives, to enable India to be one of the global hubs of design, manufacturing, and exporting of electronics and IT hardware, we request that the budget 2016-17 focus on increasing flow of fund to start-ups and Medium and Small-Scale Manufacturing Enterprises (MSMEs) in the form of research and development grants (ideally connected to government, especially defense-related, spending on IT hardware innovation), seed capital, and venture capital.&lt;/p&gt;
&lt;p&gt;Generation of awareness and industry-specific strategies to develop intellectual property regimes and practices favourable for manufacturers of electronics and IT hardware in India is an absolutely crucial part of promotion of the same, especially in the current global scenario. Start-ups and MSMEs must be made thoroughly aware of intellectual property concerns and possibilities, including limitations and exceptions, flexibilities, and alternative models such as open innovation.&lt;/p&gt;
&lt;p&gt;We request the budget 2016-17 to give special emphasis to facilitation of technology licensing and transfer, through voluntary mechanisms as well as government intervention, such as compulsory licensing and government enforced patent pools.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;Applied Mathematics Research is Fundamental for Cybersecurity&lt;/h3&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Recent global reports have revealed that some national governments have been actively involved in sponsoring distortion in applied mathematics research so as to introduce weaknesses in encryption standards used in for online communication. Instead of trying to regulate key-length or mandating pre-registration of devices using encryption, as suggested by the withdrawn National Encryption Policy draft, would not be able to address this core emerging problem of weak cybersecurity standards.&lt;/p&gt;
&lt;p&gt;For effective and sustainable cybersecurity strategy, we must develop significant expertise in applied mathematical research, which is the very basis of cybersecurity standards development. We request the budget 2016-17 to give this topic the much-needed focus, especially in the context of the Digital India initiative and the upcoming National Encryption Policy.&lt;/p&gt;
&lt;p&gt;Along with developing domestic research capacity, a more immediately important step for the government is to ensure high quality Indian participation in global standard setting organisations, and hence to contribute to global standards making processes. We humbly suggest that categorical support for such participation and contribution is provided through the budget 2016-17, perhaps by partially channeling the revenues obtained from spectrum auctions.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/openness/pre-budget-consultation-2016-submission-to-the-ministry-of-finance'&gt;https://cis-india.org/openness/pre-budget-consultation-2016-submission-to-the-ministry-of-finance&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>sumandro</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Open Standards</dc:subject>
    
    
        <dc:subject>Open Source</dc:subject>
    
    
        <dc:subject>Cybersecurity</dc:subject>
    
    
        <dc:subject>Open Data</dc:subject>
    
    
        <dc:subject>Intellectual Property Rights</dc:subject>
    
    
        <dc:subject>Open Government Data</dc:subject>
    
    
        <dc:subject>Featured</dc:subject>
    
    
        <dc:subject>Patents</dc:subject>
    
    
        <dc:subject>Openness</dc:subject>
    
    
        <dc:subject>Open Innovation</dc:subject>
    
    
        <dc:subject>Encryption Policy</dc:subject>
    

   <dc:date>2016-01-12T13:34:41Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/the-short-lived-adventure-of-india2019s-encryption-policy">
    <title>The Short-lived Adventure of India’s Encryption Policy</title>
    <link>https://cis-india.org/internet-governance/blog/the-short-lived-adventure-of-india2019s-encryption-policy</link>
    <description>
        &lt;b&gt;Written for the Berkeley Information Privacy Law Association (BIPLA). &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;During his recent visit to Silicon Valley, Indian Prime Minister Narendra Modi &lt;a href="http://www.thehindu.com/news/resources/full-text-of-narendra-modis-speech-at-san-jose/article7694680.ece" target="_blank"&gt;said&lt;/a&gt; his government was “giving the highest importance to data privacy and  security, intellectual property rights and cyber security”. But a  proposed &lt;a href="http://www.scribd.com/doc/282239916/DRAFT-NATIONAL-ENCRYPTION-POLICY" target="_blank"&gt;national encryption policy&lt;/a&gt; circulated in September 2015 would have achieved the opposite effect.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The policy was comically short-lived. After its poorly-drafted provisions invited ridicule, it was swiftly &lt;a href="http://www.cnn.com/2015/09/23/asia/india-withdraws-encryption-policy/" target="_blank"&gt;withdrawn&lt;/a&gt;.  But the government has promised to return with a fresh attempt to  regulate encryption soon. The incident highlights the worrying assault  on &lt;a href="http://www.frontline.in/cover-story/india-privacy-in-peril/article4849211.ece?homepage=true" target="_blank"&gt;communications privacy&lt;/a&gt; and &lt;a href="https://www.washingtonpost.com/world/asia_pacific/indias-modi-wants-to-woo-silicon-valley-but-censorship-and-privacy-fears-grow-at-home/2015/09/23/2ab28f86-6174-11e5-8475-781cc9851652_story.html" target="_blank"&gt;free speech&lt;/a&gt; in India, a concern compounded by the enormous scale of the telecommunications and Internet market.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Even with only around &lt;a href="http://www.livemint.com/Politics/BvW1QKrvU0zKeH23fvKAoK/India-Internet-userbase-crosses-350-million-milestone-in-Jun.html" target="_blank"&gt;26 percent&lt;/a&gt; of its population online, India is already the world’s &lt;a href="https://en.wikipedia.org/wiki/List_of_countries_by_number_of_Internet_users" target="_blank"&gt;second-largest&lt;/a&gt; Internet user, recently overtaking the United States. The number of  Internet users in India is set to grow exponentially, spurred by  ambitious governmental schemes to build a ‘&lt;a href="http://www.digitalindia.gov.in/" target="_blank"&gt;Digital India&lt;/a&gt;’ and a country-wide &lt;a href="http://www.wsj.com/articles/SB10001424052702304870304577490442561089140" target="_blank"&gt;fiber-optic backbone&lt;/a&gt;. There will be a corresponding &lt;a href="http://www.nytimes.com/2015/09/28/technology/india-replaces-china-as-next-big-frontier-for-us-tech-companies.html?_r=0" target="_blank"&gt;increase&lt;/a&gt; in the use of the Internet for communicating and conducting commerce.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Encryption on the Internet&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Encryption protects the security of  Internet users from invasions of privacy, theft of data, and other  attacks. By applying an algorithmic cipher (key), ordinary data  (plaintext) is encoded into an unintelligible form (ciphertext), which  is decrypted using the key. The ciphertext can be intercepted but will  remain unintelligible without the key. The key is secret.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There are several methods of encryption. &lt;a href="https://en.wikipedia.org/wiki/Transport_Layer_Security" target="_blank"&gt;SSL/TLS&lt;/a&gt;,  a family of encryption protocols, is commonly used by major websites.  But while some companies encrypt sensitive data, such as passwords and  financial information, during its &lt;a href="https://www.schneier.com/blog/archives/2010/06/data_at_rest_vs.html" target="_blank"&gt;transit&lt;/a&gt; through the Internet, most data at rest on servers is largely &lt;a href="http://www.wired.com/2014/04/https/" target="_blank"&gt;unencrypted&lt;/a&gt;. For instance, &lt;a href="http://www.forbes.com/sites/hollieslade/2014/05/19/the-only-email-system-the-nsa-cant-access/"&gt;email providers&lt;/a&gt; regularly store plaintext messages on their servers. As a result, governments simply demand and receive &lt;a href="https://www.schneier.com/blog/archives/2015/07/the_risks_of_ma.html" target="_blank"&gt;backdoor&lt;/a&gt; access to information directly from the companies that provide these services. However, governments have long insisted on &lt;a href="https://www.eff.org/issues/calea" target="_blank"&gt;blanket backdoor access&lt;/a&gt; to all communications data, both encrypted and unencrypted, and whether at rest or in transit.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On the other hand, proper &lt;a href="http://www.wired.com/2014/11/hacker-lexicon-end-to-end-encryption/" target="_blank"&gt;end-to-end encryption&lt;/a&gt; – full encryption from the sender to recipient, where the service  provider simply passes on the ciphertext without storing it, and deletes  the &lt;a href="https://www.privacyinternational.org/node/53" target="_blank"&gt;metadata&lt;/a&gt; – will defeat backdoors and protect privacy, but may not be &lt;a href="http://www.thenation.com/article/privacy-and-profit-motive/" target="_blank"&gt;profitable&lt;/a&gt;. End-to-end encryption alarms the &lt;a href="https://www.fbi.gov/news/speeches/going-dark-are-technology-privacy-and-public-safety-on-a-collision-course" target="_blank"&gt;surveillance establishment&lt;/a&gt;, which is why British Prime Minister David Cameron wants to &lt;a href="http://www.theguardian.com/commentisfree/2015/jan/13/cameron-ban-encryption-digital-britain-online-shopping-banking-messaging-terror" target="_blank"&gt;ban&lt;/a&gt; it, and many in the US government want Silicon Valley companies to &lt;a href="http://www.nytimes.com/2015/09/08/us/politics/apple-and-other-tech-companies-tangle-with-us-over-access-to-data.html" target="_blank"&gt;stop using it&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Communications privacy&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Instead of relying on a company to secure  communications, the surest way to achieve end-to-end encryption is for  the sender to encrypt the message before it leaves her computer. Since  only the sender and intended recipient have the key, even if the data is  intercepted in transit or obtained through a backdoor, only the  ciphertext will be visible.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For almost all of human history,  encryption relied on a single shared key; that is, both the sender and  recipient used a pre-determined key. But, like all secrets, the more who  know it, the less secure the key becomes. From the 1970s onwards,  revolutionary advances in cryptography enabled the generation of a pair  of dissimilar keys, one public and one private, which are uniquely and  mathematically linked. This is asymmetric or &lt;a href="https://en.wikipedia.org/wiki/Public-key_cryptography" target="_blank"&gt;public key cryptography&lt;/a&gt;, where the private key remains an exclusive secret. It offers the strongest &lt;a href="http://www.newyorker.com/tech/elements/hard-to-crack-the-governments-encryption-conundrum" target="_blank"&gt;protection&lt;/a&gt; for communications privacy because it returns &lt;a href="http://www.wired.com/2015/09/apple-fighting-privacy-imessage-still-problems/" target="_blank"&gt;autonomy&lt;/a&gt; to the individual and is immune to backdoors.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For those using public key encryption, Edward Snowden’s revelation that the NSA had &lt;a href="http://www.newyorker.com/tech/elements/how-the-n-s-a-cracked-the-web" target="_blank"&gt;cracked&lt;/a&gt; several encryption protocols including SSL/TLS was worrying. &lt;a href="https://www.schneier.com/blog/archives/2013/09/the_nsas_crypto_1.html" target="_blank"&gt;Brute-force decryption&lt;/a&gt; (the use of supercomputers to mathematically attack keys) questions the  integrity of public key encryption. But, since the difficulty of  code-breaking is directly proportional to &lt;a href="https://en.wikipedia.org/wiki/Key_size" target="_blank"&gt;key size&lt;/a&gt;, notionally, generating longer keys will thwart the NSA, for now.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The crypto-wars in India&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Where does India’s withdrawn encryption  policy lie in this landscape of encryption and surveillance? It is  difficult to say. Because it was so badly drafted, understanding the  policy was a challenge. It could have been a ham-handed response to  commercial end-to-end encryption, which many major providers such as &lt;a href="http://www.washingtonpost.com/business/technology/2014/09/25/68c4e08e-4344-11e4-9a15-137aa0153527_story.html" target="_blank"&gt;Apple&lt;/a&gt; and &lt;a href="http://www.wired.com/2014/11/whatsapp-encrypted-messaging/" target="_blank"&gt;WhatsApp&lt;/a&gt; are adopting following consumer demand. But curiously, this did not  appear to be the case, because the government later exempted &lt;a href="http://indianexpress.com/article/explained/whatsapp-might-be-out-but-the-encryption-policy-is-still-ambiguous/" target="_blank"&gt;WhatsApp&lt;/a&gt; and other “mass use encryption products”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Indian establishment has a history of battling commercial encryption. From 2008, it fought &lt;a href="https://www.schneier.com/blog/archives/2008/05/blackberry_givi_1.html" target="_blank"&gt;Blackberry&lt;/a&gt; for backdoor access to its encrypted communications, coming close to &lt;a href="http://www.bbc.com/news/technology-10951607" target="_blank"&gt;banning&lt;/a&gt; the service, which &lt;a href="http://www.theregister.co.uk/2012/02/21/rim_india_bbn_server/" target="_blank"&gt;dissipated&lt;/a&gt; only once the company lost its market share. There have been similar  attempts to force Voice over Internet Protocol providers to fall in  line, including &lt;a href="http://timesofindia.indiatimes.com/india/Spooks-want-govt-to-block-Skype/articleshow/5082066.cms" target="_blank"&gt;Skype&lt;/a&gt; and &lt;a href="http://www.bbc.com/news/technology-11137647" target="_blank"&gt;Google&lt;/a&gt;. And there is a new thrust underway to regulate &lt;a href="http://www.trai.gov.in/WriteReaddata/ConsultationPaper/Document/OTT-CP-27032015.pdf" target="_blank"&gt;over-the-top&lt;/a&gt; content providers, including US companies.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The policy could represent a new phase in India’s &lt;a href="http://arstechnica.co.uk/tech-policy/2015/09/india-joins-war-on-crypto-wants-everyone-to-keep-plaintext-copies-of-all-encrypted-data-for-90-days/" target="_blank"&gt;crypto-wars&lt;/a&gt;.  The government, emboldened by the sheer scale of the country’s market,  might press an unyielding demand for communications backdoors. The  policy made no bones of this desire: it sought to bind communications  companies by mandatory contracts, regulate key-size and algorithms,  compel surrender of encryption products including “working copies” of  software (the key generation mechanism), and more.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The motives of regulation&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The policy’s deeply intrusive provisions manifest a &lt;a href="http://thewire.in/2015/05/30/mastering-the-art-of-keeping-indians-under-surveillance-2756/" target="_blank"&gt;long-standing effort&lt;/a&gt; of the Indian state to dominate communications technology unimpeded by  privacy concerns. From wiretaps to Internet metadata, intrusive  surveillance is not judicially warranted, does not require the  demonstration of probable cause, suffers no external oversight, and is  secret. These shortcomings are enabling the creation of a sophisticated &lt;a href="http://www.thehoot.org/media-watch/digital-media/turning-india-into-a-surveillance-state-i-7149" target="_blank"&gt;surveillance state&lt;/a&gt; that sits ill with India’s constitutional values.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Those values are being steadily besieged.  India’s Supreme Court is entertaining a surge of clamorous litigation  to check an increasingly intrusive state. Only a few months ago, the  Attorney-General – the government’s foremost lawyer – argued in court  that Indians &lt;a href="http://thewire.in/2015/08/02/the-battle-for-a-right-to-privacy-still-has-a-long-way-to-go-7685/" target="_blank"&gt;did not have&lt;/a&gt; a right to privacy, relying on 1950s case law which permitted invasive  surveillance. Encryption which can inexpensively lock the state out of  private communications alarms the Indian government, which is why it has  skirmished with commercially-available encryption in the past.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On the other hand, the conflict over encryption is fueled by irregular laws. Telecoms licensing regulations restrict &lt;a href="http://dot.gov.in/sites/default/files/Internet%20Service%20Guideline%2024-08-07.doc" target="_blank"&gt;Internet Service Providers&lt;/a&gt; to 40-bit symmetric keys, a primitively low standard; higher encryption  requires permission and presumably surrender of the shared key to the  government. &lt;a href="http://www.sebi.gov.in/cms/sebi_data/commondocs/anncir2_p.pdf" target="_blank"&gt;Securities trading&lt;/a&gt; on the Internet requires 128-bit SSL/TLS encryption while the country’s &lt;a href="https://www.rbi.org.in/scripts/BS_ViewMasCirculardetails.aspx?id=8992" target="_blank"&gt;central bank&lt;/a&gt; is pushing for end-to-end encryption for mobile banking. Seen in this  light, the policy could simply be an attempt to rationalize an uneven  field.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Encryption and freedom&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Perhaps the government was trying to restrict the use of public key encryption and Internet anonymization services, such as &lt;a href="https://www.torproject.org/" target="_blank"&gt;Tor&lt;/a&gt; or &lt;a href="https://geti2p.net/en/" target="_blank"&gt;I2P&lt;/a&gt;, by individuals. India’s telecoms minister &lt;a href="http://indianexpress.com/article/india/india-others/government-withdraws-draft-national-encryption-policy-after-furore/" target="_blank"&gt;stated&lt;/a&gt;:  “The purport of this encryption policy relates only to those who  encrypt.” This was not particularly illuminating. If the government  wants to pre-empt terrorism – a legitimate duty, this approach is flawed  since regardless of the law’s command arguably no terrorist will  disclose her key to the government. Besides, since there are &lt;a href="http://geography.oii.ox.ac.uk/?page=tor" target="_blank"&gt;very few&lt;/a&gt; Internet anonymizers in India who are anyway &lt;a href="https://www.washingtonpost.com/world/national-security/secret-nsa-documents-show-campaign-against-tor-encrypted-network/2013/10/04/610f08b6-2d05-11e3-8ade-a1f23cda135e_story.html" target="_blank"&gt;targeted&lt;/a&gt; for special &lt;a href="http://www.cnet.com/news/nsa-likely-targets-anybody-whos-tor-curious/" target="_blank"&gt;monitoring&lt;/a&gt;, it would be more productive for the surveillance establishment to maintain the status quo.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This leaves harmless encrypters –  businesses, journalists, whistle blowers, and innocent privacy  enthusiasts. For this group, impediments to encryption interferes with  their ability to freely communicate. There is a proportionate link  between encryption and the freedom of speech and expression, a fact  acknowledged by &lt;a href="http://www.ohchr.org/EN/Issues/FreedomOpinion/Pages/OpinionIndex.aspx" target="_blank"&gt;Special Rapporteur&lt;/a&gt; David Kaye of the UN Human Rights Council, where &lt;a href="http://www.ohchr.org/EN/HRBodies/HRC/Pages/MembersByGroup.aspx" target="_blank"&gt;India&lt;/a&gt; is a participating member. Kaye &lt;a href="http://www.ohchr.org/EN/HRBodies/HRC/RegularSessions/Session29/Documents/A.HRC.29.32_AEV.doc" target="_blank"&gt;notes&lt;/a&gt;:  “Encryption and anonymity are especially useful for the development and  sharing of opinions, which often occur through online correspondence  such as e-mail, text messaging, and other online interactions.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This is because encryption affords privacy which promotes free speech, a relationship &lt;a href="http://www.ohchr.org/Documents/HRBodies/HRCouncil/RegularSession/Session23/A.HRC.23.40_EN.pdf" target="_blank"&gt;reiterated&lt;/a&gt; by the previous UN Special Rapporteur, Frank La Rue. On the other hand, surveillance has a “&lt;a href="http://scholarship.law.wm.edu/cgi/viewcontent.cgi?article=2010&amp;amp;context=facpubs" target="_blank"&gt;chilling effect&lt;/a&gt;” on speech. In 1962, Justice Subba Rao’s &lt;a href="http://liiofindia.org/in/cases/cen/INSC/1962/377.html" target="_blank"&gt;famous dissent&lt;/a&gt; in the Indian Supreme Court presciently connected privacy and free speech:&lt;/p&gt;
&lt;blockquote style="text-align: justify; "&gt;
&lt;p&gt;The act of surveillance is certainly a  restriction on the [freedom of speech]. It cannot be suggested that the  said freedom…will sustain only the mechanics of speech and expression.  An illustration will make our point clear. A visitor, whether a wife,  son or friend, is allowed to be received by a prisoner in the presence  of a guard. The prisoner can speak with the visitor; but, can it be  suggested that he is fully enjoying the said freedom? It is impossible  for him to express his real and intimate thoughts to the visitor as  fully as he would like. To extend the analogy to the present case is to  treat the man under surveillance as a prisoner within the confines of  our country and the authorities enforcing surveillance as guards. So  understood, it must be held that the petitioner’s freedom under [the  right to free speech under the Indian] Constitution is also infringed.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Kharak Singh&lt;/i&gt; v. &lt;i&gt;State of Uttar Pradesh&lt;/i&gt; (1964) 1 SCR 332, pr. 30.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Perhaps the policy expressed the  government’s discomfort at individual encrypters escaping surveillance,  like free agents evading the state’s control. How should the law respond  to this problem? Daniel Solove &lt;a href="http://yalepress.yale.edu/book.asp?isbn=9780300172317" target="_blank"&gt;says&lt;/a&gt; the security of the state need not compromise individual privacy. On the other hand, as Ronald Dworkin &lt;a href="http://www.hup.harvard.edu/catalog.php?isbn=9780674867116" target="_blank"&gt;influentially maintained&lt;/a&gt;, the freedoms of the individual precede the interests of the state.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Security and trade interests&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, even when assessed from the  perspective of India’s security imperatives, the policy would have had  harmful consequences. It required users of encryption, including  businesses and consumers, to store plaintext versions of their  communications for ninety days to surrender to the government upon  demand. This outrageously ill-conceived provision would have created  real ‘&lt;a href="https://en.wikipedia.org/wiki/Honeypot_%28computing%29" target="_blank"&gt;honeypots&lt;/a&gt;’ (originally, honeypots are &lt;a href="http://time.com/3094404/defcon-hackers-robocalls-honeypot/" target="_blank"&gt;decoy&lt;/a&gt; servers to lure hackers) of unencrypted data, ripe for theft. Note that India does not have a data breach law.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The policy’s demand for encryption  companies to register their products and give working copies of their  software and encryption mechanisms to the Indian government would have  flown in the face of trade secrecy and intellectual property protection.  The policy’s hurried withdrawal was a &lt;a href="http://www.reuters.com/article/2015/09/22/us-india-encryption-law-idUSKCN0RM1CO20150922" target="_blank"&gt;public relations&lt;/a&gt; exercise on the eve of Prime Minister Modi’s visit to Silicon Valley. It was &lt;a href="http://www.zdnet.com/article/indian-pm-modi-visits-us-tech-chiefs-in-wake-of-draconian-encryption-policy-debacle/" target="_blank"&gt;successful&lt;/a&gt;. Modi encountered no &lt;a href="https://www.hrw.org/mk/node/281554" target="_blank"&gt;criticism&lt;/a&gt; of his government’s &lt;a href="http://thewire.in/2015/08/02/the-battle-for-a-right-to-privacy-still-has-a-long-way-to-go-7685/" target="_blank"&gt;visceral opposition&lt;/a&gt; to privacy, even though the policy would have severely disrupted the  business practices of US communications providers operating in India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Encryption invites a convergence of state interests between India and US as well: both countries want to &lt;a href="https://www.eff.org/document/crypto-wars-governments-working-undermine-encryption" target="_blank"&gt;control&lt;/a&gt; it. Last month’s &lt;a href="http://www.state.gov/r/pa/prs/ps/2015/09/247192.htm" target="_blank"&gt;joint statement&lt;/a&gt; from the US-India Strategic and Commercial &lt;a href="http://www.state.gov/p/sca/ci/in/strategicdialgue/" target="_blank"&gt;Dialogue&lt;/a&gt; pledges “further cooperation on internet and cyber issues”. This innocuous statement masks a &lt;a href="http://www.state.gov/r/pa/prs/ps/2014/09/232330.htm" target="_blank"&gt;robust&lt;/a&gt; information-gathering and -sharing regime. There is no guarantee  against the sharing of any encryption mechanisms or intercepted  communications by India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The government has promised to return with a &lt;a href="http://indianexpress.com/article/india/india-others/government-withdraws-draft-national-encryption-policy-after-furore/" target="_blank"&gt;reworked&lt;/a&gt; proposal. It would be in India’s interest for this to be preceded by a  broad-based national discussion on encryption and its links to free  speech, privacy, security, and commerce.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Click to read the post published on &lt;a class="external-link" href="http://notacoda.net/2015/10/10/the-short-lived-adventure-of-indias-encryption-policy/"&gt;Free Speech / Privacy / Technology website&lt;/a&gt;.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/the-short-lived-adventure-of-india2019s-encryption-policy'&gt;https://cis-india.org/internet-governance/blog/the-short-lived-adventure-of-india2019s-encryption-policy&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>bhairav</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Encryption Policy</dc:subject>
    

   <dc:date>2015-11-29T09:03:42Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/first-post-naina-khedekar-september-23-2015-online-outcry-forces-government-to-withdraw-draft-encryption-policy">
    <title>Online outcry forces government to withdraw draft encryption policy</title>
    <link>https://cis-india.org/internet-governance/news/first-post-naina-khedekar-september-23-2015-online-outcry-forces-government-to-withdraw-draft-encryption-policy</link>
    <description>
        &lt;b&gt;The article by Naina Khedekar discussing encryption policy was published in First Post on September 23, 2015. Pranesh Prakash has been quoted.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;Read the original published by First Post &lt;a class="external-link" href="http://tech.firstpost.com/news-analysis/online-backlash-forces-government-to-withdraw-draft-encryption-policy-282106.html"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Yesterday, the government &lt;a href="http://tech.firstpost.com/news-analysis/after-backlash-govt-exempts-whatsapp-facebook-payment-gateways-from-encryption-policy-282095.html" target="_blank"&gt;&lt;b&gt;released a draft encryption policy&lt;/b&gt;&lt;/a&gt; aimed  at keeping a tab on the use of technology by specifying algorithms and  length of encryption keys used by ‘all’. It wanted businesses, telcos  and Internet companies to store all encrypted data for 90 days in plain  text which should be presented before the law enforcement agencies  whenever asked to. Moreover, failing to do so would mean legal action as  per the laws of the country.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;After a huge outcry, most of us woke up to the new proposed addendum  this morning wherein the government has clarified to exempt products  such as social media sites including WhatsApp, Facebook and Twitter;  payment gateways; e-commerce and password based transactions and more  from the draft policy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Finally, the government has decided to &lt;a href="http://tech.firstpost.com/news-analysis/government-withdraws-controversial-draft-encryption-policy-reports-282170.html"&gt;&lt;b&gt;withdraw the draft encryption policy&lt;/b&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;blockquote class="twitter-tweet" style="text-align: justify; "&gt;
&lt;p dir="ltr"&gt;I have written for that draft to be withdrawn, made changes to and then re-released: RS Prasad : ANI &lt;a href="http://t.co/W2IP4meEGb" rel="nofollow"&gt;pic.twitter.com/W2IP4meEGb&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;— Firstpost (@firstpost) &lt;a href="https://twitter.com/firstpost/status/646221371932962816" rel="nofollow"&gt;September 22, 2015&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote class="twitter-tweet" style="text-align: justify; "&gt;
&lt;p dir="ltr"&gt;Some sort of encryption policy is there all over the world: Ravishankar Prasad &lt;a href="http://t.co/cDvsOWtjcM" rel="nofollow"&gt;pic.twitter.com/cDvsOWtjcM&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;— Firstpost (@firstpost) &lt;a href="https://twitter.com/firstpost/status/646222621495812096" rel="nofollow"&gt;September 22, 2015&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;What’s fascinating is how the whole process felt like déjà vu.  Haven’t we seen the drama unfold before. While the dust on the net  neutrality sage has barely settled, we’re already facing newer issues  related to encryption and privacy. We never learn from our mistakes, do  we? A new draft policy, public outcry, and then comes the much-needed  changes.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;img alt="social_media" class="size-full wp-image-235071" height="360" src="http://tech.firstpost.com/wp-content/uploads/2014/09/social_media.jpg" width="640" /&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Indian government hasn’t just caused anxiety and chaos among the  netizens, but the initial draft completely misguided people. According  to &lt;a href="http://thenextweb.com/in/2015/09/21/india-still-doesnt-understand-how-online-security-works/" rel="nofollow" target="_blank"&gt;&lt;b&gt;TheNextWeb&lt;/b&gt;&lt;/a&gt;,  “The Indian government has made a fool of itself and caused anxiety  among citizens with a woefully misguided proposal for a national  encryption policy that it’s just released to the public for feedback.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While we sit back and talk about Digital India, smarter cities and so  on, the makers of the law seem to be clueless about some major  by-products concerning these initiatives such as security, privacy and  likewise. Each time the government talks about a new initiative meant to  bring in some law and order pertaining to digital rights, it somehow  manages to come up with implications that could affect us far worse.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In this case, the Indian government is trying to ensure that its law  enforcement agencies have easy access to encrypted information whenever  required, but this could easily compromise security and privacy in the  process.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Moreover, each time the government releases a proposal for our  digital lives, it’s people who remind the government about the adverse  implications it could have. Does the expert panel writing these reports  know nothing about privacy and how it possibly works? Or is the  government simply looking at a trial balloon policy to gauge reactions  by people. So, next time we don’t react, a draconian rule might just be  governing our digital lives.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The whole net neutrality saga continued for months with assurance  from the government on how it supports free and equal Internet, and  eventually made ‘certain changes’. This seems headed on a similar path.  Though the new addendum comes with changes, it still leaves us as  muddled as before.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Pranesh Prakash of the CIS has tweeted out how the new clarification clarifies nothing.&lt;/p&gt;
&lt;blockquote class="twitter-tweet" style="text-align: justify; "&gt;
&lt;p dir="ltr"&gt;This clarification by the govt does not clarify anything, but further muddles the encryption policy. &lt;a href="http://t.co/1KK8AFRp6Q" rel="nofollow"&gt;pic.twitter.com/1KK8AFRp6Q&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;— Pranesh Prakash (@pranesh_prakash) &lt;a href="https://twitter.com/pranesh_prakash/status/646164649436549120" rel="nofollow"&gt;September 22, 2015&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote class="twitter-tweet" style="text-align: justify; "&gt;
&lt;p dir="ltr"&gt;All  OSes will be illegal in India (IV.6 + V.3 of draft encryption policy)  unless Microsoft, Apple, Red Hat, etc, sign agreement w/ govt.&lt;/p&gt;
&lt;p&gt;— Pranesh Prakash (@pranesh_prakash) &lt;a href="https://twitter.com/pranesh_prakash/status/645871490408255489" rel="nofollow"&gt;September 21, 2015&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote class="twitter-tweet" style="text-align: justify; "&gt;
&lt;p dir="ltr"&gt;If  India enacts that National Encryption Policy, their global back-end and  support business will be drastically reduced. If it survives.&lt;/p&gt;
&lt;p&gt;— Lin S (@Just_this_time) &lt;a href="https://twitter.com/Just_this_time/status/645781278244012033" rel="nofollow"&gt;September 21, 2015&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;A new &lt;a href="http://www.medianama.com/2015/09/223-india-draft-encryption-policy/" rel="nofollow" target="_blank"&gt;&lt;b&gt;Medianama&lt;/b&gt;&lt;/a&gt; report also points out loopholes in the changes announced. The report  adds how any encrypted service would have to sign an agreement with the  government. With the heavy mobile penetration and increasing number of  encrypted mobile services that people use, it is really feasible for the  government to ink an agreement with all the services that are based  outside the country.&lt;/p&gt;
&lt;blockquote class="twitter-tweet" style="text-align: justify; "&gt;
&lt;p dir="ltr"&gt;Problems with the update to India's draft anti-privacy policy  &lt;a href="http://t.co/gKus1o3uaC" rel="nofollow"&gt;http://t.co/gKus1o3uaC&lt;/a&gt; &lt;a href="http://t.co/adqVJTedFI" rel="nofollow"&gt;pic.twitter.com/adqVJTedFI&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;— Nikhil Pahwa (@nixxin) &lt;a href="https://twitter.com/nixxin/status/646153774231228416" rel="nofollow"&gt;September 22, 2015&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;In the past, we’ve seen the blame game around the laws, usually the  ‘hurriedly’ changed laws passed (after the inability to monitor  encrypted messages during the Mumbai terrorist attacks) in the winter  session of 2008 without any debate or discussion by bears the brunt.  Earlier this year, we saw the government crack down the Section 66A of  the 2008 Information Technology Act describing it “unconstitutional” and  “hit at the root of liberty and freedom of expression, the two cardinal  pillars of democracy.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Why can’t all the thinking be done before drafts are penned down for  public review. A well thought out report would help avoid  retractions later.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="http://tech.firstpost.com/wp-content/uploads/2014/09/social_media.jpg"&gt;&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/first-post-naina-khedekar-september-23-2015-online-outcry-forces-government-to-withdraw-draft-encryption-policy'&gt;https://cis-india.org/internet-governance/news/first-post-naina-khedekar-september-23-2015-online-outcry-forces-government-to-withdraw-draft-encryption-policy&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Encryption</dc:subject>
    
    
        <dc:subject>Encryption Policy</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2015-10-01T02:05:01Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/asian-age-september-27-2015-s-raghotham-and-mayukh-mukherjee-by-weakening-our-security-govt-is-putting-us-at-risk-of-espionage">
    <title>‘By weakening our security, govt is putting us at risk of espionage’</title>
    <link>https://cis-india.org/internet-governance/news/asian-age-september-27-2015-s-raghotham-and-mayukh-mukherjee-by-weakening-our-security-govt-is-putting-us-at-risk-of-espionage</link>
    <description>
        &lt;b&gt;After the BlackBerry encryption and IT Act fiascos of recent years, the government last week sent yet another cyber policy howler, the Draft National Encryption Policy, only to withdraw it in the face of severe protests. S. Raghotham and Mayukh Mukherjee spoke with Pranesh Prakash, policy director, Centre for Internet &amp; Society, on the government’s continued misadventures with data privacy and encryption.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;This interview of Pranesh Prakash was &lt;a class="external-link" href="http://www.asianage.com/interview-week/weakening-our-security-govt-putting-us-risk-espionage-183"&gt;published in Asian Age&lt;/a&gt; on September 27, 2015.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;First we had Section 66A in the Information Technology Act.  Now we have these attempts at breaking encryption and invading privacy.  Your comment.&lt;/b&gt;&lt;br /&gt; The Draft National Encryption Policy (DNEP) was not only an invasion of  privacy and a restriction on anonymous speech, but was, most  importantly, a direct assault on national security. It was quite clearly  drafted by people who did not understand encryption, who think that  encryption is something that only a handful of people do, without  realising that encryption is baked into most of our technologies.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It is clear that the government’s cyber-law division needs people who  are better versed in both the law (including constitutional rights) as  well as technical aspects of IT. It’s not just Section 66A, but a host  of other provisions in the IT Act which display a similar cluelessness.  For instance, gaining unauthorised access to a protected system for  purposes of defamation is, as per Indian law, sufficient to commit the  offence of “cyber terrorism”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;How does this compare with the previous government’s attempts to gain access to BlackBerry communications?&lt;/b&gt;&lt;br /&gt; L’affaire BlackBerry concluded with the government realising that while  they could get BlackBerry to locate a network operations centre in  India, they still couldn’t decrypt everything since BlackBerry  Enterprise Service allowed enterprises to control the encryption.  However, the government seems to have drawn the wrong lesson from that,  and wants to prevent end-users from using encryption the way they have  already managed with telecom companies and Internet service providers,  who are not allowed to deploy bulk encryption which saves their  customers’ data from being intercepted by attackers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The government seems to be saying, if the US National  Security Agency (NSA) doesn’t get you, we will. How are we to respond to  this?&lt;/b&gt;&lt;br /&gt; If you’re using Gmail, Yahoo Mail, Hotmail, etc., you already have  opportunistic traffic-level encryption for email. Ironically, no  @deity.gov.in or @nic.in address has even this basic level of  encryption. This is the shocking state of affairs even many years after  National Informatics Centre (NIC) publicly acknowledged that multiple  email accounts that they host were hacked into. National security is a  collective form of security — we can’t increase national security by  making individuals less secure. We can’t, for instance, improve national  security by telling people not to use locks on their houses. That will  only decrease security, not increase it. And we are in a situation where  our government conducts all their email communications using the online  equivalent of postcards, rather than using sealed envelopes. The  Central government urgently needs to appoint a group of security experts  who work with NIC to shore up our defensive security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A slide on an NSA programme called BOUNDLESSINFO-RMANT showed that in  the month of February 2013, the NSA has collected 12.5 billion data  records relating to phone calls from India, far more than what they had  collected from China. The fact that our government mandates weak telecom  security (by restricting bulk encryption) might account for this. By  weakening our security, the government is putting us at greater risk of  espionage and at the hands of hackers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;What are some of the ramifications for businesses and  individuals if the government were to have keys to all encrypted  information as it seeks?&lt;/b&gt;&lt;br /&gt; The government, in the DNEP, did not even seek key escrow (which is what  the debate was about in the 1990s in the US’ “crypto war”). Here the  government more or less sought to tell companies and individuals that  they have to keep plain text, making storage-level encryption pointless.  This means that all your company’s information — emails, passwords and  financial records — would be vulnerable to compromise by hackers. It is  like telling a company that it is allowed to own a government-approved  safe for storing important documents, but it has to keep a copy of all  the important documents outside the safe.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Is the encryption policy fiasco some junior bureaucrat’s  ignorance of what he was proposing or is it part of the government’s  continued efforts to somehow gain control over information flows?&lt;/b&gt;&lt;br /&gt; The government intended to gain greater access to everyday transactions.  This would violate citizens’ privacy, which the government has been  arguing is not a fundamental right. They went about it in a manner that  is absurd in its consequences. The policy would have required you to  record every mobile phone call and Skype call, to keep a plain text  version of communications, which would harm national security. While I  don’t believe the government would intentionally weaken national  security, as they would have had this draft policy been carried forward,  one cannot say that the government wouldn’t do so wantonly, much in the  same way that they haven’t even employed basic security in their email  systems.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Do you perceive a higher level of desire in the current government to control information flows?&lt;/b&gt;&lt;br /&gt; The Indian government’s pursuance of harmful technology policies is  nothing new. However, I hope that as a tech-savvy person heading an  ostensibly tech-savvy government, Prime Minister Narendra Modi steps in  and halts these deleterious policies. One disappointment of the last  year has been the lack of progress on the Privacy Act, which seems to  have been shelved for the time being. I believe the government’s  motivations are genuine and grounded in the public interest. However, as  in any constitutional democracy, the citizenry ought to be engaged in  both defining the public interest as well as in debating how we best  protect and uphold it within the norms laid down in our Constitution,  which includes guarantees of fundamental rights which are inviolable  except in limited circumstances.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For most of these policy problems, the best way forward is to ensure  that the government follow a system of issuing green papers —  essentially non-papers meant to stimulate public discussion — before it  issues white papers which contain statements of policy intent, based on  which it finally formulates policies or laws. Currently, interaction  between policymakers and civil society is far too infrequent. The  government needs to inject far more subject-matter expertise into  policymaking.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/asian-age-september-27-2015-s-raghotham-and-mayukh-mukherjee-by-weakening-our-security-govt-is-putting-us-at-risk-of-espionage'&gt;https://cis-india.org/internet-governance/news/asian-age-september-27-2015-s-raghotham-and-mayukh-mukherjee-by-weakening-our-security-govt-is-putting-us-at-risk-of-espionage&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Encryption Policy</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2015-10-02T03:09:46Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/hindustan-times-september-22-2015-bowing-to-public-pressure-govt-withdraws-draft-encryption-policy">
    <title>Bowing to public pressure, govt withdraws draft encryption policy </title>
    <link>https://cis-india.org/internet-governance/news/hindustan-times-september-22-2015-bowing-to-public-pressure-govt-withdraws-draft-encryption-policy</link>
    <description>
        &lt;b&gt;Bowing to pressure from the public, the government on Tuesday withdrew a draft policy that sought to control secured online communication, including through mass-use social media and web applications such as WhatsApp and Twitter.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was published by the &lt;a class="external-link" href="http://www.hindustantimes.com/tech/bowing-to-public-pressure-govt-withdraws-draft-encryption-policy/story-kOVNjpFZIuzyuQZGqv4JSN.html;jsessionid=C7FD668754FD1868D4BFE90D6D3C98B5"&gt;Hindustan Times&lt;/a&gt; on September 22, 2015. Pranesh Prakash was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Communications and information technology minister Ravi Shankar  Prasad announced the government’s decision at a news conference, saying  the draft National Encryption Policy will be reviewed before it is again  presented to the public for their suggestions.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“I read the draft. I understand that the manner in which it is  written can lead to misconceptions. I have asked for the draft policy to  be withdrawn and reworded,” Prasad said. He said the draft would be  re-released, but did not say when it would be made public.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Experts had framed a draft policy...This draft policy is not the  government’s final view,” he added. “There were concerns in some  quarters. There were some words (in the draft policy) that caused  concern.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The draft will be reviewed and experts will be asked to specify to  whom the policy will be applicable, Prasad said. He did not say when the  new draft will be made public.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Those using social media platforms and web applications fell outside the scope of an encryption policy, Prasad said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Several countries have felt the need for an encryption policy because  of the boom in e-commerce and e-governance, he remarked. “Cyber space  interactions are on the rise. There are concerns about security. We need  a sound encryption policy,” he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Before Prasad announced the withdrawal of the draft policy, the  government had issued an addendum early on Tuesday to keep social media  and web applications like WhatsApp, Twitter and Facebook out of its  purview.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Secure banking transactions and password protected e-commerce  businesses too will be kept out of the ambit of the proposed policy, the  addendum said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The climb down by the government came following a storm of protests  from users who objected to any stringent state controls on the use of  email, social media accounts and apps.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to the original draft, users of apps such as WhatsApp and  Snapchat would be required to save all messages for up to 90 days and be  able to produce them if asked by authorities.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Experts told Hindustan Times the draft policy, if implemented in its  current form, could compromise the privacy of users and hamper the  functioning of several multi-national service providers in India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Nikhil Pahwa, editor of the MediaNama website that tracks cyber  issues and tech news, said there were several problems even with the  addendum to the draft policy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“The usage of the phrase ‘currently in use’ renders the policy vague:  Firstly, when is ‘currently’?” he questioned in a post on his website.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Will a new service that uses a different kind of encryption to  protect its users, still be covered? Why should users be ‘restricted to  encryption currently in use’? Why should services like Whatsapp,  Facebook and Twitter define our security standards?” said Pahwa, who  also volunteers for savetheinternet.in.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Pranesh Prakash, policy director for The Centre for Internet and  Society, tweeted that even the addendum “does not clarify anything, but  further muddles the encryption policy”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Social media users called the draft “draconian” and “delusional”, and  Congress leader Manish Tewari too attacked the Union government.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“The encryption policy (draft) is a snooping and spying orgy. After  net chats, the government may want you to keep a video record of what  you do in your bedroom for 90 days,” the Congress spokesperson told  reporters.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The draft policy had been posted online last week to seek suggestions from the public.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/hindustan-times-september-22-2015-bowing-to-public-pressure-govt-withdraws-draft-encryption-policy'&gt;https://cis-india.org/internet-governance/news/hindustan-times-september-22-2015-bowing-to-public-pressure-govt-withdraws-draft-encryption-policy&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Encryption</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Encryption Policy</dc:subject>
    

   <dc:date>2015-10-01T02:15:17Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>




</rdf:RDF>
