<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 1011 to 1025.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-wire-may-1-2015-130-million-aadhaar-numbers-were-made-public-says-new-report"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/hindustan-times-rachel-lopez-august-26-2018-20-years-of-google-privacy-fake-news-and-future"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/new-indian-express-may-2-2017-akram-mohammed-13-crore-aadhaar-numbers-on-four-government-websites-compromised"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/11th-meeting-of-information-systems-security-sectional-committee-litd-17"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/best-practices-meet-2015"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/ssn-2014-sixth-biannual-surveillance-and-society-conference"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/popular-myths-about-uid"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/crea-reconference"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/privacy/privacy-matters-report-from-ahmedabad"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/cio-july-1-2015-irctc-aadhaar-play-can-violate-sc-order-and-derail-national-security"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-telegraph-august-3-2014-i-am-going-to-ruin-you-dear"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/saket-modi-calls-for-stronger-cyber-security-discussions"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/attempts-to-censor-the-web-ill-advised"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-wire-may-1-2015-130-million-aadhaar-numbers-were-made-public-says-new-report">
    <title>130 Million Aadhaar Numbers Were Made Public, Says New Report</title>
    <link>https://cis-india.org/internet-governance/news/the-wire-may-1-2015-130-million-aadhaar-numbers-were-made-public-says-new-report</link>
    <description>
        &lt;b&gt;The research report looks at four major government portals whose poor information security practices have exposed personal data including bank account details.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was &lt;a href="https://thewire.in/130948/aadhaar-card-details-leaked/"&gt;published in the Wire&lt;/a&gt; on May 1, 2017. This was also mirrored on &lt;a class="external-link" href="http://www.mensxp.com/technology/latest/36661-over-130-million-aadhaar-numbers-bank-details-were-leaked-way-are-not-surprised.html"&gt;MensXP.com&lt;/a&gt; on May 5, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Irresponsible         information security practices by a major central government         ministry and a state government may have exposed up to 135         million Aadhaar numbers, according to a new research report         released on Monday.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;The&lt;a href="https://thewire.in/118250/government-expose-personal-data-thousands-indians/" rel="noopener           noreferrer" target="_blank" title=" last two months "&gt; last two months &lt;/a&gt;have seen a wave of data         leaks, mostly due improper information security practices, from         various central government and state government departments.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This &lt;a rel="noopener noreferrer" target="_blank" title="new report"&gt;new report&lt;/a&gt;, released by the Centre       for Internet and Society, studied four government databases. The       first two belong to the rural development ministry: the National       Social Assistance Programme (NSAP)’s dashboard and the National       Rural Employment Guarantee Act (NREGA)’s portal.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The second two databases deal with the state of       Andhra Pradesh: namely, the state government’s own NREGA portal       and the online dashboard of a state government scheme called       “Chandranna Bima”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Based on the numbers available on the websites       looked at, estimated number of Aadhaar numbers leaked through       these 4 portals could be around 130-135 million and the number of       bank accounts numbers leaked at around 100 million from the       specific portals we looked at,” the report’s authors, Amber Sinha       and Srinivas Kodali, state.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The data leaks come, in part, from the       government’s decision to provide online dashboards that were       likely meant for general transparency and easy administration.       However, as the report notes, while open data portals are a       laudable goal, if there aren’t any proper safeguards, the results       can be downright disastrous.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“While availability of aggregate information on       the dashboard may play a role in making government functioning       more transparent, the fact that granular details about individuals       including sensitive PII such as Aadhaar number, caste, religion,       address, photographs and financial information are only a few       clicks away suggest how poorly conceived these initiatives are,”       the report says.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Consider the NSAP portal for instance. The       dashboard allows users to explore a list of pensioners, whose       personally identifiable information include bank account number,       name and Aadhaar number. While these details are “masked for       public view”, the CIS report points out that if “one of the URL       query parameters of the website… was modified from ‘nologin’ to       ‘login'”, it became easy to gain access to the unmasked details       without a password.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“It is entirely unclear to us what the the       purpose behind making available a data download pption on the NSAP       website is. This feature allows download of beneficiary details       mentioned above such as Beneficiary No., Name, Father’s/Husband’s       Name, Age, Gender, Bank or Post Office Account No. for       beneficiaries receiving disbursement via bank transfer and Aadhaar       Numbers for each area, district and state,” the report states.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;UIDAI role?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Kodali and Sinha also prominently finger the role       of the Unique Identification Authority of India (UIDAI), the       government agency that manages the Aadhaar initiative, in the data       leaks.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“While the UIDAI has been involved in proactively       pushing for other databases to get seeded with Aadhaar numbers,       they take little responsibility in ensuring the security and       privacy of such data.With countless databases seeded with Aadhaar       numbers, we would argue that it is extremely irresponsible on the       part of the UIDAI, the sole governing body for this massive       project, to turn a blind eye to the lack of standards prescribed       for how other bodies shall deal with such data, such cases of       massive public disclosures of this data, and the myriad ways in       which it may used for mischief,” the report states.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Still public?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A crucial question that arises is whether these       government databases are still leaking data. Over the last two       months, some of information has been masked.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“It must be stated that since we began reviewing       and documenting these portals, we have noticed that some of the       pages with sensitive PII (personally identifiable information)       have now been masked, presumably in response to growing reports       about Aadhaar leaks,” the report notes.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-wire-may-1-2015-130-million-aadhaar-numbers-were-made-public-says-new-report'&gt;https://cis-india.org/internet-governance/news/the-wire-may-1-2015-130-million-aadhaar-numbers-were-made-public-says-new-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T06:32:32Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/hindustan-times-rachel-lopez-august-26-2018-20-years-of-google-privacy-fake-news-and-future">
    <title>20 years of Google: Privacy, fake news and the future</title>
    <link>https://cis-india.org/internet-governance/news/hindustan-times-rachel-lopez-august-26-2018-20-years-of-google-privacy-fake-news-and-future</link>
    <description>
        &lt;b&gt;Google once directed you to information. Today, it’s often the source of information, using data you and others have shared, often without you realising it. Public knowledge goes where Google takes it. And 20 years on, not everyone’s happy with the journey.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Rachel Lopez was published in &lt;a class="external-link" href="https://www.hindustantimes.com/india-news/20-years-of-google-privacy-fake-news-and-the-future/story-0jmwFxnhwz8lWFUCbMxBjM.html"&gt;Hindustan Times&lt;/a&gt; on August 26, 2018. Pranesh Prakash was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Happy Birthday, Google. The search engine is 20 this year, and what a  ride it’s been! When Sergey Brin and Larry Page were developing  software that &lt;a href="https://www.hindustantimes.com/india-news/20-years-of-google-when-information-was-not-just-a-click-away/story-aIDWzxXMQd10ShuhL62vcI.html" target="_blank"&gt;searched better and loaded faster &lt;/a&gt;than Explorer, Navigator and AltaVista, the web  itself consisted of just 1 lakh websites.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Google’s  mission statement was succinct: To organise the world’s information and  make it universally accessible. Their corporate code of conduct was  even simpler: Don’t be evil.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Perhaps even Google didn’t realise  where its mission would take it. The following decade brought Google  News, Gmail, Maps and Chrome. By 2014, the internet had grown to 1  billion websites. The search engine, their core product, had become the  default homepage of the Internet.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In May this year, Google quietly  dropped the ‘Don’t be evil’ tag. The same month, its Android operating  system crossed 2 billion monthly active devices. &lt;a href="https://www.hindustantimes.com/india-news/20-years-of-google-there-s-something-for-everyone-here/story-eS5rDm76QFNgZIXwY3kGuM.html" target="_blank"&gt;Seven products (including YouTube and Google Play&lt;/a&gt;) now reach a combined 1 billion users.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Google  once directed you to information. Today, it’s often the source of  information (in ads and top-of-the-page blocs), using data you and  others have shared, often without you realising it. Public knowledge  goes where Google takes it. And 20 years on, not everyone’s happy with  the &lt;a href="https://www.hindustantimes.com/india-news/20-years-of-google-the-journey-to-omnipresence/story-Ehr55MBGNOV0j3Jd9XhdyO.html" target="_blank"&gt;journey&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“The  key concern is that Google has grown so big,” says Pranesh Prakash,  policy director at Bangalore’s Centre for Internet &amp;amp; Society. “It’s  like the classic line from [Spiderman’s] Uncle Ben: With great power  comes great responsibility. In Google’s case, its great size is what  brought great power to begin with.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For billions of Google users, the biggest concerns are now of &lt;a href="https://www.hindustantimes.com/india-news/i-believe-the-most-exciting-moment-for-google-in-india-hasn-t-happened-yet-rajan-anandan/story-8goKIyIadDBKit0wyz7xYP.html" target="_blank"&gt;privacy and accountability&lt;/a&gt;,  says Nikhil Pahwa, founder of Medianama, which analyses digital and  telecom businesses. “There are few checks on Google’s ability to take,  retain and process information from users,” he says.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Hits and misses&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;For Google, all is going according to plan. Its search engine is now  smart enough to complete your sentences. It’s learning constantly from  what you search for, watch, spend on, share and regret; it knows your  commute and your vacation plans. And it’s profiting from this knowledge.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In  the UK, Google is being sued for bypassing iPhone privacy settings to  track and collect data from 4.4 million users in 2011 and 2012.  Information on race, physical and mental health, political leanings,  sexuality, shopping habits and locations was apparently used to build  advertising categories. Google also creates products for the US  government, and has user data from around the world. “Any entity that  has this much insight into us, and is in a position to use it, whether  for the government or commercial gain, is cause for worry,” says  Prakash. Most users aren’t worried, and that’s worrying too. We don’t  realise how much data is being tracked or collected. The more we share,  the more useful Google gets, and the greater its potential for misuse,  for mapping say, beef-eaters, online dissenters, LGBT supporters or  single women who work late.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Internet’s other giant, Facebook,  recently suspended 400 apps over  privacy concerns, admitting that 87  million users may have had data  compromised in 2016. Meanwhile, even  non-Google apps are capable of  hijacking data using software developed  by Google. Weather apps look at  your photo gallery, ride-sharing  software keep tracking you after the  ride, games are checking out your  texts as you play. Gmail knows your  flight timings, how many steps  you’ve walked, and your last bank  transaction.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Search for tomorrow&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Perhaps the biggest concerns are with Google’s artificial intelligence technology, the brand’s great leap forward fuelled by its massive data reserves. The tech is already being criticised for being fed biased data, creating global services that mirror the prejudices of an insular, mostly white, mostly male, tech industry.&lt;br /&gt;&lt;br /&gt;Sara Wachter-Boettcher, author of Technically Wrong, which looks at how technology reflects sexism and the biases of the people that create it, says this creates problems. “Google develops tools that other tech companies rely on to build other products,” she says. So its biases spread to other products too. As machines learn, Google is starting to unlearn too.&lt;br /&gt;&lt;br /&gt;“Machine unlearning is basically recognising when a machine has learned something inaccurate, or biased, and then erasing that learning,” says Wachter-Boettcher. In Africa, the company (along with Facebook) now funds a Masters course in machine intelligence to improve the industry’s diversity. Last year, Google took its first steps to curb fake news hits on its search engines with tools that allow users to report misleading or offensive content.&lt;br /&gt;&lt;br /&gt;But perhaps it’s time to work towards a future in which Google will be monitored in real time, in different countries, rather than depending on the company to offer a fix after a misstep. Prakash believes that the way forward is reimagining an Internet where Google isn’t the first and last word on everything. “This doesn’t mean more companies like Google but searching that happens in a more decentralised way,” he says. “We need to save the web from large monopolies in the long run.”&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/hindustan-times-rachel-lopez-august-26-2018-20-years-of-google-privacy-fake-news-and-future'&gt;https://cis-india.org/internet-governance/news/hindustan-times-rachel-lopez-august-26-2018-20-years-of-google-privacy-fake-news-and-future&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-08-30T02:49:06Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/new-indian-express-may-2-2017-akram-mohammed-13-crore-aadhaar-numbers-on-four-government-websites-compromised">
    <title>13 crore Aadhaar numbers on four government websites compromised: Report</title>
    <link>https://cis-india.org/internet-governance/news/new-indian-express-may-2-2017-akram-mohammed-13-crore-aadhaar-numbers-on-four-government-websites-compromised</link>
    <description>
        &lt;b&gt;The lack of information security practices in key government websites which hosts Personally Identifiable Information (PII) has left citizens of the country more vulnerable to identity theft and financial fraud, a research paper has argued. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Akram Mohammed was &lt;a href="http://www.newindianexpress.com/nation/2017/may/02/13-crore-aadhaar-numbers-on-four-government-websites-compromised-report-1599999.html"&gt;published by the New Indian Express&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;A paper by Amber Sinha and Srinivas       Kodali of Centre for Internet and Society analysed four government       websites and found that more than 13 crore Aadhaar numbers with       related PII were available on the websites, exposing lax security       features.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The paper published under Creative       Commons is titled ‘Information Security Practices of Aadhaar (or       lack thereof): A documentation of public availability of Aadhaar       Numbers with sensitive personal financial information’ and was       released on Monday.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Sinha and Kodali looked at databases       on four government portals -- National Social Assistance       Programme, National Rural Employment Guarantee Scheme, Chandranna       Bima Scheme, Govt. of Andhra Pradesh and Daily Online Payment       Reports website of NREGA, Govt. of Andhra Pradesh.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“We chose major government       programmes that use Aadhaar for payments and banking transactions.       We found sensitive and personal data and information accessible on       these portals,” the report said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Leaked through portals&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Based on the numbers available on       the websites, estimated number of Aadhaar numbers leaked through       these 4 portals could be around 130-135 million and the number of       bank account numbers leaked at around 100 million.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While these numbers are only from       two major government programmes of pensions and rural employment       schemes, other major schemes, that have also used Aadhaar for DBT,       could have leaked PII similarly due to lack of information       security practices,” it said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;They fear that data of over 23 crore       beneficiaries under DBT of LPG subsidies could be leaked also.       Identity theft and financial fraud “risks increase multifold in       India...,” they said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Aadhaar payments unsafe&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In case a financial fraud takes       place through Aadhaar enabled Payment System (AePS), the consumer       may not be able to assert his claims for compensation due to the       terms and conditions around liabilities.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“These terms force the consumer to       take liabilities onto oneself than the payment provider.....       Regulations and standards around Aadhaar are at a very early and       nascent stage causing (an) increase in financial risk for both       consumers and banks to venture into AePS,” they added. The authors       also pulled up UIDAI for their inability in providing strong       legislation against such leaks.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Leaky govt portals&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;National Social Assistance Programme&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;PII available - Access to Aadhaar no., name, bank account number, account frozen status  94,32,605 bank accounts linked with Aadhaar&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;14,98,919  post office accounts linked with Aadhaar numbers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Though total Aadhaar number is  1,56,42,083, not all are linked to bank accounts&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;NREGA&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;PII Details available: Job card no., Aadhaar number, bank/postal account number, no. of days worked, registration no., account frozen status&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;78,74,315  post office accounts of individual workers seeded with Aadhaar numbers,&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;8,24,22,161 bank accounts of individual workers with Aadhaar numbers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;10,96,41,502 total number of Aadhaar numbers stored by portal&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Other websites&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Chandranna Bima Scheme, Govt. of Andhra Pradesh&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Daily Online Payment Reports website of NREGA, Govt. of Andhra Pradesh&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/new-indian-express-may-2-2017-akram-mohammed-13-crore-aadhaar-numbers-on-four-government-websites-compromised'&gt;https://cis-india.org/internet-governance/news/new-indian-express-may-2-2017-akram-mohammed-13-crore-aadhaar-numbers-on-four-government-websites-compromised&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-03T15:19:52Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/11th-meeting-of-information-systems-security-sectional-committee-litd-17">
    <title>11th Meeting of Information Systems Security Sectional Committee (LITD 17)</title>
    <link>https://cis-india.org/internet-governance/news/11th-meeting-of-information-systems-security-sectional-committee-litd-17</link>
    <description>
        &lt;b&gt;Udbhav Tiwari represented CIS at this meeting organized by the Bureau of Indian Standards (BIS) at Manak Bhavan, New Delhi on April 13, 2017.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The meeting was the national mirror meeting for the 28th ISO/IEC JTC 1/SC 27 Plenary and Working Group Meetings being held at Hamilton, New Zealand between the April 18 and 25, 2017. The meeting provided a fascinating insight into the government and industry viewpoints on key cyber security and privacy issues, especially on the Aadhaar.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/11th-meeting-of-information-systems-security-sectional-committee-litd-17'&gt;https://cis-india.org/internet-governance/news/11th-meeting-of-information-systems-security-sectional-committee-litd-17&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-04-19T02:57:03Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites">
    <title>১৩ কোটি আধার তথ্য ফাঁস চার সরকারি পোর্টাল থেকে! বিস্ফোরক দাবি রিপোর্টে </title>
    <link>https://cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites</link>
    <description>
        &lt;b&gt;খোদ সরকারি পোর্টাল থেকে কয়েক কোটি আধার নম্বর ও যাবতীয় তথ্য ‘ফাঁস’!&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;This was published by &lt;a class="external-link" href="http://abpananda.abplive.in/india-news/13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites-334778"&gt;Amar Bazar Patrika&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;অভিযোগ, গত কয়েক মাসে প্রায় ১৩ কোটি আধার  নম্বরের যাবতীয় ব্যক্তিগত ও সংবেদনশীল তথ্য ফাঁস হওয়ার ঘটনা ঘটেছে। আর এসবই  হয়েছে চারটি সরকারি পোর্টাল থেকে তথ্যপ্রযুক্তি সুরক্ষার ঘাটতির জেরে! যা  ঘিরে এখন তোলপাড় দেশ।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;সম্প্রতি, এমনই বিস্ফোরক রিপোর্ট প্রকাশ  করেছে অলাভদায়ক সংগঠন সেন্টার ফর ইন্টারনেট অ্যান্ড সোসাইটি (সিআইএস)।  তাদের আশঙ্কা, চারটি সরকারি পোর্টালের মাধ্যমে ১০ কোটি মানুষের ব্যাঙ্ক  অ্যাকাউন্ট নম্বরও ফাঁস হয়ে থাকতে পারে।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;সংস্থার দাবি, যে চারটি পোর্টাল থেকে এই  সব তথ্য ফাঁসের অভিযোগ, তার মধ্যে দু’টি অন্ধ্রপ্রদেশ সরকারের ওয়েবসাইট।  বাকি দুটি পোর্টাল হল ন্যাশনাল সোশ্যাল অ্যাসিস্ট্যান্স প্রোগ্রাম এবং  ন্যাশনাল রুরাল এমপ্লয়মেন্ট গ্যারান্টি স্কিম-এর।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;এই গোটা ঘটনার জন্য ইউনিক আইডেন্টিফিকেশন  অথরিটি অফ ইন্ডিয়া বা ইউআইডিএআই–কেই দায়ী করেছে সিআইএস। তাদের দাবি, আধার  নিয়ন্ত্রক সংস্থার ‘দায়িত্বজ্ঞানহীনতার’ জন্যই এই উদ্ভুত পরিস্থিত সৃষ্টি  হয়েছে।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;সিএনআই-এর আরও দাবি, বিভিন্ন সরকারি ও  বেসরকারি পোর্টাল—যারা আধার তথ্য ব্যবহার করে থাকে, তাদের নিজস্ব  সুরক্ষা-ব্যবস্থা খতিয়ে দেখেনি ইউআইডিএআই। ফলত, এই বিপত্তির সম্মুখীন কয়েক  কোটি মানুষ।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;যদিও, ইউআইডিএআই -এর দাবি, তাদের ডেটাবেস থেকে কোনও তথ্য ফাঁস হয়নি।&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites'&gt;https://cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T11:45:42Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/best-practices-meet-2015">
    <title>7th Best Practices Meet 2015</title>
    <link>https://cis-india.org/internet-governance/news/best-practices-meet-2015</link>
    <description>
        &lt;b&gt;Data Security Council of India (DSCI) organized the 7th edition of its Best Practices Meet (BPM) from July 9 - 10, 2015 at Hotel ITC Gardenia in Bengaluru. BPM2015 had “Architecting Security for Digital Transformation” as its theme. Sunil Abraham and Elonnai Hickok were speakers at this event. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The two-day deliberations, reflected on policy, endeavours at national and industry levels, proposed industry steps, market response, best practices, industry standards and technology designs and see how they play their roles in architecting of information systems and enterprise security within organizations. Sunil Abraham was a panelist in the session "Architecting Security for transformation to Digital India". Elonnai Hickok was a panelist in the session "Steering privacy in the age of extreme innovation technology &amp;amp; business models."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/best-practices-meet-2015.pdf" class="external-link"&gt;&lt;b&gt;See the Agenda&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/best-practices-meet-2015'&gt;https://cis-india.org/internet-governance/news/best-practices-meet-2015&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2015-07-17T13:11:20Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/ssn-2014-sixth-biannual-surveillance-and-society-conference">
    <title>6th Biannual Surveillance and Society Conference </title>
    <link>https://cis-india.org/news/ssn-2014-sixth-biannual-surveillance-and-society-conference</link>
    <description>
        &lt;b&gt;Malavika Jayaram is a speaker at the conference organized by Eticas Research and Consulting at the University of Barcelona and CCCB from April 24 to 26, 2014.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;Malavika will present on the UID and biometrics at the session on “Surveillance: Ambiguities and Uncertainties". Malavika's talk title is "Biometrics in beta: experimenting on a nation (while normalising surveillance for 1.2 billion people)" and is being held on April 26. See the full event details &lt;a class="external-link" href="http://www.ssn2014.net/?cat=80"&gt;on this page&lt;/a&gt;.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;In the developing world, privacy is often portrayed as a luxury, as something alien to local culture and of interest only to the elite. This ignores the probability of the most marginalized sections of a society being disproportionately impacted by privacy intrusive technologies. The hype about ‘big data’, ‘open data’, ‘data for development’, ‘ICT4D’ and other buzzwords often ignores the fact that the global south is particularly vulnerable to data collection and processing. Literacy issues (lingual and technical), a massive digital divide, desperate socioeconomic conditions and the lack of a robust data protection law render ideas of consent or tradeoffs all but meaningless.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Techno-utopian welfare schemes present technology as progressive, neutral and frictionless – a seductive and compelling narrative in a region wracked by inequalities, corruption, lack of transparency and structural violence. This vision underpins the world’s largest biometric ID project, which has already registered the irises and fingerprints of 540 million people without even being completed. Yet the assumption that bodies can be rendered into infallible verifiers, as repositories of unchanging truth, ignores embedded biases and normative baselines within such technologies. Welfare projects are further complicated when they are architected as public-private partnerships: the collusion of governmental and corporate agendas in creating massive databases and profiles, in a manner that transforms the citizen-state relationship in profound ways, has sweeping implications for choice, autonomy, anonymity and ultimately, democracy. This is true even when the systems function as intended, without mechanical failure, data breaches, or other consequences of trading privacy for convenience, welfare and security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;I would like to discuss the risks of using technologies such as biometrics to solve socioeconomic problems, and their potential for excluding the very demographics that they seek to include. I intend to locate my presentation in the context of India’s growing surveillance state, which deliberately intends to use the unique identification number to link disparate databases. I propose to describe the new Centralised Monitoring System, the relative legal vacuum in which data is mined and harvested, and the shaky constitutional foundations on which many of these new regimes stand. In so doing, I will effectively have provided a tour of India’s Rogue’s Gallery of recent incursions into the zone of privacy, free speech, informational self-determination and dignity. I hope also to redress in some small measure the largely western focus of academic and policy debates in this field, despite the risks of developing countries seeking to commoditize and export identity schemes, normalize censorship or opportunistically benefit from the west no longer having the moral ground to resist third country surveillance practices.&lt;br /&gt; &lt;br /&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/ssn-2014-sixth-biannual-surveillance-and-society-conference'&gt;https://cis-india.org/news/ssn-2014-sixth-biannual-surveillance-and-society-conference&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2014-05-05T04:57:59Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/popular-myths-about-uid">
    <title>4 Popular Myths about UID</title>
    <link>https://cis-india.org/internet-governance/popular-myths-about-uid</link>
    <description>
        &lt;b&gt;By now, there is already a lot of material in the public domain that is critical about the UID/Aadhar project, writes Prashant Iyengar in this blog entry published in Privacy India on January 22, 2011.&lt;/b&gt;
        
&lt;p&gt;(See &lt;a class="external-link" href="http://aadhararticles.blogspot.com/"&gt;aadhararticles.blogspot.com&lt;/a&gt; for an exhaustive catalogue). Much of this material has criticized the UID for the ‘big brotherly’ techno-surveillance regime that it threatens to unleash, usually under the guise of delivering assured benefits to the marginal peasant. Many commentators have questioned the haste with which a project of this scale and complexity has sought to be pushed through. Some have expressed doubts on the feasibility – financial, technical or&amp;nbsp; logistical – of the scheme. Much of this material has criticized the UID for the ‘big brotherly’ techno-surveillance regime that it threatens to unleash, usually under the guise of delivering assured benefits to the marginal peasant. Many commentators have questioned the haste with which a project of this scale and complexity has sought to be pushed through. Some have expressed doubts on the feasibility – financial, technical or&amp;nbsp; logistical – of the scheme.&lt;/p&gt;
&lt;p&gt;I do not intend to rehearse these arguments in this post. Instead, I pick four somewhat obscure, but troublesome assertions made about the UID and test their veracity against documents available on the UIDIA site itself. The purpose is to cut through all the equivocation behind the claims that UID officials have been making, and arrive at some minimal clarity on what the UID is (and isn’t).&lt;/p&gt;
&lt;h3&gt;Registration is voluntary!&lt;/h3&gt;
&lt;p&gt;How does one make sense of Nandan Nilenkani’s cryptic remark, “I wouldn’t call it compulsory. I would rather say that it will become ubiquitous”?&lt;br /&gt;&lt;br /&gt;In a sense, this is true enough. Nowhere in the entire bulk of UID documentation will you encounter the express words “mandatory” or “compulsory”. Hence, proved!&amp;nbsp; But that isn’t to say, however, that there is any way you will be able to avoid getting registered.&lt;br /&gt;&lt;br /&gt;Very rapidly, accessing basic services and your very status as a citizen will be conditional on your possessing an Aadhar number. This is owing to the complex operational structure that the UID Scheme adopts which leaves the task of enrollment entirely in the hands of third party ‘Registrars’ who include a host of Central and State social security and welfare departments (including the Ministry of Rural Development which administers the Rural employment guarantee scheme), banks and insurance companies. There is nothing in the Aadhar Scheme that forbids these Registrars from making access to their services conditional on one’s consent to UID registration. In practice, many of them have and will continue to make UID registration a preliminary formality before access is granted to their services. So your ‘freedom’ to resist UID registration will depend on your ability to forego your minimum guarantee of the right to employment, cooking gas, banking and insurance services, food rations etc.&lt;br /&gt;&lt;br /&gt;And if miraculously you are able to subsist without these services, there is still one minor detail that is seldom mentioned in conversations about UID: without a UID number, you will not be counted as a citizen of India. This is owing to the fact that the Registrar General of India, the authority responsible for compiling the National Population Register of India under the Citizenship Act, also happens to be a ‘Registrar’ for the purposes of the UID. Which means that one’s registration in the NPR will entail automatic enrollment in the UID. The Citizenship (Registration of Citizens and Issue of National Identity Cards) Rules, 2003 makes it mandatory for everyone to be enrolled in the National Population Register. So, paradoxically, although the Aadhar number does not confer citizenship, one cannot be a citizen anymore without owning an Aadhar number.&lt;/p&gt;
&lt;p&gt;In other words, the UID scheme avoids the charge of being compulsory, by outsourcing its compulsion entirely.&lt;/p&gt;
&lt;h3&gt;The UID Scheme will only collect a minimal set of information&lt;/h3&gt;
&lt;p&gt;A frequently made assertion about the UID scheme is that the data collected will be limited to a standard set of information like one’s name, residence, date of birth, photo, all 10 finger prints and iris image. Once again, this is only a half truth. As mentioned previously, the entire process of enrollment is carried out through Registrars who have absolute freedom to expand the categories of information collected to include data that is entirely orthogonal to the purposes of the UID. This freedom is typically guaranteed by a clause in the MOUs which the UIDAI has signed with Registrars enabling them to collect additional data that “is required for their business or service”. Thus, for instance, in Himachal Pradesh, citizens are asked to provide additional details such as information about their ration cards, PAN cards, LPG connection and bank accounts[i]&lt;br /&gt;&lt;br /&gt;To employ a telling epithet found in one of the UID documents, the ‘Registrars own the process of enrollment’.&lt;/p&gt;
&lt;h3&gt;Privacy is guaranteed&lt;/h3&gt;
&lt;p&gt;Although the UIDAI makes repeated assertions regarding its intent to respect privacy and ensure data protection, the precise mechanism through which these objectives will be secured is extremely unclear.&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;&amp;nbsp;To begin with, the entire responsibility for devising schemes for safeguarding information during the collection phase rests entirely on the Registrars. The UIDAI’s own responsibility for privacy begins only from the moment the information is transmitted to it by the Registrars – by which time the information has already passed through many hands including the Enrolling Agency, and the Intermediary who passes on information from the Registrar to the UIDAI.&lt;/li&gt;&lt;li&gt;Rather than setting out an explicit redressal mechanism and a liability regime for privacy violations, the UID’s documents stop at loosely describing the responsibility of the Registrars as a ‘fiduciary duty’ towards the resident/citizen’s information.&amp;nbsp; The Registrars are tasked with maintaining records of the data collected for a minimum period of six months. No maximum period is specified and Registrars are free to make what use of the data they see fit.&lt;/li&gt;&lt;li&gt;In addition, the Registrars are mandated to keep copies of all documents collected from the Resident either in physical or scanned copies “till the UIDAI finalizes its document storage agency.”[ii]&lt;/li&gt;&lt;li&gt;The ‘Data Protection and Security Guidelines’ which the UIDAI requires all Registrars to observe merely contains pious injunctions calling on them to observe care at all stages of data collection and to develop appropriate internal policies. There is mention of the desirability of external audits and periodic reporting mechanisms, but the details of these schemes are left to the individual Registrar to draw up.&lt;/li&gt;&lt;li&gt;Although the Draft National Identification Authority of India Bill penalizes the intentional disclosure or dissemination of identity information collected in the course of enrollment or authentication, this does not guard against accidental leaks and does not mandate the service providers to positively employ heightened security procedures. Prosecution of offences under the Act can only proceed with the sanction of the UID Authority, which further burdens the task of criminal enforcement in these cases and would make it difficult for individuals to obtain redress quickly. The total absence of a provision for civil remedies against Registrars makes it unlikely that they will take the task of protecting privacy seriously.&lt;/li&gt;&lt;li&gt;In other words, the individual’s right to privacy is only as strong as the weakest link in the elaborate chain of information collection, processing and storage.&lt;/li&gt;&lt;/ol&gt;
&lt;h3&gt;The UIDAI will not disclose any information and will only authenticate information with Yes/No answers&lt;br /&gt;&lt;/h3&gt;
&lt;p&gt;This is another of the frequently misleading claims made by the UID Authority. Thus, for instance, in April, 2010, in response to a question in the course of an interview, Nandan Nilekani said “UID itself has very limited fields, it has only four or five fields — name, address, date of birth, sex and all that. But it also does not supply this data to anybody. .. the only authentication you can get from our system is a yes or no. So, you can’t query and say what’s this guys name or what’s his date of birth, you can’t get all that.”[iii]&lt;br /&gt;&lt;br /&gt;This statement is, however belied by many of the UIDAI’s own documents.&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;The draft NIA Bill, for instance, permits the Authority to issue regulations on the sharing of “the information of aadhaar number holders, with their written consent, with such agencies engaged in delivery of public benefits and public services as the Authority may by order direct”. In practice, prior “written consent” for sharing is obtained from the resident as a matter of course at the time of enrollment itself, and it is impossible to obtain an Aadhar number without consenting to sharing by the UID Authority.[iv] In practice, in India, a large number of forms will be filled in by assistants and the written consent box will be ticked as a matter of course without the resident understanding the full implications of her “consent”.&lt;/li&gt;&lt;li&gt;The draft NIA Bill permits the authority to “make any disclosure of information (including identity information) made in the interests of national security in pursuance of a direction to that effect issued by an officer not below the rank of Joint Secretary or equivalent in the Central Government after obtaining approval of the Minister in charge”. There is nothing in the Act that requires that this information be made available on an individual basis – in other words, it is possible for the data to be shared en-masse with any agency “in the interests of national security”.&lt;/li&gt;&lt;li&gt;There is nothing preventing “Registrars” who carry out the actual data collection functions from sharing this information with anyone they choose. Thus, for instance, the Aadhar information collected during the exercise of compiling the National Population Register will can be shared in whichever manner the Registrar General of India chooses – irrespective of what the UIDAI does with that information.&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;So, while ordinarily, the UIDAI would not authenticate information other than giving Yes/No responses, there are mechanisms already in place that presume that all this information will be made available, on demand, to whichever agency that happens to be interested.&lt;/p&gt;
&lt;p&gt;[i] 2011. UID project picks up pace. Indian Express. Available at: &lt;a class="external-link" href="http://www.indianexpress.com/story-print/735790"&gt;http://www.indianexpress.com/story-print/735790&lt;/a&gt; [Accessed January 22, 2011].&lt;br /&gt;[ii] UIDAI – Document Storage Guidelines for Registrars Ver. 1.2, August 2010.&lt;br /&gt;[iii] 2010. To issue first set of UIDs by Feb 2011: Nilekani – CNBC-TV18 -. Money Control. Available at: &lt;a class="external-link" href="http://www.moneycontrol.com/news/business/to-issue-first-setuids-by-feb-2011-nilekani_449820-4.html"&gt;http://www.moneycontrol.com/news/business/to-issue-first-setuids-by-feb-2011-nilekani_449820-4.html&lt;/a&gt; [Accessed January 22, 2011].&lt;br /&gt;[iv] For instance, a flowchart of the Resident Enrollment Process issued by the UID stipulates&amp;nbsp; “Record Resident’s consent for Information Sharing” as the tenth step in the enrollment process. Unless this step is followed, the enrollment process cannot proceed!&lt;/p&gt;
&lt;p&gt;&lt;a class="external-link" href="http://privacy-india.org/2011/01/22/4-popular-myths-about-the-uid/"&gt;Click&lt;/a&gt; to read the original here&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/popular-myths-about-uid'&gt;https://cis-india.org/internet-governance/popular-myths-about-uid&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Prashant Iyengar</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2012-06-20T04:37:08Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1">
    <title>(Updated) Information Security Practices of Aadhaar (or lack thereof): A documentation of public availability of Aadhaar Numbers with sensitive personal financial information</title>
    <link>https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1</link>
    <description>
        &lt;b&gt;Since its inception in 2009, the Aadhaar project has been shrouded in controversy due to various questions raised about privacy, technological issues, welfare exclusion, and security concerns. In this study, we document numerous instances of publicly available Aadhaar Numbers along with other personally identifiable information (PII) of individuals on government websites. This report highlights four government projects run by various government departments that have made sensitive personal financial information and Aadhaar numbers public on the project websites.
&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;Read the updated report: &lt;a class="external-link" href="https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof/" target="_blank"&gt;Download&lt;/a&gt; (pdf)&lt;/h4&gt;
&lt;h4&gt;Read the first statement of clarification (May 16, 2017): &lt;a class="external-link" href="https://cis-india.org/internet-governance/clarification-on-information-security-practices-of-the-aadhaar-report/" target="_blank"&gt;Download&lt;/a&gt; (pdf)&lt;/h4&gt;
&lt;h4&gt;Read the second statement of clarification (November 05, 2018): &lt;a class="external-link" href="https://cis-india.org/internet-governance/blog/clarification-on-the-information-security-practices-of-aadhaar-report" target="_blank"&gt;Link to page&lt;/a&gt; (html)&lt;/h4&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;We are grateful to Yesha Paul and VG Shreeram for research support.&lt;/em&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;In the last month, there have been various reports pointing out instances of the public disclosure of Aadhaar number through various databases, accessible easily on Twitter under the hashtag #AadhaarLeaks. Most of these public disclosures reported contain personally identifiable information of beneficiaries or subjects of the non UIDAI databases containing Aadhaar numbers of individuals along with other personal identifiers. All of these public disclosures are symptomatic of a significant and potentially irreversible privacy harm, however we wanted to point out another large fallout of such events, those that create a ripe opportunity for financial fraud. For this purpose, we identified benefits disbursement schemes which would require its databases to store financial information about its subjects. During our research, we encountered numerous instances of publicly available Aadhaar Numbers along with other PII of individuals on government websites. In this paper, we highlight four government projects run by various government departments with publicly available financial data and Aadhaar numbers. Our research is focussed largely on the data published by or pertaining to where Aadhaar data is linked with banking information. We chose major government programmes using Aadhaar for payments and banking transactions. We found sensitive and personal data and information very easily accessible on these portals.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1'&gt;https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Amber Sinha and Srinivas Kodali</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Digital ID</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>NDSAP</dc:subject>
    
    
        <dc:subject>Data Protection</dc:subject>
    
    
        <dc:subject>Accountability</dc:subject>
    
    
        <dc:subject>Featured</dc:subject>
    
    
        <dc:subject>Data Governance</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Digitisation</dc:subject>
    
    
        <dc:subject>Homepage</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Data Management</dc:subject>
    

   <dc:date>2019-03-13T00:29:01Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/crea-reconference">
    <title>(re) conference</title>
    <link>https://cis-india.org/internet-governance/news/crea-reconference</link>
    <description>
        &lt;b&gt;From 10 to 12 April 2019, Aayush Rathi participated in a "reconference" a global conference designed to provoke conversations around the new possibilities and opportunities for feminist movements.  It was held in Kathmandu, and was organised by CREA, a feminist human rights organisation based in New Delhi.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;At the (re)conference, Aayush Rathi spoke on a panel as a part of the  technology track curated by Point of View. The research Ambika Tandon  and Aayush have undertaken on reproductive health and its datafication in  India, as a part of the BD4D project, was selected to be presented on  the panel. The presentation can be &lt;a class="external-link" href="http://cis-india.org/internet-governance/files/framing-reproductive-health-as-a-data-problem"&gt;found here&lt;/a&gt;. The agenda and theme of the (re) conference can be &lt;a class="external-link" href="https://reconference.creaworld.org/program/"&gt;found here&lt;/a&gt;.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/crea-reconference'&gt;https://cis-india.org/internet-governance/news/crea-reconference&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2019-05-02T02:01:48Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/privacy/privacy-matters-report-from-ahmedabad">
    <title>'Privacy Matters', Ahmedabad: Conference Report </title>
    <link>https://cis-india.org/internet-governance/blog/privacy/privacy-matters-report-from-ahmedabad</link>
    <description>
        &lt;b&gt;On 26 March 2011, civil society, lawyers, judges, students and NGO’s, gathered together at the Ahmedabad Management Association to take part in 'Privacy Matters' –  a public conference organised by Privacy India in partnership with IDRC and Research Foundation for Governance in India (RFGI) — to discuss the challenges of  privacy in India, with an emphasis on national security and privacy. The conference was opened by Prashant Iyengar, head researcher at Privacy India and Kanan Drhu, director of RFGI. Mr. Iyengar explained Privacy India’s mandate to raise awareness of privacy, spark civil action, and promote democratic dialogue around privacy challenges and violations in India. RFGI is a think tank established in 2009 which aims to research, promote, and implement various reforms to improve the legal and political process in Gujarat and across India. ‘Privacy Matters – Ahmedabad’ is the third conference out of the eight that Privacy India will be hosting across India. The next conference will take place in Hyderabad on 9 April 2011. It will focus on human rights and privacy.&lt;/b&gt;
        
&lt;h2&gt;The keynote speech, delivered by Usha Ramanathan, focused on links not often made between privacy and social phenomenon.&lt;br /&gt;&lt;/h2&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p align="left"&gt;&lt;img class="image-left" src="../it-act/usha.jpg/image_preview" alt="Usha Ramanathan " /&gt;Ms. Usha Ramanathan opened the conference by examining the links not often made between privacy and personal security, between databases and national security, and the centrality of dislodging privacy in projects of social control. In her presentation she spoke about the inverse relationship between national and personal security, making the point that an important part of privacy is the ability of an individual to secure their own person. Today, because national security follows a policy of ubiquitous surveillance, it is almost impossible for an individual to secure their person from the state. Ms. Ramanathan also traced the beginnings of ubiquitous surveillance to the increasing global fear of terrorism, and the national break down of the criminal justice system in India. Instead of looking to the roots of terrorism and the roots of failure in the criminal justice system, the Indian State has responded to both these factors by superimposing a system of surveillance on top of the existing rule. Consequently, the state has become pan-optical — closely following the movement of its entire population. The state has been able to achieve this level of surveillance through technology, which it has used to create identifiers for its population. The use of technology by the state mediates a link between corporate interest and state interest. Thus, by facilitating the easy and ubiquitous creation of identifiers and surveillance, technology is changing the idea and the nature of privacy. For example, it is now important that a privacy law allows for individuals to protect and secure their identity, something that every individual has and every individual controls, while regulating the creation and external use of identifiers — something that is used by another (not you) to distinguish a person from the rest of the population.&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;Questions to Consider&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;How can privacy legislation work to positively regulate the use of technology by the government, so that invasion of privacy does not consequently become state policy?&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;How can privacy legislation distinguish between and work to protect an identity while regulating the creation and use of personal information as identifiers?&lt;/li&gt;&lt;/ul&gt;
&lt;h2&gt;Session I of the Conference featured a Judicial Perspective of Privacy and a Presentation on the Connections between Privacy and the Federal Income Tax Regime in India.&lt;/h2&gt;
&lt;h3&gt;Privacy and the Constitution&lt;/h3&gt;
&lt;img class="image-right" src="../it-act/judge.jpg/image_preview" alt="Justice Bhatt" /&gt;
&lt;p&gt;&lt;strong&gt;&amp;nbsp;J N Bhatt&lt;/strong&gt;, the former Chief Justice of Gujarat and Bihar, and currently the head of the Gujarat State Law Commission, spoke about privacy as a fundamental right that has been written into articles 19 and 21 of the Constitution of India. Important points from his presentation include:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;&amp;nbsp;As privacy is already a recognized fundamental right, the question at hand is not if there is a right to privacy, but instead how can the right to privacy be best proliferated.&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;Within the question of how a privacy can best be proliferated, is a question about rights and duties. Wherever there is a right to privacy there is also a corresponding duty to privacy — as rights and duties are interdependent.&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;Though privacy has been recognized as a fundamental right in India, when looking at the actual assertion of the right, it is important to be aware of the cultural realities of India. India is a country with 39 per cent of her population living below the poverty line, with an even lower literacy rate, and there is a direct connection between the assertion of civil liberties, an individual’s civic sense, and education.&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;When looking at how to best proliferate the right to privacy, governance and common law, a methodology to reach the poorest of the poor should be laid out first.&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;Questions to Consider&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;What is the best way to proliferate the right to privacy ?&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;What legal structures need to be in place to ensure that the poor can assert their right to privacy?&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p&gt;What social structures need to be in place to ensure that the poor can assert their right to privacy?&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;&lt;img class="image-left" src="../it-act/profdrhu.jpg/image_preview" alt="Prof. Drhu" /&gt;&amp;nbsp;Privacy and the Indian Tax Regime&lt;br /&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Professor Amal Dhru&lt;/strong&gt;, visiting professor from the Indian Institute of Management, Ahmedabad and a practicing Chartered Accountant spoke on the connections between privacy and the federal income tax regime in India. In his presentation he explained how the information collected by the federal income tax regime in India can be both useful in holding a citizen accountable, and invasive of one’s personal privacy if mis-used. Important points from his presentation include:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;The Indian tax regime highlights the tension between public interest as tax evasion is considered an exception to the right to privacy as it is a matter of public interest.&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;&amp;nbsp;There is a lack of confidence in the existing banking and tax system in India. For example in the business sector, Indian investors have deposited over 700 billion dollars abroad as they are given complete privacy and security over their money. &lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;Though there is a lack of confidence in the current banking and tax system, a tighter law is not necessarily the solution. For example, studies have found that tighter tax regimes lead to greater evasion, while looser tax regimes have higher compliance rates.&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;On April 1, 2011 the new tax codes for India will be implemented. The reform will give enormous power to tax offices, and as the tax authorities will become equipped to do taxes smarter – this will come at a cost to citizen’s privacy. &lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;Questions to Consider&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;&amp;nbsp;Just as a tighter tax law leads to a higher percentage of tax evasion, will a tight privacy law simply lead to greater numbers of privacy violations?&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;What creates public confidence in a law?&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;Should a privacy legislation be responsible for defining the public good?&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;Should privacy protection of tax-related information be incorporated into a privacy legislation or contained only in tax law?&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;To what extent should tax authorities be allowed to investigate potential tax evasion i.e., one’s computer, house or e-mail? &lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;How does one balance the private vs. the public good? &lt;/li&gt;&lt;/ul&gt;
&lt;h2&gt;&amp;nbsp;Session II of the Conference focused on National Security and Privacy, and Cultural Conceptions of Privacy &lt;br /&gt;&lt;/h2&gt;
&lt;h3&gt;National Security and Privacy&lt;img class="image-right" src="../it-act/mathew.jpg/image_preview" alt="Mr. Thomas " /&gt;&lt;/h3&gt;
&lt;p style="text-align: left;"&gt;In the second session on Privacy and National Security, Colonel Mathew Thomas spoke on privacy and national security. Colonel Thomas is a management consultant and activity leader for development centers and has held top positions in the Indian Army, and the Defence Research and Development Organisation, where he headed the missile manufacturing facility. Sharing his personal experiences in the army he explained the connection between privacy and national security. Important points from his presentation include:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&amp;nbsp;National Security is often not an internal threat, but instead an external threat. &lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;There is a connection between the increase in surveillance and liberalization of Government. &lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;More surveillance does not bring more security. &lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;Foreign software poses as a threat to national security.&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;Greater security is gained through intelligent use and analysis of data. &lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;A strong national security plan should not rely solely on surveillance of its citizens. &amp;nbsp;Instead national security should be brought about through strong economic policies, non-reliance on foreign software, neutrality in foreign policy, fair trade policies, rural development and prevention of migration to cities, and having a politically honest and accountable governance.&lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;Questions to Consider&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;Is it effective for&amp;nbsp; privacy to be compromised in the name of anti- terror laws?&lt;/li&gt;&lt;li&gt;&amp;nbsp;Can the development and distribution of indigenous software protect national privacy?&lt;/li&gt;&lt;li&gt;&amp;nbsp;How can strong economic policies indirectly protect &amp;nbsp;an individual's privacy?&lt;/li&gt;&lt;li&gt;&amp;nbsp;How can a strong foreign policy protect an Indian citizen's privacy when it is stored or sent abroad?&lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;&amp;nbsp;&lt;img class="image-left" src="../it-act/gagan.jpg/image_preview" alt="Gagan Sethi" /&gt;Privacy as a Cultural Construct&lt;br /&gt;&lt;/h3&gt;
&lt;p&gt;Gagan Sethi from the Centre for Social Justice, Ahmedabad shared his opinion on privacy. Important points from his presentation include:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;Privacy is a cultural construct that changes with context, perspective, and time.&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p&gt;When considering a privacy policy it is important to create a policy that does not strictly define what privacy is and what it is not, but instead create a policy that defines and promotes a common respect for human dignity.&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;Questions to Consider&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;&amp;nbsp; If a privacy policy is developed to promote a common respect for human dignity – will it be effective?&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;Can you develop a policy that has a loose definition and mandate, but has strong legal teeth?&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;h2&gt;Session III of the Conference focused on Minority Identities and Privacy, Prisoner Rights, and Cyber Security.&lt;/h2&gt;
&lt;h3&gt;Privacy and Minority Identities&lt;img class="image-right" src="../it-act/copy_of_bobby.jpg/image_preview" alt="Bobby Kuhnu " /&gt;&lt;br /&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Bobby Kuhnu&lt;/strong&gt;, a lawyer and activist, presented in the third session on Privacy, Minority Identities, and Security. &amp;nbsp;In his talk Mr. Kuhnu through the use of three examples examined the ideological underpinnings of the discourse on privacy and its bearings on socially marginalized identities in the context of the Indian State and the constitutional right to privacy. Important points from his presentation include:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;In India, names can be sensitive and personal information like one’s religion, family, caste, and background can all be known through a&amp;nbsp; name.&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p&gt;Because of the sensitivity of a person’s name, many people do not feel safe or comfortable in their own identity.&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p&gt;Reservation lists and public postings of information, can and have been used to discriminate and violate another’s privacy.&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;Questions to Consider&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;Should a privacy legislation requirement throughout&amp;nbsp; institutions and government bodies that names should not be publicly displayed to the point of identification?&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p&gt;What is the most effective way of legally protecting an individual from discrimination based on their name?&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;Perspectives of Privacy&amp;nbsp; &lt;br /&gt;&lt;/h3&gt;
&lt;p&gt;&lt;img class="image-left" src="../it-act/interns.jpg/image_preview" alt="Interns " /&gt;In the last portion of the day, Yash Sampat and Aditya Yagnik spoke on the origins of privacy and privacy in the cyber world. Vimmi Surti spoke on prisoner's rights and privacy and Ramswaroop Chaudhary presented on minority identities in South Asia and privacy. Important points from their presentation include:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;&amp;nbsp;Internet has led to an increase in privacy violations.&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p&gt;The result of privacy infringements is often the deprivation of individuals from safe access to services availed to them.&lt;/p&gt;
&lt;/li&gt;&lt;li&gt;
&lt;p&gt;When looking at privacy as the protection of human dignity, prisoner’s rights are violated through overcrowding in prisons, poor health, and poor sanitation.&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;Questions to Consider&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;&amp;nbsp;Are there legal mechanisms that can be put in place to ensure the least amount of deprivation to services when an individual’s privacy is invaded?&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;
&lt;p&gt;&amp;nbsp;To what extent should prisoners be availed the right to privacy?&lt;/p&gt;
&lt;/li&gt;&lt;/ul&gt;
&lt;h2&gt;The concluding session was a time for discussion and&amp;nbsp; opinion sharing&lt;img class="image-right" src="../it-act/kananandjudge.jpg/image_preview" alt="Kanan and the Judge " /&gt;&lt;/h2&gt;
&lt;p&gt;From the closing session, and the above sessions many themes and questions pertaining to privacy came out that will need to be addressed when considering the way forward &amp;nbsp;for a privacy legislation including:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Regulation of ubiquitous surveillance in the name of national security&lt;/li&gt;&lt;li&gt;Regulation over public display of names and personal information&lt;/li&gt;&lt;li&gt;The need to distinguish between identity and identifier. &lt;/li&gt;&lt;li&gt;The need to protect an individual's identity while regulating the production and use of identifiers.&lt;/li&gt;&lt;li&gt;Privacy rights and prisoners: what does the right to privacy mean to a prisoner, i.e., clean facilities and health care. &lt;/li&gt;&lt;li&gt;Can the right to privacy be a platform for individuals to claim sanitary/safe working and living conditions. &lt;/li&gt;&lt;li&gt;Recognize the changing nature of&amp;nbsp; privacy rights in a technological society.&lt;/li&gt;&lt;li&gt;Privacy implications of biometric usage.&lt;/li&gt;&lt;li&gt;Creation of a definition of when privacy rights will supersede identification needs.&lt;/li&gt;&lt;li&gt;How can government institutions, like the tax department, incorporate and protect the right to privacy with the collection of large amounts of data for more efficient services. &lt;/li&gt;&lt;li&gt;Privacy and the family&lt;/li&gt;&lt;/ul&gt;
&lt;strong&gt;
&lt;div&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;/strong&gt;
&lt;div class="pullquote"&gt;&lt;strong&gt;
Download the report and agenda&amp;nbsp;&lt;a href="https://cis-india.org/internet-governance/blog/privacy-conference-ahmedabad.pdf" class="internal-link" title="Privacy Conference in Ahmedabad PDF"&gt;here&lt;/a&gt;&amp;nbsp;[pdf - 452kb]&lt;/strong&gt;&lt;/div&gt;
&lt;p class="callout"&gt;&lt;strong&gt;Also see Matthew's &lt;a href="https://cis-india.org/internet-governance/blog/privacy-ahmedabad-conference-presentation.pptx" class="internal-link" title="Privacy Conference in Ahmedabad Powerpoint Presentation"&gt;presentation&lt;/a&gt;&amp;nbsp;[powerpoint file 116kb]&lt;/strong&gt;&lt;/p&gt;
&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/privacy/privacy-matters-report-from-ahmedabad'&gt;https://cis-india.org/internet-governance/blog/privacy/privacy-matters-report-from-ahmedabad&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Featured</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2011-04-04T04:45:49Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/cio-july-1-2015-irctc-aadhaar-play-can-violate-sc-order-and-derail-national-security">
    <title>'IRCTC’s Aadhaar play can violate SC order and derail National Security'</title>
    <link>https://cis-india.org/internet-governance/news/cio-july-1-2015-irctc-aadhaar-play-can-violate-sc-order-and-derail-national-security</link>
    <description>
        &lt;b&gt;Your online railway bookings are going to become a wee bit more difficult if they aren’t already so. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The blog entry by Shubhra Rishi was &lt;a class="external-link" href="http://www.cio.in/feature/%27irctc%E2%80%99s-aadhaar-play-can-violate-sc-order-and-derail-national-security%27"&gt;published by CIO.IN&lt;/a&gt; on July 1, 2015. Sunil Abraham gave his inputs.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;That is, if the IRCTC makes Aadhaar card compulsory during the registration process for e-ticketing. The move, according to a recent announcement by IRCTC, will ensure that users registering on the IRCTC website are properly identified of their identity and address through the Aadhaar card number verification.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;So in case, you already have an Aadhaar card, then you need not worry. For those who don't have it yet or are reluctant to apply for it, are in for a tough time.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to Sandip Dutta, public relations officer at IRCTC, the plan, although still in the &lt;a href="http://aadhaarcarduid.org/railway-reservation-planning-to-be-done-using-aadhaar/"&gt;preliminary state&lt;/a&gt;, is to make Aadhaar compulsory which will prevent touts from further exploiting the e-ticketing platform.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;IRCTC which already has around three crore registered users, adds 15,000 new registrations every day. Just to give you the scale of an IRCTC website, a 15-minute &lt;a href="http://www.cio.in/feature/how-irctc%E2%80%99s-new-servers-make-bookings-and-enquiries-easier"&gt;tatkal window has about 1,000,000 people&lt;/a&gt; trying to log on to the IRCTC website. This means a new user won't be able to book a railway ticket on the IRCTC site until he owns an Aadhaar card.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Also Read: &lt;a href="http://www.cio.in/article/indian-cisos-don-t-trust-uid-their-data"&gt;Indian CISO don’t trust UID with their data&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"This is a complete overkill and will only result in harassment of an ordinary citizen," says Sunil Abraham, executive director at &lt;a href="http://cis-india.org/"&gt;The Centre for Internet &amp;amp; Society&lt;/a&gt;. "Aadhaar, he says, should be used to prevent politicians and bureaucrats from engaging in big-ticket fraud or whole-sale corruption. It should be used to make the state more accountable to citizens and not the other way around. It is unfortunate that techno-utopians are using biometric technology to fight retail corruption or small-ticket fraud.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;If IRCTC makes Aadhaar mandatory for user registrations, they will be in direct violation of the Supreme Court's &lt;a href="http://www.dnaindia.com/india/report-supreme-court-turns-down-centres-plea-to-modify-interim-order-on-aadhar-cards-they-are-not-compulsory-1900570"&gt;interim order of September 23, 2013&lt;/a&gt; where it has ordered that no person should suffer for not getting the Aadhaar card in spite of the authority making it mandatory, since government says it is voluntary.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On &lt;a href="http://indiatoday.intoday.in/education/story/supreme-court-nulls-the-mandatory-status-of-aadhaar-card-scheme-in-india/1/424229.html"&gt;March 24, 2014 again, the Supreme Court reiterated its earlier order of 2013&lt;/a&gt; and directed all government authorities and departments to modify their forms/circulars, etc., so as to not compulsorily require an Aadhaar number. In the same order the Supreme Court also restrained the UIDAI from transferring any biometric data to any agency without the consent of the person in writing as an interim measure.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to cyber law expert and Supreme Court Lawyer, Pavan Duggal, till the time Aadhaar has been brought to a legislative sanctity, no government agency must make it compulsory and if they do so, they will be in gross violation of the order and will be held for contempt of court. "&lt;a href="http://pib.nic.in/newsite/erelease.aspx?relid=100438"&gt;The National Identification Authority of India Bill&lt;/a&gt; that intends to give statutory backing to UIDAI (introduced in Rajya Sabha in 2010) is yet to be passed by the Parliament. Aadhaar is also non-compliant with the Information Technology Act 2000," says Duggal. Aadhaar, he says, is the unwanted child that hasn't proven legitimacy yet.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The illegitimacy, which continues to prevail due to several anomalies in the UIDAI’s Aadhaar allotment process. In March this year, about &lt;a href="http://www.hindustantimes.com/newdelhi/aadhaar-registrations-in-delhi-outstrip-population/article1-1328023.aspx"&gt;20 million people enrolled in Delhi for an Aadhaar identification numbe&lt;/a&gt;r, according to Census. However, the UIDAI generated about 17.7 million unique numbers in Delhi, about a million more than the city population.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In another incident, Aadhaar numbers were assigned to adult residents in 13 of the country's 36 states, and union territories surpassed their respective population as per 2011 census figures. However, the UIDAI blames that ‘gaps’ in census evaluation may have resulted in inaccuracy of the population data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There have also been bizarre instances in the past &lt;a href="http://timesofindia.indiatimes.com/india/Dogs-trees-and-chairs-have-Aadhaar-cards/articleshow/20359001.cms"&gt;where some Aadhaar cards displayed pictures of an empty chair&lt;/a&gt;, a tree, and a dog instead of the actual applicant.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;So how does it aid unscrupulous elements in misusing the flaws of the Aadhaar card system?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;To start with, Aadhaar captures biometrics of a user, which is neither permanent nor immovable, says Dr. Anupam Saraph, innovator, professor and an advisor in governance, informatics and strategic planning.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"&lt;a href="https://en.wikipedia.org/wiki/Biometrics"&gt;Biometrics&lt;/a&gt; change during the life of a person, sometimes even within a year, or without warning. Biometrics can be easily stolen, replicated or misused as has been demonstrated by instances of fingerprints and iris scans of high profile targets being hacked. The enrollment agencies that have captured the biometric have the entire demographic and biometric database in their possession and as such it can be misused or stolen. Once the biometric fails or is stolen, all the functions that have crept to link access to the biometric are denied with little or no recourse to the victim," says Saraph.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Another benign scenario may be large scale fake bookings to make tickets pricier, the malignant scenario will be entire trains used to transfer armies of anti-nationals and terrorists. Therefore, the Railway Minister must rise to cancel any such plans," says Saraph, and the Home Minister and Defence Minister must immediately scrap the linkage of Aadhaar to any database, require that the entire UID is destroyed as was done in the UK. “This kind of compromise requires the initiation of a time-bound judicial probe by a retired CAG and Supreme Court Judge supported by the CBI to investigate the exposure of the country to serious threats to national security due to UID,” he says.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;And therefore, the bigger question isn't whether Aadhaar should be made compulsory or not, but whether it is a foolproof method to validate someone's identity. If it isn’t, then why is IRCTC playing the Aadhaar card?&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/cio-july-1-2015-irctc-aadhaar-play-can-violate-sc-order-and-derail-national-security'&gt;https://cis-india.org/internet-governance/news/cio-july-1-2015-irctc-aadhaar-play-can-violate-sc-order-and-derail-national-security&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2015-07-07T15:10:08Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-telegraph-august-3-2014-i-am-going-to-ruin-you-dear">
    <title>'I'm going to ruin you, dear'</title>
    <link>https://cis-india.org/internet-governance/news/the-telegraph-august-3-2014-i-am-going-to-ruin-you-dear</link>
    <description>
        &lt;b&gt;Revenge porn is sweeping across the developed world. And now it's being seen in India. The culprit, says Prasun Chaudhuri, is often a former friend, partner, relative or colleague.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;This article by Prasun Chaudhuri with additional reporting by Varuna Verma in Bangalore was &lt;a class="external-link" href="http://www.telegraphindia.com/1140803/jsp/7days/18682133.jsp"&gt;published in the Telegraph&lt;/a&gt; on August 3, 2014. Rohini Lakshane gave her inputs.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;How would you feel if you casually opened a mail and found the link to a  pornographic site — and it turned out to contain pictures of yourself  naked? That's what Kalpana did. She clicked on a link sent to her and,  to her horror, found that the face of the girl who "was available for  sex" was hers. Her stomach lurched when she saw that the pictures showed  her own bedroom. The site also contained her personal and contact  details.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Kalpana was shattered. The subject line of the mail had said "I'm going  to ruin you, dear". It had seemed like a prank. Only, it wasn't. It was a  very real and malevolent attempt to destroy her reputation.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The 24-year-old Mumbai-based bank executive had become a victim of revenge porn — a new form of cybercrime in which ex-lovers or boyfriends upload intimate photos and videos of their former partners for the world to see. Mostly, the sexually explicit pictures are of women posted by jilted or spurned men.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Kalpana's photos, it was later found, were posted by her recently divorced husband, Pranay. They were taken when the two lived together.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Revenge porn is a trend sweeping across the developed world — from the US and Japan to countries in Europe. And now it's being seen in India, fuelled by the growing access to the Internet and camera-wielding mobile phones — all that is needed for taking and posting offensive pictures.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"Now that you have gadgets you tend to capture every moment of your life in pictures or videos," Calcutta-based psychiatrist J.R. Ram points out. "Not only that, you want to share these images through networking apps in your mobile phone or the Internet — without ever thinking of the consequences."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;National Crimes Record Bureau (NCRB) figures — released on July 1, 2014 — show a 63.7 per cent rise in cyber offences from 2012 to 2013. During this period, the category "transmission of obscene content in electronic form" reflects a quantum jump —104.2 per cent — with 1,203 cases registered and 737 people arrested. "The data show cyber offences against women have increased sharply," NCRB director-general R.R. Verma says. "But we do not have any specific data on revenge crimes."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;More and more such cases, however, are now coming to light. Kalpana lodged a complaint with the Navgarh police station in Mumbai. Ashish was arrested under a number of sections of the Indian Penal Code and the Information Technology Act.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Sneha, a 22-year-old college student from Udupi in Karnataka, also went to the police with the complaint that her ex-boyfriend had put up her photographs and videos on the Internet. M.B. Boralingaiah, superintendent of police, Manipal district, says the boy was arrested and sent to judicial custody.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"There has been an exponential rise in the number of cases of cyber revenge being reported to the police," Boralingaiah says. "This could also be because of increasing awareness of cyber laws, which prompts more people to approach the police." The Karnataka police are now setting up cyber crime police stations at regional levels across the state. Currently, only one police station, in Bangalore, deals with such crimes.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The profile of the criminal in revenge porn, Boralingaiah adds, is different from that of the average criminal plotting a scam using the Internet. In all the cases that have been reported, the accused is a former friend, partner, relative or colleague with no criminal history. They are also educated, intelligent and technologically savvy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;And that is why, despite suspicions, it is not always easy to catch the offender. The police say they have to first track down the origin of the pornographic site where the pictures are posted. "When we receive a complaint we try to locate the IP address (the unique identifier for the computer)," says Siddhartha Chakraborty, in charge of Cyber Police Station, Lalbazar, Calcutta. "But these crooks are clever enough to use some fake IP address of a distant country."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Once the police zero in on the IP address, it asks the web hosts to remove the offensive images, which they normally do. "But the procedure can take weeks or even months," Chakraborty adds.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Debarati Halder, a lawyer and cyber victim counsellor based at Tirunelvelli, Tamil Nadu, says she comes across 10-15 cases of revenge porn every month across the country, mostly involving college students. Often, the victims themselves take pictures while taking a shower or in their inner wear and share them with their boyfriends.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Many young women, Halder says, see such acts as symbols of independence or defiance.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"Taking 'sexy' images of themselves offers them a false sense of liberty, bypassing the repression imposed upon them in the real world," she says. "They feel relatively uninhibited in cyberspace and tend to experiment with their looks and sexuality, but are unable to determine where to draw the line."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The young are not greatly concerned with privacy and security on the Internet, Canada-based Internet safety expert &lt;a href="http://www.terrycutler.com" target="_blank"&gt;Terry Cutler&lt;/a&gt; stresses. "They don't understand that once you send out an inappropriate photo or video, you no longer control it."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There are, according to some estimates, at least 3,000 voyeuristic websites where such pictures can be posted. The visuals are often copied and replicated across multiple porn sites, making it virtually impossible for the authorities to wipe off the digital prints. "Often these clips are available on mirror sites, web archives and caches. Video footage can also go viral on social networks and porn buffs even share these images offline," Chakraborty warns.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But people seldom think that the intimate pictures that they shoot with their lovers may one day become public. "When you're in love you trust your partner. You don't expect him to use these pictures to humiliate you when things fall apart," says Antara, a 32-year-old IT analyst in a government agency who has been a victim of revenge porn. She says that her husband, to seek a quick divorce, uploaded intimate pictures on porn sites to show that she was a woman of "bad character".&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Also worrying is that a large number of women are victims of non-consensual and amateur pornography. Abir Atarthy, a Calcutta-based cyber-security expert, recently solved a case in which a college student found her pictures, shot in her bedroom, circulating on a social networking site.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"She was shocked because she not taken those pictures, nor had anybody else," Atarthy says. A thorough check revealed that a boy whose advances she had spurned had installed a hidden spy program in her laptop. "The program — capable of switching on the webcam even if the machine was offline — had been taking her snaps from her private life and sending the visuals to the youth whenever she connected to the Internet," he says.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Rohini Lakshané, a researcher at the Bangalore-based Centre for Internet and Society, describes such non-consensual acts as sexually violent crimes. "I don't like to use the term 'revenge porn', for it's an act of violence against women," she says. "Sometimes women are even raped and coerced into sex, filmed, threatened and blackmailed over the release of the footage online," Lakshané says.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The intention is to humiliate the woman and make her life miserable is the equivalent of throwing acid on her face, holds Dr Subhrangshu Aditya, a student counsellor at Jadavpur University, Calcutta. "These men can't accept rejection and it's their way to settle scores."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The victim, the experts say, doesn't just feel betrayed but often falls into depression — not just because of the ex-partner's action but because she sees herself as a partner in the crime, for the pictures uploaded may have been shot with her consent. "Their guardians also blame her for this and avoid reporting the matter to the police apprehending a bigger scandal," Halder adds.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The lawyer urges victims of such crimes to always approach the police. "Indian women have a strong legal recourse against perpetrators of revenge porn," she says. The amended 354 [C] of the Criminal Law (Amended) Act 2013, also known as the "voyeurism section", criminalises capturing and sharing images of a woman in private space. Section 66(E) of the IT Act criminalises the publication and transmission of images of an individual's private parts without his or her consent.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"These are watertight laws, strong enough to book an offender," she says, adding that the law also protects a victim's identity.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Across the world, laws are now being framed to punish cyber porn offenders. In January, Israel voted to define posting of images without consent as sexual harassment, punishable by up to five years in jail. Many states in the US already have laws against revenge porn and Britain may bring in one soon.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But perhaps the best way to prevent such crimes is by safeguarding privacy — at home and in the virtual world (see box). Cyber security expert Cutler sums it up aptly: "Just think this before you click the send button: If I were to post the visual on the Internet, would I care if it landed on the front page of a newspaper or the 8pm news?"&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Some names have been changed to protect identities&lt;/i&gt;&lt;/p&gt;
&lt;h2 style="text-align: justify; "&gt;How to Safeguard Your Privacy?&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Get acquainted with the privacy settings of the social networks, dating and matrimonial websites you use&lt;/li&gt;
&lt;li&gt;Do not upload any single close-shot picture on the Internet; this can be morphed and misused&lt;/li&gt;
&lt;li&gt;Never film yourself during sexually intimate acts; even if you delete the pictures and videos these can be recovered from your device&lt;/li&gt;
&lt;li&gt;Watch out for weird webcam activity; malicious software can easily infect your computer or phone and control the webcam&lt;/li&gt;
&lt;li&gt;Remove your memory card from your mobile or format the hard disc of your computer before giving the device to service centres&lt;/li&gt;
&lt;li&gt;Don't give your device to others and always lock your applications (especially picture galleries) in your mobile&lt;/li&gt;
&lt;li&gt;Install and update antivirus and antimalware in your device&lt;/li&gt;
&lt;/ul&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-telegraph-august-3-2014-i-am-going-to-ruin-you-dear'&gt;https://cis-india.org/internet-governance/news/the-telegraph-august-3-2014-i-am-going-to-ruin-you-dear&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Access to Knowledge</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2014-09-09T09:55:47Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/saket-modi-calls-for-stronger-cyber-security-discussions">
    <title>'Ethical Hacker' Saket Modi Calls for Stronger Cyber Security Discussions</title>
    <link>https://cis-india.org/internet-governance/blog/saket-modi-calls-for-stronger-cyber-security-discussions</link>
    <description>
        &lt;b&gt;Twenty-two year old Saket Modi is the CEO and co-founder of Lucideus, a leading cyber security company in India which claims to have worked with 4 out of 5 top global e-commerce companies, 4 out of 10 top IT companies in the world, and 3 out of 5 top banks of the Asia Pacific. &lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC&lt;/i&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;At the Confederation of Indian Industry (CII) conference on July 13, titled “&lt;a href="https://cis-india.org/internet-governance/blog/cii-conference-on-act" class="external-link"&gt;ACT – Achieving Cyber-Security Together&lt;/a&gt;,” Modi as the youngest speaker on the agenda delivered an impromptu talk which lambasted the weaknesses of modern cyber security discussions, enlightened the audience on modern capabilities and challenges of leading cyber security groups, and ultimately received a standing ovation from the crowd. As a later speaker commented, Modi’s controversial opinions and practitioner insight had "set the auditorium ablaze for the remainder of the evening". Since then the Centre for Internet and Society (CIS) has had the pleasure of interviewing Saket Modi over Skype.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It is quite easy to find accounts of Saket Modi's introduction into hacking just by typing his name in the search engine. Faced with the pressure of failing, a teenage Saket discovered how to hack into his high school Chemistry teacher’s test and answer database. After successfully obtaining the answers, and revealing his wrong doings to his teacher, the young man grew intrigued by the possibilities of hacking. "I thought, if I could do this in a couple hours, four hours, then what might I be able to do in four days, four weeks, four months?"&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Nowadays, Modi describes himself and his Lucideus team as "ethical hackers", a term recently espoused by hacker groups in the public eye. As opposed to "hacktivists", who utilize hacking methods (including attacks) to achieve or bring awareness to political issues, ethical hackers claim to exclusively use their computer skills to support defenses. At first, incorporation of &lt;i&gt;ethics&lt;/i&gt; into a for-profit organization’s game plan may seem confusing, as it leaves room for key questions, like how does one determine which clients constitute ethical business? When asked, however, Modi clarifies by explaining how the ethics are not manifest in the entities Lucideus supports, but instead inherent in the choice of building defensive networks as opposed to using their skills for attack or debilitation. Nevertheless, considerations remain as to whether supporting the cyber security of some entities can lead to the insecurity of others, for example, strengthening the agencies which work in covert cyber espionage. On this point, Modi seems more ambivalent, saying "it depends on a case by case basis". But he still believes cyber security is a right that should be enjoyed by all, "entitled to [you] the moment you set foot on the internet".&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As an experienced professional in the field who often gives input on major cyber policy decisions, Modi emphasizes the necessity of youth engagement in cyber security practice and policy. He calls his age bracket the “web generation,” those who have “grown with technology.” According to Modi, no one over 50 or 60 years of age can properly meet the current challenges of the cyber security realm. It is "a sad thing" that those older leaders carry the most power in policy making, and that they often have problems with both understanding and acceptability of modern technological capabilities. For the public, businesses, and also government, there are misconceptions about the importance of cyber security and the extent of modern cyber threats, threats which Modi and his company claim to combat regularly. "About 90 per cent of the crimes that take place in cyber space are because of lack of knowledge, rather than the expertise of the hacker,” he explains. Modi mentions a few basic misconceptions, as simple as, "if I have an anti-virus, my system is secured" or "if you have HTTPS certificate and SSL connection, your system is secured". “These are like wearing an elbow guard while playing cricket,” Modi tells. “If the ball comes at the elbow then you are protected, but what about the rest of the body?”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This highlights another problem evident in India’s current cyber security scene, the problem of lacking “quality institutes to produce good cyber security experts.” For example, Modi takes offence at there not being “a single institute which is providing cyber security at the undergraduate level [in India].” He alludes to the recently unveiled National Cyber Security Policy, specifically the call for five lakh cyber security experts in upcoming years. He calls this “a big figure,” but agrees that there needs to be a lot more awareness throughout the nation. “You really have to change a lot of things,” he says, “in order to get the right things in the right place here in India.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When considering citizen privacy in relation to cyber security, and the relationship between the two (be it direct or inverse), Saket Modi says the important factor is the governing body, because the issue ultimately resolves to trust. Citizens must trust the “right people with the right qualifications” to store and protect their sensitive data, and to respect privacy. Modi is no novice to the importance of personal data protection, and his company works with a plethora of extremely sensitive information relating to both their clients and their clients’ clients data, so it operates with due care lest it create a “wikileaks part two.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On internationalization and cyber security, he views the connection between the two as natural, intrinsic. “Cyberspace has added a new dimension to humanity,” says Modi, and tells how former constructs of physical constraints and linear bounds no longer apply. International cooperation is especially pertinent, according to Modi, because the greatest challenge for catching today’s criminal hackers is their international anonymity, “the ability to jump from one country to the other in a matter of milliseconds.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;With the extent of the challenges facing cyber defense specialists, and with the somewhat disorderly current state of Indian cyber security, it is curious to see that Saket Modi has devoted himself to the "ethical" side of hacking. Why hasn’t he or the rest of the Lucideus team resorted to offensive hacking, since Modi claims the majority of cyber attacks of the world who are committed by people also fall between the ages of 15 and 24? Apparently, the answer is simple. “We believe in the need for ethical hacking,” he defends. “We believe in the purpose of making the internet safer.”&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/saket-modi-calls-for-stronger-cyber-security-discussions'&gt;https://cis-india.org/internet-governance/blog/saket-modi-calls-for-stronger-cyber-security-discussions&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>kovey</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-08-05T13:11:08Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/attempts-to-censor-the-web-ill-advised">
    <title>'Attempts to censor the web ill-advised'</title>
    <link>https://cis-india.org/news/attempts-to-censor-the-web-ill-advised</link>
    <description>
        &lt;b&gt;Amid concerted government attempts to censor the internet and the recent blocking of file-sharing websites due to a court order based on a petition by producers of a Tamil film, speakers at a discussion on Saturday felt that there was a fear of freedom of expression among those affected by it, primarily the powerful.&lt;/b&gt;
        
&lt;p&gt;&lt;a class="external-link" href="http://articles.timesofindia.indiatimes.com/2012-06-03/goa/32005718_1_internet-access-censorship-free-speech"&gt;Article by Krish Fernandes published in the Times of India on June 3, 2012&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;At the discussion on 'freedom of expression and privacy: Proposition' held at Goa University, senior journalist Paranjoy Guha Thakurta felt the increasing attempts at online censorship were a consequence of the government being unable to formulate coherent responses to the widening of the limits to freedom of expression on the internet.&lt;/p&gt;
&lt;p&gt;He was of the view that all stakeholders should be consulted before any legislation in this regard.&lt;/p&gt;
&lt;p&gt;Vickram Crishna of Privacy International spoke about "the fear of freedom of expression". While stating that the internet access had jumped due to the increased usage of smartphones, he observed that "there were concerted moves to make these things (censorship) happen in India".&lt;/p&gt;
&lt;p&gt;"What use is access, if we don't have freedom of expression?" Crishna questioned.&lt;/p&gt;
&lt;p&gt;Geeta Seshu of The Hoot was of the opinion that the world was also seeing the rise of powerful web players such as search engines and social networks with no obligations to permit free speech.&lt;/p&gt;
&lt;p&gt;Chinmayi Arun of the National University of Juridical Sciences echoed this view. She felt freedom of speech and expression were vulnerable because they receive very little protection from non-state factors. She felt surveillance may soon become as serious a threat to free speech as censorship.&lt;/p&gt;
&lt;p&gt;Advocate Apar Gupta felt there are better safeguards against banning books, while web content bans see almost no safeguards.&lt;/p&gt;
&lt;p&gt;Touching on the ban on file-sharing sites, Lawrence Liang of Alternative Law Forum felt private bodies such as ISPs were being given powers of the state.&lt;/p&gt;
&lt;p&gt;Anja Kovacs of Internet Democracy Project was critical of the government instructing internet service providing companies to setup servers in the country. The internet as we know it will stop to exist if we have server requirements in all countries, she said.&lt;/p&gt;
&lt;p&gt;Frederick Norohna of publishing house Goa 1556, Siddhart Narrain and Danish Sheikh of the Alternative Law Forum, Paromita Vohra of Devi Pictures and Werner Souza also spoke on the occasion.&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/attempts-to-censor-the-web-ill-advised'&gt;https://cis-india.org/news/attempts-to-censor-the-web-ill-advised&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2012-06-17T07:11:39Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>




</rdf:RDF>
