💥Join UPSC 2027,2028 Mentorship (July Batch) + XFactor Notes & Microthemes PDF

GS Paper: Cyber Security

  • Ensuring Internal Security by Securing Communication Networks

    Communication

    Context

    • In a bid to upgrade the Indian Telegraph Act 1885, a law that is more than a century old, the Department of Telecommunications, or DoT, issued the Draft Indian Telecommunications Bill 2022 on 21 September. Among other things, the proposed legislation brings digital communications applications like Signal and Telegram under telecommunications law and regulation and treats them like internet and telecom service providers and broadcasters.

    What are the Current regulations of communication networks?

    • Information Technology Act 2000: Digital communication applications are currently governed by the Ministry of Electronics and Information Technology (MeitY) and the Information Technology Act 2000 where there is no licensing requirement.
    • Telecom Regulatory Authority of India (TRAI): The move has been debated for some years now, with the Telecom Regulatory Authority of India (TRAI) issuing multiple consultations on the matter, most recently in 2018.
    • National Digital Communications Policy in 2018: DoT may have legitimate grounds for extending its jurisdiction over digital communications applications, including a policy mandate established by the National Digital Communications Policy in 2018. However, there is a conflict that must be resolved, namely the jurisdictional overlap between the prospective law and the existing information technology framework.

    Communication

    Why is security of communication networks important?

    • National security: Communication networks are a part of our critical information infrastructure which was defined in the IT Act, 2000 as “the computer resource, the incapacitation or destruction of which, shall have debilitating impact on national security, economy, public health or safety.”
    • Protecting critical Infrastructure: Communications networks are crucial to the connectivity of other critical infrastructure, viz. civil aviation, shipping, railways, power, nuclear, oil and gas, finance, banking, communication, information technology, law enforcement, intelligence agencies, space, defence, and government networks. Therefore, threats can be both through the networks as well as to the networks.
    • Ready to Information Warfare (IW): Because of the increasing relevance of information technology (IT) to people’s lives, individuals who take part in IW are not all soldiers and that anybody who understands computers may become a fighter.
    • To stop the adverse impact on information system: IW is inexpensive as the targeted party can be delivered a paralysing blow through the net and it may be difficult for the latter to discern where the attack originated. Large amount of useless information can be created to block or stop the functioning of an adversary’s information system.
    • For Possible mass mobilisation: Thus, a People’s War in context of IW can be carried out by hundreds of millions of people, using open-type modern information systems. Even political mobilisation for war can be achieved via the internet, by sending patriotic e-mail messages and by setting up databases for education.

    Communication

    Why new law is necessary?

    • No obligation on communication applications: A key reason for the DoT to bring such applications under telecommunications law is national security. Licensed telecom service providers must provide law enforcement authorities access to their networks and intercept messages in the course of investigations.Conversely, there is a contention that there is no corresponding obligation on digital communications applications, potentially leaving a gap in safeguarding national security interests.
    • For increased Encryption and secrecy: A further assertion is that the encryption used by most digital communications apps hampers investigative efforts as it becomes difficult to ascertain user identity on these platforms and stop malfeasance.
    • Necessary to Ensure security: The draft telecom bill attempts to address this gap by including a provision which enables the government to undertake measures in the name of national security, including issuing directions regarding the use of any telecommunication service.
    • Licensing for more transparency: Presumably, licences issued for digital communications applications under the proposed legislation will prescribe conditions that would require these apps to give law enforcement authorities access to their systems for monitoring and intercepting communications.

    Communication

    What is the criticism over the new bill?

    • Existing law is sufficient: the IT Act already has provisions to enable lawful interception and monitoring of messages sent through digital communications applications. Under Section 69 of the IT Act, the central or state government may issue directions to do so in the interest of preserving, among other things, national security and public order. Moreover, rule 4 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) 2021 requires digital communications applications with 50 lakh users or more to enable identification of those sending messages on their platforms.
    • Possible mass surveillance by Government: The implication here is that digital communications apps would have to break encryption and create meaningful pathways for the surveillance of their services. Importantly, while rule 4 has been challenged, it has not been stayed by any court, meaning digital communications apps must comply with it.
    • New laws will overlap with IT Act: It would appear, then, that the provisions regarding national security in the draft telecom bill and the IT Act overlap. So how would the situation be resolved, as both have clauses that give them the ability to override provisions in other laws? Specifically, both the Draft Telecom Bill, 2022 and the IT Act have a non-obstante clause, a provision that enables a statute to uphold the enforceability of its provisions over others that contradict it. Thus, in case of a contradiction between these two laws, which would prevail?
    • Introducing Digital India Act will likely to override other laws: Reports indicate that MeitY aims to introduce a newer version of the IT Act, namely the ‘Digital India Act’. This law will likely deal with matters related to lawful interception and other matters related to the governance of digital communications applications. If such a law is passed, the ‘Digital India Act’ would override the enacted version of the telecom bill.
    • Judicial challenge of acknowledgment: A situation emerges where the telecom bill, if enacted, may face a judicial challenge. Based on the analysis of the court’s treatment of special laws, this proposed legislation is unlikely to prevail as the ‘Digital India Act’ will emerge after it

    Conclusion

    • National security and privacy of citizens an equally important. One cannot be traded for other. Arbitrary power of surveillance must be regulated by independent body under the parliament which will seek the transparency and accountability from law enforcement authorities.

    Mains Question

    Q.Unchecked communication networks are grave internal security threat. Comment why new law is necessary for interception and regulation of communication networks in India?

    UPSC 2023 countdown has begun! Get your personal guidance plan now! (Click here)

  • Regulating online speech

    Online Speech

    Context

    • The Ministry of Electronics and Information Technology (Meity) has mooted two proposals for governance of online speech government appointed grievance appellate committees (GAC) and the industry self-regulatory body (SRB) seek to preclude this contest in favour of a unilateral government and industry agenda.

    What is an online speech?

    • A recorded online speech is delivered, recorded, and then uploaded to the Internet for later viewing. Examples are TED Talks and presentations in online or blended speech classes.
    • Such speech are recorded or sometimes made in real time using various social media platforms.

    Online Speech

    How unregulated online speech is becoming dangerous day by day?

    • Gendered disinformation and harassment campaigns: Impacting the mental health, job performance, and if and how they engage with online spaces.
    • GLAAD’s 2021 Social Media Safety Index says: 64% of LGBTQ social media users reported experiencing harassment and hate speech, including on social media platforms such as Facebook, Twitter, YouTube, Instagram, and TikTok.
    • Contributing to communal violence: In countries like India and Sri Lanka, failure to remove and prevent the amplification of harmful content can contribute to profound offline consequences, including violence and death.

    What are the proposals for the regulation of online speech?

    • Setting up Grievance appellate committees (GAC): The GACs, as per the draft issued by the Ministry of Electronics and Information Technology (Meity), will be constituted by the central government and will serve as an appellate body against decisions of various social media platforms.
    • Appointing Self-regulatory body by social Media platforms(SRB)?: As the name suggests, industries such as twitter, meta etc will appoint their own personnel and constitute the self-regulatory body to hear the grievances against the social media posts.

    Online Speech

    What are the Criticism over GAC and SRB?

    • Lack of substantive framework: Not only has the government not laid down a substantive policy with objectively defined contours of forbidden speech, the government wants the right to apply this highly subjective criteria on individual pieces of content and/or users.
    • Unreasonable removal of content: It is notable that the government has already arrogated this right and routinely issues take down orders (without providing rationale) to social media platforms to take down or block content with minimal pushback from platforms.
    • Serving the Governments agenda: However, the national security, public order logic of takedowns does not apply to reinstatement of content/users proactively blocked by the platforms and it is likely that an additional purpose of the GACs is to provide an institutional avenue for the ruling government machinery to get a set of aligned accounts/content reinstated instead of just takedowns.
    • Such regulations are said to be Non-democratic: It is evident that the GAC doesn’t meet even minimal standards of democratic legitimacy and should be scrapped. The industry SRB proposal too lack democratic legitimacy.
    • Profit before public interest: Platforms have repeatedly shown themselves to be driven by profit motives, which are often at odds with public interest. It is thus likely that such a platform-led body will try and maximise the interests of the industry and individual platforms as opposed to the interests of the Indian people.
    • It will increase Government’s unrestrained powers: Notwithstanding Twitter’s plea in Karnataka High Court against Centre’s “disproportionate use of power” to issue “overbroad and arbitrary” content-blocking orders, the track record of platforms in India of resisting government pressure has been very poor.
    • For example recent Twitter episode: For instance, a former safety head with Twitter reportedly told US regulators that Twitter put a government agent on its payroll under duress.
    • High Chances of Government’s pressure: The SRB may act as a rubber stamp providing false legitimacy for covert government pressure while the binding nature of SRB orders will make it easier for the government to exercise pressure on a single lever to ensure compliance across all platforms.
    • Lack of consensus in SRB: The other real possibility is that such a body will be a non-starter, wracked by internal dissensions or non-compliance and thus pave the way for the government GAC. This possibility is indicated by the divergent views of the constituent platforms.

    Online Speech

    What are the Suggestions?

    • Relooking the proposals: It is evident that neither of the two proposals meet the minimum standards of democratic legitimacy and need to be rethought.
    • Follow the democratic way: Given the centrality of free speech in a democracy, no government or private body can have unmitigated right to make decisions regarding the contours of acceptable speech. The argument that an elected government has earned the executive right to determine standards of speech like other policy decisions is fallacious because speech is the only democratic way to contest the government itself.
    • Least government interference: The governance of speech, including setting standards and implementation, must thus sit squarely outside the ambit of government.
    • Independent body answerable to parliament: This can be achieved through a statutory regulator answerable to Parliament.
    • Standard operating procedure to remove content: In the meantime, there has to be transparency in the manner content moderation decisions are taken, including the takedown orders issued by the government.

    Conclusion

    • The current proposals are preoccupied with policing individual pieces of content whereas the impact of social media platforms on our information ecosystems is fundamental. Social media platforms now play an increasingly interventionist role in amplifying certain voices and our public debate must move forward to review structural issues affecting information ecosystems.

    Mains Question

    Q.What are the perils of unrestrained online speech? Critically analyse the recent proposals by government to regulate the free speech.

    UPSC 2023 countdown has begun! Get your personal guidance plan now! (Click here)

  • Is Draft Telecommunications Bill, 2022 Flawless?

    Draft Telecommunications Bill, 2022Context

    • Keeping an eye on the telecommunication regulatory framework Supreme Court issued substantive legal reform on surveillance laws in India. Union government has published the Draft Telecommunications Bill, 2022 to replace the Telegraph Act, 1885.

    Background

    • Over two decades ago, allegations of surveillance against politicians led to a CBI inquiry and report against V P Singh’s government. The allegations revealed that imaginary reasons were given for ordering phone tapping without authorization.
    • Last years, many publications reported that phones of several dozen Indian journalists, lawyers and human rights activists had been compromised using an invasive Israeli-developed malware called Pegasus.

    Draft Telecommunications Bill, 2022What is Draft Telecommunications Bill, 2022?

    • The draft Indian Telecommunication Bill, 2022 is an attempt by the Department of Telecommunications (DoT) to consolidate various legislations presently governing the telecommunication landscape in India.
    • The Bill seeks to replace three laws, the Indian Telegraph Act, 1885, the Indian Wireless Telegraphy Act, 1933 and the Telegraph Wires (Unlawful Possession) Act, 1950.
    • The new regulatory framework is to bring the law at par with technological advancements and remove obsolete provisions from the colonial era laws.

    What are the current laws governing communication surveillance in India?

    Communication surveillance in India takes place primarily under two laws:

    • Telegraph Act, 1885: It deals with interception of calls.
    • Call interception:Under Section 5(2) of this law, the government can intercept calls only in certain situations.
    • For sovereignty:They include the interests of the sovereignty and integrity of India, the security of the state, friendly relations with foreign states or public order, or for preventing incitement to the commission of an offense.
    • Free speech restrictions:These are the same restrictions imposed on free speech under Article 19(2) of the Constitution.
    • Exceptions for journalists:A provision in Section 5(2) states that even this lawful interception cannot take place against journalists.
    • Information Technology Act, 2000: It was enacted to deal with surveillance of all electronic communication, following the Supreme Court’s intervention in 1996.
    • Electronic surveillance:Section 69 of the IT Act and the IT (Procedure for Safeguards for Interception, Monitoring, and Decryption of Information) Rules, 2009 were enacted to further the legal framework for electronic surveillance.
    • Data interception:Under the IT Act, all electronic transmission of data can be intercepted.
    • Section 69 of the IT Act adds another aspect that makes it broader — interception, monitoring, and decryption of digital information “for the investigation of an offense”.

    Draft Telecommunications Bill, 2022How the loopholes in the current system breaching the Data Privacy?

    • No comprehensive data Protection Law:
    • No comprehensive data protection law leaving ambiguities over several laws.
    • A comprehensive data protection law to address the gaps in existing frameworks for surveillance is yet to enact.
    • Unaccountable, opaque exercise of surveillance:
    • The Telegraph Act contains broad and excessive powers of interception and surveillance of communications carried out through any telegraph.
    • The surveillance power is principally contained under Section 5(2), and has resulted in an unaccountable, opaque and unconstitutional exercise of surveillance that has led to accusations across the political spectrum.
    • Less transparency:
    • Ministry of Home Affairs refuses to disclose even aggregate data on the number of surveillance orders issued by it each year illegally gathered evidence is being sought to prosecute people.
    • For instance, the Bombay High Court about three years ago noted in a case that premier investigating agencies such as the CBI have used, interception orders (that) neither have sanction of law nor issued for legitimate aim.

    Draft Telecommunications Bill, 2022Key features of the Draft Telecommunications Bill, 2022

    • Broad Definitions:
    • The Bill introduces a broad definition of ‘telecommunication services’.
    • It now includes internet-based services, in-flight and maritime connectivity, interpersonal communications services, machine to machine communication services, and over-the-top (OTT) based communication services that are made available to users by telecommunication
    • KYC and caller id requirements:
    • The Bill requires licensed entities to ensure that they identify the persons to whom they provide telecommunication services.
    • The Bill places an obligation on telecommunication service providers to do this through a ‘verifiable mode’, as prescribed by the government.
    • Licensing, registration, and authorization:
    • Under the Bill, four types of permissions are identified – license, registration, authorization and assignment.
    • While the Bill does not differentiate between the four types of permissions, it clarifies that a license is only required for providing telecommunication services or operating telecommunication networks
    • Wide ranging powers of Central Government:
    • The Bill includes wide-ranging powers for the central and state governments in the event of a public emergency or in interest of public safety.
    • These powers include taking temporary possession of any telecommunication services, suspension of transmission in cases of public emergency, interception/detainment/disclosure of messages, suspension of communications, or otherwise transmit certain announcements for public safety and national security purposes.
    • User protection and duties: User has been declared as an important policy objective of the Government. It places a duty on users to not furnish false information, suppress material information or impersonate others when proving identity to avail telecommunication services.
    • Offences and penalties: Any offence under the Bill may be punished with a fine, imprisonment, suspension of telecommunication services or a combination of the above. For companies, the employees who were responsible for the conduct or the business relating to the offence at the time the offence was committed will be punished.
    • Dispute resolution mechanism: The Bill provides for the right of appeal before the appellate authority. It also creates an enabling provision for the Central Government to set up an alternate dispute resolution mechanism such as arbitration, mediation or other processes of dispute resolution

    What are Concerns over the Draft Telecommunication bill, 2022?

    • Regulatory overlaps:The broad of the definition of ‘telecommunication services’ include OTT communication platforms such as WhatsApp, Telegram, Signal among others, may potentially lead to regulatory or jurisdictional overlaps.
    • Unchecked use of State powers:The Bill gives broad powers to the central government in prescribed situations without any accompanying checks and balances. The Bill empowers the central and state government to intercept messages in the interest of public safety and emergency without the providing clearly defined guardrails for it.
    • Undefined National security: The term, national security is left undefined and does not match constitutional precedent or text which instead uses the phrase,in the interests of the security of state
    • Users Less choice in the privacy and security of their digital footprint:
    • Power to prescribe standards under Clause 23, which may result in regulations as recently issued by the Computer Emergency Response Team (CERT-In) that have resulted in the closure of servers or services by leading, global VPN providers such as Proton and TunnelBear.
    • All of this practically means that users will have less choice in the privacy and security of their digital footprint, as these powers will lead to requirements to locally register and host data, and comply with requirements to identify users (KYC requirements).

    Conclusion

    • There should be some reasonable basis or some tangible evidence to initiate or seek approval for interception by State authorities. Any digression from the ethical and legal parameters set by law would be tantamount to a deliberate invasion of citizens.

    Mains Question

    Q. Any deviation from the moral and legal parameters set by the law would amount to a deliberate attack on citizens. In this context discuss the data privacy of citizens in the era of massive expansion of internet and mobile usage.

    UPSC 2023 countdown has begun! Get your personal guidance plan now! (Click here)

     

  • India’s new VPN Rules

    On April 28, Computer Emergency Response Team (CERT-In) passed a rule mandating VPN (virtual private network) providers to record and keep their customers’ logs for 180 days.

    What is VPN?

    • VPN describes the opportunity to establish a protected network connection when using public networks.
    • It encrypts internet traffic and disguise a user’s online identity.
    • This makes it more difficult for third parties to track your activities online and steal data.
    • The encryption takes place in real time.

    How does a VPN work?

    • A VPN hides your IP address by letting the network redirect it through a specially configured remote server run by a VPN host.
    • This means that if you surf online with a VPN, the VPN server becomes the source of your data.
    • This means your Internet Service Provider (ISP) and other third parties cannot see which websites you visit or what data you send and receive online.
    • A VPN works like a filter that turns all your data into “gibberish”. Even if someone were to get their hands on your data, it would be useless.

    Why do people use VPN?

    • Secure encryption: A VPN connection disguises your data traffic online and protects it from external access. Unencrypted data can be viewed by anyone who has network access and wants to see it. With a VPN, hackers and cyber criminals can’t decipher this data.
    • Disguising whereabouts: VPN servers essentially act as your proxies on the internet. Because the demographic location data comes from a server in another country, your actual location cannot be determined.
    • Data privacy is held: Most VPN services do not store logs of your activities. Some providers, on the other hand, record your behaviour, but do not pass this information on to third parties. This means that any potential record of your user behaviour remains permanently hidden.
    • Access to regional content: Regional web content is not always accessible from everywhere. Services and websites often contain content that can only be accessed from certain parts of the world.
    • Secure data transfer: If you work remotely, you may need to access important files on your company’s network. For security reasons, this kind of information requires a secure connection. To gain access to the network, a VPN connection is often required.

    What does the new CERT-IN directive say?

    • VPN providers will need to store validated customer names, their physical addresses, email ids, phone numbers, and the reason they are using the service, along with the dates they use it and their “ownership pattern”.
    • In addition, Cert is also asking VPN providers to keep a record of the IP and email addresses that the customer uses to register the service, along with the timestamp of registration.
    • Most importantly, however, VPN providers will have to store all IP addresses issued to a customer and a list of IP addresses that its customers generally use.

    What does this mean for VPN providers?

    • VPN services are in violation of Cert’s rules by simply operating in India.
    • That said, it is worth noting that ‘no logs’ does not mean zero logs.
    • VPN services still need to maintain some logs to run their service efficiently.

    Does this mean VPNs will become useless?

    • The Indian government has not banned VPNs yet, so they can still be used to access content that is blocked in an area, which is the most common usage of these services.
    • However, journalists, activists, and others who use such services to hide their internet footprint will have to think twice about them.

    Why such move?

    • Crime control: For law enforcement agencies, a move like this will make it easier to track criminals who use VPNs to hide their internet footprint.
    • Curbing dark-net activities: Users these days are shifting towards the dark and deep web, which are much tougher to police than VPN services.

    Back2Basics: Indian Computer Emergency Response Team (CERT-IN)

    • CERT-IN is an office within the Ministry of Electronics and Information Technology.
    • It is the nodal agency to deal with cyber security threats like hacking and phishing. It strengthens the security-related defense of the Indian Internet domain.
    • It was formed in 2004 by the Government of India under the Information Technology Act, 2000 Section (70B) under the Ministry of Communications and Information Technology.

     

    UPSC 2023 countdown has begun! Get your personal guidance plan now! (Click here)

  • Explained: Critical Information Infrastructure

    The Union Ministry of Electronics and IT (MeitY) has declared IT resources of ICICI Bank, HDFC Bank and UPI managing entity NPCI as ‘critical information infrastructure’.

    Try this PYQ:

    In India, the term “Public Key Infrastructure” is used in the context of

    (a) Digital security infrastructure

    (b) Food security infrastructure

    (c) Health care and education infrastructure

    (d) Telecommunication and transportation infrastructure

     

    [wpdiscuz-feedback id=”2d4o8z90sm” question=”Please leave a feedback on this” opened=”1″]Post your answers here.[/wpdiscuz-feedback]

    What is Critical Information Infrastructure (CIC)?

    • The Information Technology Act, 2000 explicitly gives definition of CIC.
    • It defines CIC as a computer resource, the incapacitation or destruction of which shall have debilitating impact on national security, economy, public health or safety.
    • It basically aims to protect the digital assets.
    • The government, under the Act, has the power to declare any data, database, IT network or communications infrastructure as CII.
    • Any person who secures access or attempts to secure access to a protected system in violation of the law can be punished with a jail term of up to 10 years.

    Why is CII classification and protection necessary?

    • IT resources form the backbone of countless critical operations in a country’s infrastructure.
    • Given their interconnectedness, disruptions can have a cascading effect across sectors.

    What led to the classification of CICs?

    • In 2007, a wave of denial-of-service attacks, allegedly from Russian IP addresses, hit major Estonian banks, government bodies – ministries and parliament, and media outlets.
    • It was cyber aggression of the kind that the world had not seen before.
    • The attacks played havoc in one of the most networked countries in the world for almost three weeks.

    Recent incidents of CIC incapacitation

    • In October, 2020 as India battled the pandemic, the electric grid supply to Mumbai suddenly stopped.
    • It hit the mega city’s hospitals, trains and businesses.
    • Later, a study by a US firm claimed that this power outage could have been a cyber-attack, allegedly from a China-linked group.
    • The government, however, was quick to deny any cyber-attack in Mumbai. But prospects cannot be denied.
    • The incident underlined the possibility of hostile state and non-state actors probing internet-dependent critical systems in other countries, and the necessity to fortify such assets.

    How are CIIs protected in India?

    • Created in January 2014, the National Critical Information Infrastructure Protection Centre (NCIIPC) is the nodal agency.
    • It takes all measures to protect the nation’s critical information infrastructure.
    • It is mandated to guard CIIs from “unauthorized access, modification, use, disclosure, disruption, incapacitation or distraction”.
    • NCIIPC monitors and forecasts national-level threats to CII for policy guidance, expertise sharing and situational awareness for early warning or alerts.

     

    UPSC 2023 countdown has begun! Get your personal guidance plan now! (Click here)

  • The Cyber factor in the Russia-Ukraine war

    Context

    After 100 days of Ukraine crisis, Russia is yet to achieve what can be termed as a decisive victory in any sector of the current conflict.

    Reasons for the lacklustre performance of Russia

    • Several reasons have been adduced by experts in the West for the lacklustre performance of the Russian army.
    • Lack of motivation: There is a lack of motivation and the poor morale of the Russian forces sent to Ukraine.
    • Outdated weaponry: Russian weaponry being outdated and ineffective to fight an informationalised war under modern conditions.
    • Leadership issue: Russian commanders have also proved inept in devising plans and taking appropriate decisions in battlefield conditions against a determined enemy.

    Important role of cyber warfare

    • Given that cyber is often touted as the Fifth Dimension of warfare, it may be worthwhile to examine whether this indeed is the first major conflict in which ‘cyber’ is playing a crucial role, allowing a weaker nation with cyber capabilities to use it to its advantage.
    • A former Chief of the National Security Agency of the U.S., in his memoirs had said that although cyberspace is a man-made domain, it had become critical to military operations on land, sea, air and in space.
    • A former U.S. Secretary of Defence a few years ago,, even talked of a possible ‘cyber Pearl Harbour to paralyze nations and create a profound sense of vulnerability’.
    • The Russian military oligarchy is indeed among the world leaders in digital disruption and cyber-methodology.
    • One could have reasonably presumed that even before the conflict commenced, Russia would have swamped Ukraine with an avalanche of digital attacks.
    • Ukraine, for its part, has its own digital army, including a corps of digital weapons.

    Limits of cyber warfare

    • There are several publicised instances earlier, of alleged Russian operatives waging a cyberwar against Ukraine.
    • Both sides now possess and use malware such as data-wipers which have proved highly effective.
    • On the day the Russian invasion of Ukraine began, Russian cyber units are believed to have successfully deployed destructive malware against several Ukrainian military targets.
    •  A series of distributed denial-of-service (DDoS) attacks against Ukrainian banking and defence websites occurred simultaneously.
    • As far as the conduct of the war is concerned, the string of small-scale cyberattacks cannot be said to have had any material impact on the conduct or outcome of the conflict.
    • Hence, the cardinal question is why given that Ukraine has put up such a heroic defence — and to a considerable extent stalled the Russian offensive — Russia has not embarked on a massive all-out cyber-offensive.
    • If that be the case, then much of the speculation that cyberattacks in the event of a war provide a perpetrator the capability to enact another ‘Pearl Harbour’ seems highly unrealistic.

    Conclusion

    It is very likely, and possibly a fact, that there are major difficulties in planning and executing massive cyberattacks on a short timeline to ensure higher efficacy of kinetic attacks.

    UPSC 2023 countdown has begun! Get your personal guidance plan now! (Click here)

  • SC tests phones for Pegasus Spyware

    The Supreme Court has said its technical committee had so far received and tested 29 mobile devices suspected to be infected by Pegasus malware.

    Why in news?

    • It was alleged that the government used the Israel-based spyware to snoop on journalists, parliamentarians, prominent citizens and even court staff.

    What is Pegasus?

    • Pegasus is a spyware developed by NSO Group, an Israeli surveillance firm that helps spies hack into phones.
    • In 2019, when WhatsApp sued the firm in a U.S. court, the matter came to light.
    • In July 2021, Amnesty International, along with 13 media outlets across the globe released a report on how the spyware was used to snoop hundreds of individuals, including Indians.
    • While the NSO claims its spyware is sold only to governments, none of the nations have come forward to accept the claims.

    Threats created by Pegasus

    • What makes Pegasus really dangerous is that it spares no aspect of a person’s identity.
    • It makes older techniques of spying seem relatively harmless.
    • It can intercept every call and SMS, read every email and monitor each messaging app.
    • Pegasus can also control the phone’s camera and microphone and has access to the device’s location data.
    • The app advertises that it can carry out “file retrieval”, which means it could access any document that a target might have stored on their phone.

    Dysfunctions created

    • Privacy breach: The very existence of a surveillance system, whether under a provision of law or without it, impacts the right to privacy under Article 21 and the exercise of free speech under Article 19.
    • Curbing Dissent: It reflects a disturbing trend with regard to the use of hacking software against dissidents and adversaries. In 2019 also, Pegasus software was used to hack into HR & Dalit activists.
    • Individual safety: In the absence of privacy, the safety of journalists, especially those whose work criticizes the government, and the personal safety of their sources is jeopardised.
    • Self-Censorship: Consistent fear over espionage may grapple individuals. This may impact their ability to express, receive and discuss such ideas.
    • State-sponsored mass surveillance: The spyware coupled with AI can manipulate digital content in users’ smartphones. This in turn can polarize their opinion by the distant controllers.
    • National security: The potential misuse or proliferation has the same, if not more, ramifications as advanced nuclear technology falling into the wrong hands.

    Snooping in India:  A Legality check

    For Pegasus-like spyware to be used lawfully, the government would have to invoke both the IT Act and the Telegraph Act. Communication surveillance in India takes place primarily under two laws:

    1. Telegraph Act, 1885: It deals with interception of calls.
    2. Information Technology Act, 2000: It was enacted to deal with surveillance of all electronic communication, following the Supreme Court’s intervention in 1996.

    Cyber security safeguards in India

    • National Cyber Security Policy: The policy was developed in 2013 to build secure and resilient cyberspace for India’s citizens and businesses.
    • Indian Computer Emergency Response Team (CERT-In): The CERT-In is responsible for incident responses including analysis, forecasts, and alerts on cybersecurity issues and breaches.
    • Indian Cyber Crime Coordination Centre (I4C): The Central Government has rolled out a scheme for the establishment of the I4C to handle issues related to cybercrime in the country in a comprehensive and coordinated manner.
    • Budapest Convention: There also exists Budapest Convention on Cybercrime. However, India is not a signatory to this convention.

    Issues over government involvement

    • It is worth asking why the government would need to hack phones and install spyware when existing laws already offer impunity for surveillance.
    • In the absence of parliamentary or judicial oversight, electronic surveillance gives the executive the power to influence both the subject of surveillance and all classes of individuals, resulting in a chilling effect on free speech.

    Way forward

    • The security of a device becomes one of the fundamental bedrock of maintaining user trust as society becomes more and more digitized.
    • Constituting an independent high-level inquiry with credible members and experts that can restore confidence and conduct its proceedings transparently.
    • The need for judicial oversight over surveillance systems in general, and judicial investigation into the Pegasus hacking, in particular, is very essential.

    Conclusion

    • We must recognize that national security starts with securing the smartphones of every single Indian by embracing technologies such as encryption rather than deploying spyware.
    • This is a core part of our fundamental right to privacy.
    • This intrusion by spyware is not merely an infringement of the rights of the citizens of the country but also a worrying development for India’s national security apparatus.

     

    UPSC 2023 countdown has begun! Get your personal guidance plan now! (Click here)

  • How India’s new VPN rules change the Status Quo?

    Recently, the Indian Computer Emergency Response Team (Cert-In) issued new directives that require Virtual Private Network (VPN) providers to store user data for five years.

    What is VPN?

    • VPN describes the opportunity to establish a protected network connection when using public networks.
    • It encrypts internet traffic and disguise a user’s online identity.
    • This makes it more difficult for third parties to track your activities online and steal data.
    • The encryption takes place in real time.

    How does a VPN work?

    • A VPN hides your IP address by letting the network redirect it through a specially configured remote server run by a VPN host.
    • This means that if you surf online with a VPN, the VPN server becomes the source of your data.
    • This means your Internet Service Provider (ISP) and other third parties cannot see which websites you visit or what data you send and receive online.
    • A VPN works like a filter that turns all your data into “gibberish”. Even if someone were to get their hands on your data, it would be useless.

    Why do people use VPN?

    • Secure encryption: A VPN connection disguises your data traffic online and protects it from external access. Unencrypted data can be viewed by anyone who has network access and wants to see it. With a VPN, hackers and cyber criminals can’t decipher this data.
    • Disguising whereabouts: VPN servers essentially act as your proxies on the internet. Because the demographic location data comes from a server in another country, your actual location cannot be determined.
    • Data privacy is held: Most VPN services do not store logs of your activities. Some providers, on the other hand, record your behaviour, but do not pass this information on to third parties. This means that any potential record of your user behaviour remains permanently hidden.
    • Access to regional content: Regional web content is not always accessible from everywhere. Services and websites often contain content that can only be accessed from certain parts of the world.
    • Secure data transfer: If you work remotely, you may need to access important files on your company’s network. For security reasons, this kind of information requires a secure connection. To gain access to the network, a VPN connection is often required.

    What does the new CERT-IN directive say?

    • VPN providers will need to store validated customer names, their physical addresses, email ids, phone numbers, and the reason they are using the service, along with the dates they use it and their “ownership pattern”.
    • In addition, Cert is also asking VPN providers to keep a record of the IP and email addresses that the customer uses to register the service, along with the timestamp of registration.
    • Most importantly, however, VPN providers will have to store all IP addresses issued to a customer and a list of IP addresses that its customers generally use.

    What does this mean for VPN providers?

    • VPN services are in violation of Cert’s rules by simply operating in India.
    • That said, it is worth noting that ‘no logs’ does not mean zero logs.
    • VPN services still need to maintain some logs to run their service efficiently.

    Does this mean VPNs will become useless?

    • The Indian government has not banned VPNs yet, so they can still be used to access content that is blocked in an area, which is the most common usage of these services.
    • However, journalists, activists, and others who use such services to hide their internet footprint will have to think twice about them.

    Why such move?

    • Crime control: For law enforcement agencies, a move like this will make it easier to track criminals who use VPNs to hide their internet footprint.
    • Curbing dark-net activities: Users these days are shifting towards the dark and deep web, which are much tougher to police than VPN services.

    Back2Basics: Indian Computer Emergency Response Team (CERT-IN)

    • CERT-IN is an office within the Ministry of Electronics and Information Technology.
    • It is the nodal agency to deal with cyber security threats like hacking and phishing. It strengthens the security-related defense of the Indian Internet domain.
    • It was formed in 2004 by the Government of India under the Information Technology Act, 2000 Section (70B) under the Ministry of Communications and Information Technology.

     

    UPSC 2023 countdown has begun! Get your personal guidance plan now! (Click here)

  • India is now 3rd highest military spender

    World military spending continued to grow in 2021, reaching a record $2.1 trillion despite the economic fallout of the pandemic, according to new data on global military spending published by the Stockholm International Peace Research Institute (SIPRI).

    Top defence spenders in 2021

    • The five largest spenders in 2021 were the U.S., China, India, the U.K. and Russia, together accounting for 62% of expenditure.
    • The U.S. and China alone accounted for 52%.

    India’s defence expenditure

    • India’s military spending of $76.6 billion ranked third highest in the world.
    • This was up by 0.9% from 2020 and by 33% from 2012.
    • Amid ongoing tensions and border disputes with China and Pakistan that occasionally spill over into armed clashes, India has prioritised the modernisation of its armed forces and self-reliance in arms production, the report said.

    What about Russia and Ukraine?

    • Russia increased its military expenditure by 2.9% in 2021, to $65.9 billion, at a time when it was building up its forces along the Ukrainian border.
    • On Ukraine, the report remarked that as it had strengthened its defences against Russia, its military spending “has risen by 72% since the annexation of Crimea in 2014”.
    • Spending fell in 2021, to $5.9 billion, but still accounted for 3.2% of the country’s GDP.

    Also read-

    [Sansad TV] Perspective: Self-Reliance in Defence

    UPSC 2023 countdown has begun! Get your personal guidance plan now! (Click here)

  • Strontium: A Cyber-Espionage Group

    Recently, Microsoft said that it had disrupted cyberattacks from a Russian nation-state hacking group called ‘Strontium’.

    What is Strontium?

    • Strontium, also known as Fancy Bear, Tsar Team, Pawn Storm, Sofacy, Sednit or Advanced Persistent Threat 28 (APT28) group, is a highly active and prolific cyber-espionage group.
    • It is one of the most active APT groups and has been operating since at least the mid-2000s, making it one of the world’s oldest cyber-spy groups.
    • It has access to highly sophisticated tools to conduct spy operations, and has been attacking targets in the US, Europe, Central Asia and West Asia.
    • The group is said to be connected to the GRU, the Russian Armed Forces’ main military intelligence wing.
    • The GRU’s cyber units are believed to have been responsible for several cyberattacks over the years and its unit 26165 is identified as Fancy Bear.

    How does it attack networks?

    • The group deploys diverse malware and malicious tools to breach networks.
    • In the past, it has used X-Tunnel, SPLM (or CHOPSTICK and X-Agent), GAMEFISH and Zebrocy to attack targets.
    • These tools can be used as hooks in system drivers to access local passwords, and can track keystroke, mouse movements, and control webcam and USB drives.
    • APT28 uses spear-phishing (targeted campaigns to gain access to an individual’s account) and zero-day exploits (taking advantage of unknown computer-software vulnerabilities) to target specific individuals and organizations.
    • It has used spear-phishing and sometimes water-holing to steal information, such as account credentials, sensitive communications and documents.
    • A watering hole attack compromises a site that a targeted victim visits to gain access to the victim’s computer and network.

     

    UPSC 2022 countdown has begun! Get your personal guidance plan now! (Click here)