Primary Country (Mandatory)

Other Country (Optional)

Set News Language for United States

Primary Language (Mandatory)
Other Language[s] (Optional)
No other language available

Set News Language for World

Primary Language (Mandatory)
Other Language(s) (Optional)

Set News Source for United States

Primary Source (Mandatory)
Other Source[s] (Optional)

Set News Source for World

Primary Source (Mandatory)
Other Source(s) (Optional)
  • Countries
    • India
    • United States
    • Qatar
    • Germany
    • China
    • Canada
    • World
  • Categories
    • National
    • International
    • Business
    • Entertainment
    • Sports
    • Special
    • All Categories
  • Available Languages for United States
    • English
  • All Languages
    • English
    • Hindi
    • Arabic
    • German
    • Chinese
    • French
  • Sources
    • India
      • AajTak
      • NDTV India
      • The Hindu
      • India Today
      • Zee News
      • NDTV
      • BBC
      • The Wire
      • News18
      • News 24
      • The Quint
      • ABP News
      • Zee News
      • News 24
    • United States
      • CNN
      • Fox News
      • Al Jazeera
      • CBSN
      • NY Post
      • Voice of America
      • The New York Times
      • HuffPost
      • ABC News
      • Newsy
    • Qatar
      • Al Jazeera
      • Al Arab
      • The Peninsula
      • Gulf Times
      • Al Sharq
      • Qatar Tribune
      • Al Raya
      • Lusail
    • Germany
      • DW
      • ZDF
      • ProSieben
      • RTL
      • n-tv
      • Die Welt
      • Süddeutsche Zeitung
      • Frankfurter Rundschau
    • China
      • China Daily
      • BBC
      • The New York Times
      • Voice of America
      • Beijing Daily
      • The Epoch Times
      • Ta Kung Pao
      • Xinmin Evening News
    • Canada
      • CBC
      • Radio-Canada
      • CTV
      • TVA Nouvelles
      • Le Journal de Montréal
      • Global News
      • BNN Bloomberg
      • Métro
Privacy depends on cybersecurity — why government must rethink the new rules 

Privacy depends on cybersecurity — why government must rethink the new rules 

The Hindu
Friday, June 10, 2022 05:51:20 AM UTC

While increasing surveillance, the directions issued by CERT-In present few, if any, benefits for security of the state or individuals

If you had to choose between privacy and security, which would you prefer? While the answer may lean towards security for many, imagine losing out on both. This is likely to be the fallout of directions issued by the Indian Computer Emergency Response Team (CERT-In) on April 28, 2022. 

Let’s first cover the basics. CERT-In is a body established under the Information Technology Act, 2000 tasked with the broad mandate of “securing Indian cyberspace”, and reports to the Ministry of Electronics and IT (MEITY). With ubiquitous digitisation, cyber security has gained prominence in recent years. For instance, as per a parliamentary response CERT-In reported an almost nine-fold increase over six years to a total of 48,285 cyber security incidents related to government authorities. It mirrors the experience of users and the private sector who feel unsafe with their personal data being routinely breached, often leading to cyber crime. As per the Crime In India report in 2020, there has been an almost 12% rise  in cyber crimes, with the large majority clustered in the categories of fraud, sexual exploitation and extortion. These are serious consequences for national and user security that increase the importance of CERT-In’s mission.

Woefully, the directions issued by CERT-In, while increasing surveillance, present few, if any, benefits for security of the state or individuals. These directions go into effect on June 27, 2022, and have six operative provisions whose violation carries a one-year term of imprisonment. While much of the concern has arisen from users of Virtual Private Networks (VPNs), the directions go much further. 

Let us deal with each direction individually, starting with the requirement for all service providers to connect their system clocks to the network time protocol servers of the government. On the face of it, this is a welcome move, as all computer systems contain logs which require verifiable timestamps. However, by linking them to government servers, security experts have observed that it creates a single point of failure and increases the attack surface for a supply chain attack. 

The second direction requires all service providers to inform CERT-In whenever any “cyber incidents” occur, within six hours of gaining knowledge. This is again another direction which is positive at first glance, as it indicates that the government will now need to be informed any time there is a data breach rather than the information being tucked away in a corporation’s black box. However, there are core deficiencies which undermine the positives. One, “cyber incident” is not properly defined and makes reference to vague categories such as “fake mobile apps”. Even routine events such as “unauthorized access to social media accounts” will need to be reported. This will not only increase the reporting burden of system administrators, but flood CERT-In with notifications beyond their response capacity. Furthermore, there is no obligation on CERT-In to inform users who are ultimately at risk. There is no mention of what actions CERT-In must take and how its actions will be publicly disclosed. Reporting “cyber incidents” is also an incomplete measure, given there is no provision for penalties and fines on the public or private sector. 

The third direction enhances the power of CERT-In to seek information from service providers by extending them to “protective and preventive actions”. Again, there is little transparency on how CERT-In will exercise this power which now includes seeking “real time” information that could be used for the purpose of surveillance. Quite simply, CERT-In can direct any system provider even without a security incident occurring, with little oversight, and seek any data. Such surveillance fears become obvious when we look at the next two directions. 

Imagine that each online service provider will now maintain and store logs of all your online activity for 180 days and store them within India. This is not all — some, including data centres and VPNs, will be required to mandatorily register users. These two directions have gathered the bulk of public criticism from many users of VPNs. VPNs provide a tunnel for online activity in which a user first plugs into a VPN server that in turn fetches information from the Internet. Hence, all it shows to an Internet service provider such as Airtel or Jio, or even the websites a user visits, is the connection and address of the VPN server. This permits accessing blocked content, geolocating to another country or also, as claimed, surfing the Internet without logging. While the privacy claims of VPN providers are contentious, according to the Freedom of the Press Foundation if chosen well they “offer key security benefits to your workflow”. All of this will be a thing of the past with the mandate to store logs, that will essentially mean that whether you are a VPN user or not, each service provider will be required to collect and store more personal data of users. This may result in zero knowledge services such as messaging applications like Signal or secure browsing technologies like Tor being blocked in India. In addition to this, providers will now need to mandatorily register users on seven data points like a bank’s KYC process and store it for five years. This is a tremendous expansion in data collection which will match a person’s online activity with their real world identity. 

Read full story on The Hindu
Share this story on:-
More Related News
Itanagar Police arrests two from J&K for espionage activities in Arunachal

Itanagar Police arrest two from J&K for espionage, allegedly gathering sensitive information for handlers in Pakistan.

London-Hyderabad British Airways flight gets bomb threat, lands safely

A British Airways flight from London to Hyderabad received a bomb threat but landed safely; standard safety protocols were followed.

Four arrested and 20 cars seized for cheating the owners

Four arrested in Guntur for a car fraud scheme; police seize 20 vehicles and uncover a larger gang operation.

Telangana HC declines interim relief to GITAM university over power disconnection

Telangana HC denies GITAM University interim relief for power restoration

It's not really up to me, is it?: McCullum on continuing as England coach

Brendon McCullum reflects on his uncertain future as England coach amid scrutiny after a disappointing Ashes series.

Messi event fiasco: Calcutta High Court refuses to interfere in SIT probe

Calcutta High Court declines to intervene in SIT's investigation into chaos at Messi's Kolkata event, citing preliminary status.

Services of BLOs required during second phase of SIR also, says order

BLOs' duty extended to January 22 for crucial verification tasks during the electoral roll's special intensive revision phases.

Does Chennai have enough shared spaces for competitive exam aspirants? Premium

Chennai's aspiring competitive exam students face challenges finding affordable, dedicated study spaces amid rising demand and limited resources.

Bird flu outbreak confirmed in Kerala’s Alappuzha and Kottayam districts

Bird flu confirmed in Kerala's Alappuzha and Kottayam districts, threatening poultry farmers ahead of the festive season.

How Bengaluru celebrated Christmas in the ‘80s and ‘90s, a look at bygone days

We gather a few of Bengaluru’s nostalgic Christmas stories, from Nilgiris cake exhibitions to the towering Christmas tree on Brigade Road

Rahul Gandhi is anti-India leader: BJP MP slams Lok Sabha LoP over his remarks in Germany

BJP MP Shobha Karandlaje labels Rahul Gandhi an "anti-India leader" over his remarks during a visit to Germany.

Clare Mackintosh: Crime novels depicting ordinary women finding their inner strength appeal to female readers

Clare Mackintosh: Crime novels depicting ordinary women finding their inner strength appeal to female readers

M.B. Patil to convince Karnataka CM of need for government medical college in Vijayapura, drop idea of PPP model

M.B. Patil advocates for a government medical college in Vijayapura, emphasizing support for farmers and sustainable irrigation practices.

Roadside surgery: Heroic response by three young doctors saves accident victim in Kerala; earn praise

Three young doctors heroically save an accident victim in Kerala through quick thinking and teamwork, earning widespread admiration.

Watch: India pledges $450 million to rebuild Sri Lanka after Cyclone Ditwah

Shorts News:Watch: India pledges $450 million to rebuild Sri Lanka after Cyclone Ditwah

From biryani to sorpotel: How different communities in Bengaluru celebrate Christmas

Bengaluru is a melting pot of people from different backgrounds, from Anglo-Indians and Goan Catholics to North Easterners. What do they cook for their Christmas lunch?

Karnataka Minister promises early execution of PM MITRA Textile Park in Kalaburagi

Karnataka Minister Shivanand Patil assures swift progress on the PM MITRA Textile Park in Kalaburagi, addressing key infrastructure needs.

Hindu right descends on Bangladesh High Commission in hundreds over mob lynching

Hindu activists protest at Bangladesh High Commission in New Delhi over mob lynching, causing chaos despite heavy police presence.

HC disposes of pleas seeking continuation of excavations at Adichanallur, Sivagalai

The Madurai Bench of the Madras High Court has disposed of two public interest litigations pertaining to archaeological excavations at sites in Adichanallur and Sivagalai in Thoothukudi district.

Precision and finesse marked A. Lakshmanaswamy’s performance

A. Lakshmanaswamy’s dance for Sri Krishna Gana Sabha’s 69th Margazhi Mela, reflected the maturity of his nritta and abhinaya explorations. 

Permission denied for cricket match at M. Chinnaswamy Stadium in Bengaluru

Karnataka government denies permission for cricket match at M. Chinnaswamy Stadium due to safety concerns following past incidents.

Remove bushes along tracks to ensure clear signal visibility: SCR chief during winter safety protocols review

SCR chief emphasizes winter safety measures, ensuring operational safety and punctuality through thorough inspections and equipment reviews.

Karnataka government will weed out Gruha Laxmi beneficiaries who have passed away, says Minister

Karnataka will eliminate deceased beneficiaries from the Gruha Laxmi scheme using software to ensure funds reach eligible recipients.

Amaravati to anchor Knowledge Economy as India’s Quantum Valley: Naidu

Andhra Pradesh aims to establish Amaravati as India's Quantum Valley, fostering innovation in technology, aerospace, and data infrastructure.

Congress attacks Modi Govt. on Aravalli issue, asks why 'hell-bent' on redefining mountain range

Congress questions Modi government's motives behind redefining the Aravallis, emphasizing the need for ecological protection and restoration.

© 2008 - 2025 Webjosh  |  News Archive  |  Privacy Policy  |  Contact Us