In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label national security. Show all posts
Showing posts with label national security. Show all posts

Wednesday, May 2, 2018

13415 - India’s ambitious digital ID project faces new security nightmare - Asia Times


A slew of complaints and alerts to UIDAI reveal that operators can bypass biometric and geo-location safeguards to access the database illegally


By SAIKAT DATTA MAY 1, 2018 12:52 PM (UTC+8)

A citizen's biometric data is collected for his Aadhaar card. Photo: Wikipedia Commons

India’s all-pervasive digital identity programme Aadhaar appears to be facing a fresh security scare. The concern may also have national security implications, as suggested by material accessed by Asia Times.

The key to the latest security breach comes from a modified Aadhaar enrolment software, known as ECMP, which is being distributed illegally for a cost ranging from Rs 500 to Rs 2,000.

Must-reads from across Asia - directly to your inbox

Alerts to the Unique Identification Authority of India (UIDAI) and other government agencies have been acknowledged, but no detail of any follow-up action has been revealed. This has given rise to suspicion that the breach is yet to be resolved.

The ECMP was developed as software that can be used by operators to register people so they can get unique digital Aadhaar numbers. There is an elaborate program that allowed “enrolment partners” to be contracted by UIDAI to sign up citizens and residents across the country. The ECMP software ensures that sensitive personal data of those signing up is securely collected in a prescribed format to generate their Aadhaar number.

However, as reports of enrolment fraud began to surface, the UIDAI blacklisted nearly 50,000 private operators and mandated public sector banks and post offices to carry out the enrolment.

For the erstwhile private operators, the blacklisting was a major blow. Public sector banks were overloaded with the additional work of signing up citizens and residents.  The government has made Aadhaar mandatory for filing taxes as well as having bank accounts and a cell-phone connection. Nearly a billion people were signed up, even as the government was engaged in a slew of litigation in India’s Supreme Court challenging the project.

A number of petitioners have challenged the Aadhaar project on the ground that it enables mass surveillance by the state, violates citizens’ privacy and poses a major danger to legitimate entitlements guaranteed by the Indian Constitution. The slew of cases led to an unprecedented nine-judge constitutional bench of the Supreme Court ruling that privacy was a “fundamental right” under the Constitution. The other petitions challenging the program are still being heard by the Supreme Court.

The ECMP software allowed the operators to collect biometric data such as iris scans and fingerprints, as well as details of address and date of birth, among other sensitive personal data. The software has two major safeguards to ensure that it can not be misused. It asks for the biometrics of the authorized operator and seeks the geo-location to ensure that not only is the data being collected by someone authorized to do so, but to also ensure that it is being done at a secure and mandated location. There are many videos explaining how this software can be downloaded and installed.

Software ‘compromised to bypass safeguards’
But material gleaned from group WhatsApp messages of erstwhile private operators and complaints to the UIDAI reveal that the software has been compromised. This allows illegal access to the Aadhaar database by by-passing the biometric and geo-location safeguards.

Messages posted in several WhatsApp groups among Punjab-based operators began to surface at the end of last year, offering to sell a “jailbreak” version of the software. This version, to be installed on the laptops of anyone willing to pay the amount, could bypass the biometric and geo-location safeguards. This basically meant that anyone posing as an “authorized operator” could make changes to the data and enrol new people from anywhere and pass their information off as legitimate. This is easier as the number is only proof of residency and not citizenship.

An Aadhaar government identification card. Photo: iStock

Two information security professionals who looked at the compromised software confirmed to Asia Times that the safeguards had been bypassed. “(The) Aadhaar Enrolment client can be installed on any laptop and is available for public download. It needs to be configured for use by a  registrar (Banks, State governments) by importing registrar data and user credentials of the registrar”, the information security professional said, on strict condition of anonymity.

According to a second information security professional, enrolment and updates are possible only if an operator’s credentials match with their biometrics. However, the illegal enrolment software has been patched to bypass biometric checks and comes preconfigured with user credentials of various registrars. “The GPS module to track the location of the enrolment has also been disabled through a patch,” this expert said. “This allows anyone to become an Aadhaar enrolment operator, thereby violating all the security protocols that UIDAI has put in place for enrolment, including document verification such as proof of identity, proof of address. It also allows anyone to update their proof of identity or address details without any checks whatsoever.”

According to the experts, disabling or ‘spoofing’ the GPS checks gives rise to the possibility of the enrolment happening anywhere in the world, thereby allowing even foreign nationals who have never visited India, to enrol in Aadhaar.

None of these hacks are new. On February 23 this year, UIDAI authorities from the city of Chandigarh filed an official complaint with the Haryana Police. The case found a group of people working in the district of Hisar, using fake rubber thumbprints to bypass the biometric safeguards of the operator. This group was illegally accessing the database, as well as carrying out enrolments.

In the neighboring state of Uttar Pradesh, the police registered an official complaint in the capital Lucknow in August 2017. In this case, the UIDAI found operators who had managed to bypass the biometric safeguards as well.

‘Hostile’ UIDAI
These details and possibilities were brought to the UIDAI’s knowledge by email by an operator from Punjab. Bharat Bhushan Gupta sent them several warnings, which were acknowledged by UIDAI. But he was never informed about any follow-up. Gupta said he was willing to help the UIDAI access the compromised software and enable officials to examine the bypass in detail. But he never heard from them again.
Subsequently, a Punjab-based journalist with a major newspaper also accessed details of the compromised software and promptly alerted the UIDAI in writing in mid-April. This was also acknowledged, but no details of any follow-up action were shared.

To ensure good cybersecurity, the discovery of vulnerabilities depends largely on voluntary disclosure from hackers and information security professionals. However, despite being in existence from 2009, UIDAI lacks a responsible disclosure program, and in fact adopts a hostile stance against any disclosure. In the past, the agency has filed police complaints, not even sparing journalists who only reported on similar vulnerabilities. As a result, most experts shy away from informing the UIDAI about such problems. It continues to claim that their database is safe, despite mounting evidence to the contrary.

Asia Times sent the following queries to the CEO and chairman of UIDAI, to seek a response to these issues. The story will be updated as and when they respond.

1. Is it true that the Enrolment Client Management Platform (ECMP) software, being used for off-line enrolment has been found to have vulnerabilities, which can be exploited to bypass geo-location and biometrics?
2. Is the UIDAI aware that a group of illegal operators are using this software and installing it for a price, enabling people to carry out illegal enrolment and updates?
3. What is the progress on the UP Aadhaar hack – illegal enrolment case, where the Enrolment software was hacked as per the registered First Information Report in September 2017?
4. Was the ECMP software sufficiently hardened so that the above vector of patching the software to bypass an operator’s biometrics cannot happen?
5. If yes, what are the technical measures put in place to plug this vulnerability?
6. A similar incident was reported by operator Bharat Bhushan Gupta from Jullundur on Feb 1, 2018, which the UIDAI has acknowledged. What was the resolution of that incident and details thereof?
7. The same vulnerability was reported by Ms Rachna Khaira and also reported to the National Critical Information Infrastructure Protection Center on April 15, 2018. What is UIDAI’s response to this?

Thursday, August 4, 2016

10229 - Modi asks States to share intelligence - The Hindu

NEW DELHI, July 17, 2016

SPECIAL CORRESPONDENT

Federal spirit:Prime Minister Narendra Modi with Telangana Chief Minister K. Chandrasekhar Rao at the Inter-State Council Meeting in New Delhi on Saturday.— Photo: Special Arrangement

Prime Minister Narendra Modi on Saturday asked the States to focus on intelligence-sharing to help the country stay “alert” to, and “updated” on, internal security challenges.

Addressing the Inter-State Council meeting, convened after 10 years, he saidinternal security could not be strengthened unless the States and the Centre focussed on sharing intelligence.
The Chief Ministers, Lieutenant-Governors of the Union Territories and 17 Union Ministers are members of the Inter-State Council. Modi was interacting with the Chief Ministers on a single platform for the first time since coming to power two years ago.

“With close cooperation, we will not only strengthen the Centre-State relations but also make a better future for the citizens,” he said.

The Chief Minister of Uttar Pradesh, Akhilesh Yadav, of Karnataka, Siddaramaiah, and of Jammu and Kashmir, Mehbooba Mufti, did not attend the meeting.

Financial resources
“It would be difficult for any government to successfully implement a scheme on its own. Therefore, provision of adequate financial resources is as important as the responsibility for implementation,” Mr. Modi said.

Mr. Modi appreciated the efforts of Union Home Minister Rajnath Singh for restarting the process of dialogue between the States and the Centre over the past year.

The Prime Minister noted that with the acceptance of the 14th Finance Commission’s recommendations, the States’ share in Central taxes increased from 32 per cent to 42 per cent. “… the total amount received by the States from the Centre during 2015-16 is 21 per cent higher than the amount received in 2014-15.”

Mr. Modi said panchayats and urban local bodies would receive Rs. 2,87,000 crore during the period of the 14th Finance Commission, substantially higher than last time. The rights of the States were kept in mind, even in revenue from the auction of natural resources. “Auctions of coal blocks will yield Rs. 3.35 lakh crore to the States in the years to come. Auctions of other mines will yield an additional Rs. 18,000 crore to the States.”
Mr. Modi said that through amendments to the CAMPA Act (Compensatory Afforestation Fund Bill), the Centre was trying to free up Rs. 40,000 crore lying in banks for disbursal to the States. The Centre also wished to share with the States the amount saved as a result of transparency being introduced in the system.

He said India’s greatest asset is its youth as over 30 crore children are now of school-going age. Hence, the country has the potential to provide the world skilled manpower for many years to come. “The Centre and the States must work together to provide our children an enabling environment in which they can develop their skills and prepare themselves for today’s needs. Merely going to school is not education. Education should generate curiosity among children. It should teach them how to attain and enhance knowledge. It should motivate them to continuously keep learning throughout their lives.”

On Aadhaar card
Referring to the Aadhaar card, he said the Aadhaar Act, 2016, enabled the government to use the Aadhaar for direct cash transfer for subsidy and other services. “As on date, 102 crore Aadhaar cards have been distributed in our country of 128 crore people. Seventy-nine per cent of our people now have Aadhaar cards. Among adults, 96 per cent people have the cards. With your support, we shall connect every citizen with an Aadhaar card by the year-end.”

Mr. Modi said the Centre launched a scheme under which, if there is a reduction in kerosene consumption by a State, the Centre would disburse 75 per cent of the resultant savings in subsidy as grant to that State. He lauded the Karnataka government for moving swiftly on this initiative

Monday, March 14, 2016

9515 - AADHAAR Cuts Into Personal Privacy and National Security - The Citizen.In


Sunday, March 13,2016


MYSORE: The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Bill, 2016 (“Aadhaar Bill”, for short) was passed in the Lok Sabha on March 11, 2016, as a money bill, a stratagem clearly meant to prevent delay in the Rajya Sabha, where the BJP does not command a majority.

Leaving aside the questionable stratagem, the Aadhaar Bill leaves much to be desired, especially considering its troubled “history” ever since the beginning of the Aadhaar scheme. In particular, according to this writer, two of the major issues involved are personal privacy and national security.

At present there is no law on privacy, but in Rajagopal Vs. State of Tamil Nadu (1994), the Supreme Court opined that privacy is inherent in an individual's right to personal liberty. Also, Section 8(1)(j) of the RTI Act 2005, protects the private individual against unwarranted invasion of his/her privacy, proof enough that privacy is a right even if it is not a fundamental right.

On whether privacy is a fundamental right, the Government of India succeeded in convincing a 3-Judge Supreme Court bench hearing a bunch of petitions challenging Aadhaar on multifarious grounds, that privacy is important enough an issue to warrant consideration by a Constitution bench.

There is little doubt that mass surveillance for suspicion-less, untargeted snooping into people's private spaces to identify a possible threat to security, is questionable.

The privacy issue was brought to international attention in 2013, with the US admitting that its National Security Agency had been clandestinely collecting billions of pieces of information worldwide including personal data and emails from computer networks and telephones. India was one of USA's many surveillance targets.

Today, the technical capability of shadowy intelligence agencies for mass surveillance to collect, sort and process enormous quantities of data or meta-data has multiplied enormously. Hacking into databases for data is not very difficult for a person with the necessary motivation, skills and time, and it is quipped that systems are hack-proof only until the first hack.

Cyber security concerns in the face of clandestine, untargeted surveillance are not only about national security but also citizens' right to privacy.

Whether or not it succeeds in its declared primary aim of targeted welfare services for the poor, Aadhaar enables surveillance and tracking. Aadhaar promoters claim that access to its data base will not be permitted to any agency, and will be secure from intelligence agencies that spy on citizens. 

This claim is questionable since, according to its website, UIDAI contracted to receive technical support for biometric capture devices, from L-1 Identity Solutions, Inc. (now MorphoTrust USA), a US-based intelligence and surveillance corporation. 

According to the corporation's website, its top executives are acknowledged experts in the US intelligence community. Other companies awarded contracts for key aspects of the Aadhaar project, are Accenture Services Pvt Ltd (implementation of Biometric Solution for UIDAI) which works with US Homeland Security, and Ernst & Young (setting up of Central Identities Data Repository (CIDR) and Selection of Managed Service Provider (MSP)).

It is difficult to have confidence in the security of sensitive national information when the technical provider which creates, holds or manages the database is a business corporation with strong connections to foreign intelligence organizations.

Furthermore US corporations are mandated by US law to reveal to the US government, information obtained during their legitimate operations, when called upon to do so. The extent to which India's cyber security has been already invaded by surveillance is not even known, and when the security of the Aadhaar system is not water-tight, compromise of the Aadhaar system's security will tantamount to compromise of national security.

When the cyber systems of high-security organizations like USA's NASA or India's DRDO have been repeatedly hacked, UIDAI's self-certification of its database security rings hollow. As far as institutional cyber security in India is concerned, barring one database protected by an indigenously developed network security system, official databases in India, including Aadhaar's Central ID Repository (CIDR), are protected by purchased commercial network security and cryptographic products.

There is little need to emphasise the vulnerability of the Aadhaar database to access by unauthorized persons/agencies for data destruction, corruption or simply copying by surveillance or hacking. The effect on individual privacy is unquestionably adverse.

Intelligence agencies operate by conducting general surveillance on citizens in public places and linking this with personal information available in various databases maintained by banks, income tax offices, ration cards, electoral rolls, airline and railway ticketing, internet and telecom service providers, etc. 

Since the Aadhaar number is “seeded” in these various data bases, Aadhaar itself will inevitably be at the core of a system to enable profiling and tracking of any and every private individual. Therefore Aadhaar is a prize target for intelligence agencies to hack or surveil to acquire data to invade individual privacy and compromise national security.
There have been a host of objections – especially including those of privacy and security – to the Aadhaar scheme itself since its inception, with several petitions still pending before the Supreme Court.

The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Bill, 2016, does nothing to address those objections including especially those articulated unambiguously and vigorously by the Parliamentary Standing Committee on Finance headed by Yashwant Sinha, in December 2011.

In particular, the Aadhaar Bill fails to address the serious systemic issues of national security and individual privacy and indeed, the word “privacy” is absent from its text. However, concerning the security and confidentiality of information, the value of individual privacy is indirectly acknowledged in Section 33(2), by specifying that an individual's Aadhaar number, and biometric and demographic information may be revealed in the interest of national security, only by a specially authorized officer not below the rank of Joint Secretary of the Government of India. Yet here again, the interpretation of the term “national interest” remains at the sole discretion of a bureaucrat.

Further, the Aadhaar Bill omits to explicitly state whether enrolling into the Aadhaar scheme is “mandatory” or “not mandatory”. This can be interpreted as a deliberate omission to justify the on-going coercive enrolment into the Aadhaar scheme. The effect of the final order of the Supreme Court on this omission remains to be seen.

The several issues pleaded in the outstanding petitions before the Supreme Court and the outcome of the privacy issue placed before a Constitutional bench will surely have a bearing on the details of the Aadhaar Bill if not on its structure. Thus, ramming the Aadhaar Bill through the Lok Sabha without waiting for the Supreme Court to give its orders may result in unnecessary litigation, besides exposing lack of respect for transparent democratic procedures.

Notwithstanding, genuine national interest may dictate that laws on data/digital privacy protection and cyber security be urgently enacted and linked with the Aadhaar Bill, before it becomes operational in the public sphere.

( Major General S.G. Vombatkere, VSM, retired in 1996 as Additional DG Discipline & Vigilance in Army HQ AG's Branch. President of India awarded him Visishta Seva Medal in 1993 for distinguished service rendered in the high-altitude region of Ladakh. He holds a PhD degree in Structural Dynamics from I.I.T, Madras. With over 470 published papers in national and international journals and seminars, his area of interest remains strategic and development-related issues.)

Friday, November 20, 2015

9070 - Alarm over seizure of fake passports from illegal Bangladeshi immigrants - The Hindu

MUMBAI, November 16, 2015


The ATS claims that many illegal immigrants not only have forged ration cards, Aadhaar and other documents but also Indian passports. File photo

Matter came to light during a verification drive in Thane
The Mumbai police and the State Anti-Terrorism Squad (ATS) have raised serious security concerns over infiltrating Bangladeshi nationals obtaining forged Indian passports. The latest development came to light after the recent arrest of scores of illegal immigrants from Thane, revealing as many as 40 infiltrators have possibly managed to obtain Indian passports from remote districts in Jharkhand.

Sources in the ATS said the agency has now handed over this fresh list to the Thane police, claiming many of them have not only forged ration cards, Aadhaar and other documents but likely an Indian passport as well. This has sent alarm bells ringing in the security establishment.

“This matter came to light during a passport verification drive of a recently-arrested group of illegal immigrants. It seems they paid about Rs. 5,000 to agents for pretending to be Indian nationals and thereby obtaining Indian passports. This is a very serious and sensitive issue, and we are investigating how these infiltrators are obtaining fake passports with such ease,” said a senior official from the ATS.

The ATS investigation has revealed some touts are helping these illegal immigrants ferry back and forth a trip from and to Bangladesh once the passport is ready. These passports, officials said, were applied for through an online system last year as per the usual procedures of the Regional Passport Office, and its requirements to fill a passport form. The immigrants had provided their Aadhaar and voter ID card for identification to the police and the local administration, sources in the ATS said.


In 2012, Maharashtra Navnirman Sena (MNS) chief Raj Thackeray had held Bangladeshi infiltrators responsible for the widespread violence on August 11, which left two persons dead and 45 others injured. While blaming the illegal immigrants for attacks on the Mumbai police and media persons, Mr. Thackeray had flashed what he claimed was a green-coloured passport found at the venue and purportedly belonging to a Bangladeshi.

Thursday, October 1, 2015

8783 - Why the Draft National Encryption Policy is likely to return - News Laundry


Posted by Saikat Datta | Sep 29, 2015 in Criticles, Featured | 0 

Just three over-worked officials occasionally meet in the corridors of power in Delhi to ensure that the Indian Republic does not turn into a police state. These officials – the Cabinet Secretary, the Union Law Secretary and the Union Telecom Secretary – are tasked with the onerous mission to ensure that the power to intercept private communications is not misused. 

Currently, there are 10 law enforcement agencies that are authorised to intercept private communication in India.

The burden that these officials carry would have increased exponentially if the Draft National Encryption Policy, issued by the Department of Telecommunications (DoT), had come through. Designed by junior officials of the DoT, the policy is meant to protect the privacy of communications between common citizens. Instead, it emerged as a deliberate road map to strengthen the government’s right to snoop proactively on private communications under the garb of “national security”.

Fortunately, the order came and vanished in less than 48 hours following a widespread online protest, forcing the government to beat a hasty retreat.

A government that’s all ears

The Centre may have withdrawn the proposed rules for now. But if senior government officials are to be believed, this is a tactical retreat.

The rules will return under the guise of opaque frameworks that will be slipped in licensing conditions that allow companies to set up communication networks. “Rest assured, the government will not give up its right to intercept all forms of communication. If this is not included in the proposed encryption policy, then it will be included in a new set of rules and regulations that govern over-the-top [OTT] applications,” a senior government official overlooking cyber security issues in the Prime Minister’s Office (PMO) told me on the condition of strict anonymity.

A few months ago, when a furious debate erupted on Net Neutrality, major telecom companies fought back by raising the bogey of security threats posed by OTT services like WhatsApp and Facebook Messenger. Telecom companies claimed that OTTs were eating into their revenues and giving consumers a means to use Internet services for free, at their cost. What they conveniently avoided mentioning was the fact that, according to telecom companies’ declared revenue earnings, their earnings had actually gone up owing to greater use of data services.

With their backs to the wall, telecom companies, then, raised the issue of “regulating OTTs” so that “national security” was not compromised. According to them, since OTTs were based abroad and used high levels of encryption, this would prevent Indian security agencies from listening to conversations taking place between terrorists planning major strikes against India. While most experts rejected the argument as alarmist, officials in the DoT took the bait.

“Telecom companies had a point,” a senior DoT official familiar with security-related issues told me last week. “If OTTs can’t be intercepted, how will our security agencies listen into terrorists using them,” he said.

This article is made possible because of Newslaundry's subscribers.CLICK HERE AND PAY TO KEEP NEWS FREE

In the name of national security

While surveillance is a necessity for counter-terrorism, there is no data to establish how effective it really is. A fact that is cleverly kept vague so that the government of the day can retain its right to tap into the private communications of its citizens at will.

A year ago, in response to a Right to Information (RTI) application, which I had filed earlier, the Union Ministry of Home Affairs admitted to an astounding number of phone calls being tapped every year. It admitted that, on average, the Union Home Secretary would sign on 7,000 to 9,000 orders every month allowing some agency or the other to tap phone calls.

This meant that the Union Home Secretary had to sign nearly 300 such orders every day, amid the hundred other official duties he has to discharge. Clearly, the process is a mechanical ritual with little or no scope for applying any judicious thought.

Worryingly, the only safeguard against the Union Home Secretary’s authorisation orders is a three-person committee that was set up in 1987. This committee, headed by the Union Cabinet Secretary along with the Union Telecom and Law Secretaries, is supposed to review the orders signed by the Union Home Secretary authorising phone and email interceptions.

But faced with such massive numbers, this committee routinely clears all such orders, and refuses to reveal any data about the anomalies they may have spotted in their review meetings. I filed several RTI applications seeking this data, but I was repeatedly told that revealing the data on any possible misuse would be “prejudicial to the national interest”. I fail to see how revealing meta-data on instances of misuse of interception powers could be “prejudicial to the national interests” of India.

Under the existing laws, Indian citizens are already vulnerable to the state’s intrusion. Here’s a sample of the powers and mechanisms that already exist. The United Progressive Alliance government introduced the Central Monitoring System (CMS) that makes surveillance even more opaque than what it was earlier. They also created NATGRID, a body that would connect 22 databases of information that can be used by security agencies to track citizens. The Aadhar programme, a passive surveillance programme, which was never cleared by Parliament, ended up collecting biometric data of citizens.

Conversely, India does not have a privacy law that could offer some protection to Indian citizens against the passive and active forms of surveillance to which they are currently subjected. A few years ago a Privacy Bill was circulated by the Department of Personnel & Training (DoPT) but it never surfaced again.

In May last year, it was reported that intelligence agencies, which have the powers to legally intercept communications, had sought a blanket exemption under any future privacy law.

More recently, on Sunday, Prime Minister Narendra Modi gave public assurances in Silicon Valley that his government would give the “highest importance to data privacy and cyber security”. Judging from his government’s actions, he seems to be addressing “data privacy” and not privacy per se. This means there are no assurances on the privacy of citizens against surveillance, but data security and privacy of corporations investing in India would be guaranteed.

The proverbial Big Brother flexing its muscle

Under this existing opaque and intrusive regime comes the now withdrawn the Draft National Encryption Policy that would have added to the vast intrusive powers that the government already holds. It proposed that “…users in India are allowed to use only the products registered in India”. Which meant that OTTs like WhatsApp and Facebook Messenger would have to be registered in India if they are to be used by Indians.

Ironically, while the NDA government came to power on the promise of “maximum governance and minimum government”, this policy would have ensured maximum government in even private and personal WhatsApp messages between citizens.

It also threatened that the “…government reserves the right to take appropriate action as per Law of the country for any violation of this Policy”.

Understandably, common citizens are outraged. Law researcher and a veteran privacy activist, Usha Ramanathan, was horrified at what the government had almost enacted. “What is this? An attempt to be a know-all state? It would be a mistake to not see this desire to control the thoughts and conversations of people as a privacy issue. And, maybe those who think privacy is irrelevant as a value today will also baulk at a state that is saying ‘I want to know everything about you and if you don’t let me know all, it must mean you have something diabolic to hide’.”

A few months ago the NDA government submitted an affidavit in the Supreme Court rejecting privacy as a fundamental right for citizens in India. Clearly, this was more than coincidence.

To be fair, security agencies do have a difficult task at hand. Two years ago, when the Intelligence Bureau (IB) launched an operation in neighbouring Nepal to nail Yasin Bhatkal, one of India’s most wanted terrorists, it was left groping in the dark. Bhatkal was a clever fugitive, and as his subsequent interrogation revealed, he was adept at using different forms of encrypted chat platforms to communicate key messages with his compatriots.

For the IB, the only means to get this information was by using the Mutually Legal Assistance Treaty (MLAT) to get the information from servers in the United States of America. “Everyone accepts that the MLAT process is irreparably broken. The information we seek is rarely shared and even if the Americans do share something, it is too late before it arrives,” a senior intelligence official told me last week.

While this argument has merit, it fails to address the dangers that unfettered surveillance powers can pose to a democratic polity. Information is power and a rogue government could easily use legitimate laws, such as those proposed by the Draft National Encryption Policy to snoop on citizens. Every totalitarian state has always used the bogey of national security and national interest to accumulate such intrusive surveillance powers. The results have always been disastrous.

In India, had this policy gone through, it would have taken a step closer to becoming a police state where citizens spy on citizens.


The author can be contacted on Twitter @saikatd