Tuesday, December 22, 2020

Demystifying Digital signatures and electronic signatures

With the advancement in technology, the usage of the digital signature in place of the conventional signature has widely increased. The Information Technology Act, 2000 talks widely about the concept of Digital Signature, the authorities who have been given the power of issuing the digital signature certificate and the circumstances which require affixation of the digital signature. Digital signatures are recognized by IT Act 2000, as a valid means of authentication of any electronic record by a subscriber by means of an electronic method or procedure. The digital signatures cryptographically bind the electronic identity to the electronic document and provide it with authentication, integrity and non-repudiation.


In ITAA -2008, section 3 which was originally “Digital Signature” was renamed as “Digital Signature and Electronic Signatures” The Act now includes digital signature as one of the modes of signatures and is far broader in ambit covering biometrics and other forms of creating electronic signatures. Electronic signatures hence allow a subscriber to authenticate any electronic record by such electronic signatures or electronic authentication techniques. The key differences between Electronic and Digital signatures are enumerated below

Electronic Signature

·         Defined under Section 2(1) (ta) of the Information Technology Act, 2000.

·         It is technologically neutral

·         It can be created by using various available technologies - signature picture, It can be in the form of a name typed at the end of an email, a digital version of a handwritten signature in the form of an attachment, a code or even a fingerprint

·         It is less authentic and is easily vulnerable to tampering.

·         It is verified through the signer’s identity.

Digital Signature

·         Defined under Section 2(1)(p) of the Information Technology Act, 2000.

·         Follows a technology-specific approach such as usage of hash functions

·         It involves the usage of Cryptographic system of constructing the signature with a two-way protection system. It uses public key cryptography system to sign up for a message which requires a pair of keys -public and private

·         It has more authenticity and is more secure and highly reliable.

·         It has a certificate-based digital verification.

Friday, November 13, 2020

Software Piracy & India Laws

Software Piracy is an intellectual property related crime related to illegal copying, distribution, or use of software that is not licensed for use by the installer and violating the EULA or underlying licensing agreement between software publisher and user. It may include use of a software unauthorizedly without obtaining a proper license from the software company or simultaneous use of single user license or loading software on more machines, than authorized under the license terms. Software Piracy includes Counterfeiting, Internet Piracy, End-User Piracy, Client-Server Overuse and Hard-Disk Loading

Software piracy is a crime under two or three different laws in India:

·      The Copyright Act, 1957 - Copyright protection for software with an individual author lasts for the duration of the author's life and continues 60 years after the author's death. Under the Indian Copyright Act, a software pirate can be tried under both civil and criminal law. The minimum jail term for software copyright infringement is seven days, and the maximum jail term is three years. Statutory fines range from a minimum of 50,000 to a maximum of 200,000 rupees.

·         Section 120B read with Section 420 of the Information Technology Act, 2000, The Information Technology Act provides for punishment with up to 3 years of imprisonment and fines up to Rs 2 lakhs for illegal online distribution of copyrighted content.

·         Sections 468 and 471 of Indian Penal Code

Saturday, October 17, 2020

Chain of Custody about Digital Evidences

 For electronic evidence to be admissible, it must comply with the ‘best evidence rule’ and ‘chain of custody’ must be so that rules out any tampering. The chain of custody in digital forensics can also be referred to as the forensic link, the paper trail, or the chronological documentation of electronic evidence. It indicates the collection, sequence of control, transfer, and analysis. It also documents each person who handled the evidence, the date/time it was collected or transferred, and the purpose for the transfer.


Chain of custody requires to establish positively the possession of an item of evidence from time it is collected till the time it is used in court. In order to preserve digital evidence, the chain of custody should  span  from the first point of data collection, through examination, analysis, reporting, and the time of presentation to the Courts. 

In order to ensure that the chain of custody is as authentic as possible and enabled forensics run on the evidences to stand in court, the following steps can be followed:

·         Work with copies of the digital evidence as opposed to the original.

·         Photos of physical (electronic) evidence establish the chain of custody and make it more authentic.

·         Take screenshots of digital evidence content

·         Document date, time, and any other information of receipt. - Recording the timestamps of whoever has had the evidence allows investigators to build a reliable timeline of where the evidence was prior to being obtained.

·         Inject a bit-for-bit clone of digital evidence content into the forensic computers. 

·         Creation and preservation of MD5 Hashes - Performing a hash test ensures that the data obtained from the previous bit-by-bit copy procedure is not corrupt and reflects the true nature of the original evidence.

Friday, October 9, 2020

Limitations in Cyber Laws, and Legal Issues to prove evidences

The IT Act 2000 is sometimes a complex document to understand. The original legislation was passed by the parliament in a hurry without enough public debate. This may have led to limitations creeping into the Act. Many problems of the act were amended by the amended act of 2008. Conviction in cases of cybercrime in India continues to be abysmally low. One other impediment to the enforcement of cybercrime laws is the nature of evidence available in the custody of prosecution and the admissibility of same, during the course trial of cybercriminals. Cyber law proceedings require parties to meet different burdens of proof, the typical examples being beyond a reasonable doubt, clear and convincing evidence, and preponderance of the evidence. The limitations in cyberlaws and legal issues to prove cybercrime related evidences are enumerated below

  • Anonymous nature of the identity of cybercriminals

Cyber laws were principally enacted to prosecute cybercriminals, so, if the criminals are not identifiable, the law become a misnomer. The Internet is free and there is no perquisite that needs to be fulfilled, before a user can login to connect with anywhere and anyone across the globe. Digital technologies such as VPN, TOR, etc. provide ample opportunities for impersonation by way of identity disguise so as make it difficult if not impossible to ascertain who the perpetrator of cybercrimes is. Anonymization and IP spoofing is well advanced and cyber criminals can forgo identity easily. Further if the IP address is traced to a location, the next hurdle cannot be scaled as the identity of a cybercriminal is undisclosed to the owner or operator of Internet service provider. Communication are often routed via many servers which further compounds the possibility of cybercriminals being traced.

  • Jurisdictional challenges and lack of Uniform Global law

Cybercrimes span the global cyber space; by so doing, the extant laws and policies which are fragmented, national, regional or quasi international cannot possibly cope with the problems engendered by cybercrimes Location of the cybercrime may cross borders and hence local laws of the land may lead to limitation in application of law in India. Cybercrime is a global phenomenon and therefore the initiative to fight it should come from the same level. Each nation-state of the world has the authority to make laws binding on things and all persons within its geographical entity. Since multiple nation-states are enacting Cyber Crime laws on the same matter for different jurisdictions, conflict of laws is unavoidable. The extant laws also are not punitive enough when it comes to extent of the fine/incarceration for cybercrime acts. Hence even if the extant laws are enforced, it would make little or no impact on the cybercriminals as the laws cannot possibly deter criminals from their illegal acts. A cybercriminal may sit in the comfort of his home, office, café or wherever he chooses, with a desktop, laptop, tablet or phone connected to the Internet and carry out his illegal activities, that may impact a different geography and jurisdiction.

 

  • Extradition challenges for international cybercrime 

Cyber Crimes can span extra-territorial and intra-territorial situations. A court may lack the geographical jurisdiction. Even if a cybercriminal is clearly identified but he is situated in another country aside from where the victim is domiciled, the court of the forum cannot effectively try such a criminal as the court lacks jurisdiction geographically. Extradition of criminals to bring them within jurisdiction is also fraught with its own challenges. This includes challenges such as the double criminality requirement and extradition treaty between countries. Multiple countries such as Austria, Brazil, Japan, France, etc. have in their laws, jurisdiction to conduct trials over their nationals for offences committed abroad. Further processes of returning criminals are overly cumbersome, time consuming and costly.

 

·         Multiple enactments covering Cybercrime

Information Technology Act (IT Act), 2000 is not the singular enactment covering cybercrime in India. The Indian Penal Code (IPC) could also relied upon for cybercrimes related prosecution.: hacking, data theft, virus attacks, denial of service attacks, illegal tampering with source codes including ransomware attacks could be prosecuted under S.66 r/w S.43 of the IT Act covers DDOS, Data Theft, Hacking, Virus and ransomware. Cases of SIM card cloning or Bank Card duplication with intent to cause wrongful loss or wrongful gain can be prosecuted under IPC provisions (S.463 to S.471 IPC, as applicable). IPC also have overlap for cases against identity theft (IT Act 2008 - S.66C) or cheating by impersonating online (IT Act 2008 - S.66D). Similar there are other overlapping laws for example S.67A and S.67B also provide for prosecution of pornography and child pornography respectively. In case of the latter, the provisions of the Prevention of Children from Sexual Offences Act, 2012 (POCSO) may also be invoked. These multiple enactments have varying levels of prosecution and applying the wrong section/law can lead to limitations.

 

·         Hesitation to report offenses

One fatal drawbacks of the Act have been the cases going unreported. Cases reported have long closure lifetimes and there have been reported cases where police have wielding the rod and harassed innocents, preventing them from going about their normal cyber business. There is also a lack of awareness related to cybercrimes amongst the masses and hence people do not report offenses. Companies to evade possibilities of liabilities and public exposure and reputational impacts also tend to underreport cybercrimes.  If only the people are vigilant about their rights, can the law protect their rights.

  • Trained Police Force

The present form of police system and many police officials are not familiar with the cybercrimes and they need training to be familiar with the “Modus operandi” of cybercrimes. Though the existing relevant act is comprehensive legislation but from the practical point of view there are some shortcomings in the errant form of the act. At times it becomes difficult to test the veracity of electronic evidences. For ‘electronic evidence’ to be admissible, it must comply with the ‘best evidence rule’ and ‘chain of custody’ must be so that rules out any tampering. Doing this at ground level where police may not have the resources is difficult. There is a lack of standard documented procedures for searching, seizing of digital evidence and standard operating procedures for forensic examination of digital evidence and this contributes to fewer convictions in cybercrimes.

  • Secondary electronic evidence

Electronic Evidence under
Indian Evidence Act, 1872 allows for electronic evidence as primary method for evidence if the electronic records are certified by a person occupying a responsible official position. However there are few gaps which are still unresolved as what would be the fate of the secondary electronic evidence seized from the accused wherein, the certificate u/s 65B of Evidence Act cannot be taken and the accused cannot be made witness against himself as it would be violative of the Article 19 of the Constitution of India.

 

  • Challenge regarding the nature of evidence

 

Unlike in terrestrial crimes where physical evidence could be presented to the court with the view of securing conviction of the accused, physical evidence is rare in cybercrime prosecution. Digital logs and evidence are footprints on the computers used by the criminals and traces left on the Internet; the nature of these proofs may have little evidential value. Mere examination by inexperienced investigators may contaminate or out rightly damage digital evidence

The Priority Gap: When Patchability Does Not Equal Protection

Vulnerability management often fails at the point where security mandates collide with IT operations, creating a Priority Gap between vulne...