Friday, October 9, 2020

Limitations in Cyber Laws, and Legal Issues to prove evidences

The IT Act 2000 is sometimes a complex document to understand. The original legislation was passed by the parliament in a hurry without enough public debate. This may have led to limitations creeping into the Act. Many problems of the act were amended by the amended act of 2008. Conviction in cases of cybercrime in India continues to be abysmally low. One other impediment to the enforcement of cybercrime laws is the nature of evidence available in the custody of prosecution and the admissibility of same, during the course trial of cybercriminals. Cyber law proceedings require parties to meet different burdens of proof, the typical examples being beyond a reasonable doubt, clear and convincing evidence, and preponderance of the evidence. The limitations in cyberlaws and legal issues to prove cybercrime related evidences are enumerated below

  • Anonymous nature of the identity of cybercriminals

Cyber laws were principally enacted to prosecute cybercriminals, so, if the criminals are not identifiable, the law become a misnomer. The Internet is free and there is no perquisite that needs to be fulfilled, before a user can login to connect with anywhere and anyone across the globe. Digital technologies such as VPN, TOR, etc. provide ample opportunities for impersonation by way of identity disguise so as make it difficult if not impossible to ascertain who the perpetrator of cybercrimes is. Anonymization and IP spoofing is well advanced and cyber criminals can forgo identity easily. Further if the IP address is traced to a location, the next hurdle cannot be scaled as the identity of a cybercriminal is undisclosed to the owner or operator of Internet service provider. Communication are often routed via many servers which further compounds the possibility of cybercriminals being traced.

  • Jurisdictional challenges and lack of Uniform Global law

Cybercrimes span the global cyber space; by so doing, the extant laws and policies which are fragmented, national, regional or quasi international cannot possibly cope with the problems engendered by cybercrimes Location of the cybercrime may cross borders and hence local laws of the land may lead to limitation in application of law in India. Cybercrime is a global phenomenon and therefore the initiative to fight it should come from the same level. Each nation-state of the world has the authority to make laws binding on things and all persons within its geographical entity. Since multiple nation-states are enacting Cyber Crime laws on the same matter for different jurisdictions, conflict of laws is unavoidable. The extant laws also are not punitive enough when it comes to extent of the fine/incarceration for cybercrime acts. Hence even if the extant laws are enforced, it would make little or no impact on the cybercriminals as the laws cannot possibly deter criminals from their illegal acts. A cybercriminal may sit in the comfort of his home, office, café or wherever he chooses, with a desktop, laptop, tablet or phone connected to the Internet and carry out his illegal activities, that may impact a different geography and jurisdiction.

 

  • Extradition challenges for international cybercrime 

Cyber Crimes can span extra-territorial and intra-territorial situations. A court may lack the geographical jurisdiction. Even if a cybercriminal is clearly identified but he is situated in another country aside from where the victim is domiciled, the court of the forum cannot effectively try such a criminal as the court lacks jurisdiction geographically. Extradition of criminals to bring them within jurisdiction is also fraught with its own challenges. This includes challenges such as the double criminality requirement and extradition treaty between countries. Multiple countries such as Austria, Brazil, Japan, France, etc. have in their laws, jurisdiction to conduct trials over their nationals for offences committed abroad. Further processes of returning criminals are overly cumbersome, time consuming and costly.

 

·         Multiple enactments covering Cybercrime

Information Technology Act (IT Act), 2000 is not the singular enactment covering cybercrime in India. The Indian Penal Code (IPC) could also relied upon for cybercrimes related prosecution.: hacking, data theft, virus attacks, denial of service attacks, illegal tampering with source codes including ransomware attacks could be prosecuted under S.66 r/w S.43 of the IT Act covers DDOS, Data Theft, Hacking, Virus and ransomware. Cases of SIM card cloning or Bank Card duplication with intent to cause wrongful loss or wrongful gain can be prosecuted under IPC provisions (S.463 to S.471 IPC, as applicable). IPC also have overlap for cases against identity theft (IT Act 2008 - S.66C) or cheating by impersonating online (IT Act 2008 - S.66D). Similar there are other overlapping laws for example S.67A and S.67B also provide for prosecution of pornography and child pornography respectively. In case of the latter, the provisions of the Prevention of Children from Sexual Offences Act, 2012 (POCSO) may also be invoked. These multiple enactments have varying levels of prosecution and applying the wrong section/law can lead to limitations.

 

·         Hesitation to report offenses

One fatal drawbacks of the Act have been the cases going unreported. Cases reported have long closure lifetimes and there have been reported cases where police have wielding the rod and harassed innocents, preventing them from going about their normal cyber business. There is also a lack of awareness related to cybercrimes amongst the masses and hence people do not report offenses. Companies to evade possibilities of liabilities and public exposure and reputational impacts also tend to underreport cybercrimes.  If only the people are vigilant about their rights, can the law protect their rights.

  • Trained Police Force

The present form of police system and many police officials are not familiar with the cybercrimes and they need training to be familiar with the “Modus operandi” of cybercrimes. Though the existing relevant act is comprehensive legislation but from the practical point of view there are some shortcomings in the errant form of the act. At times it becomes difficult to test the veracity of electronic evidences. For ‘electronic evidence’ to be admissible, it must comply with the ‘best evidence rule’ and ‘chain of custody’ must be so that rules out any tampering. Doing this at ground level where police may not have the resources is difficult. There is a lack of standard documented procedures for searching, seizing of digital evidence and standard operating procedures for forensic examination of digital evidence and this contributes to fewer convictions in cybercrimes.

  • Secondary electronic evidence

Electronic Evidence under
Indian Evidence Act, 1872 allows for electronic evidence as primary method for evidence if the electronic records are certified by a person occupying a responsible official position. However there are few gaps which are still unresolved as what would be the fate of the secondary electronic evidence seized from the accused wherein, the certificate u/s 65B of Evidence Act cannot be taken and the accused cannot be made witness against himself as it would be violative of the Article 19 of the Constitution of India.

 

  • Challenge regarding the nature of evidence

 

Unlike in terrestrial crimes where physical evidence could be presented to the court with the view of securing conviction of the accused, physical evidence is rare in cybercrime prosecution. Digital logs and evidence are footprints on the computers used by the criminals and traces left on the Internet; the nature of these proofs may have little evidential value. Mere examination by inexperienced investigators may contaminate or out rightly damage digital evidence

No comments:

Post a Comment

The Priority Gap: When Patchability Does Not Equal Protection

Vulnerability management often fails at the point where security mandates collide with IT operations, creating a Priority Gap between vulne...