PayTM predicament could be a new “Me-Too” in Data Security

The developments regarding the PayTM extortion case is a grave development which has huge ramifications to the Indian corporate sector.

For records, PayTM case came to public light with a complaint filed by Mr Ajay Shekar Sharma, the brother of the PayTM CEO, Mr Vijay Shekhar Sharma, on 22nd October 2018 that an extortion claim has been made on Mr Vijay Shekar Sharma initially for Rs 30 crores and later negotiated down to rs 10 crores by a caller from Kolkata named Rohit Chomol, under the threat that some sensitive personal information is in their possession and the money is demanded in that context.

Following the preliminary investigation, three persons have been arrested and one more accused is to be apprehended. The arrested persons include Mrs Sonia Dhawan, Vice President Communications and Secretary of Mr Vijay Shekar Sharma, her husband Mr Roopak Jain and another employee by name Devendra Kumar.  All the three have been sent to Police remand. A fourth person namely Rohit Chomol who is supposed to have made the phone call for ransom is still to be apprehended.

The advocates of Sonia have claimed that this is a “Cover-up” and Sonia has been framed. They point out that she was a senior employee getting a salary  of Rs 80 lakhs per annum and shares worth Rs 10-15 crores in the Company and it was unthinkable that she would have jeopardized her career by the fraud. Police claim that Sonia’s husband had suffered losses in real estate business and was in need of money.

Mr Vijay Shekar Sharma has hinted that there could be larger conspiracy behind this attempt.

In the meantime, it is not clear what information if at all were stolen by Sonia and whether it was worth Rs 10-30 crores for extortion.

Did it involve PayTm customer data?… Mr Vijay says no…

If as Sonia’s lawyers say that she had stumbled on sensitive information following an investigation entrusted to her by Mr Vijay, they should also explain why was she suspected to betray the trust and  enough to be framed?

Police have seized a laptop and electronic information that could be evidence in the case which are yet to come to light.

Could there be business rivalry and espionage behind the controversy?

The Kolkata Link to the controversy and Mr Vijay Shekar being perceived as close to Mr Modi, the possibility that the stolen information included some communication with the Government agencies also indicate the suspicion that the “Tukde Tukde gang” could be behind a conspiracy to defame the Modi Government. I will not be surprised if the political opponents of Mr Modi jump from Rafeal to PayTm to continue their smear campaigns.

Nothing can be ruled out.

We are seeing an attempt in Bangalore where one actor is being targeted with a Me-Too allegation allegedly because of his BJP leanings. The crooked political brains can do anything to achieve their means and PayTM is a small fry for their designs.

We also have to keep in mind that the Pakistani friends of the political opponents may also have a specific grudge against PayTM because the company provided some details of Stone pelters to the Government recently in Kashmir which would not have gone down well with the sympathizers of the anti national elements. It could be the correspondence between the Government and Company in this regard which Sonia (Not to be confused with another more illustrious political character) could have valued at Rs 30 crores.

Like many other financial crimes, which ever way this is resolved, the immediate reputational and internal de-motivational impact on PayTm is huge enough to be called a “Setback” for the company when it was implementing certain expansion projects.  Possibility of business rivalry fuelling the controversy cannot be ruled out.

We keep our fingers crossed and await further developments as they emerge. But there is no doubt that this incident has the potential to be a new “Me-Too movement in Data Security” where any data breach incident could cause upto 4% of Global turnover of a Company in terms of administrative fines besides the other costs which could virtually kill a company.

It highlights that “Trust” is the most scarce commodity to day in the “Greedy world” and Information Security managers cannot trust even a personal secretary with a Rs 80 lakhs package to keep the secrets. The lack of “Ethics” in our young generation and the general corrupt environment that this society represents indicate that there could be many more such internal trusted employees turning into rogues and first demanding un-justified rewards while in service or under severance pay or resort to such extortion.

The solution for this should start with a revamping of our education system that should inculcate “Moral and Ethical Standards of Life” before teaching them  “Innovative Disruption” and “Ethical Hacking”.

(P.S: More discussions will follow)

Naavi

 

Related Articles:

At inc42.com : Firstpost.com  : At Wire.com


Views expressed here are the personal views of Naavi and does not reflect the views of any organization that he may be associated with.


Posted in Cyber Law | Tagged , , , | Leave a comment

Bitcoin is Illegal… says NASSCOM chief

In a significant development, Hindu has reported that that the Nasscom President Debjani Ghosh has stated that from Nasscom perspective it was very clear that crypto currencies were illegal.

Some people  refuse to see the writing on the wall mostly because it hurts them directly. Just because we wish so, Bitcoin (or any other Crypto Currency) cannot become a legal tender and replace INR as many may wish. Neither the Nasscom, nor the RBI nor the Finance Ministry can change the law unilaterally.

The undersigned was the first person in India way back in 2013 who declared that Bitcoin should be treated as a “Commodity” and it is recognized as an electronic document under ITA 2000/8. But this does not make it eligible to be a Currency replacement for INR.

The word “Crypto” can be associated with a “Commodity” and we can call something a “Crypto commodity”. But it cannot be associated with the word “Currency”. The moment we do, it becomes an illegal commodity.

In the early days of Bitcoin in India, I have tried to convince the Bitcoin promoters including people like Sathvik to find a way by which we can have a “Cyber Law Compliant Crypto currency”. But every body said that the very foundation of Bitcoin is its “Anonymity” and refused to listen. Even about an year back when I happened to meet Mr Sathvik in Bangalore, I had hinted that Bitcoin has become a Digital Black Money and has no future.

But, as we could see even after the arrest of Mr Harish, Sathvik continued to give statements as if all of us were wrong and he alone was right. He was carried away in the rhetoric “What is not legal is not necessarily not illegal”. But Bitcoin was illegal from many perspectives and opening an ATM and announcing a plan to set up similar ATMs elsewhere in India catering to 30 different Crypto currencies etc was height of arrogance.

Perhaps he did not bargain for one honest Police officer to take note of this and act in a manner which they are expected to do.

It is shameful that now there are several supporters of Bitcoin who have come up to criticize the Police for their prompt action, even while I would like the FIR to be hardened further.

When Mr Abhinav Srivatsava was arrested last year for an Aadhaar related complaint, I was the only person who jumped to say that the arrest should not have taken place etc.. But the current case is different. It is not that a 32 year old Tumkur based engineer from a middleclass family made a successful entry to the IT world and is now in trouble. If it was only that, he would have had even my sympathies. But it is whether the Crypto Currency should be rooted out from India or not.

I am strongly for eliminating all Crypto Currencies like Bitcoin (Currencies not issued by the authorities like RBI) and therefore I am happy about the action taken so far.

I am aware that there are many who would support Mr Sathvik not because they love him but because they love Bitcoin since it helps them keep their black money more efficiently than in bundles of Rs 2000/- currency notes.

I would not be surprised if they continue to support Bitcoin and try to run down the Police. The first indication of such an attempt would be visible if the current IO is changed. I hope it would not happen.

In this context the words of wisdom from Nasscom President should seal the controversy once for all.

With apologies to all my friends who are feeling uncomfortable with the developments and the stand that I have personally taken in this regard.

Naavi

Also refer: cointelegrah.com

Posted in Cyber Law | Tagged | Leave a comment

Who is lying? Unocoin Advocates ? or the Press?

Over the last few days the arrest of the executives of Unocoin the Bitcoin trading company for installing a “Bitcoin ATM” in Bangalore is making news. There are views and counter views on whether it was fair to arrest the two executives, whether any offence was committed etc. In this context it is interesting to observe how the representatives of the Company are defending themselves in the Public with statements which either make either them or the Press which has quoted them earlier liers.

The public wants to know who is lying.

According to this report in Deccan Herald, the legal adviser of Unocoin, Mr Swaroop says “…The general public referred to  the kiosk as an ATM, which perhaps added to the misunderstanding and police action…”The Company never termed it an ATM”.

Mr Anand Swaroop also said “The kiosk had been set up but wasn’t operational. “There are certain bugs which we are addressing and the kiosk isn’t live yet,”

But, look at the photograph above and the word “ATM” is written all over it. So, it is not the public or the press to be blamed. The Company wanted it to be called a “Bitcoin ATM”.

Now see the words spoken by Mr Sathvik in his interview  

He says “We have completed our trials on Thursday afternoon. We have completed all the procedures. It will go live on Monday morning,” (Ed: This interview was published on October 19th and “Monday” referred to 22nd October 2018).

Sathvik also explained in his interview credited to Mr Furquan Moharkhan of the DH News Service, that

“…The company has made adjustments to a normal bank ATM to equip it for cryptocurrency transactions….We have purchased the same ATM machine that banks will install for customers, but we have modified the software to contact our servers,” .

He also confirmed

“In order to deposit money into the ATM, KYC compliant customers have to enter their user ID and the OTP that they receive as an SMS on their registered mobile number. The user will then confirm his account details and deposit the funds into the machine. Their Unocoin account will be updated with the deposited funds immediately. And these funds can be used to buy Bitcoin or Ethereum, or on Unodax place BID orders on 30 different crypto assets.”

Mr Sathvik was fully aware of the views of the regulators in India and conspired to beat the system as his words below indicates.

“Due to the RBI’s recent notification on ‘Prohibition on Dealing in Virtual Currencies’, Unocoin’s banking relationships were disrupted. Since then, the company has been in the process of deploying new mechanisms for rupee deposits and withdrawals. The company is also planning two more such ATMs in Mumbai and Delhi.”

It is therefore unbecoming of the advocates representing the Company to now claim that it was only a “Cash Machine” to deposit and withdraw money from the Company” and it was not meant to be a “Bitcoin Converter”.

The machine was meant for people to deposit cash into the Company, authorize the company to buy any of the 30 Crypto currencies from other exchanges and credit it to the Crypto wallets. The customer of Unocoin may under go a simple verification based on a SIM card which may or may not be KYC compliant, but the counter party which sells the crypto currency is unknown and untraceable.

Similarly, when the Unocoin customer sells his the Crypto Currency, the buyer who pays cash is not known.

The counter parties who sell or buy may come from abroad and hence the machine will facilitate conversion of INR to Foreign Exchange.

Business Standard headlined its report on October 20, as “Soon you can pay cash and get bitcoin, other cryptocurrencies at nearby ATM”

This report also was based on an interview with Mr Sathvik and leaves one in no doubt of what the Company intended to do and exposes the lies that are being peddled now to defend the promoters.

Police have booked the case under Section 66 of ITA 2000, Section 120b, 420, 465, 474 and 471 of IPC.  Perhaps more sections can be added under FEMA and RBI Act. There is a conspiracy, an attempt to cheat and violation of Foreign Exchange regulations etc. Hence Police has a strong case particularly under IPC though the evidences are in electronic form. The website of Unocoin would also be a key evidence.

The Google Apps

The ATM has a prominent display of a QR code which is for downloading an App. If we search the Google play store, we find the following two Apps provided by Unocoin.

The Unocoin App  is a wallet. The details about Unocoin mentioned here are as follows:

About Unocoin

Unocoin is India’s leading Crypto asset & Blockchain company with over a million customers. We make it easy to buy, sell, store, use & accept crypto assets securely in India. 

• Raised 2.5 million USD in pre-series A funding from top investors like Blume Ventures, ah! Ventures, Mumbai Angels, Boost VC, Digital Currency Group, FundersClub, Future Perfect Ventures, Huiyin Blockchain Ventures.
• Featured among the top 20 out of 350 companies in The FinTech 20: India list.
• Unocoin is a member of NASSCOM.
• Picked amongst top 30 technology startups for Tech30 2017 by YourStory India.

Unocoin has one mission – “Bringing bitcoin to the billions”.

Highlights

– Buy/Sell bitcoin/ether instantly
– Low transaction fees
– Consolidated wallet for crypto-holdings
– Live price tracker widget
– Transact (Send/Request) in bitcoin/ether
– Accept/Request bitcoin/ether
– Deposit/Withdraw INR
– Mobile/DTH Recharge with bitcoin
– Offers pertaining to bitcoin in India
– Latest updates/news from Unocoin
– Bitcoin/Ether SBP subscription
Hedge against the market volatility using Unocoin SBP (Systematic Buy Plan) module to automate bitcoin buying with fixed amount and frequency.

– View Merchant transactions
Enabling merchant gateway would provide complete history of merchant transactions processed on all the paired devices.

– Earn free bitcoin referring Unocoin to your friends

What is bitcoin?

• Bitcoin is often referred to as “A peer-to-peer decentralised digital currency”.
• Bitcoin was first invented in 2009 by a pseudonymous identity called ‘Satoshi Nakamoto’.
• Bitcoin is the pioneer of cryptoassets – type of digital assets in which advanced encryption techniques are used to regulate the generation of new token units and verify the transfer of funds, operating independently of a central bank.
• Bitcoin is set to solve a major problem of digital era – “trust” opening up avenues of new industries.

To learn more about Bitcoin: https://wikipedia.org/wiki/Bitcoin

Unocoin blog for latest updates

Keep updated with the latest trends, bitcoin & blockchain happenings and merchant partnerships for bitcoin payments at https://blog.unocoin.com and get involved in hot discussions in the Crypto asset space.

For important alerts, please look forward to https://news.unocoin.com

Youtube channel for help

Head on to our YouTube Channel ( https://m.youtube.com/channel/UCxTztdOn_HjYhMGiT8su6Bg) for more detailed step-by-step tutorials on availing services from https://unocoin.com along with the happening in the bitcoin space.

Support details of Unocoin

For further support please go to https://www.unocoin.com/support
Mail: support@unocoin.com
Toll free number: 1800-103-2646 (24/7 Services)

Conditions Apply
For detailed terms & conditions, please refer: https://www.unocoin.com/post/98

The Unodox is an Exchange App the details of which are presented as follows:

About Unodax

Unodax is India’s Leading Digital Asset Exchange, powered by Unocoin with over a million customers. We make it easy to buy, sell, store, use & accept cryptoassets(BTC, ETH, XRP, LTC, BCH, BTG…) securely in India. 

• Raised 2.5 million USD in pre-series A funding from top investors like Blume Ventures, ah! Ventures, Mumbai Angels, Boost VC, Digital Currency Group, FundersClub, Future Perfect Ventures, Huiyin Blockchain Ventures.
• Featured among the top 20 out of 350 companies in The FinTech 20: India list.
• Unocoin is a member of NASSCOM.
• Picked amongst top 30 technology startups for Tech30 2017 by YourStory India.

Unocoin has one mission – “Bringing bitcoin to the billions”.

Highlights

– High-frequency order matching engine with an open order book
– Supporting multiple cryptoassets
– Transact (Send/Request) in cryptoassets
– Accept/Request cryptoassets
– Deposit/Withdraw INR
– Crypto Basket (place basket orders now)

Cryptoassets supported on the exchange:

Bitcoin: Bitcoin is peer-to-peer electronic cash for the Internet. It is fully decentralized, with no central bank and requires no trusted third parties to operate.
Ethereum: Blockchain based distributed computing platform featuring smart contract functionality.
Litecoin: Litecoin is a peer-to-peer digital asset that enables instant, near-zero cost payments to anyone in the world.
Ripple: The world’s only enterprise blockchain solution for global payments.
Bitcoin Cash: Continuation of the Bitcoin project as peer-to-peer digital cash forked from the Bitcoin blockchain ledger, with upgraded consensus rules that allow it to grow and scale.
Bitcoin Gold: Bitcoin Gold is a Hard Fork that allows you to mine Bitcoin with GPU. BTG implements a new PoW algorithm, Equihash, that makes mining decentralized again.
Civic: Civic provides blockchain-based, on-demand, secure and low-cost access to identity verification (IDV).
Tron: TRON is a world-leading blockchain-based decentralized protocol that aims to construct a worldwide free content entertainment system with the blockchain and distributed storage technology.

Crypto Basket:

Go a step further in placing an order with new weighted basket orders. Presenting ‘Crypto Basket’ on Unocoin Exchange – Read more about ‘Crypto Basket’ click here.

Unocoin blog for latest updates

Keep updated with the latest trends, bitcoin & blockchain happenings and merchant partnerships for bitcoin payments at https://blog.unocoin.com and get involved in hot discussions in the Crypto asset space.

For important alerts, please look forward to https://news.unocoin.com

Youtube channel for help

Head on to our YouTube Channel ( https://m.youtube.com/channel/UCxTztdOn_HjYhMGiT8su6Bg) for more detailed step-by-step tutorials on availing services from https://unocoin.com along with the happening in the bitcoin space.

Support details of Unocoin

For further support please go to https://www.unodax.com/contactus
Mail: support@unocoin.com
Facebook: https://www.facebook.com/Unocoin
Twitter: https://twitter.com/Unocoin

24/7 365 days support service.
Telegram: http://t.me/Unocoin_Group
Toll-free number: 1800-103-2646 (24/7 Services).

Conditions Apply
For detailed terms & conditions, please refer: https://www.unodax.com/termsofuse

The above details along with the information on the two websites unocoin.com and unodax.com and the related Youtube channels provide enough information on the activities of the company.

The Unocoin website has the following menu items with further details

Possibility of Tampering with the Evidence

I anticipate that Unocoin would be advised by its well wishers to immediately delete the contents of the Google Playstore as well as the website.

I therefore request the Police to immediately secure this evidence.

I also notify that if any persons including the advocates of Unocoin advise and get the website or playstore information deleted, it would be considered as a further offence under Sections 65 of ITA 2000/8 and Section 204 of IPC since they  are identified as “Evidence” in an investigation of a “Cognizable offence”. 

I also anticipate that there could be pressure on the honest investigating officers continuing the investigation and taking it up to the logical end and senior police officers should take care that this does not happen.

Once again, I appreciate the Police for their work so far.  According to the  statement of Mr S. Girish, DCP, who perhaps is the IO, they consider the ATM set up as a means of “Gambling”.

It is Economic Terrorism

But actually the offence is much more than this. The Bitcoin and Crypto Currency business is an “Offence Against the State”. It is an attempt to run a parallel economic system causing a destabilization of the economy. It is therefore an act of “Economic Terrorism” and has to be treated as such.

If according to the plans of the Company such ATMs had come up across the country, it would have meant that there would be a national chain of virtual havala centers and it would have created a huge blow to the fight against black money in India. This national impact of the intended business model has to be recognized and brought into the investigation.

Naavi

Posted in Cyber Law | Tagged , , , , | 2 Comments

Self Inflicted disaster strikes on Bitcoin Start ups

Today’s report in Times of India states that “Crypto, Startup players worry about action on Unicoin” 

This follows the news that the second co-founder of Unocoin namely Mr Sathvik Vishwanathan was also arrested following the arrest of another co-founder B V. Harsih a few days back.  It is unfortunate that the company Unocoin and it’s promoters find themselves in this predicament.

However, it is necessary to point out that Naavi.org has been pointing out that the operations of Bitcoin in India is an undesirable activity and the way it was operated was always illegal.

The moment some body refers to Bitcoin as a “Currency”, they are committing an offence for which they can be arrested. When they call a vending machine a “Bitcoin ATM”, they are making another mistake for which they could be and are being arrested.

Whatever people say, Bitcoin is an open challenge to the national currency system and promotes conversion of currency into un-identifiable asset. The fact that it has a market abroad and some recognition by Governments is not a virtue. It makes Bitcoin as an “Unauthorized Foreign Currency” and directly in violation of FEMA.

Naavi has personally taken up a crusade against Bitcoin and has tried to move every law enforcement institution without sparing even Mr Modi. We are therefore happy that at last the Bangalore Police acted when they were challenged with the ATM concept.

We need to see how this case will be followed up, but the beginning has been good.

The Start up industry should have noted that last Diwali there was a full page advertisement asking investors to invest in Bitcoin instead of Gold. There has been advertisements for recruitment of a CEO also for Bitcoin operations in Bangalore both of which were vehemently opposed by Naavi.

Despite this, the argument “RBI has not said Bitcoin is illegal. It has only said it is not legal, the two are different..etc” were given out to continue doing this business of money laundering through Bitcoins.

I will therefore be happy that finally a lesson is being driven home to the “Technology Intoxicated Entrepreneurs” who think that “Disruption” means “Challenging the current legal and economical structure” of the society.

I am sorry that I will be hurting the sentiments of many of my friends who have their hard earned money stuck in Bitcoins. But at least I can feel that I have warned them enough number of times and they had ignored my warnings.

These startups who are complaining now should have at least woken up when Zebpay ran out of the country but failed to do so.

Hence I consider this as a self inflicted disaster the Bitcoin entrepreneurs have inflicted on themselves. If they continue to ignore the developments and try to argue that Bitcoin is not illegal, Bitcoin is great for the economy etc.,even God cannot save them.

Naavi

Reference Articles

Also see:

Petition in Cryptocurrency case quashed

Now, CEO held for installing Cryptocurrency Kiosk

Legal or not? The curious case of “city’s bitcoin ATM”

Interview of Sathvik explaining the functioning of ATM

Posted in Cyber Law | Tagged | Leave a comment

Bitcoin ATM in Bangalore Closed… Kudos to Bangalore Police for Prompt Action

On 21st October 2018, we carried an article titled “Virtual Havala Center opens up in Bangalore. Are the Police…RBI and Arun Jaitely aware ?

This was followed up with necessary alerts being sent to law enforcement agencies in different places. Fortunately, at least one Kannada daily namely  Vijayavani took up the issue and published a story on 22nd October 2018.

It appears that the Police have taken prompt action and on 23rd itself moved in to arrest one of the co-founders of Unocoin, the Company that owned the ATM. A case of cheating and IT act violations has been booked against the operator B.V. Harish.

However, in a show of arrogance, the owners have given out a statement that shows that they may not stop their efforts and move the ATM to another State.

Police should have seized the ATM as it may contain evidence of some illegal transactions. At present the Company says that it has temporarily moved the machine some where.  As per this report in Bangalore Mirror , 

Police have said that

“They (ed: the company) did not have any licence from RBI, Sebi or any other agency to carry out the bitcoin transaction. They were running it without obtaining any trade license from the BBMP,”…users had been approaching the ATM after they received a 12-digit OTP for making the deposit or withdrawal. It was also pointed out that there was no indicators affixed at the kiosk to indicate the bitcoin exchange rate…”

In the meantime, Unocoin and its supporters are proceeding to continue their con game to lure gullible investors. A video on youtube highlights the views of the Company that “Mr Arun Jaitely says that Bitcoin is not legal …but has not said it is illegal…and it makes a huge difference..” etc.

This video indicates that the machine has been temporarily removed and will be back. The narrator projects it as a “Sad News” and it says that similar machines would be set up in Mumbai and Delhi.

It is clear that these videos are meant to project Bitcoin as a means of legit investment and Police should initiate action against such covert operators who are responsible for projecting a false information about Bitcoin and its legitimacy.

A word of appreciation is however due to the Bangalore Police (CCB) which took prompt action to get the ATM removed.

I hope any attempt to set up such ATMs in Mumbai and Delhi should be stopped forthwith.

Naavi

Posted in Cyber Law | Tagged , | Leave a comment

4th Annual INBA Privacy Summit 2018 in Bengaluru on October 25, 2018

The Indian National Bar Association is holding a day long event in Bengaluru on October 25, 2018 which is the “4th Annual INBA Privacy Summit”.

The tentative agenda is available here

If you are interested in more information about the event and participation, kindly visit www.privacysummit.in

Naavi

 

 

Posted in Cyber Law | Leave a comment