5 Indians in US$ 200 million Credit Card fraud

5 Indians are amongst the persons charged in US in a massive credit card fraud said to involve US $ 200 million loss to various credit card holders. Details in TOI

Among those charged are Babar Quereshi (59), Ijaz Butt (53), Raghbir Singh (57), Mohammad Khan (48), Sat Verma (60), Vijay Verma (45), Tarsem Lal (74) and Vinod Dadlani (49). Each of them faces a maximum penalty of 30 years in jail and a $1 million fine. All are residents of New Jersy US.

The fraud appears to be an Indo-Pak cooperative bid !

While Pakistan is notorious as a Terror center, India sadly appears to be gaining in Cyber Crime related notoriety.  It is necessary for all responsible Netizens in India to ensure that the situation does not go out of hand. This requires urgent measures from the Government towards Cyber Security.

I reiterate that the Government of India headed by Dr Man Mohan Singh and the Ministry of Communications and Information Technology headed by Mr Kapil Sibal are guilty of not addressing issues such as operationalizing Cyber Appellate Tribunal and are showing their apathy towards controlling Cyber Crimes in India.

Related article in TOI on “Dexter”malware

Naavi

Posted in Cyber Crime, ITA 2008 | Leave a comment

Mobile Apps Company fined $800,000

The Federal Trade Commission (FTC) of USA has fined a two year old Mobile Apps manufacturing company “Path” a sum of US$ 800,000 for violating the privacy of US Citizens. In particular the Social Networking Apps manufacturer was charged with violating the privacy of children since it collected personal information on underage users including any person in the user’s address book.

The incident is a serious notice to all mobile apps manufacturers to offer a strict “opt out” option by default and a proper check on the identification of children.

Identifying whether a person is an adult or a minor is a huge challenge and companies need expert advise from appropriate Privacy Consultants to steer clear of the risks indicated by the above incident.

Related Report

Naavi

Posted in Cyber Law, Information Assurance, TELCO | Leave a comment

Women’s protection Ordinance clashes with ITA 2008

Government of India has promulgated an ordinance titled “The Criminal Law (Amendment) Ordinance, 2013” following the public outrage on the the recent incident in which a girl was gangraped in a Delhi bus. The Ordinance has initiated some provisions to strengthen the laws against sexual assault on women including acid attacks, rape and rape leading to death or reduction of the victim to vegetable status etc.

Apart from some of the provisions that directly relate to physical society offences, there are at least two provisions which directly conflict with the provisions of ITA 2008.

One of the conflicting provisions is “voyeurism” which conflcits with Section 66E of ITA 2008 and the other is on “Stalking” which conflicts with Section 66A.

The amended IPC section 354C states as follows.

Section 354C: voyeurism:

“Whoever watches, or captures the image of, a woman engaging in a private act in circumstances where she would usually have the expectation of not being observed either by the perpetrator or by any other person at the behest of the perpetrator shall be punished on first conviction with imprisonment of either description for a term which shall not be less than one year, but which may extend to three years. and shall also be liable to fine, and be punished on a second or subsequent conviction, with imprisonment of either description for a term which shall not be less than three years, but which may extend to seven years, and shall also be liable to fine.

Explanation 1.- for the purpose of this section, “private act” includes an act carried out in a place which. in the circumstances,would reasonably be expected to provide privacy, and where the victim’s genitals, buttocks or breasts are exposed or covered only in underwear,or the victim is using a lavatory or the person is doing a sexual act that is not of a kind ordinarily done in public.

Explanation 2.- Where the victim consents to the capture of images or any act, but not to their dissemination to third persons and where such image or act is disseminated, such dissemination shall be considered an offence under this section.”

Section 66E of ITA 2008 on the other hand states

“Whoever, intentionally or knowingly captures, publishes or transmits the image of a private area of any person without his or her consent, under circumstances violating the privacy of that person, shall be punished with imprisonment which may extend to three years or with fine not exceeding two lakh rupees, or with both”

For the first time offender Section 66E has a harsher punishment where as for the second time offender, IPC 354C will be harsher. It is not clear however if a person can be punished for the first time under ITA 2008 and for the second time under IPC. Also section 66E addresses capture as well as publishing and transmission of a picture of a private part of a person. If however the publishing and transmission involves content which falls under Section 67, 67A or 67B (Obscenity) then there would be harsher punishments under ITA 2008.

In the IPC section however, the offence relates to “watching and capturing” a “Private act” and the punishment may be as little as one year in the first instance. “Watching a private act” falls only under IPC, where as “Capturing” falls under both IPC and ITA2008 “Publishing” and “Transmission” falls only under ITA 2008.

Section 354D of the proposed ordinance states as under:

354D: Stalking:

(1) Whoever follows a person and contacts or attempts to contact such person to foster personal interaction repeatedly, despite a clear indication of disinterest by such person, or whoever monitors the use by a person of the internet, email or any other form of electronic communication, or watches or spies on a person in a manner that results in a fear of violence or serious alarm or distress in the mind of such person, or interferes with the mental peace of such person, commits the offence of stalking:

Provided that the course of conduct will not amount to stalking if the person who pursued it shows
(i)that it was pursued for the purpose of preventing or detecting crime and the person accused of stalking had been entrusted with the responsibility of prevention and detection of crime by the state; or
(ii) that it was pursued under any law or to comply with any condition or requirement imposed by any person under any law. or
(iii) that in the particular circumstances the pursuit of the course of conduct was reasonable.

(2) Whoever commits the offence of stalking shall be punished with imprisonment of either description for a term which shall not be less than one year but which may extend to three years, and shall also be liable to fine.’

Section 66A has been extensively discussed on this site (Refer : Misconceptions about Section 66A). It applies to “Persistent” sending of emails/messages to create annoyance which is the effect of “Stalking”. The punishment is 3 years.

Section 354 D overlaps with Section 66A since it specifically refers to “Use of internet or email”. The punishment is between one to three years.

If the ordinance had been carefully drafted the overlapping of IPC with ITA 2008 could have been avoided. It may be noted that IPC ordinance is issued from the Ministry of Home Affairs and ITA 2008 is managed by Ministry of Communications and Information Technology. Unfortunately the two ministries perhaps had no consultation process which could have avoided the conflicts.

Naavi

Posted in Uncategorized | Leave a comment

Advisory on Section 66A

A copy of the advisory sent by the Ministry of Communications and Information Technology to State Governments following the recent controversies on arrest of Palghar ladies is now available here

The advisory is issued by the Group Coordinator & Director General, Department of Electronics and Information Technology, Government of India to the Chief Secretaries and DGPs of all States and Union Territories.

According to the Advisory

“State Governments are advised that as regard to arrest of any person in complaint registered under section 66A of the Information Technology Act 2000, the concerned police officer of a police station under the State’s jurisdiction may not arrest any person until he/she has obtained prior approval of such arrest from an officer not below the rank of the Inspector General of Police in the metropolitan cities or af an officer not below the ran of Deputy Commissioner of Police or Superintendent of Police at the district level, as the case may be.

It is requested that appropriate instructions may be issued in the matter to all concerned”

Since the advisory is in conflict with the provisions of Section 80 of ITA 2000/8 this advisory appears to be ultra-vires the Act.

Naavi

Posted in Cyber Crime, Cyber Law, ITA 2008 | Leave a comment

Dont be confused with iaadhaar.com or iaadhar.com

Cyber Squatting is a practice where some people register popular domain names or small typographic variations thereof with the object of attracting visitors. Some times it may be harmless to the visitor since the purpose may be to only generate advertisement revenue out of such stray visitors. But there is a potential risk of the site being misused for gathering personal information of visitors.

We have recently come across two websites iaadhar.com and iaadhaar.com both being “Confusingly similar” to the Government of India project of issuing Aadhar cards through UID authoity of India (UIDAI).

Both these sites are not related officially to UIDAI. Though the site iaadhaar.com provides information about the aadhaar registration process only and also provides a disclaimer, the iaadhar.com site is presently only a domain parking site.

It is necessary for the public not to misunderstand these as the official sites and part with any sensitive information about them. UIDAI is however is using a sub domainĀ http://eaadhaar.uidai.gov.in.

It is to address situations like these that naavi had way back in 2000 introduced a service which is still available at www.lookalikes.in.

It is preferable for UIDAI to place a possible disclaimer in its own site so that public are not at any time in future be misguided with cyber squatters resulting in identity thefts.

Screen shots: iaadhaar.com :: iaadhar.com::eaadhar.uidai.gov.in

Naavi

Posted in Uncategorized | Leave a comment

2.5 lakh Twitter passwords compromised

It is reported that about 2.5 lakh Twitter IDs with passwords have been compromised. It is also reported that Twitter has informed the affected users and asked them to change passwords.

Details in TOI

Posted in Cyber Crime, Privacy | Leave a comment