Showing posts with label Intelligence Gathering Skills Development In India. Show all posts
Showing posts with label Intelligence Gathering Skills Development In India. Show all posts

Saturday, November 12, 2011

Indian Counter Terrorism Capabilities Needs Rejuvenation

Terrorism is a serious problem for India and so far Indian counter terrorism responses are far from satisfactory. Whether it is traditional terrorism or cyber terrorism, India is lagging far behind. Unfortunately, a tragedy is always needed in India to wake up Indian government temporarily.

Once the tragedy is over, the concerns for national security and cyber security also subsides. On the contrary, in the name of national security and cyber security, corruption, myopic vision and e-surveillance are the only chosen options by Indian government. If you add the fact of turf war between various Indian ministries and departments, the chaotic picture of Indian national security in general and counter terrorism capabilities in particular emerges very clearly.

There is no second opinion about the fact that intelligence gathering is an essential part of national security of India. However, intelligence gathering skills developments in India are far from satisfactory. Naturally, India cannot fight with terrorism and cyber attacks with the present intelligence infrastructure of India. The present intelligence infrastructure of India is in big mess.

The intelligence infrastructure of India needs urgent rejuvenation. It is high time to move away from mere lips services and political statements and to move ahead in the direction of developing counter terrorism capabilities. We have an obvious but unresolvable terrorism dilemma in India.

With the growing use of social media by cyber criminals and terrorists, the intelligence agencies world over are engaging in open source intelligence through these social media and platforms.

Indian intelligence agencies must develop not only open source intelligence capabilities in India but they must also learn how to deal with highly sophisticated encryption usages. By limiting their capabilities to a weak encryption usage limited 40 bits encryption alone, this aim is absolutely frustrated. We must formulate a well drafted encryption policy of India that covers all the possible uses and prevention of the abuses of encryption.

India has been ignoring all these issues for many decades. It is high time to think about these issues and do some actual and hard core work in this regard.

Thursday, June 16, 2011

Encryption Service Providers Would Not Be Banned In India

Encryption related issues have always posed problem for our intelligence agencies and law enforcement agencies. Unable to deal with the encrypted services, the intelligence and law enforcement agencies of India tried to adopt the next possible approach. They decided to take the easier route of eavesdropping and e-surveillance instead of developing the cyber skills.

Naturally, the threats to ban encryption service providers like research in motion’s (RIM) Blackberry, Gmail, Skye, etc was the measure of last resort for our central home ministry. However, home ministry of India did not realise the effect of this decision and now this decision seems to be haste one.

A government panel set up to examine security threats regarding 15 forms of communications that cannot be tracked by law enforcement agencies here, has recommended that no service be banned purely on the grounds that it cannot be monitored.

It has recommended that in the short term, India should force operators who offer such services to either locate servers in the country or share encryption keys with security agencies and assist security agencies here in monitoring these services.

As a long-term solution, the committee has recommended that the upcoming Central Monitoring System (CMS) be made capable of intercepting any form of communication service offered within the country.

It has also endorsed the telecom ministry's stance that the ultimate solution should involve intelligence agencies building up capabilities indigenously to monitor and intercept these technologies. The panel has also added that security agencies must avail the help of companies to build such capabilities.

The committee has said that security agencies must first check whether monitoring solutions are available in other counties before threatening to ban any specific communication service.

Before banning or blocking of encrypted communication impact on business and industry, e-commerce, e-governance, e-medicine, e-health, passport services etc should be taken into consideration. Further, banning or blocking services without providing an alternative may have international reactions and could affect other Indian industries such as BPO and IT outsourcing.

The government panel, with members from different ministries, including telecoms and IT, has also recommended that India raise its encryption levels from the present 40 bits to 256 bits, which is the standard in Europe and the US. Most western countries do not allow financial transactions on the internet through computers and mobile handsets, if the encryption level is less than 128 bits. India on the other hand does not legally allow encryptions beyond the 40-bit on the grounds that its security agencies lacked the technological capabilities to monitor data transfers on the internet when the coding is beyond this limit.

However, the Home Ministry and Intelligence Bureau (IB) whose members were part of the panel, have not signed these recommendations and have given their dissent note. The IB has said the recommendations by the panel shift the onus on encryption and decryption from mobile phone companies to the 'designated agency' (CMS) authorised by the home ministry, when 'current experience was that government agencies were unable to track such services'. It has also pointed out that it may be impossible to persuade foreign players to locate servers in India or share encryption keys with security agencies here as recommended by the panel.

India needs to upgrade its intelligence infrastructure that is in real mess. Intelligence agencies need to develop intelligence gathering and analysis skills so that situations like the present one can be taken care of.

Finally, there are no legal frameworks for intelligence agencies, law enforcement agencies, data protection, privacy protection and data security. These legal frameworks must be at place so that legal and constitutional intelligence gathering can be taken place. India has to cover a long gap before all these requirements and capabilities are developed.