Showing posts with label Mobile Security In India. Show all posts
Showing posts with label Mobile Security In India. Show all posts

Wednesday, February 29, 2012

Mobile Cyber Security In India

Mobile phones have become ubiquitous these days. They are used for multiple purposes ranging from personal use to mobile banking. Cyber criminals have also realised the importance of mobile phones for committing cyber crimes and financial frauds. This is also the reason why malware writers are also writing mobile phone specific malware to steal confidential and sensitive information.

Mobile cyber security in India has become a cause of concern these days. Mobile phones are now proposed to be used for mobile banking and mobile governance in India. Naturally, we must ensure robust mobile cyber security in India. An electronic authentication policy of India can help in more active and secure mobile usages in India. Mobile governance and e-authentication in India are also closely related and with the proposed electronic delivery of services in India this is also a must have requirement.

For the time being we have no implementable electronic delivery of services policy of India though it may be in pipeline. Indian government is working in the direction of ensuring electronic delivery of services in India. In fact a legal framework titled electronic delivery of services bill 2011 (EDS Bill 2011) has also been proposed by Indian government.

Once the EDS Bill 2011 becomes an applicable law, governments across the India would provide electronic services through various modes, including mobile phones. This requires putting a robust and reliable mobile security infrastructure in India.

However, using of mobile phones for commercial and personal transactions in India is also risky. For instance, the mobile banking in India is risky as the present banking and other technology related legal frameworks are not conducive for mobile banking in India. Similarly, we do not have a well developed e-governance infrastructure in India. As a result India is still not ready for m-governance.

We at Perry4Law and Perry4Law Techno Legal Base (PTLB) believe that the biggest hurdles before the mobile related uses in India pertain to use of weak encryption standards and non use of mobile cyber security mechanisms in India. Absence of encryption laws in India has further made the mobile security very weak in India.

The ever evolving mobile malware are further increasing the woes of mobile users’ world wide. Recently 50 applications within Google’s official Android Market were found to be contaminated with DroidDream malware. The malware stole sensitive information like phone’s International Mobile Equipment Identity (IMEI) Number and the SIM card’s International Mobile Subscriber Identity (IMSI) number. It then sent it to a command-and-control server. Similarly, other spyware and bugs are also infecting mobile phones worldwide.

It is high time for India to seriously work upon mobile cyber security aspects as soon as possible. The policy decisions in this regard must be taken urgently and must be implemented as soon as possible.

Tuesday, August 23, 2011

Indian Encryption Policy Must Be Formulated

Encryption policy of India is long overdue but India has been slow in formulating this much needed policy. At the same time encryption is also a controversial issue in India that requires a balancing of conflicting interests of law enforcement requirements and personal privacy and security.

Provisions pertaining to encryption usage in India are scattered in various laws, rules and regulations of India. We do not have a centralised or dedicated legal framework for encryption related matters and this is hindering proper usage and innovation in the field of encryption in India.

The cyber law of India, as applicable through information technology act 2000 (IT Act 2000) has a single provisions in this regard. Section 84A of IT Act 2000 says that the Central Government may prescribe the modes or methods of encryption. Till now the Central Government has not prescribed any “modes or methods” of encryption usage in India.

We are compromising the cyber security of India, mobile security of India and mobile governance in India by insisting upon a weak encryption infrastructure. Mobile cyber security in India is not up to the mark and unencrypted communication would further increase the risks.

There are many service providers that use encryption for private and secure communications. The ministry of home affairs has been insisting upon surrendering of encryption keys of such services and in the absence of same banning such encrypted services. However, the ministry of communication and information technology has made it clear that it is not possible to do so.

India has taken too much time to resolve encryption issues and the same must be resolved as soon as possible. Encrypted services would bring both benefits and problems for India. On the benefit side, it would bring secure, private and confidential services. The problem with encryption, like any other technological service, is that it can be abused by criminals.

However, the possibility of abuse should not deter Indian government from using encryption in India. Further, Indian government must develop core cyber skills to deal with encryption related crimes rather than downsising the same and making Indian cyber and mobile security vulnerable to threats.

India needs to upgrade its intelligence infrastructure that is in real mess. Intelligence agencies need to develop intelligence gathering and analysis skills so that situations like the present one can be taken care of. E-surveillance is not a substitute for cyber skills and Indian government and its agencies must realise this truth as soon as possible. However, the call is for the Indian government to take that is shying away from taking a well informed decision in this regard.

Thursday, May 19, 2011

Mobile Banking In India Still Not Popular Says RBI

Electronic banking in India is still at the infancy stage. Whether it is electronic banking, Internet banking, mobile banking or any other form of e-banking, Indian banks have yet to take the lead. Further, in the context of mobile banking, mobile security in India is also emerging as a roadblock. This has also made mobile banking in India risky. Absence of encryption laws in India has further made the mobile security very weak in India.

Recently, G Gopalakrishna, the executive director of Reserve Bank of India (RBI) said that all Banks would have to create a position of Chief Information Officers (CIOs) as well as Steering Committees on Information Security at the Board Level at the earliest. The idea is to use information technology to the maximum possible extent while maintaining the cyber security of banks.

However, banks in India are shying away from using technology assisted banking. Indian banks have shown little progress in the areas of mobile banking and cash at point-of-sales (PoS) terminals, even after nearly two years of the RBI allowing banks to run such facilities.

According to G. Padmanabhan, chief general manager, RBI, though the number of users who registered for mobile banking is substantial in absolute numbers, it is very low vis-à-vis the number of mobile phone subscribers. Implementation of some of the policy directives, which were emanated largely on the demands of stakeholders, has been far from satisfactory, he said.

Earlier this month, RBI had raised the limits on mobile-based transactions without end-to-end encryption from Rs 1,000 to Rs 5,000. The limits on mobile-based semi-closed prepaid instruments issued by non-banks were also raised from Rs 5,000 to Rs 50,000.

RBI has been taking many pro active reforms for the banking sector of India. RBI is not only ensuring strict compliance with various laws, regulations and norms but is also prescribing various policies and strategies for effective and secure banking in India. Further, deviant behaviour of banks is also punished by RBI from time to time. It seems RBI needs to be stricter regarding implementation of its policies and recommendations.