Thursday, February 10, 2011

That space is yours and you must not SHARE the KEY

http://www.cybervictims.org

Couple of years back a friend of ours had proudly announced that he no more cares for postmen or the snail mails through post offices. He now ‘owns’ an email id and would love to get updates, new year wishes from his friends in his ‘inbox’. He happily distributed his email id to all of us and wait…… he gave away the password too. This was the time when Indian users of the internet were slowly getting accustomed with the concept of email transactions and there were no consolidated laws to protect the internet /computer users from the big bad world out there. In no time, our friend’s email id was no more his personal id, it became almost a ‘public id’ and he felt every one had known his private life. He closed his email id and went back to snail mails. However, he ensured that no one opens his post box without his permission and kept it under strict vigilance. Nearly 12 years have passed and now almost all of us are equally vigilant with our email inboxes. The first and foremost thing we learnt from our friend’s experience was never to share the “key” of the inbox with anyone; not even with boy friends, or even husbands. Well, we do vow to share each secret of our lives with our lovers when the hearts bond strongly, with our spouses when we get married, with our close friends when we trust each other ; but  I made it a point to not to share my passwords with anyone after I owned my own email id  in due course. The worst result one can expect when one shares his/her own password is, to find himself/herself in a messy situation like misuse of email id, hacking, cyber terrorism, monetary crimes ( if the email id is used for business and official transactions), defamation ( when the personal informations are taken out and publicized without your knowledge) and offcourse,severe spouse- abuse especially when one of the spouse is more dominant and feels it is absolutely right to monitor the other even in the cyber space.
 In 2010, on behalf of  Centre for Cyber victim Counseling (CCVC), we did a baseline survey where we found that 46.6% respondents share  passwords of their email ids and/or other profiles with others (see Halder, D., & Jaishankar, K. (2010). Cyber Victimization in India: A Baseline Survey Report. Tirunelveli, India: Centre for Cyber Victim Counselling. @http://www.cybervictims.org/CCVCresearchreport2010.pdf ). Yes, in some circumstances, sharing the passwords with business partners or even spouse becomes inevitable especially when one can not access internet due to unavoidable circumstances and still needs to keep up with his/her acquaintances. But then think of the risks: a very recent news report states that a  spouse "hacked" her husband’s and her father in law’s email ids to gather evidence for dowry harassment. In course of prosecution, she denied that it was hacking and maintained that the passwords were provided by her husband himself. Indeed, the case got a U turn and she got a “clean chit”( see “Sharing passwords with spouse is risky” by Pankaj Sharma (23rdJan, 2011) in DNA. Retrieved on 5th February, 2011 from http://www.dnaindia.com/india/report_sharing-passwords-with-spouse-is-risky_1497980). Now, the case may need more investigation to establish the truth; but what makes a point in this case is, if it was really a consensual act on the part of the complainant himself to pass over the secret to the to the other party, he may not claim the benefit of innocence in the process of victimization. Definitely this could make a perfect case of breach of trust when financial loss is incurred. But imagine the plight of the complainant if he really had shared the password! The bitter promises of long techno-legal battles,  the harassments and finally the uncomfortable feeling when in the cyber space may never leave the poor soul to rest in peace .Such instances must not be taken lightly as many readers may feel this was a case of ‘washing dirty linens in public’; Do not forget
1.      cyber space can be used as a double edged weapon;
2.      If you share passwords with persons you do not trust or you fear that the relationship is vulnerable, trust your instincts. Be ready for legal battles such as this;
3.      Do not allow your children to use your emails/profiles and do not share your passwords with them. You never know, they may ‘leak’ your well possessed password.
4.      Change the passwords regularly.

Have a safer cyber venturing

Please Note: Do not violate copyright of this blog. If you would like to use informations provided in this blog for your own assignment/writeup/project/blog/article, please cite it as “Halder D. (2011), “That space is yours and you must not SHARE the KEY”, 10th January,2011, published in http://cybervictims.blogspot.com/

Tuesday, January 4, 2011

Leakage that threatened world politics in 2010: my thoughts

http://www.cybervictims.org
We have ushered in another new year with numbers of resolutions, plans and programmes for the coming 361 days. Nonetheless many may have tightened their securities to prevent a dangerous “leakage”…….leakage of significant informations to the largest talked over media channel, the ‘WikiLeaks’. When this not-for profit media organization came under lime light recently by exposing the secret US embassy cables ( See Secret US embassy Cables, retrieved from http://213.251.145.96/cablegate.html on 04.01.11), the world witnessed a huge wave of concern over the question of “data privacy” and “free speech” rights. WikiLeaks promised to release these Cables ‘in stages’, which may add more embarrassment to the concerned government/s as well as those who had taken active parts in these communications.
See how the internet is being used to expose corruption, secret conspiracies and probably executable plans for violence against mankind. But note that this particular organization gives a message: “messengers are not to be killed”. They are also concerned that the ‘spies’ may be protected from possible atrocious reaction from the person/agency once these secret informations are submitted and then published. Unlike the newspaper censorship, cyber-page can not be censored abruptly unless it is proved that this website is not following due diligence; further, ‘Free Speech’ must be viewed as the most sacred gift of modern democracy. But nonetheless, WikiLeaks had been attacked to prevent the leakage of secret cables. The biggest legal jolt against WikiLeaks were perhaps the criticisms which described the operations of Wikileaks as against national security ("Congress Mulls How to Stop WikiLeaks in Its Tracks". Associated Press. Fox News. 7 April 2010. http://www.foxnews.com/politics/2010/12/16/congress-mulls-stop-wikileaks-tracks/. Retrieved 17 December 2010. Also see WikiLeaks. (2011, January 3). In Wikipedia, The Free Encyclopedia. Retrieved 13:56, January 4, 2011, from http://en.wikipedia.org/w/index.php?title=WikiLeaks&oldid=405722954.) The website was also hacked and suspended for apparently cementing the leaking point. But it was a fruitless effort. The website was back on the web soon and restarted functioning.
I remember a brain storming session at my alma-matter, NLSIU with my guide and two other senior faculties. The session was about  protection for the ‘whistle-blowers’ and the seniors were of the view that Kautilya’s Artha Sashtra’s dictum about protection of spies by the King, needs to be re-established with more stronger laws. The question which ‘bugs’ me is, when the whistle blower alerts the people against the law-makers, who will dare to break the law?...................... Not to forget, ‘Rule of law’ theory made the supreme lawmaker also to follow the law and not break it.
Please Note: Do not violate copyright of this blog. If you would like to use informations provided in this blog for your own assignment/writeup/project/blog/article, please cite it as “Halder D. (2011), “Leakage that threatened world politics in 2010: my thoughts”, 4th January,2011, published in http://cybervictims.blogspot.com/


Monday, November 29, 2010

Mobile phones : some thoughts about victimisations done through it

http://www.cybervictims.org

In my law school days, I came across with a family who had gone through land line phone stalking for continuously six years. The stalker took pain to find out the name of the registered customer for  the number, the neighboring homes etc by manually scrutinizing the huge public phone directory itself. This incident happened nearly ten years back when stalking by phone was an unknown term   in India. The victim family felt terribly humiliated, but kept the matter to themselves because when they contacted the local police, they were advised to switch to new communication media , the mobile phone. They were told that   mobile phones were better as there were no such easily available public directory. Well….ignorance is no bliss. Mobile phones are vicious devises indeed. I finished my law degree and joined the profession. One day I too owned a brand new mobile phone and felt as secured as the victim-family because I circulated  my number to only chosen few. One fine day I found a charming voice of a caller who randomly pushed the buttons and got my voice to hear. He felt it was the best option to flirt with women. But by then I was so busy with my baby daughter that I preferred to hear to her yelling rather than hearing this mobile romeo. I handed over the phone permanently to my husband and the mobile romeo obviously didn't prefer to hear male voices, neither felt like inquiring about the female voice which suddenly changed into a male voice . 
  But this may not be the case always for every one. There are many ignorant 'first time mobile owners'  like me who use social networking sites as public platforms to announce their “prize numbers”. Resultant they become the prize catch for many predators also. I understand that there are three typical routes to harass women by mobile numbers: 1. leaking the number in one of the numerous adult website and cache the number so that in the search engine this number will appear again and again; 2. leaking it in the social networking sites with detailed name and informations ,so that any one and every one of the 'cyber socialites' can have ‘good time’ with the victim; 3.hacking the mobile network to tap the calls and thereby making life miserable for the victim. We do have laws in India to prevent such data leaking. But I consider them very weak when compared to the laws of US or the UK. Yes, we do not have public directory for mobile phone numbers like what we did have for our land numbers, but there are numerous data available in the cyber space by which the victim can be found out and if the harasser is as desperate as the stalker I mentioned above, such easily available data can work better than public directories. 
But, very few note that the ‘safety pin’ actually remains with us from the beginning and we, the general mobile phone users tend to ignore the need to pin up the hole. The safety pin could be used when filling up the profile for the social networking sites, when emailing with ‘signature’ or even when exchanging mobile phone numbers with virtual friends etc by following some awareness notes such as:not to publish the mobile phone number anywhere, not to circulate it among not so known acquaintances etc .
However, I do note that while filling up the form for BSNL services, we are required to choose whether to go for ‘national do not call registry’ or not. No this does not serve any purpose when you speak about personal data protection for mobile  customers from potential harassers who may go for data mining and leave threatening /annoying messages  ( the objectives of the NDNCR clarifies that ‘message’ means only unsolicited commercial communication (UCC) .See http://ndncregistry.gov.in/ndncregistry/index.jsp?reqtrack=qvwhHPNkiQGNDNpwrlvARvsog) But yes, if seen from a broad perspective, this could to a certain extent prevent messy situations that may result due to cloud computing. However, even though harassments through mobile phones are now being considered as one of the core cyber crimes, more stricter laws (well, we do have I.T Act, 2008 to penalize such communications, but it still needs to be broadened) may be needed to restrict unsolicited data mining.
Please Note: Do not violate copyright of this blog. If you would like to use informations provided in this blog for your own assignment/writeup/project/blog/article, please cite it as “Halder D. (2010), “Mobile phones : some thoughts about victimisations done through it”, 29th November,  2010, published in http://cybervictims.blogspot.com/

Thursday, October 14, 2010

Think before you type your heart out

http://www.cybervictims.org
Do you remember the old saying ‘think before you take a leap’? When in the cyber space, this particular saying stands on a far firmer foot than in the virtual world. Often we invite a messy situation for our selves by floating some thoughts and expressions of ours in the web, which may bring unanticipated danger to us. I often get to see victims crying and repenting over their ‘karma’. True, many are unaware of the true nature of the ‘space’ where they spend maximum of their time. A released spade never comes back, but a digitally typed expression may come back in a disastrous form to devastate the creator. Examples of such sorts of ‘boomerangs’ are many…….an ugly caricature;  flaming words; fussing over the issue unnecessarily and creating a huge trail of followers who will say nay or ye to add more pain to the insults; the list may be unending. The mediums of such hounding could be either emails, or chat messages or wall posts or forum boards; and such attacks could instigate cyber bullying, offending messages, stalking, defamation and even phishing. Hence , do think before the followings:
  1. Mailing to your girl friend or boy friend or spouse after an emotional outburst.
  2. Updating your status in the Facebook, Myspace etc in an agitated mood especially after a fight.
  3. Expressing your feelings over political /administrative decisions.
  4. Telling about the teacher or fellow student you hate the most, to your friends in open forums or in their message boards.
  5. Opting for easy money by replying to ‘lucrative offers’.
The list is not exhaustive.

                        The advocates of ‘Free Speech’ may use their power to express their opinions in this matter. Experiments with the First Amendment Guarantees of the US constitution had broaden the scope to exercise Right to speech and expression in a more extensive way. The social value system in India is also getting new interpretations from the judiciary and it is expected that very soon notions of ‘modest speech’ may also get new legal color. Given this situation, these typical issues and ‘warnings’ that I just mentioned, may chill some personal rights. I do agree.  But, do remember, Rights beget responsibility and every ‘netizen’ is responsible to protect others Right. I would also emphasize that law protects our Rights, but may not guarantee mental peace while protecting our Rights. It is our good senses that we have to use when in the cyber space and only then Rights can peacefully coexist with responsibilities. Hence do not hurt others or others feelings and exercise your right to speech and expression cautiously and with responsible words.

Please Note: Do not violate copyright of this blog. If you would like to use informations provided in this blog for your own assignment/writeup/project/blog/article, please cite it as “Halder D. (2010),“Think before you type your heart out”
”,October  2010, published in  http://cybervictims.blogspot.com/

Monday, July 19, 2010

Phishing : How can the victim recover the lost fortune

http://www.cybervictims.org

Nearly a year back, in this blog forum I had posted  about phishing and the Indian laws in my earliest blog 'Phishing:the lawyer says' (Halder.D. 2009, August) @ http://cybervictims.blogspot.com/2009/08/phishing-lawyer-says.html . One thing that kept on bothering me during these days was could the victim get the money back that he had lost ? In one of my feedbacks to cyber crimes that was published in LiveIT, (19th july, 2010)a magazine dedicated for cyber affairs, I had said that victims of phishing some times can not come to terms with the loss and it is my job to make them understand that the amount they have lost MAY NOT ALWAYS  be recovered. Yes, the heart breaking news is sometimes, the amount is 'really gone'. Our laws punish the offender for money laundering in this cyber way; but what about the victim's right to recover the full amount ? I doubt.........from my professional experience, I have seen in such cases, after registering the case with the police, very few lucky victims get back the fortune that he /she lost. But I know the victim's pain myself because I had seen a family member of mine who had been victim of monetary cheating in the hands of cheat funds. Well, the story is the same when the case happens to a victim who is residing in UK, US or any other developed nation.I know a couple of victims who had lost a good amount of money in the UK and the government reporting agency could be of no help for recovering the amount.  
What do the law says  in this case? in India, according to me, the nearest provision which is provided by the IT Act, 2008 (amended) is section 66D whereby the offender is punished for cheating by impersonation and also Section 66C which speaks of Identity theft; along with provisions of Indian penal Code which  explains cheating and punishments(such as section 415,416, 417) etc   But the victimization that I had mentioned in the LiveIT interview is more about cheating by impersonation where offender poses as person who is willing to give money as cash prize for lottery , 'daughter/son/relative' of the dead person, banker of the dead person etc  whose money is 'intended to be shared' with the victim etc., and where the offender appears in person to 'do business.' In certain of these sorts of scams, if the victim informs the police before hand about the phishing emails and probable meeting dates and places, the 'scam' could come to an abrupt end and recovery of the money could be more swift. 
But it is always not the same story. in some cases, a paltry amount or even full amount may be recovered......how?The only way to recover the money lost in this way, is to be aware (especially when the scammer had not asked the bank informations and asked the victim to pay him in person.........in cases where the victim is asked provide bank informations, he/she should never respond to such emails........you may never know how these people can break into strictly secured bank accounts) and inform the police when the deal has unfortunately reached  either  the beginning stage or in the mid way..........i.e, when the individual at the receiving end has emailed back to the victim's response to the fraud, promising him to pay lumpsome if the victim meets the 'offender' at a designated place and hands over some documents/cash etc as processing money.
Remember,' prevention is better than cure '.......and it stands true in phishing cases also.

Please Note: Do not violate copyright of this blog. If you would like to use informations provided in this blog for your own assignment/writeup/project/blog/article, please cite it as “Halder D. (2010), “Phishing : How can the victim recover the lost fortune”, July  2010, published in  http://cybervictims.blogspot.com/

Saturday, May 15, 2010

Death threats in the Information Super Highway

http://www.cybervictims.org

After communication became online, sending threatening mails/messages became an easy job for many who want to vent out their inner anger, frustration or revenge. Today’s breaking news proves that again……. Noted lyricist Javeb Akhtar , one of my favourite personalities in Bombay filmdom has now been enlisted as the newest victim of cyber crime; he has received death threats from someone who felt it necessary to mail this ‘magician of words and lyrics’ stating that his time is limited (see Mohammed Wajihuddin & Vijay V Singh, ‘Javed Akhtar gets death threats on e-mail and SMS’,16th may, 2010,Times of India, available at http://epaper.timesofindia.com/Default/Client.asp?Daily=TOICH&showST=true&login=default&pub=TOI&Enter=true&Skin=TOINEW&GZ=T)
Akhtar plays with words in fine tunes. Usage of language to express thoughts about social issues, evil customs, corruption and moral duties to prevent such corruption; about beauty of women;  responsibilities of  men; how mothers play their roles forever;what children mean to the society………is his forte. When the actor speaks Akhtar’s words, Indian audience, and in that matter, cinema lovers of all countries who understand Hindi/Urdu or are made to understand Hindi/Urdu through subtitles, either criy simultaneously with the other characters of the movie or laugh their heart out when the actor tries to make others jubilant with the help of Akhtar’s words.
The message of the mailer was even stronger than what Javed Akhtar spreads through movie actors………… the message conveys ‘shut up or you will die’. The impact of the words was so distraught that even the ‘magician of words’, felt disturbed and could not ignore the message but to report it to the police. I know many individuals may have received such threats which are inclusive of death threats, threat to kidnap their kin, threat to defame their name and reputation etc. And who are these people who send death threats? Strangely enough, they are infact one among us, educated, successful in their own ways, probably satisfied in their lives, but do not know their limitations while they are in the cyber space. Well, it is a curse of technology ………….people can use offensive language in any way they can and still remain anonymous. Isn’t it enough to create a panic? Those who have read the epic Ramayana, must know about Meghanad’s attack from behind the clouds. No one can see the attacker, and the attacker successfully carries out his operation and then returns to his own kingdom as a winner. I find ‘anonymous death threats through emails’ quite similar with the acts of this epic worrier prince. The victim becomes so traumatized due to the sudden attacks from ‘no where’ that he /she forgets his own potentials to fight back. And the attacker becomes successful……..yes, he created what he wanted to create…. ………the FEAR.
Well, our Information technology Act,2008 does not permit the offender to run away. Section 66A puts strong words against playing dangerous games with words in electronic communications. The provision is engraved with multipurpose effects: it covers grossly offensive communications which annoys the receiver; which is knowingly false but is communicated for the purpose of causing annoyance, inconvenience, danger, obstruction, insult, injury, criminal intimidation, enmity, hatred, or ill will to and also against the receiver; and of course which may try to deceive or to mislead the addressee or recipient about the origin of such messages. And the punishment? Well… a jail term for two to three years and fine. The offence is bailable. But this must be read along with Indian Penal Code provision also for cases where the message carries threat to death, as that has happened to Javed Akhtar. Section 506 of the Indian penal Code prohibits criminal intimidation with punishment for two to three years or with fine. But the same law becomes stricter if the intimidation is meant to cause death, grievous hurt, destruction of the property etc.; or the threat is meant to cause any offence which is generally punishable with death, imprisonment for life or jail term for minimum seven years periods. In such cases the punishment may even put the offender behind bar for seven years and also inclusive of fines in certain cases.
The laws successfully convey the message that no one will be spared if they try to play with human emotions, especially, feelings for personal safety and security. Well, it depends upon the technology users to use cyber technologies in a lawful way or illegal way……………but remember, cyber space is created for good of mankind and not for destruction purpose; and if anybody plays hide and seek game, there are some others also who are interested to play cat and mouse chasing game and the mouse *will* be caught because the cat is trained to prevent injustice.

A Note to readers: Please do not violate the copyright issues of this blog .If you would like to use informations provided in this blog for your own assignment/writeup/project/blog/article, please cite it as “Halder D. (May 2010), “Death threats in the Information Super Highway”, published in http://cybervictims.blogspot.com on May16, 2010,"

Saturday, April 24, 2010

Cyber victimization: We can prevent it…..and we will

http://www.cybervictims.org/


In India, cyber victimization remains a hush hush issue when it comes to individuals. In 2009 I, a lawyer and a Ph.d candidate of NLSIU myself, along with my criminologist husband created “Centre for Cyber Victim counseling”© for the cause of cyber crime victims of India. We are happy to note that our organization’s website http://www.cybervictims.org/ proves useful to many. Indeed, me as a woman and as an internet user also, have been ridiculed and teased several times in the internet and I know there are several men and women who have been victimized like me in the cyber space. I have learnt to use my bad experiences, my knowledge of   law and my legal background for good and I dedicate my experiences for the cause of betterment of the society through “Centre for Cyber Victim counseling”© . Our organization will be celebrating it’s first birthday in July this year and as a first anniversary celebration, we have revamped our organization website and it can be seen @ http://www.cybervictims.org/. We help victims through online counseling and we have teamed up with our national and international knowledge partners to work towards prevention of cyber victimization. We are now spreading our wings and we will be arranging awareness programmes.  As our first initiative, we will be the “support partner” for the first international conference of South Asian Society of Criminology and Victimology (SASCV) (  http://www.sascv.org/). We are also requesting the print media to contact us for more information in this regard which will be a fruitful effort towards prevention of cyber crime.
From my own personal experiences I can say “being a victim” is the hardest truth one may have to come across. I started ‘interneting’ since 2005 .As a new owner of a personal computer and the broadband connection; I loved to mail my friends and cousins in different cities and countries. I was practically confined in a house with a two year old baby and some arrears in for my   Master of Law (ML) degree examinations. I felt ridiculous with no law teachers who can guide me for the study materials, no fellow students with whom I can discuss and no friends around to whom I can confide how hard it is write exams with a two year old baby. I didn’t take to depression –drugs , instead I went for internet. I started getting huge study materials and friends .Well,   I did pass the exams well, but I didn’t leave internetting even after I was conferred ML degree. Those days privacy in the internet was relatively little known issue. I became members of couple of social networking sites and within days my inbox was swept with teasing, vulgar messages. I loved to fuss about my husband and I prominently displayed “married” status every where. No wonder, he started getting unwanted mails and bullying attacks soon. In fact I remember a particular occasion when I demanded a dinner outside because he “won a lottery”. Fortunately he is well read and he told me no dinner because that was a fake mail. I really didn’t believe it as long as one of our friends reported to have lost nearly Rs. 25,000/-  .Well, that was one of my first encounters with cyber crime. Slowly my interest grew in this area and I found so many victims of similar incidences around me. I know I may sound odd, but it is a bitter truth …....many don’t know how they are being victimized online and many individuals willingly become victims. “Centre for cyber victim counseling”© is build upon the trust that the victim’s immediate need would be looked after. I call all the victims who fear to face the reality, to really face it bravely. Consider our organization at http://www.cybervictims.org/ as your friend ……we are there to help you.