Showing posts with label cyber. Show all posts
Showing posts with label cyber. Show all posts

Saturday, August 27, 2011

Contemplations on Mandatory Key Disclosure Law: I

One of the issues raised in mandatory key disclosure controversy is about the nature of a key or password. I intend to discuss the same here.

Existence of password
It is clear that the knowledge of the password exists in the mind. But the question is whether the password in itself also exists only in the mind or has some existence in reality. This can probably be tackled by asking if the password ceases to exist when the person who knows the password, or in whose mind the password exists dies, ie. when his mind is destroyed. From Descartes point of view, probably yes. Because the destruction of the knowledge of the password obviously happens when a person dies. Once the knowledge of the password is gone, the password ceases to exist until someone else comes along and "discovers" the password. 

But can this analogy be applied here? Because people would still know there exists something which can cause the computer system to unlock- they just do not know what it is. In other words, is the password a perception? I would like to compare it with another analogy here. Imagine the situation before Ptolemy said that earth revolved around the sun. Everyone was of the opinion that the Sun revolved around the Earth. So should we be saying that the people were mistaken and "reality" was different- which is that the Earth revolves
around the Sun? Can it be said that there is a reality existing outside of our minds and perceptions? Because on the other hand, it can be said that Ptolemy "perceived" something else- this perception including certain observations- which won over the previous perceptions. So this new perception became the reality. And it is well possible that future observations can change this perception propounded by Ptolemy too- maybe the sun
and the earth revolve around each other. Physics after all does understand the importance of point of reference. Now can this analogy be used to draw parallels with existence of a password?

Maybe not really, because in our example- everyone, which means the accused and the police perceive that the password can be used to unlock the system-- no one really has a different perception here. Password would still be valid if anyone else other than the accused enters it, even after the accused's death. Even if he does it without realisation of what it is. This is because- everyone- the accused, humankind and the computer-system made by human kind operate under the same assumption- that the right password once entered will unlock the computer and give access to its contents. The problem for the police here really lies in the too large number of possibilities to find out what the password really is. And not its existance. Thus in the human reality, the password exists not just in the mind of the accused but in "reality". It is only the knowledge of what password is which exists with the accused.

Revealing password as testimony v. Password as a link to reaching incriminating material
One argument goes that revelation of password would be a testimony sure because it would be revealing knowledge within mind. Issue lies is that the defence then argues that speaking out the password would be a testimony but entering the password in the computer would not, because in entering the password the accused would not be revealing the contents of "his mind" which would be the case when he simply enters the password rather than divulging it. But the counter-argument goes that even by simply entering the password the accused in fact does reveal contents of his mind, e.g. the knowledge of the fact that he has control over any evidence found on the computer, which was earlier unknown to/unverified by law enforcement, and was only within accused's knowledge.
Now notice that law grants privilege of self incrimination to even mere knowledge about existence of a thing which exists in mind- and not just to things which completely exist in the mind, or which can be modified by mental powers. For example, self incrimination privilege is granted to the knowledge of the accused of the fact that he was carrying a knife on the night of 14th March 2011. This fact is something which would have been accepted as reality by any human who saw him on that night with a knife. Accused cannot change this fact of him carrying his knife with the power of his mind. Thus for all human purposes this fact is "reality". Yet the accused's knowledge of this fact is privileged. In the password situation, two things may happen.
a. Accused may say he has control over the computer but refuse to disclose the password pleading right against self incrimination.
b. Accused may say he has no control over the computer, so he is unable to disclose the password.

Let's take situation b. first. Accused has set the password at some prior time. Knowledge of password is only within his mind, though it sure exists in reality too. He sure cannot change the password by using his mental powers. Yet by drawing analogy with the knife carrying situation, accused can keep silent about his knowledge of the fact that he had set the password at a prior time, or that he knows the password at any level. In this case even forcing him to enter the password will demonstrate his control over the password or the computer under right against self-incrimination.

Situation a.  now. Accused has set the password at some prior time. Knowledge of password is only within his mind, though it sure exists in reality too. He sure cannot change the password by using his mental powers. Yet by drawing analogy with the knife carrying situation, accused can keep silent about his knowledge of what the password is and hence disclosing it under right against self-incrimination.

Hmm...looks like arguments for situation a. and b. are more or less the same. 

Tweet This

Sunday, May 01, 2011

Is E2 labs right in getting zone-h.org blocked?


(Reproduced from http://www.bloggernews.net/124029 , a link admitted to as being bloacked by the Indian DIT http://cis-india.org/advocacy/igov/blog/rti-response-dit-blocking , but which is apparently (and thankfully) working fine with Tata DSL and MTNL)

It has been brought to the attention of Naavi.org that the Government of India might have blocked the website zone-h.org. Naavi.org has therefore checked the background of the non availability of zone-h.org from India and  place its reading of the situation as under.
 As of now (march 11), it appears that the site zone-h.org is not accessible in India.  Zone-h.org is a reputed information security website often referred to by security professionals and there is no apparent reason for the same to be blocked because of any content on the site.
However what is interesting is to note that the site has been carrying a few articles in recent days which are critical of a Hyderabad based company called E2 Labs. In a recent article, Zone-h has categorically stated that E2 labs has been trying to attract investors with certain project information which states that zone-h is a business partner for E2 labs. The site zone-h.org states that it has no business relationship with E2 labs and the contents of the documents released by E 2 labs and accessed by Zone-h.org through wikileaks is false. (For a copy of the complete article visithttp://www.naavi.org/cl_editorial_10/e2labs_zoneh_org.pdf )
If the contention of Zone-h .org is true, then a serious question is raised on the business ethics of  E 2 labs . It is open for Zone-h.org to take appropriate legal action against E2 labs. If the contents are incorrect,  E2 labs can take-up defamatory action against zone-h.org.
In this fight, readers may wonder where is the scope for blocking of Zone-h.org website because it carries a potentially defamatory article on E2 labs. So far except when political leaders such as Sonia Gandhi or community icons such as Shivaji have been defamed, Government has not taken any action to block the websites. In fact the Government has developed a cold feet even in blocking of kirtu.com. It is therefore surprising that potential defamation of E2 labs is considered sufficient ground to block a respected website such as zone-h.org.
In information just received, it appears that CERT In was not instrumental in the blocking of the website but the same was ordered through a Court action in Hyderabad.
One option available for Zone-h.org now is to request for reconsideration of the Court decision which should have been restricted to removing of the contentious article alone instead of blocking of the website.
 At the same time we need to take note that the document referred to in the artcile also highlights that E 2 labs is the “Principal Consultant of CERT_In”.  It also states that it is going to be appointed as an advisor of Defense establishments etc.
Since CERT-In is the nodal agency for the national cyber security of India, if the charges made by Zone-h.org is true, E 2 labs would be unsuitable for partnering CERT-In.
In veiw of the fact that this is a serious national security issue, it would be better if Government of India makes a suitable statement clarifying the role of E2 labs in national cyber security. In particular, public are entitled to know if E 2 labs is really the principal consultant of CERT-In and if E 2 labs is also going to be appointed as a consultant for the Indian Defence Forces as they have claimed in the said document.
Naavi of naavi.org
Tweet This