Business Daily from THE HINDU group of publications
Wednesday, Mar 19, 2008
ePaper | Mobile/PDA Version


News
Features
Stocks
Cross Currency
Shipping
Archives
Google

Group Sites

Home Page - Security
Info-Tech - E-Commerce & E-Business
E-commerce: Watch on encryption code compliance

DoT move is a fallout of Blackberry controversy


Encryption codes are a way to scramble information sent online in such a way that only the desired recipient has the key to unscramble them.


Thomas K Thomas
Rahul Wadke

New Delhi/Mumbai March 18

Online banking operations and e-commerce transactions including purchase through credit cards may be open to Government surveillance as a fallout of the recent Blackberry controversy.

The Department of Telecom is now taking steps to ensure that all providers of Internet services strictly follow the prescribed encryption code. As per the existing law, all Internet-based service providers are required to submit a decryption key to the Government if they use more than 40 bit encryption code to secure the transactions.

Encryption codes are essentially a way to scramble information sent online in such a way that only the desired recipient has the key to unscramble it and convert it back to its original form.

However, as it was found out in the Blackberry case, a number of service providers are not strictly following the rule and have not submitted the decryption code. The issue came to light when telecom operators providing Blackberry services told DoT last week that the Government was singling out one service for allegedly violating the encryption laws.

Most of the e-commerce web sites like those selling airline and movie tickets and banking application web sites use more than 128 bit encryption code. The higher code is required to keep the transactions secure. The problem with using higher encryption codes is that the Indian security agencies find it impossible to track any specific transaction unless they have the decryption codes.

However, the Internet Service Providers termed DoT’s policy as archaic and said that they have already requested DoT to raise the permitted levels from 40 bits to at least 128 bits in line with the changing technology. “The existing encryption laws were made when Internet services were just beginning to take shape in the country. It is really unfair to stick to the same standards when technology is enabling more secure transactions and highly complex transactions. If DoT insists on the 40 bit encryption then it will be taking the Internet back to the dark ages,” said Mr Rajesh Chharia, President, Internet Service Providers Association.

Industry experts said that DoT’s policy was not practical on two counts. First, no company will give away its patented codes to leaky Government departments as it could make e-commerce applications unsecure and, therefore, useless. Second, under the existing rules, the procedure for submitting decryption keys, which is in digital form, has not been laid out. So even if anyone was bold enough to give the code to the Government, they would not know how to submit it. “In developed countries like the US there is no limit on the encryption code. Monitoring is done by their security agencies using the most sophisticated technology. DoT should invest in setting up monitoring centres which can do the job without limiting the scope of Internet services,” said Mr Amitabh Singhal of Elxess Consulting Services.

Related Stories:
No question of banning BlackBerry, says DoT
DoT unlikely to stop Blackberry services

More Stories on : Security | E-Commerce & E-Business | ISPs

Article E-Mail :: Comment :: Syndication :: Printer Friendly Page



Clasic Hiring

Stories in this Section
Procurement services’ demand rising: Logica


Holdings in US treasury papers rise in value
Promoter selling, FCCBs drag Orchid Chemicals
SEBI examining alleged insider trading in Reliance Petroleum shares: Govt
Cipla (Rs 204.45): Buy
Day trading guide
Mission on technical textiles soon, says PM
Few bidders at Mumbai property sale
Ban on edible oils export
Cross-currency hedging backfires on small, medium export units
Will the US remain US? Or become a neo-USSR?
Stocks end flat after early gains
Post-Bear Stearns’ sell off, select stocks recover
New FII registrations provide silver lining
Tatas mull common credit card to push sales
TRAI move on unwanted calls unfair: Telcos
E-commerce: Watch on encryption code compliance

BusinessLine E-paper


The Hindu Group: Home | About Us | Copyright | Archives | Contacts | Subscription
Group Sites: The Hindu | The Hindu ePaper | Business Line | Business Line ePaper | Sportstar | Frontline | The Hindu eBooks | The Hindu Images | Home |

Copyright © 2008, The Hindu Business Line. Republication or redissemination of the contents of this screen are expressly prohibited without the written consent of The Hindu Business Line