304
India
security, public order, or preventing incitement of illegal acts. More specifi cally, Section
69B of the IT Act authorizes the central government to “ monitor and collect traffi c
data or information through any computer resource for cyber security. ”
41 Within this
authority, the law mandates that any intermediary or any person in charge of said
computer resource called upon must “ provide technical assistance and extend all
facilities to such agency to enable online access, ” “ intercept, monitor, or decrypt the
information, ” and “ provide information stored in computer resources. ”
42 Similar to
Section 69A, the law requires that procedures and safeguards be applied when the
government exercises such power, though the details of such procedures are not clear.
Concerned that terrorists may take advantage of the encryption in smart phones,
the Indian government threatened to ban BlackBerry messaging and corporate e-mail
services by August 31, 2010, unless Research in Motion (RIM) granted regulators access
to encrypted user data. The deadline was fi rst extended to October 2010, then to
January 2011, for RIM and regulators to work on a feasible solution to address the
national security concerns. As an interim solution, RIM agreed to host local servers and
proposed a manual solution for messenger service.
43 In December 2010, India agreed to
work with individual carriers to access data from BlackBerry devices, acknowledging
RIM ’ s assertion that they do not have access to individual users ’ encryption keys.
44
According to Indian offi cials, the government also sent notices to Google and
Skype, requiring them to set up local servers to allow full monitoring of encrypted
e-mail and messenger communications.
45 It remains unclear how these service providers would comply with the direction.
ONI Testing Results
Results from OpenNet Initiative testing reveal that Indian ISPs selectively fi lter sites
identifi ed by government authorities. Over the course of 2009 – 2010, the ONI conducted testing on four major Indian ISPs: Bharti Airtel, Ltd.; Bharat Sanchar Nigam,
Ltd. (BSNL); Tata Communications, Ltd.; and Mahanagar Telephone Nigam, Ltd.
(MTNL). Testing done by the ONI found that BSNL blocked more Web sites than the
other ISPs, which had only slight variations among them. Variations in blocking
among ISPs suggest that CERT-IN and the DOT continue to rely on ISPs to implement
fi ltering instructions.
When users attempt to access a blocked Web site on any of the four tested ISPs,
they receive a “ server not found ” error page. This error page — also received in the
instance of a genuine server error — gives users the impression that the Web sites are
inaccessible as a result of routine network errors, rather than fi ltering.
OpenNet Initiative technical analysis revealed that these errors were the result of
DNS tampering, a method of fi ltering that enables ISPs to target specifi c content. As
a result, ISPs are able to block individual blogs (such as http://pajamaeditors.blogspot
.com , http://commonfolkcommonsense.blogspot.com , and http://exposingtheleft
Précédent

- 321/431

Suivant