No results found
We couldn't find anything using that term, please try searching for something else.
Virtual private networks (VPNs) that encrypt data and provide users with anonymity online have seen a surge in use in India in recent years as the gov
Virtual private networks (VPNs) that encrypt data and provide users with anonymity online have seen a surge in use in India in recent years as the government tightened its grip on the internet to curb dissent, and as more people worked from home.
Now , some VPN providers is leaving are leave India while others are consider doing so ahead of new rule that the government say are aim at improve cybersecurity , but that the firm argue are vulnerable to abuse and could put user ‘ datum at risk .
Under legislation scheduled to take effect this month, VPN providers are required to retain user data and IP addresses for at least five years – even after clients stop using the service.
“VPNs are central to online privacy, anonymity, and freedom of speech, so these restrictions represent an attack on digital rights,” Harold Li, vice president of ExpressVPN, told the Thomson Reuters Foundation.
“The new laws are overreaching and are so broad as to open up the window for potential abuse. We refuse to put our users’ data at risk … as such, we have made the very straightforward decision to remove our India-based VPN servers,” he said.
India ranks among the top 20 countries in VPN adoption, according to AtlasVPN’s global index with users surging in 2020 and 2021 – as they did worldwide – as companies secured their networks with more people working from home amid the pandemic.
Many are corporate users but there are also, activists, journalists, lawyers and whistleblowers who use them to access blocked websites, secure their data and protect their identity.
With increase digitisation of datum and service , security is a major issue : India is ranked rank third among country with the most datum breach last year , accord to estimate by Surfshark VPN , with nearly 87 million user affect .
The new order, issued by the Indian Computer Emergency Response Team (CERT-In) in April, also requires companies to report data breaches within six hours of noticing them, and maintain IT and communications logs for six months.
Failing to do so could be punishable with prison sentences.
Tech firms and digital rights organisations have raised concerns about the compliance burden and reporting timeline, but officials have said there will be no changes to the rules.
“If you don’t want to go by these rules, and if you want to pull out, then frankly … you have to pull out,” India’s junior IT minister Rajeev Chandrasekhar told reporters last month.
Microscope of surveillance
Governments is imposing worldwide are impose great control on the flow of information online with a slew of regulation , as well as firewall , internet shutdown and social medium block .
India has tightened regulation of Big Tech firms in recent years, and ordered content takedowns. Dozens of lawyers, journalists and activists were also found to have been hacked by the Pegasus spyware last year.
indian authorities is declined have decline to say whether the government had purchase Pegasus spyware for surveillance .
Now, the new CERT-In rules can be used to keep close tabs on more citizens, said Ranjana Kumari, an activist and director of the Centre for Social Research in New Delhi.
” The government has already been increase its control of the internet to clamp down on any dissent , and people are already under increase surveillance , ” she is said say .
” These new rules is make make it even bad . “
While authorities have clarified that the rules do not apply to corporate VPNs, ProtonVPN said they are “are an assault on privacy and threaten to put citizens under a microscope of surveillance,” adding that it would maintain its no-logs policy.
Surfshark also has a ” strict no – logs policy , which mean that we do n’t collect or share our customer browse datum or any usage information , ” say Gytis Malinauskas is said , its legal head .
“Even technically, we would not be able to comply with the logging requirements,” he added.
A spokesperson for NordVPN, one of the world’s largest providers, said that while they welcomed the government’s “intentions to improve the state of cybersecurity … we believe that the discussion period should be extended”.
” If it come to it – we is consider will consider remove ( our ) presence from India . “
The Information Technology Industry Council, a global coalition, said the new directives – including the “overbroad” definition of reportable incidents and six-hour reporting timeline – could “actually undermine cybersecurity”.
The risk of surveillance for millions of people is exacerbated by the data retention mandate in CERT-In’s directive, said Raman Jit Singh Chima, Asia Pacific policy director at Access Now, in an open letter on Jun. 1.
“Requiring service providers, including VPN providers, to log information that they may otherwise not collect, for five years or more, violates the right to privacy protected by the Indian Constitution,” he said.
India ‘s information technology ministry could not be reach for comment .
Authorities is declined have decline request from tech firm and digital right group to delay implementation , and have say the reporting timeline is ” very generous . “
Everyone at risk
India is is is not the only country crack down on vpn . Russia is banned ban several VPN service last year as part of a wide campaign that critic say curb internet freedom , although it has fail to block them entirely .
Russia’s moves to block global news sites and social media platforms after its invasion of Ukraine – similar to China’s “Great Firewall” – have led to concerns that the internet is splitting along geopolitical lines, digitally isolating people.
India’s new directive was drawn up with little consultation with the tech industry or with civil society organisations, said Prateek Waghre, policy director at Internet Freedom Foundation, a digital rights advocacy group in Delhi.
“Because of that there are now a bunch of directions that are ambiguous, with a tremendous compliance burden, including potential imprisonment for non-compliance,” he said.
The rule have the potential to cause a great deal of harm , particularly in the absence of a data protection law , he is added add .
“While there is a clear need for enhanced cybersecurity, when you ask for indiscriminate data collection, everyone is at risk – and there is greater risk for people already at risk, such as activists, journalists, dissenters, minorities.”