News: 1655180239

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Indian government signals changes to infosec rules after industry consultation

(2022/06/14)


Indian media is reporting that the government has consulted with industry about its controversial infosec reporting rules, possibly resulting in concessions that slightly ease requirements for some businesses.

The rules, [1]introduced on April 29 with no warning and a sixty-day compliance deadline, require organizations operating in India to report 22 different types of information security incidents within six hours of detection, maintain extensive logs of their own and customers' activities and provide that info to authorities as required, and use only network time protocol (NTP) servers provided by Indian authorities or synced to those servers.

The rules generated swift and widespread opposition on grounds that they were loosely worded, imposed enormous compliance burdens, made India less attractive to foreign tech companies, and would harm privacy. The requirement to report even trivial incidents within six hours was criticized as likely delivering a deluge of reports that would contribute little to the stated goal of securing intelligence with which to defend the nation. The Internet Society warned that insistence on using Indian NTP servers would create an unhelpful reliance on that infrastructure.

[2]

Critics also pointed out that India's Computer Emergency Response Team (CERT-In), the body overseeing the rules, offered a non-interactive PDF as one way to file incident reports, and allowed organizations to send that as an email attachment or even a fax. CERT-In offered zero evidence it had built tools to ingest and analyze incoming reports, furthering the argument that the rules imposed a considerable compliance burden without improving India's security capabilities.

[3]Another VPN quits India, as government proposes social media censorship powers

[4]BSA kicks multiple holes in India's infosec reporting rules

[5]India, Twitter brawl in public as latest content rules begin to bite

[6]ExpressVPN moves servers out of India to escape customer data retention law

The government's only response to such criticisms was issuing an FAQ in the hope of clarifying the rules' intent. But that FAQ instead sparked more criticism, because its language again lacked precision and the document lacked legislative force. Those trying to comply were left with more questions about how to interpret the rules.

All that criticism appears to have reached the ears of IT minister Rajeev Chandrasekhar, who convened a meeting to discuss the rules.

[7]

[8]

But it was the American Chamber of Commerce in India – not Chandrasekhar – that publicised the meeting.

Under the chairmanship of Mr. [9]@Rajeev_GoI , Hon’ble Minister of State for Electronics and Information Technology, GoI [10]@GoI_MeitY , [11]@AmchamIndia participated in a consultation session on [12]#CERT -In Directions 2022 and shared their [13]#industry perspectives on the [14]#Directives and [15]#FAQs [16]pic.twitter.com/oZYre4oW3B — AMCHAM India (@AmchamIndia) [17]June 13, 2022

Chandrasekhar retweeted the Chamber of Commerce, but his own feed and that of the Indian IT ministry are silent on what was discussed, or any outcomes.

India outlet MediaNama [18]reports that some concessions were raised at the meeting, among them extending the compliance deadline and easing some requirements for smaller businesses.

CERT-In will reportedly create a portal for uploading incident reports, but the six-hour reporting deadline remains.

[19]

Indian authorities' official and social feeds were silent on the matter at the time of writing, and Indian government websites produced DNS errors when The Register checked for updates.

If local reports are correct, and India has softened its rules, the mooted changes won't be particularly popular. They don't address privacy concerns, NTP concentration, or change the six-hour reporting requirement that India insists is a global standard – despite other nations setting a 72-hour deadline. ®

Get our [20]Tech Resources



[1] https://www.theregister.com/2022/04/29/cert_in_directive/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YqhcQuun4NJ34-xzFY8n3QAAAFg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2022/06/08/india_it_regulation_criticism/

[4] https://www.theregister.com/2022/06/03/bsa_criticizes_cert_in_rules/

[5] https://www.theregister.com/2021/05/28/india_vs_twitter/

[6] https://www.theregister.com/2022/06/02/expressvpnservers_out_of_india/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqhcQuun4NJ34-xzFY8n3QAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YqhcQuun4NJ34-xzFY8n3QAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://twitter.com/Rajeev_GoI?ref_src=twsrc%5Etfw

[10] https://twitter.com/GoI_MeitY?ref_src=twsrc%5Etfw

[11] https://twitter.com/AmchamIndia?ref_src=twsrc%5Etfw

[12] https://twitter.com/hashtag/CERT?src=hash&ref_src=twsrc%5Etfw

[13] https://twitter.com/hashtag/industry?src=hash&ref_src=twsrc%5Etfw

[14] https://twitter.com/hashtag/Directives?src=hash&ref_src=twsrc%5Etfw

[15] https://twitter.com/hashtag/FAQs?src=hash&ref_src=twsrc%5Etfw

[16] https://t.co/oZYre4oW3B

[17] https://twitter.com/AmchamIndia/status/1536312016880963586?ref_src=twsrc%5Etfw

[18] https://www.medianama.com/2022/06/223-meity-offers-several-concessions-on-cert-in-guidelines-during-meeting-with-industry-bodies/

[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqhcQuun4NJ34-xzFY8n3QAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[20] https://whitepapers.theregister.com/



Email flood in 3, 2, 1...

ShadowSystems

They want reporting? They'll get reporting. In TeraTonne loads straight to their email servers like a nuclear-powered kick in the fork.

You want port scans reported? They'll create a script to auto-report that fact via email without any Human intervention at all. For every single port, by every single IP, in six second intervals. Your inbox will get crushed like a bowl of Petunias under an orbitally-dropped Sperm whale.

And it'll be your own damned fault for refusing to listen to reason. You refuse to listen, they'll do *exactly* as you've commanded & use scripts to auto-generate-and-send every single required report. You won't be able to fault them for following the rules, now will you?

sanmigueelbeer

The Internet Society warned that insistence on using Indian NTP servers would create an unhelpful reliance on that infrastructure.

Unless the business themselves have their own stratum 1 NTP servers (example [1]Raspberry Pi ).

[1] https://www.satsignal.eu/ntp/Raspberry-Pi-NTP.html

They're not allowed to do that

Richard 12

That's basically the problem.

They're insisting everyone syncs to one particular NTP cluster as their stratum-1 server.

So even if you have your own on-site stratum-0 atomic clock, you can't use it unless you sync it to the (far less accurate) India Time Service.

If the India NTP goes down (perhaps because several billion devices sync to it), nobody has accurate time by legal definition .

Setting a standard for "How far different to UTC-0" or some other international time standard would be sane. Requiring everyone to sync to a single domestic time source might sound like the same thing, but it's very different when you look at the detail.

The [Ford Foundation] is a large body of money completely surrounded by
people who want some.
-- Dwight MacDonald