This is an archive article published on July 27, 2021
Premium

Why privacy protection alone won’t help against illegal surveillance

Subhashis Banerjee writes: Sophisticated surveillance attempts like Pegasus, which bypass data protection architecture and regulatory oversight, must be met with public outrage, which can only emerge from commitment to constitutional morality.

Politicians, rights activists and journalists were among those targeted with phone spyware sold to various governments by the Israeli firm NSO Group Technologies, according to an international media consortium.Politicians, rights activists and journalists were among those targeted with phone spyware sold to various governments by the Israeli firm NSO Group Technologies, according to an international media consortium.
Written by: Subhashis Banerjee
6 min readJul 27, 2021 07:58 AM IST First published on: Jul 27, 2021 at 03:30 AM IST

The recent allegations and reports by Arsenal Consulting and Amnesty International on targeted electronic surveillance of selected activists, politicians, journalists, businessmen and even scientists are disconcerting, to say the least. Not only does the sophistication of the attacks engender a sense of resigned helplessness, but the incidents — if true — also have a chilling effect on personal and civil liberties that are crucial for a democracy to function. What is even more worrisome is that there seems to be a significant veiled popular opinion — among friends and families — that justifies such transgressions in the name of national security.

If indeed the charges against some of the jailed activists in the Bhima Koregaon case are primarily based on evidence in the seized hard disks, then the Arsenal reports — if verified — should weaken the grounds significantly. According to the Arsenal reports, there is clear evidence that the incriminating files were planted in the hard disks from remote command-and-control centres by unknown entities, even before the disks were seized, and that the activists were apparently not even aware of their existence. While some parts of Arsenal’s forensic analysis were based on proprietary tools, several other aspects of the reports should be verifiable by independent experts — and many in India should be able to do this — using publicly available resources. The offending files were apparently injected by planting a Trojan malware called NetWire by orchestrating some kind of phishing attacks on the unsuspecting activists. This kind of attack is fairly standard and the presence of NetWire can apparently even be detected by some of the commonly available virus and malware scanners. Given that such attacks are a reality today, governments and legal authorities need to ensure that digital evidence arising out of such forensic analysis is admissible in courts.

Latest Comment
Post Comment
Read Comments