munotes®

The Rest of the Law: Source Code, Identity, Protected Systems and Confidentiality

Get access to whole semester resourcesSemester Pass

Chapter Three

Syllabus topic Module 1, "Foundations of Ethical Hacking and Cyber Terminology ... legal boundaries"; Course Objective 1, "legal frameworks in ethical hacking"

Pages 10 to 15 of 578

In one line

Beyond sections 43 and 66, the Act punishes tampering with source code, stealing an identity, pretending to be someone by computer, touching a system the Government has declared protected, and leaking what you saw. Each maps to something this book teaches you to do, and therefore to something you must not do without authorisation.

In examination wording: the Information Technology Act 2000 supplements its core provisions with offences addressing source-code tampering (s.65), receipt of stolen computer resources (s.66B), identity theft (s.66C), cheating by personation using a computer resource (s.66D), cyber terrorism (s.66F), unauthorised access to protected systems (s.70) and breach of confidentiality (s.72), and it applies extra-territorially under s.75 where a computer located in India is involved.

Why a tester needs more than two sections

Sections 43 and 66 answer "may I touch this system?". They do not answer the questions that arise once an engagement is under way, and those questions are where a careless tester strays:

  • I captured a password during the test. May I use it? (s.66C)
  • I want to send a phishing email that appears to come from the client's HR department. (s.66D)
  • The scope names a server that turns out to be part of the national power grid's infrastructure. (s.70)
  • My report contains customer names I saw in a database. (s.72)
  • The client is in Mumbai but the server is in Singapore. (s.75)

Each has a provision behind it, and knowing which is what separates a professional from an enthusiast.

Section 65: tampering with computer source code

Whoever knowingly or intentionally conceals, destroys or alters or intentionally or knowingly causes another to conceal, destroy, or alter any computer source code used for a computer, computer programme, computer system or computer network, when the computer source code is required to be kept or maintained by law for the time being in force, shall be punishable with imprisonment up to three years, or with fine which may extend up to two lakh rupees, or with both.

Two features matter. First, the Act defines "computer source code" broadly in its own Explanation: the listing of programmes, computer commands, design and layout and programme analysis of a computer resource in any form. It is not only the text of a program. Second, and this is the limit students miss, the section bites where the source code is required to be kept or maintained by law. It is aimed at the destruction of records a person was legally obliged to preserve, not at every edit of every file.

For a tester the relevance is direct: an engagement that involves reviewing a client's source code carries an obligation not to alter it, and any modification made during a test is logged and reversed.

munotes.in10

The Rest of the Law: Source Code, Identity, Protected Systems and Confidentiality

Sections 66B, 66C and 66D: stolen resources, identity and personation

These three are the ones a penetration test can blunder into within an hour of starting.

Section 66B, dishonestly receiving a stolen computer resource. Dishonestly receiving or retaining any stolen computer resource or communication device, knowing or having reason to believe it is stolen: up to three years, or up to one lakh rupees, or both. A tester who is handed a dump of credentials from an unexplained source is in this territory, which is why data used in an engagement comes from the client or from the tester's own lawful collection, never from a breach dump of unknown provenance.

Section 66C, identity theft. Fraudulently or dishonestly making use of the electronic signature, password or any other unique identification feature of any other person: up to three years and a fine up to one lakh rupees. This is the section that governs what you do with a credential you recover during a test. Cracking a password hash in a laboratory you own is one thing; using a real employee's recovered password to log in as them is use of another person's unique identification feature, and it is lawful only because, and only to the extent that, the scope authorises it. A scope that says "you may test the login mechanism" does not automatically say "you may log in as a named human being and read their mail".

Section 66D, cheating by personation using a computer resource. Cheating by personation by means of any communication device or computer resource: up to three years and a fine up to one lakh rupees. This is the phishing section. A social-engineering exercise in which you send a message appearing to come from the client's IT department, to induce staff to do something, is personation by computer resource. Performed inside an authorised social-engineering engagement it is a service; performed on your own initiative it is an offence, and the difference is, once again, the scope.

Section 66F: cyber terrorism

Cyber terrorism is defined by intent and effect: acts done with intent to threaten the unity, integrity, security or sovereignty of India, or to strike terror, by denying access to a computer resource, attempting unauthorised access, or introducing a contaminant, and causing or likely to cause death, injuries, damage to property, or disruption of supplies or services essential to the life of the community, or affecting critical information infrastructure. It is punishable with imprisonment which may extend to imprisonment for life.

No ordinary penetration test approaches this, and the section is included for one reason: it marks how seriously the law treats attacks on infrastructure that people depend on. It is the backdrop to section 70.

munotes.in11

The Rest of the Law: Source Code, Identity, Protected Systems and Confidentiality

Section 70: protected systems, and the ten-year line

(1) The appropriate Government may, by notification in the Official Gazette, declare any computer resource which directly or indirectly affects the facility of Critical Information Infrastructure, to be a protected system.

(3) Any person who secures access or attempts to secure access to a protected system in contravention of the provisions of this section shall be punished with imprisonment of either description for a term which may extend to ten years and shall also be liable to fine.

The Act's own Explanation defines Critical Information Infrastructure as a computer resource whose incapacitation or destruction would have a debilitating impact on national security, economy, public health or safety. Power, banking, telecommunications and transport sit here.

Three things follow for a tester, and they are the practical heart of this chapter:

  1. The penalty is ten years, not three. This is the most severe ordinary provision you can stumble into.
  2. An attempt is enough. Section 70(3) punishes securing access or attempting to secure access. A scan that fails still attempted.
  3. You may not know a system is protected by looking at it. A declaration is made by notification in the Gazette, not by a banner on the login page.

That third point is why scope documents name systems explicitly and exclude everything else, and why a tester who discovers an unexpected system during an engagement stops and asks rather than probing. Authorisation to access a protected system comes from the Government's own written authorisation under s.70(2), not from the system's operator alone.

Section 72: confidentiality, and what goes in your report

Section 72 penalises a person who, having secured access to any electronic record, book, register, correspondence, information, document or other material in pursuance of powers conferred under the Act, discloses it to another person without the consent of the person concerned. (The original two-year term was revised to a monetary penalty by later amendment.)

Its neighbour, section 72A, is the one closer to a tester's life: disclosure of personal information obtained while providing services under a lawful contract, without consent and with intent to cause or knowledge of likely wrongful loss or gain, attracts a substantial penalty.

A penetration tester provides services under a lawful contract and routinely sees personal data. The professional discipline that follows is concrete:

  • Do not copy out more data than is needed to prove a finding.
  • Redact personal data in the report; prove the flaw with one masked record, not a spreadsheet of customers.
  • Store test artefacts encrypted, and destroy them at the engagement's end.
  • Never reuse client data in another engagement, a talk or a portfolio.
munotes.in12

The Rest of the Law: Source Code, Identity, Protected Systems and Confidentiality

Section 66A: dead law, still cited

Section 66A once punished sending "grossly offensive" or "menacing" messages by computer. The Supreme Court struck it down in Shreya Singhal v. Union of India (2015) as an unconstitutional restriction on the freedom of speech guaranteed by Article 19(1)(a), being vague and overbroad. The bare Act still prints the text marked Omitted.

Know it for two reasons: examiners ask, and it is still wrongly cited in news reports and even in police practice. A student who can say "66A was struck down in Shreya Singhal and is not law" is demonstrating exactly the currency this subject demands.

Section 75: the Act reaches outside India

Section 75 provides that the Act applies to an offence or contravention committed outside India by any person, if the act involves a computer, computer system or computer network located in India. So a tester in Mumbai who touches a server in Singapore is exposed to Singapore's law, and an attacker abroad who touches a server in India is within reach of this Act. Cross-border work multiplies the legal analysis; it never removes it.

A worked example

Vikram is engaged to test a bank's customer portal. His scope names two web servers and authorises credential testing but says nothing about social engineering or internal systems.

  • He recovers a test account's password from a weak hash and uses it to log in to the named portal. Lawful: the scope authorises testing the login mechanism, and the account is a test account provided by the client. Had it been a real customer's credential, s.66C would demand explicit authorisation he does not have.
  • He decides to email bank staff a message appearing to be from the IT helpdesk, to see who responds. Not lawful: that is personation by computer resource under s.66D, and social engineering is not in his scope.
  • During the test he notices a server belonging to a payment network and probes it. Serious risk: it is outside the scope, so s.43 applies at once, and if it has been notified as a protected system, s.70 applies with its ten-year maximum, and an attempt suffices.
  • His report quotes fifty customers' names and account numbers to prove a data-exposure flaw. Wrong practice and a s.72A risk: one masked record proves the flaw; the rest is unnecessary disclosure of personal information obtained under a services contract.

Every error is a scope error. That is the lesson the next chapter builds on.

Distinctions that carry marks

ProvisionConductMaximum
s.65Concealing, destroying or altering source code required to be kept by law3 years, or 2 lakh, or both
s.66BDishonestly receiving a stolen computer resource3 years, or 1 lakh, or both
s.66CFraudulently using another's signature, password or unique ID feature3 years and 1 lakh
s.66DCheating by personation using a computer resource3 years and 1 lakh
s.70Securing, or attempting to secure, access to a protected system10 years and fine
s.66FCyber terrorismUp to imprisonment for life
munotes.in13

The Rest of the Law: Source Code, Identity, Protected Systems and Confidentiality

What beginners get wrong

  • Treating a recovered password as free to use. Recovering it and using it are different acts; using a real person's credential engages s.66C and needs explicit authorisation.
  • Thinking phishing is only unethical, not illegal. It is personation by computer resource under s.66D. Authorised social-engineering testing is a contracted service; unauthorised phishing is an offence.
  • Assuming a protected system announces itself. Declaration is by Gazette notification. You find out from the scope and the client, not from the server.
  • Citing section 66A. It has been struck down since 2015 and is not law.
  • Putting raw personal data in the report to be thorough. It is the opposite of thorough; it creates a fresh disclosure risk under s.72A. Prove the finding with a masked sample.

Quick revision

  • s.65 source-code tampering (where the code must be kept by law); s.66B receiving a stolen computer resource; s.66C identity theft (using another's password or unique identifier); s.66D cheating by personation (the phishing section); s.66F cyber terrorism (up to life).
  • s.70 protected systems: ten years, and an ATTEMPT is enough. Protected status comes from a Gazette notification, so the scope is how you know.
  • s.72 and s.72A: confidentiality. A tester sees personal data; redact it, minimise it, encrypt it, destroy it.
  • s.66A is Omitted, struck down in Shreya Singhal v. Union of India (2015). Do not cite it as live law.
  • s.75: the Act reaches acts committed outside India involving a computer located in India.

Test yourself

  1. Why does section 70 matter more to a tester than its wording suggests?

Because it carries a ten-year maximum, it punishes an attempt to secure access as well as success, and protected status is conferred by Gazette notification rather than being visible on the system, so a tester can only know from the scope and the client.

  1. A tester recovers a real employee's password during an engagement. Which section governs what they do next, and what makes the use lawful?

Section 66C, identity theft, which covers fraudulently or dishonestly using another person's password or unique identification feature. Use is lawful only to the extent the client's written scope expressly authorises it.

  1. Under which section does a phishing simulation fall, and when is it lawful?

Section 66D, cheating by personation using a computer resource. It is lawful only when the engagement's scope and rules of engagement expressly authorise social-engineering testing.

munotes.in14

The Rest of the Law: Source Code, Identity, Protected Systems and Confidentiality

  1. What is the status of section 66A, and why must you know it?

It was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015) as violating Article 19(1)(a), and the Act prints it as Omitted. It must be known because it is still wrongly cited.

  1. What obligations does section 72A place on how you write a penetration-test report?

It penalises disclosing personal information obtained while providing services under a lawful contract, without consent. So a report minimises and redacts personal data, proves findings with masked samples, stores artefacts securely and destroys them at the engagement's close.

munotes.in15

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!