Analyzing and providing feedback on GOIs draft policies
Posted: 22 Sep 2015 10:46
The current GOI has been very open about its proposals and policies. For example the GOI solicits ideas and feedback via MyGov.in. It has also been noticed that actionable feedback via MyGov.in has been acted upon.
In similar efforts the Department of Electronics and Information TechnologY (DEITY) has put together several proposals on its website at http://deity.gov.in/blog and with intent of soliciting open public opinion.
First of all, this attempt to open up its proposal and solicit public feedback is laudable. Second it is important and imperative for the public to provide its critical but objective feedback to those proposals.
This thread is to track each proposal of the GoI and critically but more importantly objectively analyze the proposal and hopefully draft an objective feedback to GOI.
There is no return for the hard work and the toil that the forum members put in to objectively evaluate GOIs proposal and there is no guarantee that the feedback may even be incorporated., however great it might be. My minimum expectation is that the posts will be less of rancor and more of evaluation of a proposal that befits the professional lives of the forum members.
Further any criticism of the policies from the media will also be evaluated. That is, the criticisms of the media itself will be under scanner and the media will also be criticized - particularly if they deviate from an objective analysis. Note that the media journos are journalist firsts and subject matter expert last. And they tend to move in groups creating its own echo chambers. So if this thread can bring some sanity to such echo chambers., that will be a good outcome.
The initials proposal that kick'ed this thread is the following policy:
DRAFT NATIONAL ENCRYPTION POLICY
My belief is that the media journos should be the last people to criticize the above since they are not subject matter experts. Unless the article appearing in media itself is from a known subject matter expert.
As noted the above 6 page PDF is a draft policy and its feedback is due by October 16, 2015.
The next sections I will try to take the policy and deconstruct it.
A background on myself., I am NOT a "known" subject matter expert in Computer Security and Cryptography. However my background is Computer Security. I obtained my master's thesis on two separate areas - evaluating Generic Security Services API for object oriented languages and researching transcendental numbers for one-way hash functions*. Of course, writing DES algorithm or creating pseudo-Kerberos systems or implementing elliptic-curve algorithms are par for the course.
The reason I am putting up my background is simple., I believe that given the background - I am more qualified than an average journalist without any grounding in Comp Sec/IT Sec or experience dealing with Comp Sec/IT Sec on commenting on the draft security policy linked above.
*Side note: If the second part of the research had gone through to its conclusion, I would have been a "known" subject matter expert.
A request to mods., I understand that this thread increases your case load. However please let this thread continue. The goal is to provide an objective feedback to GOI on its policy.
As the stress is on objective feedback., I hope there is less (or none of rancor) and more of "agree to disagree" in case of conflicts. And I do humbly accept that my analysis may be completely off the mark and I may stand corrected by other more esteemed members.
In similar efforts the Department of Electronics and Information TechnologY (DEITY) has put together several proposals on its website at http://deity.gov.in/blog and with intent of soliciting open public opinion.
First of all, this attempt to open up its proposal and solicit public feedback is laudable. Second it is important and imperative for the public to provide its critical but objective feedback to those proposals.
This thread is to track each proposal of the GoI and critically but more importantly objectively analyze the proposal and hopefully draft an objective feedback to GOI.
There is no return for the hard work and the toil that the forum members put in to objectively evaluate GOIs proposal and there is no guarantee that the feedback may even be incorporated., however great it might be. My minimum expectation is that the posts will be less of rancor and more of evaluation of a proposal that befits the professional lives of the forum members.
Further any criticism of the policies from the media will also be evaluated. That is, the criticisms of the media itself will be under scanner and the media will also be criticized - particularly if they deviate from an objective analysis. Note that the media journos are journalist firsts and subject matter expert last. And they tend to move in groups creating its own echo chambers. So if this thread can bring some sanity to such echo chambers., that will be a good outcome.
The initials proposal that kick'ed this thread is the following policy:
DRAFT NATIONAL ENCRYPTION POLICY
My belief is that the media journos should be the last people to criticize the above since they are not subject matter experts. Unless the article appearing in media itself is from a known subject matter expert.
As noted the above 6 page PDF is a draft policy and its feedback is due by October 16, 2015.
The next sections I will try to take the policy and deconstruct it.
A background on myself., I am NOT a "known" subject matter expert in Computer Security and Cryptography. However my background is Computer Security. I obtained my master's thesis on two separate areas - evaluating Generic Security Services API for object oriented languages and researching transcendental numbers for one-way hash functions*. Of course, writing DES algorithm or creating pseudo-Kerberos systems or implementing elliptic-curve algorithms are par for the course.
The reason I am putting up my background is simple., I believe that given the background - I am more qualified than an average journalist without any grounding in Comp Sec/IT Sec or experience dealing with Comp Sec/IT Sec on commenting on the draft security policy linked above.
*Side note: If the second part of the research had gone through to its conclusion, I would have been a "known" subject matter expert.
A request to mods., I understand that this thread increases your case load. However please let this thread continue. The goal is to provide an objective feedback to GOI on its policy.
As the stress is on objective feedback., I hope there is less (or none of rancor) and more of "agree to disagree" in case of conflicts. And I do humbly accept that my analysis may be completely off the mark and I may stand corrected by other more esteemed members.