BIT303 Information Security

Information SecurityUnit 1010 min read

Cyber Law & Ethical Issues in Computing

Unit 10 of Information Security: Explores legal frameworks governing cyber activities, ethical dilemmas in computing, and real-world applications of cyber law in Nepal and globally, with case studies and comparative analysis.

TAKEAWAYS:

  • Cyber law in Nepal is still evolving, with key laws like the Cyber Security Act (2073 BS) and Electronic Transactions Act (2063 BS) addressing cybercrimes and digital transactions.
  • Ethical issues in computing include privacy violations, intellectual property theft, and unethical AI use, requiring frameworks like ACM Code of Ethics for guidance.
  • Trust frameworks (e.g., OpenID Connect, OAuth) enable secure authentication and data sharing across platforms, while identity management systems (e.g., eSewa, Khalti) rely on them for user verification.
  • Cyber law intersects with cybercrime, data protection, and digital rights, with global standards like GDPR influencing Nepal’s policies.
  • Malicious software and cyber attacks are legally punishable under cyber laws, but enforcement remains a challenge due to technical and jurisdictional gaps.
  • Understanding ethical hacking vs. cybercrime is critical, as ethical practices (e.g., penetration testing) are legally protected under cybersecurity laws.

1. Introduction to Cyber Law

Cyber law refers to the legal framework governing digital activities, including cybercrimes, electronic transactions, data privacy, and intellectual property in the digital realm. It bridges traditional law with technology, addressing issues like hacking, cyberbullying, and online fraud.

Nepal’s cyber law landscape is shaped by:

  • Cyber Security Act (2073 BS) – Criminalizes cybercrimes like hacking, identity theft, and spreading malicious software.
  • Electronic Transactions Act (2063 BS) – Validates digital contracts and transactions (e.g., eSewa payments, online banking).
  • Personal Data Protection Act (proposed) – Aims to regulate data collection and processing (similar to GDPR in Europe).

1.2 Comparison: Nepal vs. Global Cyber Laws

Country/Region Key Cyber Law Key Features
Nepal Cyber Security Act (2073 BS) Criminalizes hacking, enforces digital signatures, lacks strong data protection.
United States Computer Fraud and Abuse Act (CFAA) Broad definitions of cybercrime, includes penalties for unauthorized access.
European Union GDPR (General Data Protection Regulation) Strict data privacy rules, user consent requirements, heavy fines for violations.
India Information Technology Act (2000) Covers cybercrimes, e-commerce, and digital signatures.

Why this matters: Nepal’s laws are less stringent than GDPR but align with ASEAN’s cybercrime conventions. Understanding these differences helps in cross-border digital transactions (e.g., Daraz selling to international buyers).


2. Ethical Issues in Computing

Ethics in computing governs moral principles guiding technology use, ensuring fairness, transparency, and accountability.

2.1 Major Ethical Dilemmas

  1. Privacy vs. Surveillance

    • Example: Pathao’s GPS tracking for ride-sharing raises privacy concerns.
    • Ethical question: Should companies track users without explicit consent?
  2. Intellectual Property (IP) Theft

    • Example: Unauthorized software piracy in Nepal (e.g., Ncell selling cracked apps).
    • Legal recourse: Copyright Act (2063 BS) protects digital content.
  3. Unethical AI and Bias

    • Example: Bias in loan approval algorithms (e.g., Nepal Bank’s AI rejecting small business loans).
    • Ethical framework: ACM Code of Ethics requires fairness in AI decision-making.
  4. Misuse of Technology (Cyberbullying, Deepfakes)

    • Example: Fake news spread via WhatsApp during elections.
    • Legal action: Cyber Security Act penalizes defamation via digital media.

2.2 Case Study: Daraz’s Ethical Dilemma

Scenario: Daraz uses AI-driven pricing to compete with local shops. Ethical Issue: Does dynamic pricing exploit customers? Solution: Transparent pricing policies and user consent for data collection.

Mermaid Diagram: Ethical Decision-Making Process

flowchart TD
    A["Identify Issue"] --> B["Gather Facts"]
    B --> C["Consult Ethics Guidelines"]
    C --> D["Consider Stakeholders"]
    D --> E["Make Decision"]
    E --> F["Implement & Monitor"]

Cybercrime includes unauthorized access, fraud, and malicious attacks, punishable under cyber laws.

**3.1 Common Cybercrimes in Nepal

Crime Example Legal Penalty (Nepal)
Hacking Unauthorized access to NTC’s network Up to 10 years imprisonment (Cyber Act).
Phishing Fake eSewa login pages Fine + 3 years jail (Electronic Act).
Identity Theft Stealing Ncell user data 5 years imprisonment (Cyber Act).
Malware Distribution Spreading ransomware via emails 7 years imprisonment (Cyber Act).

3.2 Real-World Example: NTC Data Breach (2022)

  • Incident: Hackers leaked NTC customer data (phone numbers, emails).
  • Legal Fallout:
    • NTC faced public scrutiny under the Cyber Security Act.
    • No fines imposed yet, but future breaches may attract heavy penalties.

4. Trust Frameworks and Identity Management

Trust frameworks ensure secure authentication and data exchange between systems.

**4.1 What is a Trust Framework?

A trust framework is a set of rules and standards that validate digital identities and transactions.

  • Example: OpenID Connect (OIDC) used by Khalti for login authentication.
  • Example: OAuth 2.0 used by Google Sign-In for third-party access.

**4.2 Identity Management Systems in Nepal

System Used By How It Works
eSewa Banks, Merchants Uses digital signatures and two-factor authentication (2FA).
Khalti E-commerce Integrates bank accounts via API, ensuring secure transactions.
Ncell MyNcell Mobile Users Uses SMS-based OTP for login verification.

Mermaid Diagram: OAuth 2.0 Flow (Khalti Login)

sequenceDiagram
    participant User
    participant Khalti
    participant Bank
    User->>Khalti: Requests login
    Khalti->>Bank: Redirects to bank for OAuth
    Bank->>User: Asks for consent
    User->>Bank: Grants permission
    Bank->>Khalti: Returns access token
    Khalti->>User: Completes login

5. Cyber Law and Ethical Hacking

Ethical hacking is legally permitted under cyber laws if conducted with explicit permission.

**5.1 Ethical Hacking vs. Cybercrime

Aspect Ethical Hacking Cybercrime
Purpose Improves security (penetration testing) Steals data, causes harm.
Permission Requires written consent No permission, unauthorized access.
Legal Status Protected under cyber laws Illegal, punishable by law.

Example:

  • Legal: A Ncell IT team hacks its own network to find vulnerabilities.
  • Illegal: A hacker steals Ncell user data without permission.

6. Cyber Law and Ethical Issues in Real-World Scenarios

6.1 Case 1: NEPSE’s Data Leak (2023)

  • Issue: Hackers exposed trader data on NEPSE’s platform.
  • Ethical & Legal Response:
    • NEPSE fined traders for not using 2FA.
    • Cyber Security Act was invoked to investigate the breach.

6.2 Case 2: Pathao’s Driver Privacy Concerns

  • Issue: Pathao’s real-time GPS tracking raises privacy ethics.
  • Solution:
    • User consent is required before tracking.
    • GDPR-like data protection policies are being discussed in Nepal.

In the Real World

  1. eSewa & Khalti (Digital Payments)

    • Trust Framework: Uses OAuth 2.0 for secure bank integrations.
    • Ethical Issue: Ensures user data privacy while preventing fraud.
  2. Ncell & NTC (Telecom Security)

    • Cyber Law: Follows Cyber Security Act to prevent SIM swapping attacks.
    • Ethical Hacking: Ncell’s bug bounty program rewards ethical hackers for finding vulnerabilities.
  3. Daraz (E-commerce Ethics)

    • Legal Compliance: Must follow Electronic Transactions Act for online sales.
    • Ethical Dilemma: Balances AI pricing with fair customer treatment.

Exam Tip

  • For short-answer questions (SAQs):

    • Cyber Law in Nepal: Mention Cyber Security Act (2073 BS) and Electronic Transactions Act (2063 BS).
    • Ethical Issues: Focus on privacy, IP theft, AI bias, and cyberbullying.
    • Trust Frameworks: Explain OAuth 2.0 and OpenID Connect with Khalti/eSewa examples.
  • For long-answer questions (LAQs):

    • Compare Nepal’s cyber laws with GDPR/USA laws (use the table above).
    • Discuss ethical dilemmas in AI (e.g., Nepal Bank’s loan AI).
    • Explain how trust frameworks work (use Mermaid OAuth flow as a reference).
  • Worked Example (RSA + Legal Context):

    • Question: "Explain RSA with a numerical example and its legal implications in Nepal."
    • Answer:
      • RSA Steps:
        flowchart TD
            A["Choose p=5, q=11"] --> B["Compute n=p*q=55"]
            B --> C["Choose e=3 (coprime with φ(n)=40)"]
            C --> D["Compute d=27 (e*d ≡ 1 mod 40)"]
            D --> E["Public Key: (e,n)=(3,55); Private Key: (d,n)=(27,55)"]
      • Legal Use: Banks use RSA for secure transactions under Electronic Transactions Act.
      • Ethical Note: If RSA keys are stolen, it’s a cybercrime under Cyber Security Act.
  • Common Pitfalls:

    • Don’t confuse ethical hacking with cybercrime (always mention permission).
    • Don’t forget to link Nepal’s laws to real cases (e.g., NTC breach, Daraz AI).
    • For trust frameworks, always name a real app (Khalti, eSewa) and explain its flow.

Final Note: This unit is highly exam-focused—prioritize legal definitions, ethical dilemmas, and real-world examples (Nepal + global). Use tables, Mermaid diagrams, and case studies to stand out!

Based on the TU BIT syllabus for Information Security (BIT303), unit 10.

Discussion

Loading…