Search interesting materials

Friday, May 21, 2021

India's supply chain vulnerability with Chinese APIs: Industrial policy vs. sophisticated policy design

by Gautam Bambawale, Vijay Kelkar, Raghunath Mashelkar, Ganesh Natarajan, Ajit Ranade, Ajay Shah.

India has a remarkable drugs industry. This involves a high dependence upon Chinese manufacturers of `active pharmaceutical ingredients' (APIs). Given the willingness of the Chinese state to behave in unusual ways in economic engagement (e.g. rare earths), there is a certain supply chain risk that is faced by Indian firms.

Should state power be used in addressing this problem? And if so, how should this be done? How do we avoid the long decades of failure in industrial policy, i.e. the experiments with policy pathways where a government picks winners, with a government that claims to know the correct ways in which production should be organised? Today we saw a fascinating article: Drugmakers cry ‘monopoly’ as Modi govt picks 1 firm each to make over 20 key raw materials by Himani Chandna in The Print. This narrates the story of a 1960s style Indian industrial policy intervention played out poorly.

Our book Checkmate China: Winning through strategic patience and accelerated economic growth is forthcoming from Rupa Publications later this year. A paper based on this book has been released in the public domain and summarises our strategic thinking for India about the China question. In the book, we have a treatment of the API question. This text is excerpted ahead. It represents our attempt at learning from 75 years of failure with industrial policy. This approach would have likely avoided the difficulties described in Himani Chandna's article.

Book excerpt: Designing a government intervention to address the supply chain risk faced by Indian firms that import APIs from China

The Indian drugs industry is a heavy user of Active Pharmaceutical Ingredients (APIs) sourced from China. In an environment where we see China as a bad actor in the global economy, where Chinese nationalism can harm counterparties abroad, this presents a risk to the supply chain. It is easy to design Indian economic nationalism which can combat this. However, as with all aspects of industrial policy, such use of state power raises many concerns. It is difficult for a government agency to know whether a certain industry merits subsidies and whether certain firms merit subsidies. There is a long history, in India, of “infant industry” arguments being used for decades, in which some well-connected Indian firms stay infants and continuously collect fiscal subsidies. Similarly, trade barriers in the form of quantity restrictions are prohibited under the WTO and tariffs are harmful and should best be avoided.

Thus, we face a puzzle: How can state intervention be designed, which can make a difference to India’s China problem with the supply of APIs? Given the failures of industrial policy as it was practiced in previous decades, how can this one sharp problem (supply chain risk faced by Indian pharma companies who rely on Chinese producers of APIs) be addressed by state action? How can this state action be done at the minimum fiscal cost, and while imposing the minimum distortions upon the economy? How can the risk of central planning – of officials determining the outcomes of the market-based competitive process – be avoided?

When faced with supply chain risk with a certain API from China, we should not jump to the conclusion that the answer lies in making the API in India. Perhaps the efficient solution is to import the API from a country other than China. Perhaps the efficient solution is to make it in India. Policy makers cannot assume that India has competitive advantage in making the API, when private persons have thus far chosen to not build such factories in India.

The first step in every policy analysis must be a thorough understanding of the behaviour of the private sector assuming there is zero state intervention. When faced with this new supply chain risk, what are Indian drug companies likely to do out of self interest:

  1. Customers of these bulk drugs would be conscious about the business risk that they carry. They would watch the rise of nationalism in China with concern.
  2. They would increasingly seek to diversify their sourcing. As an example, we are seeing Fortune 500 companies increasingly reduce the share of China in their global production.
  3. One important response by the firms will be to buy APIs from countries other than China, e.g. Taiwan or Japan or Brazil. This is perfectly adequate solution, from the viewpoint of an Indian firm, to the threat of Chinese nationalism. Our problems with Chinese nationalism only imply that we should diversify away from China; this does not justify self-reliance.
  4. One element of the process of looking for non-China sourcing is higher demand for firms in India that make APIs, which would kick off a supply response. Ordinarily, this market process will work itself out. But it is a difficult and slow journey. A government program can be designed that addresses this problem, which has a few key features: (a) We do not assume that in the long run India will be a successful producer of APIs, but we consider this possible; (b) The intervention is pre-announced and in a few years, liquidates itself; (c) The intervention imposes zero trade barriers upon imports or exports of APIs or drugs with respect to any country.

This proposed intervention would involve the following steps:

  • A government agency would identify the top 50 APIs and the quantities $q = (q1, q2, .. q50)$ which are being imported from China.
  • We establish the objective of domestic production that comes up to half of the imports from China over a five year period. This suggests escalation of quantities as: $0.1q, 0.2q, 0.3q, 0.4q, 0.5q$ over a period of five years.
  • We put out a binding commitment on the part of the state that the government will run procurement restricted to domestic producers only, where there will be purchases over the next five years of these quantities. The government will commit to placing orders with 3 lowest-cost firms that produce in India, in each year’s bidding. The requirement from a bidder should be that production is done in India. Foreign or Indian firms should be permissible, subject to a restriction against firms controlled by the Chinese state e.g. bar a firm where any one member of the board of directors is an employee of the Chinese state or the CCP.
  • These commitments about a rising scale of GOI procurement will create incentives for Indian/foreign firms, located in India, to build knowledge and physical capacity to produce APIs at a large scale.
  • The government agency has only one objective: to trigger off economies of scale and competition by producers in India. Once the goods are purchased by the Indian government agency, what is it to do with them? Indian firms might not like to buy these APIs at the purchase price, as the purchase price may well be higher than the world price of these APIs. Once the goods are purchased, this agency would run a global auction to sell the same goods off, at the highest possible price. Indian drug companies could potentially choose to buy these goods, but these purchases would be at an import-parity-pricing price. As a consequence, through this program, the Indian government would be drop shipping the goods, purchased in the make-in-India auction to buyers who came into the sell-from-India auction.

This scheme constitutes a promise to buy from Indian firms, at rising quantities over five years, at the lowest prices that Indian firms are able to muster (3 firms for each product in each year). At first, the price in India will be high. Under this proposal, GOI will instantly turn around and sell off the goods at the highest possible price through a global tender. The gap between the two prices will be the fiscal subsidy that is being put down, to spark off API production in India.

At the end of five years, the domestic firms would be on their own. If the theory of change is correct – that there is a fixed cost of building knowledge and facilities to make APIs – then this is the minimum intervention that gets the job done. If the theory of change is incorrect – that India is not actually a good platform for making APIs – then in five years, this fiscal outgo would end, and India would not be a producer of APIs.

There are many strengths of this design:

  1. Private persons face no new coercion, other than the coercion implicit in mobilising tax resources which are the source of government spending on this program.
  2. There is no tariff; there is no interference in international trade. This program is layered on top of a free trade system.
  3. It is a simple and transparent intervention. What it requires is the bureaucratic capability in the Indian state to do procurement: to run these auctions, to buy APIs in India, and to sell the same goods globally, doing high volumes of non-complex commodities. Indian officials are not asked to form a judgement about what APIs are important, about whether an API can efficiently be made in India, about the technology through which an API can be made, about whether public money should be used to build factories to make APIs.
  4. There is a lack of fudge factors where there can be lobbying and negotiations.
  5. No central planner should ever assume s/he knows the way forward. This design respects the possibility that India might actually have no place in API production. In this case, at the end of this program, there will be no API manufacturing in India. The program would have wasted taxpayer resources, but it would not distort the economy.

However, there are four main difficulties of this design:

  1. For the desired impact upon incentives of private firms who should commit themselves to investing in building large scale API production, the private sector would have to believe that the deeds of the government will match the words of the government over the coming five years. If private persons feel that the Indian state cannot be trusted to stay the course for five years, then the incentive impact of the government program would not materialise.
  2. The private sector has to feel safe engaging with government procurement; it has to believe that the procurement will be done correctly, that payments will be made on time, that there will be no investigations by agencies.
  3. If this works, at the end of five years, Indian API vendors will lobby to not shut this down. Every policy designed to support an infant industry ends up with entrenched infants who like to wield state power in their favour.
  4. While the objective of the program should be to foster Indian or foreign firms who choose to produce in India, there is the possibility that this could be skewed to favour Indian firms.

Tuesday, May 18, 2021

Correction: How large is the payment delays problem in Indian public procurement?

Notice of Republication

This article was republished on 14th May 2021, to correct an error in Table 2 of the original article. The authors apologize for the errors. The article with the corrections can be accessed here.

Announcements

Position for Researchers in Public Policy and Regulatory Governance

The National Law School of India University, Bengaluru (NLS) is a premier legal university in India. NLS, with the support of the Omidyar Network India, has set up the Regulatory Governance Project. The project will generate original research aimed at 'restocking the regulatory toolkit' for India. The research will identify the administrative aspects and norms of regulatory authorities and their parent bodies that can be optimised to create autonomous, accountable and effective institutions. A key goal of the project is to assist policymakers and regulators in shaping specific modifications in regulatory frameworks and practices and make them more contemporary, particularly in the context of the proposed Data Protection Authority.

NLS is seeking a candidate for a full-time or part-time position as a Research Fellow (Economist) in this project. The research fellow will participate in shaping the research questions for the project and undertake original research in answering such questions. The role requires working as a team with the other researchers in the project and at NLS. Key deliverables will be to produce original research, working papers and any assistance to regulators, as may be required. Compensation will be based on terms of engagement and experience of the candidate.

Requirements for the Research Fellow (Economist)

Candidates should have:

  • a Masters degree in economics or statistics;
  • a minimum of five years’ experience; and
  • strong data analytics, research and writing skills.

How to Apply

Interested candidates please write to research@nls.ac.in with the subject line "Application for Research Fellow (Economist) in the Regulatory Governance Project".

Monday, May 10, 2021

Backdoors to Encryption: Analysing an Intermediary's Duty to Provide 'Technical Assistance'

by Rishab Bailey, Vrinda Bhandari, and Faiza Rahman.

The rising use of encryption is often said to be problematic for law enforcement agencies (LEAs) in that it directly impacts their ability to collect data required to prosecute online offences. While certainly not a novel issue, the matter has risen to global prominence over the last four or five years, possibly due to the increased usage of privacy enhancing technologies across the digital ecosystem.

While there have been a number of policy proposals that seek to address this perceived impasse, no globally accepted best practice or standard has been evolved thus far. In India (as in many other jurisdictions), the government has increasingly sought to regulate the use of encryption. For instance, the recently announced Intermediary Guidelines under the Information Technology Act, 2000, seek to extend the "technical assistance" mandate of certain intermediaries to ensure traceability, by enabling identification of the first originator of the information on a computer resource. The scope of the term "technical assistance" has not been clearly defined. However, the provision appears to go well beyond existing mandates in the law that require holders of encryption keys to provide decryption assistance, when called upon to do so, in accordance with due process, and based on their capability of decrypting the encrypted information. Courts have also weighed in on this debate, with the Madras High Court and the Supreme Court hearing petitions that seek to create mechanisms whereby LEAs could gain access to content protected by end-to-end encryption (E2E), thereby enabling access to user conversations on popular platforms such as WhatsApp. A Rajya Sabha Ad-hoc Committee Report released in 2020 has also recommended that LEAs be permitted to break or weaken E2E to trace distributors of illegal child sexual abuse content.

Against this background, our recently released paper examines the scope of the obligations that ought to be imposed on intermediaries to provide "technical assistance" to LEAs, and whether that should extend to weakening standards of encryption, for instance, through the creation of backdoors. Broadly speaking the term "backdoors" refers to covert methods of circumventing encryption systems, without the consent of the owner or the user. The paper also evaluates, in brief, proposals for alternatives, such as the use of escrow mechanisms and ghost protocols.

We argue that the government should not impose a general mandate for intermediaries to either weaken encryption standards or create backdoors in their products/platforms. This can significantly affect the privacy of individuals and would constitute a disproportionate infringement into the right to privacy. Such a mandate will also likely fail a cost-benefit analysis, not least in view of the possible effects on network security as well as broader considerations such as growth of the Indian market in securities products, geopolitical considerations, etc. This however, does not mean that the law enforcement agencies have no options when faced with the prospect of having to access encrypted digital data. A first step in this regard would be to implement rights-respecting processes to enable law enforcement to access data collected by intermediaries in a timely manner. In addition, there should be greater focus on enhancing government and law enforcement capacities, including by developing hacking capabilities, with sufficient oversight and due process checks and greater funding to research and development efforts in the cybersecurity and crypto spaces.

This post seeks to throw light on the key issues around the encryption debate, and summarises our main arguments and suggestions on how India should address them.

Understanding the encryption debate

Encryption is the process of using a mathematical algorithm to render plain, understandable text into unreadable letters and numbers (Gill, 2018). Typically, an encryption key is used to carry out this conversion. Reconverting the encrypted text back to plain-text also requires an encryption key. Depending on the manner of encryption, the same encryption key can be used to encrypt or decrypt information, or alternatively, one may require different encryption and decryption keys. Encryption therefore ensures that the message can only be read by the person who has the appropriate decryption key, particularly as newer forms of encryption make it inefficient, if not impossible, to reverse the encryption process (Gill, 2018).

Encryption essentially improves the security of information. It secures information against unwarranted access and ensures the confidentiality and integrity of data, thereby fostering trust in the digital ecosystem and protecting the private information of citizens and businesses alike.

However, the use of encryption can also enable criminals to "go dark", making it difficult for LEAs to carry out their functions. For instance, it is estimated that upwards of 22 percent of global communication traffic uses end-to-end encryption (Lewis et al, 2017). This puts a quarter of communications virtually out of reach for LEAs, not least as the use of modern encryption systems makes it harder for LEAs to use the traditional "brute force" method to access encrypted data (Haunts, 2019). LEAs therefore have increasingly called for limitations to be placed on the use of encryption so as to enable them to have access to information they require to pursue their law enforcement functions. They point to the need to ensure accountability for online harms, and therefore argue that intermediaries must provide them with all data relevant to an investigation.

The concerns with the use of encryption are driven by a number of factors such as the growing instances of cybercrime, the use of data minimisation practices such as disappearing messages and the use of encryption by default in various technology products. For instance, WhatsApp and Signal automatically encrypt communications in transit and also give users the option of automatically deleting their messages. Similarly, Apple uses encryption based authentication on its iPhones (which render the content accessible only if an appropriate passcode is provided. If not, the content on the phone could even be deleted after a certain number of failed attempts) (Lewis et. al, 2017).

These concerns have led to calls for Internet intermediaries to weaken encryption standards or create backdoors in their products/services. These demands are not new. Notably, the 1990s saw the issue being debated in the United States, with the FBI proposing the use of the "Clipper Chip", a mechanism whereby decryption keys would be copied from the devices of users and sent to a trusted third party, where they could be accessed on appropriate authorisation by LEAs. More recently, the FBI has been involved in face-offs with technology companies such as Apple, when it refused to provide exceptional access to an iPhone linked to a terrorist. In India too, the government has encountered similar issues - notably forcing Blackberry manufacturers to relocate their servers to India and hand over plain text of communications. The government also circulated a draft National Encryption Policy in 2015, which sought to implement obligations involving registration of encryption software vendors, and the need for intermediaries to store plain text of user data. The draft was however withdrawn after much criticism.

In response to such proposals, security researchers, cryptographers and service providers, have been near unanimous in pointing out that the creation of backdoors is likely to lead to significant costs to the entire digital ecosystem, especially as it leads to the entire population being exposed to vulnerabilities and security threats. Indeed, the need for stronger encryption and other security standards to protect user data is only heightened by the numerous and frequent data breaches that have been reported in India. Interestingly, even the Telecom Regulatory Authority of India has adopted a similar position in its Recommendations on Regulatory Framework for OTT Communication Services of 2020.

Even two commonly discussed methods of a "balanced solution" to the problem - the use of escrow mechanisms and ghosting protocols - have faced significant criticism. For instance, the use of escrow mechanisms (which, as with the Clipper Chip system described above, involve storage of the decryption key with a trusted third-party, who can then provide the same to LEAs when called upon to do so) is likely to lead to significant vulnerabilities being created in computer systems. Not only will such a system require faith in the integrity of the entity holding the decryption key, such an entity would constitute a single point of failure, which is poor system design (Kaye, 2015). Deployment of complex key recovery infrastructure is also likely to impose huge costs on the ecosystem (Abelson et al., 1997). Similarly, suggestions for using ghost protocols (which would require service providers to secretly add an extra LEA participant to private communications) have also faced significant criticism (Levy and Robinson, 2018). Given that this system would essentially require service providers to convert a private conversation between two individuals into a group chat, with a hidden third participant, critics have argued that it is just another form of a backdoor. It would erode trust between consumers and service providers, and provide for a "dormant wiretap in every user's pocket" that can be activated at will. This would also require fundamental changes in system architecture, thereby introducing vulnerabilities that can create threats for all users on platforms (Access Now et al., 2019).

Thus, while the use of such methods can enable LEAs to access user data more quickly than is currently possible, there are numerous concerns - from a civil liberties, economic and technical perspective. We outline the key concerns in this regard below.

Concerns with mandating backdoors

  • Privacy: In view of the recognition of privacy as a fundamental right, private thoughts and communications are protected from government intrusion subject to satisfaction of tests of necessity and proportionality. Mass surveillance can be considered to be per se disproportionate. It is recognised that government surveillance can lead to unwanted behavioural changes, and create a chilling effect. Encryption therefore serves as a method to protect individual privacy, particularly from government excesses.
  • Security: Creating backdoors can weaken network security as a whole since it can be exploited by governments and hackers alike (Abelson et al., 2015). Backdoors can also lead to increased complexity in systems, which can make them more vulnerable to attack (Abelson et al., 2015).
  • Right against self-incrimination: Mandating decryption of data can arguably also be seen as violating an individual's right against self-incrimination (Gripman, 1999; ACLU and EFF, 2015).
  • Due process requirements: Criminal investigation in general and surveillance in particular is not meant to be a frictionless process. Introducing inefficiencies in the functioning of LEAs is what separates a police state from a democracy (Richards, 2013; Hartzog and Selinger, 2013). As is the case of due process requirements, encryption creates procedural hurdles, ensuring some checks and balances over the functioning of LEAs and the possibility of mass surveillance. It therefore helps re-balance the asymmetric power distribution between the State and citizen.

Scope of "technical assistance": Should it extend to creating backdoors?

Given the aforementioned concerns, the question arises, should the duty of "technical assistance" that intermediaries are required to provide to LEAs, extend to the creation of backdoors or otherwise weakening encryption systems?

We argue that as far as recoverable encryption is concerned, i.e. encryption where a service provider already has a decryption key in the normal course of service provision, there is no requirement for such a mandate. Indian law already requires service providers to decrypt data in such cases, in addition to providing various other forms of assistance. Here, the need is to focus on implementing proper oversight and other procedural frameworks to ensure that LEAs exercise their powers of surveillance or decryption in an appropriate manner. We find however, that the Indian framework is lacking in this regard. There is no judicial oversight of decryption requests, no proportionality requirements in the law, and no meaningful checks and balances over decryption processes at all. We therefore proposed various changes in order to improve the transparency and accountability of the system. Further, research indicates that the primary problem of LEAs in India may relate to the relatively old and slow processes that must be used by LEAs when accessing data held by intermediaries, particularly those based outside India. This points more to the need for LEA data access processes to be revised/streamlined in accordance with modern needs.

As far as unrecoverable encryption is concerned, i.e. encryption where even the service provider cannot access the content (such as with E2E) as it does not have access to the decryption key, which is retained by the user, the situation is undoubtedly more complex. However, even in such instances, for the reasons elaborated above, we believe that mandating backdoors or weakening encryption is not an appropriate solution.

Moreover, LEAs already have multiple alternatives to collect information, including by accessing metadata and unencrypted backups of encrypted communications. They can also use targeted surveillance methods to conduct investigations (National Academy of Science, Engineering and Medicine, 2018). Indeed, the current Indian framework - governing telecom service providers in particular, but also other intermediaries - already gives significant and arguably excessive powers to the State. It should also be noted that LEAs in India are already using spying technology, as we saw in the Pegasus case. LEAs also have other covert methods of gathering data - from key-stroke logging programmes to exploiting weaknesses in implementation of encryption systems. While one cannot argue against the use of such systems in appropriate cases, it is clear that such powers must only be exercised through institutionalised processes, and importantly, subject to appropriate regulatory oversight. There is therefore a case for formulating a legal framework in India, along the lines of the US vulnerabilities equities process, to ensure due process even when the government resorts to exploitation of vulnerabilities within information systems for national security and law enforcement purposes.

Accordingly, we point to the need to carry out a more detailed cost-benefit analysis before deciding on the need to implement such a mandate (which unfortunately, has not been done in the case of the recent Intermediary Guidelines Rules). We point to how such a cost-benefit analysis should consider:

  • Whether the use of unrecoverable encryption is indeed a significant hurdle for LEAs in collecting relevant information. While no data is available in this context in India, data from the US in the period 2012-2015 indicates that of the 14,500 wiretaps ordered under the Communications Assistance for Law Enforcement Act, only about 0.2 percent of wiretaps encountered unrecoverable encryption (Lewis et al., 2017). While this share has likely increased in view of the greater use of unrecoverable encryption in the ecosystem, a similar empirical analysis must be conducted in India to understand the impact of such types of encryption.
  • The cost to intermediaries in changing their platform architecture are unlikely to be insignificant. It is also worth keeping in mind that often intermediaries will avoid using certain types of encryption purely to keep in the good books of LEAs in a form of "weakness by design". Notably, companies such as Apple and WhatsApp have dropped plans to encrypt user back-ups stored in the cloud. Such data can therefore be accessed by LEAs without compromising encryption.
  • The risk of such laws getting caught up in global geopolitics. This has been the case for example, with Huawei and ZTE, who have faced significant international pressure in view of the Chinese government's purported ability to access data flowing through their networks.
  • The possible effectiveness of such laws, considering that many criminals may use open source encryption or encryption from platforms that are not amenable to Indian jurisdiction. Further, the pace of technical development is difficult to keep up with from a regulatory perspective. Notably, institutions such as Europol and Interpol are increasingly concerned about the use of steganography (the technique of hiding the very existence of a message) and open source encryption by international criminals and terrorist groups. Therefore, even if there is a bar on using strong encryption, those who want to break this law, will continue to do so.

We therefore argue that while a mandate for targeted decryption or technical assistance may be constitutional if backed by a law with sufficient safeguards, a general mandate for the creation of backdoors (or an interpretation of the Intermediary Guidelines requirement to provide "technical assistance" to extend to such generic obligations) is unlikely to pass constitutional muster, assuming a high intensity of proportionality review is applied. A higher intensity of review will have to look at not just whether the proposed intervention would substantially improve national security, but would also need to engage with the fact that it would (a) compromise the privacy and security of individuals at all times, regardless of whether there is any evidence of illegal activity on their party, and (b) the existence of alternative means that are available to LEAs to carry out their investigations. Thus, we believe that a general mandate for creating backdoors will not be the least restrictive measure available.

Conclusions and Recommendations

We argue that a general mandate that requires Internet intermediaries to break encryption, use poor quality encryption, or create backdoors in encryption is not a proportionate policy response given the significant privacy and security concerns, and the relatively less harmful alternatives available to LEAs. Instead, the Indian government should support the development and use of strong encryption systems.

Rather than limiting the use of certain technologies, or mandating significant changes in platform/network architecture of intermediaries that compromises encryption, the government ought to take a more rights-preserving and long-term view of the issue. This will enable a more holistic consideration of interests involved, avoid unintended consequences, and limit costs that come with excessive government interference in the technology space. The focus of the government must be on achieving optimal policy results, while reducing costs to the ecosystem as a whole (including privacy and security costs). A substantive mandate to limit the use of strong encryption would increase costs for the entire ecosystem, without commensurate benefits as far as state security is concerned.

The tussle between LEAs and criminal actors has always been an arms race. Rather than adopting steps that may have significant negative effects on the digital ecosystem, the government could learn from the policies adopted by countries such as Germany, Israel and the USA. This would involve interventions along two axes - legal changes and measures to enhance state capacity.

Legal changes that the government must consider implementing, include:

  • Reforming surveillance and decryption processes, to clarify the powers of LEAs, and ensure appropriate transparency, oversight and review. It is also essential to standardise and improve current methods of information access by LEAs at both domestic and international levels. There must be greater transparency in the entire surveillance and information access apparatus, including by casting obligations on intermediaries and the State to make relevant disclosures to the public.
  • Adoption of a Vulnerabilities Equities Process, such as that adopted in the United States, which could enable reasoned decisions to be made by the government about the disclosure of software/network vulnerabilities (thereby allowing these to be patched, in circumstances where this would not significantly affect security interests of the State). Such a process, while not without critics, does chart a path forward and must become central to the Indian conversation around due process in LEA access to personal data.
  • Amending telecom licenses, which currently give excessive leeway for exercise of executive authority, without sufficient checks or safeguards.

Rather than implement ill-thought out policy solutions that would significantly harm the digital ecosystem and user rights, the government could also focus on enhancing its own capacities. This can include measures such as:

  • Developing and enhancing covert hacking capacities (though these must be implemented only subject to appropriate oversight and review processes). To this end, there must be appropriate funding of LEAs, including by hiring security and technical researchers.
  • Investing in academic and industry research into cryptography and allied areas. The government should also aid the development of domestic entities who can participate in the global market for data security related products. Enhancing coordination between industry, academia and the State is essential.
  • Increasing participation in international standard setting and technical development processes.

To conclude, the crux of this issue can be understood using an analogy. Would it be prudent for a government, engaged in a fight against black money, to require all banks to deposit a key to their customer's safe deposit boxes with it? One would venture that this would be an unworkable proposition in a democracy. It would lead to people looking for alternatives to the use of safe-deposit boxes due to the lack of trust such a system will create. Innocent people will be exposed to increased risks. A preferable solution may be for the government to develop the ability to break into a specific safe deposit box, upon learning of its illegal contents, and subsequent to following due process. This would enable more targeted interventions, that would also preserve the broader privacy interests of innocent customers while protecting banks from increased costs (or loss of business).

References

Gill, 2018: L Gill, Law, Metaphor and the Encrypted Machine, Osgoode Hall L.J. 55(2) 2018, 440-477.

Lewis et al., 2017: James Lewis, Denise Zheng and William Carter, The Effect of Encryption on Lawful Access to Communications and Data, Center for Strategic and International Studies, February 2017.

Haunts, 2019: Stephen Haunts, Applied Cryptography in .Net and Azure Key Vault: A Practical Guide to Encryption in .Net and .Net Core, APress, February 2019.

Kaye, 2015: David Kaye, Report of the Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression, United Nations, Human Rights Council, May 2015.

Abelson et al., 1997: Hal Abelson, Ross Anderson, Steven Bellovin, Josh Benaloh, Matt Blaze, Whitfield Diffie, John Gilmore, Peter Neumann, Ronald Rivest, Jeffrey Schiller, and Bruce Schneier, The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption, May 27, 1997.

Levy and Robinson, 2018: Ian Levy and Crispin Robinson, Principles for a More Informed Exceptional Access Debate, LawFare Blog, November 29, 2018.

Cardozo, 2019: Nate Cardozo, Give Up the Ghost: A Backdoor by Another Nam et al.e, Electronic Frontier Foundation, January 7, 2019.

Access Now et al., 2019: Access Now, Big Brother Watch, Center for Democracy and Technology, et al., Open Letter to GCHQ, May 22, 2019.

Harold Abelson et al., 2015: Harold Abelson, Ross Anderson, Steven Bellovin, Josh Benaloh, et al., Keys Under Doormats: Mandating insecurity by requiring government access to all data and communications, MIT-CSAIL Technical Report, July 6, 2015.

Gripman, 1999: David Gripman, Electronic Document Certification: A Primer on the Technology Behind Digital Signatures, 17 J. Marshall J. Computer and Info. L. 769 (1999).

ACLU and EFF, 2015: American Civil Liberties Foundation of Massachusetts, the American Civil Liberties Union Foundation, and Electronic Frontier Foundation, Brief for Amici Curiae in Support of the Defendant-Appellee in Commonwealth of Massachusetts v. Leon Gelfgatt, 2015

Richards, 2013: Neil Richards, Don't Let US Government Read Your E-Mail, CNN, August 18, 2013.

Hartzog and Selinger, 2013: Woodrow Hartzog and Evan Selinger, Surveillance as Loss of Obscurity, Washington and Lee L.R. 72(3), 2015.

National Academy of Science, Engineering and Medicine, 2018: National Academy of Science, Engineering and Medicine, Decrypting the Encryption Debate: A Framework for Decision Makers, National Academies Press, Washington DC.


Rishab Bailey is a researcher at NIPFP. Vrinda Bhandari is a practising advocate. Faiza Rahman is a PhD candidate at the University of Melbourne.

Monday, May 03, 2021

Announcement: Position for researchers in public finance and public procurement

xKDR Forum is looking for researchers to work on a project with the Chennai Mathematical Institution (CMI), involving studying the impact of public finance management and public procurement issues on the private sector.

xKDR Forum is a Mumbai-based inter-disciplinary group of researchers working in the fields of household and firm finance, financial markets, public finance management and public procurement and the land market. In these fields, the group engages in academic and policy oriented research, and advocacy. The new recruits will come into an active research program in the field.

xKDR Forum is looking for three researchers with the profiles described below.

Senior Researcher
As a senior researcher, you will be expected to take a lead on delivering on the project objectives. You will be part of the core group of this project, building a pipeline of research ideas, and executing them. This will mean pursuing independent research as well as supervising and advising team members in their research. The requirements for the role of a senior researcher are: knowledge of public economics, public administration, public policy; over four years of work experience; very high quality spoken and written English. Experience with running surveys is additionally desirable.
Two Research Associates
As a research associate, you will work on project deliverables under the supervision of a senior researcher. The requirements for the role of research associate are: a background in economics and public policy, quantitative skills are desirable, two years of work experience.

You must be comfortable in working in an inter disciplinary research environment with people from varying backgrounds such as economics, law, public policy and data science. You must be curious and passionate about research and must be willing to work on independent outputs as well as in teams.

The remuneration offered will be commensurate with your skill and experience and will be comparable with what is found in other research institutions.

Interested candidates must email their resume with the subject line: Application for "Senior Researcher/ Research Associate" at xKDR Forum, to Ms. Jyoti Manke at careers@xkdr.org by 8th May, 2021.

Tuesday, April 27, 2021

Vaccination in India: how will demand change when persons above age 18 are eligible?

by Renuka Sane and Ajay Shah.

  1. On 16 January 2021, the union government's vaccination program started with eligibility limited to frontline workers. On 1 March 2021, eligibility was extended to a) those above the age of 60, and b) for those above the age of 45 with comorbidities. This was further opened up to everyone above the age of 45 from 1 April 2021. On 20 April 2021, the union government announced that from 1 May 2021 the minimum age of a person that is able to obtain a vaccine will go down from 45 to 18.
  2. It is useful to juxtapose this recent expansion, from age 45+ to age 18+, against the structure of the population, and envision the magnitudes involved.
  3. The last available census in India was in 2011. It is likely that the age structure of the Indian population has changed since then. We use the CMIE Consumer Pyramids household survey data to get the following age structure, based on an estimated population of 1.4 billion for late 2020:
    Age group Population
    0-17 344 million (SE: 8 million)
    18-44 622 million (SE: 18 million)
    45-59 321 million (SE: 9.5 million)
    60+ 125 million (SE: 4.7 million)
  4. On 26 April 2021, 142 million vaccine doses have gone out. Of these 119.6 million persons have got one dose, and 22.5 million have got both doses. However, of the 142 million doses, about 11.2 million doses have been to persons below age 40. In the eligible population of 45+, a little less than 5% have received both the doses, while a little less than 27% have received the first dose. There is considerable room to go, in completing the work of vaccinating persons above age 45.
  5. The union government was pushing out approximately 2.3 million doses in the eligible population per day. This translates to 5.1 doses per 1000 eligible persons per day. This reflects a combination of distribution capabilities, vaccine hesitancy and supply constraints.
  6. Opening up the vaccination to those above age 18 has meant that the magnitude of the eligible population has gone up from 446 million to 1.06 billion. If we subtract the already vaccinated, we end up with an eligible population of 926 million.
  7. The eligible population has roughly doubled. To preserve the erstwhile run rate per unit eligible population, the number of doses/day would need to roughly double. In late April, there were anecdotal reports of shortages, where eligible persons were turned away at vaccination centres. Looking forward, this may become a bigger problem with the expansion of eligibility.
  8. If all else is held intact, then, there will be a larger mismatch between demand and the ability of the union-government led system to push out doses. There are two pathways to not hold all else intact. On one hand, there is the need to shift from a union government led system to something that is a self-organising system, with energy from many persons. On the other hand, there is a need to rethink vaccination protocols. For example, if a person has antibodies, perhaps one dose suffices.

Thursday, April 22, 2021

Analysing Bambawale, et. al., 2021 ("Strategic patience and flexible policies: How India can rise to the China challenge")

by Shubhashis Gangopadhyay.

This is the text of my discussant comments at LEPC 4.1 today, which is a session organised around a talk by Gautam Bambawale presenting the recent paper Bambawale et. al. 2021.

The paper makes a strong and convincing argument for the need to create an ecosystem that fosters growth that is fast and sustainable. It focuses strongly on what needs to be done to ensure Indian citizens a desirable future. This future is envisioned as one where we are in control of our own destiny, China notwithstanding. I am in complete agreement with the need for India to grow economic muscle. I also agree that this will play a large part or, could even be necessary, to thwart China’s adventurism in our neighbourhood. But what I like most about the paper is that the authors’ emphasis is not on diplomacy, or on battle preparedness, or on economics but on the realization that they all need to play their respective parts for India to reach a common goal.

The paper is a “must read” for all. The paper sets the tone for how public discourses need to be carried out --- state the problem, clearly articulate the solution and, explain why the solution will work. A public discourse is not simply the voicing of opinions but also explaining the reasons behind them. Reading it will not only inform, but also improve, the public discourse on this topic. Respecting the spirit in which this paper has been prepared, I will try and add to the discourse initiated by the authors.

The paper makes an excellent argument for reforming the ecosystem within which economic transactions are planned and executed. To borrow a term from game theory, building up India’s economic muscle is seen as the “dominant strategy” against the challenges posed by China. There is, or can be, very little dispute about the need for India to grow economically.

While agreeing completely with the recommendation in the paper, I would like to modify somewhat the problem statement. For that, I will distinguish between a goal, or an objective, and the strategy to achieve that goal. A winning strategy is determined by the desired objective of the player and the possible responses by her opponent. In other words, a player’s strategy cannot be independent of what the other player is doing or, of the different circumstance in which the game is being played out.

India’s strategy is not an action it should undertake but an enumeration of the set of all contingent actions that India must take. Contingent on what? Contingent on the response that China will undertake for each of the actions we take. The choice of actions could also be contingent on changing circumstances for which China may not be directly responsible. E.g., if we criticize Myanmar’s military government, China may move in and make the Myanmar government hostile to us; on the other hand, if we do not criticize, we may face problems in the Quad.

A player’s strategy is derived, among other things, from the player’s own objective and the threats to that objective posed by the responses of the other players (or competitors) and, the changes brought about in the environment by nature (uncertainty). Simply put, the strategy is derived from the objective and never the objective itself.

There are two reasons why I want to distinguish between a goal and the strategy to attain that goal. First, as stated before, formulating the problem determines the answer we get. The way the paper currently reads, China is the problem and growing economic muscle is necessary to thwart China. And, it is this that makes me nervous. Why? Our policymaking has been mostly in response to a crisis and we slip back to status quo ante as soon as the crisis blows over. As an example, consider the trade liberalization measures undertaken in the post-1991 period (when we faced a foreign exchange crisis), and the roll-backs in more recent years when we are not facing any foreign exchange shortage. Trade liberalization was never seen by our policymakers as necessary for economic growth; it was always seen as a step towards easing the foreign exchange shortage of 1991. Hence, I am afraid that if we do not clearly state that growing economic muscle is an end in itself (and not simply to thwart China’s adventurism), we will go back to our old economically inefficient ways as soon as the China threat is neutralised.

The second reason is a bit more nuanced and depends essentially on what one means by strategy. As the paper points out, correctly, the game will be played over many years giving enough time both, for China to push back on what India is doing and for circumstances to change as global uncertainties are resolved. For example, if we develop manufacturing and/or services to export into Africa, I do not think that China will simply watch us do so and not push back in various ways to defeat India’s purpose. The correct definition of strategy will enable us to consider the following options (say) --- grow through the African market, focus on the Western market, or ASEAN or, diversify in such a way that China has to push back in every market at great harm to itself (push back is always costly to the one doing it). In other words, we must plan our economic growth in such a way that China cannot, or will not, be able to force us to give up our growth plan in the way we have envisaged. Our growth path must be such that in case they want to affect it, it will be costly to them but with minimal repercussions on us.

This approach immediately alerts us to a careful formulation of our goal, along with a deep understanding of what (a) China is trying to achieve and (b) the national interests of our potential partners. This latter is very important and I get a whiff of romanticism in the paper’s suggestion of forming partnership with those who believe in individual freedom, market resourcefulness and the rule of law. The biggest supporters of the free world routinely justified their inactions against apartheid and continue to be in denial while condoning the atrocities of various “friendly” dictatorial regimes! In other words, they are going to partner with India, against China, only if it is in their interest to do so --- not because they have great regard for India’s righteousness. They will support us only when there is an alignment of our interest with theirs. Some years ago when I complained to a high level US official about how their policies in India’s neighbourhood are adversely affecting us, he was quick to point out that he was paid by US taxpayers not to meet India’s aspirations.

It could be dangerous to misread China’s objective. It may appear as an approach relevant to a zero-sum game (very “mercantilist”), when the economic world is uniquely, and definitely, a positive-sum game. So, why is China doing what it is doing? The paper seems to suggest that this is largely an attempt to raise nationalistic fervour within China to distract people from its domestic problems (of a growth slow-down amid growing disparities). If this indeed is the reason then once China gets back on its erstwhile growth path, Chinese adventurism along India’s borders will diminish. Contrast this with the possibility that irritating Indian border forces is a longer term plan. Should our responses in both cases be the same? To play the game properly, we must be able to anticipate China’s game plan. This will only happen through careful and deep investigation of the ground realities in China along with the interplay among its political actors. Not understanding fully China’s objective is where we begin to lose the game! The paper does point out that there are more people studying India in China than Indians studying China. Given our definition of strategy, the importance of correctly reading China’s objective is crucial to determine India’s optimal strategy.

I want to highlight a specific difference between our two systems that differentiates the manner in which we achieve our respective goals. China could get its banks, companies, policymakers and all other groups in their society to do exactly what the central authorities wanted them to do. In India, that is not feasible. This does not put us at a disadvantage as long as we are aware of it and, hence, stop borrowing “best practices” from China or, for that matter, any other country. We are going to rely on the resourcefulness of our people, operating through innovations and investments by the private sector, facilitated through the appropriate institutions implementing market rules. Historically, this approach has been found to be a more sustainable path to economic growth. As the paper correctly points out, this is a huge advantage for India especially if we see the fault lines now opening up in the Chinese system.

India is not a unitary system but a federal one. Indeed, whatever “ease of doing business” policies the central government rolls out, the ultimate hurdles can be taken down by state governments only. Why would various sops to foreign businesses bring in FDI when our own companies, even when they are flush with investible resources, not investing in India? So the first job of this exercise is to move out of Delhi and get the state governments aligned with the nation’s interest and coordinate their strategies. In this context, I must say that I am extremely sceptical of following a SEZ policy in India simply because China did it successfully. Its implementation invariably leads to corruption and crony capitalism, which will lead to umpteen consequential issues which are difficult to handle in a vibrant federal democracy where the rule of law should reign supreme. What China could do with its centralized economic approach and business activities through state-owned enterprises is simply not doable in India.

Our goal of sustained high growth has to be attained in a way that suits the Indian context. Japan, China, South Korea and the Far East, all followed their own paths to reach where they are now. The differences in the paths they followed are more pronounced than the similarities. And that is what we need to understand --- scholarship without thought will simply not do.


Shubhashis Gangopadhyay is a researcher on India and economics.