Live data from Hacker News

Australians who won't unlock their phones could face ten years in jail

nakedsecurity.sophos.com

161–167 of 167 posts

Re: Australians who won't unlock their phones could face ten years in jail

#161

Earlier quoted context omitted.

The problem is that you could totally have truecrypt installed and not have a second hidden partition. There is no way to prove that you do. Of course, the court could throw you in jail for not being able to provide something that doesn't exist anyway, but yeah....I'd hope that the lack of proof here would help you win the case.

A prosecutor, a jury, and a judge, will all have a chance to decide that you're telling the truth. There is not mathematical proof here (there never is in any trials, really), so it will all come down to: do we believe the LEO's and the defendant's experts' testimony? Recall, the defendant won't testify -- their lawyer won't let them -- but if they did, they'd probably do themselves in anyways, the court (jury, judge…

Putting someone in jail because they won't provide a password to a partition that might exist is truly beyond the pale. If that happens we have completely discarded the notion of presumption of innocence.

Re: Australians who won't unlock their phones could face ten years in jail

#163
post #3

Seems like the only logical solution is to carry a hammer to destroy your phone if necessary. If the heat hasn't told you they want your phone, there's nothing legally stopping you from destroying your own property if you see them coming...

Independently of legal risks, please everyone keep in mind that modern cell phone batteries are a serious hazard.

Perfect, I just need to carry a punch that's able to puncture the battery...

Immediately cause your mobile device to self-immolate on demand!

Re: Australians who won't unlock their phones could face ten years in jail

#164

It's evident citizens are not going to win the fight for privacy by trying to change policy. Voting has become nearly meaningless in the modern age when it comes to changing politics. Influencing businesses to do what's right is becoming more challenging too as this order shows they can just be forced to hand over data by authorities. I don't want the "bad guys" getting away with their activities either, but I don't…

I disagree that voting has become meaningless. The issue is that young people think and feel that voting is meaningless. Thus politicians don't really have to pay attention to what young people think or want. (You don't vote, you don't count.) If you don't vote, your peers don't vote. You transfer your power to other people. Think of NRA. It is a small relatively movement. But if they say to their members go vote X,…

>I disagree that voting has become meaningless

You literally have better odds of winning the powerball than your vote having any effect on the outcome of a general election. Even if it did, the people put in office are worried about themselves and the people they owe money to -- not your opinions.

Re: Australians who won't unlock their phones could face ten years in jail

#165

Earlier quoted context omitted.

> Definitely planning on backdooring devices and reading the messages pre-encryption and post-decryption. They actually explicitly said that was the aim. From https://www.homeaffairs.gov.au/consultations/Documents/expla... : > This includes accessing communications at points where it is not encrypted. I am an Australian, and I have been listening to the Minister for months tell everybody they were going to do somethi…

> once they roll over they will do it in the most efficient way possible Yes. To be clear, Telstra has installed devices of mass surveillance. So, this new bill is about undoing the 'snowden world' as you suggest. From this article: https://theintercept.com/2016/10/23/endace-mass-surveillance... This clearly shows how an Australian company was giving assistance in the construction of the hardware for a NZ company, En…

A few years ago I read references to LEA Racks (Law Enforcement Agency Racks) being installed into every NBN POI. I think I saw it in the NBN design documents, but a few years later I could not find it again so who knows.

After getting over the initial shock of the implications, I put my engineering hat on and then it was "of course there are LEA racks, you idiot". I presume when the TIA was written (1979) getting a tap involved filing a request with Telecom who then raised a work order for some department, and it wormed it's way down the management layers until some worker was directed to install the thing. If I was in charge of optimising that process, I too would have created LEA Racks, filled it with gear and told the LEA's "here, you look after it, and try not to bother me again".

I'd be amazed if the process hasn't been automated to the extent ASIO doesn't now have a button in Canberra somewhere they can press to tap phone or internet connection. There is no doubt in my mind commercial forces will mean Apple, Google and Microsoft go down the same road. Someone who had a hand in drafting this bill has dreams of a future where the old telephone line taps will become part of ancient history - it's all done via bugs installed at the touch of a button onto the end users devices.

I doubt their idea of utopia will last for very long. The likes of Russia and China must be delighted with the idea of democracies building a surveillance of the likes they could only dream about, and then handing it to them on a platter by just leaving it in control of just few humans easily manipulated with social engineering hacks, and a few machines they can focus enormous resources at cracking.

That's if it lasts that long. It's trivially easy to bypass now by simply using Open Source. The timing is bad for them as Debian has just added the final nail making that all possible by creating the first ecosystem using repeatable builds.

If anyone is wondering why Open Source is the solution - it's because the root cause of the problem is they are putting control in a central choke point. Compromise that choke point in a way that no one notices you have own whatever it controls. The people in charge believe they can fix that by heavily fortifying the choke point. But as the saying goes, every man has his price, as oddly does every computer and every SIM. If you are centralising, you are making the worth of what the choke point controls higher and higher, then eventually you will hit that price. They have created something that can reveal every banking password, every confidential email discussing corporate takeovers worth billions, all trade secrets and government secrets.

Open source solves that (as indeed did world the TIA was born into with its work orders involving many people) by making the cost scale. Over time there are thousands of programmer looking at the source in Debian - that's why it's called Open. You have to compromise every one of those programmers.

Re: Australians who won't unlock their phones could face ten years in jail

#166

Earlier quoted context omitted.

The article mentions both child abusers and terrorists yet the laws will rarely be used for that. Mandatory metadata retention was also bought in for the same reasons and has barely appeared as evidence in any subsequent cases, despite >300,000 warrantless metadata requests last year, overseen by a handful of public servants behind closed doors, in a country of 25 million people. Another very concerning law is about…

> she was then deemed a "fixated person", which involved incarceration without charge, being taken to a mental institution and forcibly injected with anti-psychotic drugs for months. Eventually a judge decided she could go home. All media coverage of it is banned in Australia until the trial is finished, which has been postponed at every hearing for over a year now Holy shit. Maybe I'll stop complaining about the US…

It's like Soviet Union placing dissidents in psychushka [1]. He must be insane if he can't accept comunism.

[1] https://en.m.wikipedia.org/wiki/Political_abuse_of_psychiatr...

Re: Australians who won't unlock their phones could face ten years in jail

#167
We need a certificate transparency type solution that makes pushing compromised firmware to individual devices impractical.

That still leaves forcing manufacturers to insert backdoors in all devices, which as far as I know can only be made tamper evident by open sourcing (and using reproducible builds for) all security critical software and hardware.

Post reply on HN