Live data from Hacker News

Australia Wants to Take Government Surveillance to the Next Level

nytimes.com

91–100 of 100 posts

Re: Australia Wants to Take Government Surveillance to the Next Level

#91

40 years ago my parents emigrated from an authoritarian South-East Asian country with a dubious human rights record to come to Australia where their kids could enjoy freedom and opportunity away from all that. Today, I see this announcement in the news and I am wondering which country I can emigrate to with my own kids because I am disgusted with the increasing authoritarian bent of our government, as well as our plu…

[deleted]

Re: Australia Wants to Take Government Surveillance to the Next Level

#92
post #28

Earlier quoted context omitted.

True, but once you introduce a bill of rights all your commom law protections go out the window.. including stuff you didnt know you had

The US bill of rights doesnt define the rights. The bill of rights calls out special rights that the govt shall not touch. The rights are granted to us by our creator aka natural law. The same law used to declare our independence from the crown and an inherent part of the fabric of the US. Not sure if this is clearly stated yet.

Unless you live within 100 miles of the border. Or happen to be carrying too much cash, according to the authority you’re dealing with. Or are dealing with a FISA court. There’s so many exceptions that it’s naive to think the bill of rights is some kind of magic document. The only right left relatively intact is freedom of speech.

Re: Australia Wants to Take Government Surveillance to the Next Level

#93

The article mentions that Australia has no bill of rights which, whilst technically true, doesn't mean we don't have equivalent protections. Some are enshrined in our constitution whilst others are parts of common law and other legislation. The conclusion they draw from that is right however; a lot of laws can be introduced to our parliament that might not get off the ground elsewhere. It's why we've fervently fought…

Yes, the filter got canned, but the mandatory Metadata Retention got up. That was a rare moments of bipartisan cooperation.

Re: Australia Wants to Take Government Surveillance to the Next Level

#94

Earlier quoted context omitted.

They are, among other things, paid by the government. They are not independent of it, under no definition of any of those words. Maybe oversight is lax. Maybe oversight is perfect and everything happens exactly as the overseers want it. None of that changes anything about the truth of the initial claim. "Independent of" is patently false, and an obvious attempt to sensationalise.

> They are not independent of it, under no definition of any of those words Sure. But the words actually used were: "operating independently from", which is different.

You cannot "operate independently from" without also "being independent from".

And you're just proving that bad-faith accusation, and splitting hairs into finer and finer strands.

Re: Australia Wants to Take Government Surveillance to the Next Level

#95
post #9

Earlier quoted context omitted.

Unfortunately it gives them the legal capability to require your startup/IT company/multinational to put development time in at their request to enable your software to give them the access they want. For example- get chats in real time log IP addresses and pass them to gov open containers stored on your infrastructure get into the phone or device you have sold to a client previously These are not interpretations of…

... sounds like asking a phone company to tap a phone, which is pretty well established?

> sounds like asking a phone company to tap a phone, which is pretty well established?

That is exactly what they are asking for. In fact, the legalisation enabling them to gather the data and under what conditions (the authorisation required, like a court order) isn't being changed. This new piece of legislation just extends who they can force to collect it form them. It use to be the telco's, which was originally just phone taps but then extended to internet data. They are now extending that to software companies. (Also cloud providers like SpiderOak and "secure email" companies.)

In a few words this extension allows them to order a software company to (with suitable compensation of course):

1. Develop / assist in developing an undetectable tap / bug for them, and

2. Surreptitiously install it for them via an over the air update.

This extends their reach from phone calls to any device that auto-installed software updates / patches. Whether you consider the ability to install a "phone tap" into your phone, tv, car, router, wifi camera, pc, robot vacuum, modem, that can read all the data on there, enable the microphone and camera, monitor the GPS and other sensors, read keystrokes, fingerprints and other authentication data to be roughly as intrusive as someone monitoring your phone calls is I guess a mater of taste.

Re: Australia Wants to Take Government Surveillance to the Next Level

#96
post #17

I feel like the linked article on ABC has a much more detailed and balanced description of the bill [1]. The Government says that "systemic" weaknesses cannot be demanded. That said, the third part of the demands that can be made, the "technical capability notice", seems ripe for abuse. At the very least, the acceptance of a bill like this will erode trust in app stores. I would expect to see some sort of checksum ve…

> The Government says that "systemic" weaknesses cannot be demanded.

That's because they already have a pre-existing "systemic" weakness that's better than any encryption back door: automatic software updates. If you can replace the software so it gives you the unencrypted data why on earth bother with a breaking the encryption? All they need is a hammer that forces the software companies to write undetectable bugs and silently install them for them, and that's what this legislation provides.

We handed this systemic weakness to them on a platter, and it's been there for years now. Even through it was many years ago, I still recall the horror I felt when my daughter has her phone stolen, and I discovered I could press a button on Google play that would install some spy software to report on the whereabouts of the thief. I'm sort of surprised it took them this long to wake up to it.

It isn't impossible to fix, so I suspect in the long term this loophole will be closed. The key to the fix is in the word "systemic", which translated means someone other than them can't exploit the weakness.

As an aside, they are apparently operating under the assumption they will be able to control who has access to it. Which is to say they believe they can control access to something that will be highly automated thus ultimately controlled by only a few people. They are after all subject to the same attack they are using on us - they will be asking programmers to update their software, software that they undoubtedly will never see because it's "company proprietary". As the saying goes every human has their price. The price the attackers can afford in this case is extraordinary: this system is the key that unlocks every banking password, every bank SWIFT password, every GPG key, every X509 secret key, every email, every boardroom discussion on billion dollar takeovers. They are kidding themselves if they think that can protect this - which is why it is a terrible proposal.

Worse, they don't have the defence we do, which is that the "normal" unmonitored population must be running strong, secure software. We get this unbugged software now from public servers we call app stores. So all you need is something that will compute the hash of the software you downloaded so you can compare it to publicly available one, and won't lie about the result. "Won't lie about the result" translates to "a device that can't be corrupted" which in turn translates to "can't have it's software upgraded". We already have such devices: they are called TPM's. We already know how to use them. Sort of. They work real well in 2FA dongles for example.

Nevertheless it has to be said the primary application of TPM's, secure boot, hasn't been a raging success. But then we haven't had a good reason to make it a success: how many people do you know have been victims of evil maid's? Well, that was nice while it lasted, but now we all about to come face to face with an evil maid from our worst nightmares: someone who can install software updates while your phone is sitting in the safety of your coat pocket without leaving a trace.

So the incentive is now here, the engineering task is well defined. Unfortunately the problem remains hard. We have to surround drivers, IPC, network stack with same high Chinese walls we currently put around apps, and somehow tie this all back to an all seeing TPM. So it's going to take a while. Maybe se4L will get it's day in the sun.

Re: Australia Wants to Take Government Surveillance to the Next Level

#97
post #28

Earlier quoted context omitted.

The US bill of rights doesnt define the rights. The bill of rights calls out special rights that the govt shall not touch. The rights are granted to us by our creator aka natural law. The same law used to declare our independence from the crown and an inherent part of the fabric of the US. Not sure if this is clearly stated yet.

Unless you live within 100 miles of the border. Or happen to be carrying too much cash, according to the authority you’re dealing with. Or are dealing with a FISA court. There’s so many exceptions that it’s naive to think the bill of rights is some kind of magic document. The only right left relatively intact is freedom of speech.

The interesting part to me is the lack of a constitutional amendment granting the govt these powers. The only reason the govt has these powers is we let them. Constitutionally they dont have a leg to stand on.

Re: Australia Wants to Take Government Surveillance to the Next Level

#98

Earlier quoted context omitted.

This video they made is absolutely hilarious, and shows just how un-hilarious and fucked up these proposed changes are: https://www.youtube.com/watch?v=eW-OMR-iWOE

"Reasonable and Appropriate" indeed. Funny how satirical pieces like these oft act as the best ways for the general public to understand the scope of proposed changes by a government (or lobbying efforts by companies or NGOs) - see also John Oliver, Colbert, et al.

I just wish for another cassetteboy video, and yearswipe.

Re: Australia Wants to Take Government Surveillance to the Next Level

#99

Earlier quoted context omitted.

> They are not independent of it, under no definition of any of those words Sure. But the words actually used were: "operating independently from", which is different.

You cannot "operate independently from" without also "being independent from". And you're just proving that bad-faith accusation, and splitting hairs into finer and finer strands.

I don't agree with your first comment at all, but it sounds like a particularly dull semantics argument.

Re: Australia Wants to Take Government Surveillance to the Next Level

#100

The headline is a little misleading. It's much more terrifying than that. It isn't just Australia. It is the US, Australia, Canada, UK, and New Zealand all together (known as the "Five Eyes")[1]. Australia is just the country that put the memo together. > The "Five Eyes", often abbreviated as "FVEY", refer to an intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom and the United States.…

In typical fashion, one country takes the lead (also happens with IP rights ratchets), and if/when it pans out, the others "follow that example" / harmonize / pick your particular bureaucratic mechanism and terminology.

There is no need to "pan it out" to other countries. If the law passes in Australia then other 5 Eyes countries can send their data to us, have it decrypted, and then have it sent back to the original country (this is one of the primary things that 5 Eyes exists for -- to allow for this sort of bullshit). Which means that even if such tactics are not legal in your home country, they can outsource the reprehensible shit to us.
Post reply on HN