Live data from Hacker News

Australian parliament passes encryption laws unamended

abc.net.au

41–50 of 415 posts

Re: Australian parliament passes encryption laws unamended

#42
It's over. I may as well not be a programmer anymore.

The government has effectively made it possible that anyone and everyone who develops software or hardware used by anyone in the country, or where they feel national security comes into play, must compromise their software, and tell no one.

They can ask any intern to break the software, and not tell their employer.

It's bad enough to have a gaping hole in your security, but now they can ask people who have no idea what they're doing to create a backdoor.

All Australian software has now been rendered completely untrustworthy, and when those compromises in security are found, by the nation states who now know that Australian software will have holes in it, it will result in the very thing that this bill claims to prevent.

Our infrastructure has been opened up for attack, by any of our neighbours who have a reason to do so, whilst simultaneously gutting the economy of IT in Australia. Who wants to buy shitty backdoored Chinese software? It's the same now for Australia.

Australia's government has now opened the door for widescale cyberterrorism to have a chance at wreaking destruction.

Re: Australian parliament passes encryption laws unamended

#43
Some of the comments so far seem to suggest that this bill would require software to include backdoors. However, it looks like [the bill's PDF](https://parlinfo.aph.gov.au/parlInfo/download/legislation/bi...) includes:

> Division 7—Limitations

> 317ZG Designated communications provider must not be required to implement or build a systemic weakness or systemic vulnerability etc.

> (1) A technical assistance notice or technical capability notice must not have the effect of:

> (a) requiring a designated communications provider to implement or build a systemic weakness, or a systemic vulnerability, into a form of electronic protection; or (b) preventing a designated communications provider from rectifying a systemic weakness, or a systemic vulnerability, in a form of electronic protection.

> (2) The reference in paragraph (1)(a) to implement or build a systemic weakness, or a systemic vulnerability, into a form of electronic protection includes a reference to implement or build a new decryption capability in relation to a form of electronic protection.

> (3) The reference in paragraph (1)(a) to implement or build a systemic weakness, or a systemic vulnerability, into a form of electronic protection includes a reference to one or more actions that would render systemic methods of authentication or encryption less effective.

These limitations would seem to imply that the bill can't require a "systemic weakness", either by introducing a new one or prohibiting the patching of an existing one, which would seem to suggest that end-to-end crypto wouldn't be affected.

Is this a correct reading? Or are there concerns that the government might, say, require end-to-end crypto to be vulnerable to a government-held golden key?

---

Edit: Part of the text,

> to implement or build a new decryption capability in relation to a form of electronic protection

, sounds like it's prohibiting golden-key-based schemes.

Re: Australian parliament passes encryption laws unamended

#44

I live in Australia and this is the dumbest bill I have ever seen in parliament. Australian politicians have no clue what the fuck they have just done. Rushed through in less than four days so they can go on holidays. Bigots.

To quote our last PM (well, this week anyway):

"The laws of Australia prevail in Australia, I can assure you of that. The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia."

Re: Australian parliament passes encryption laws unamended

#45

To anyone with a business from anywhere else in the world. Yes please do, publicly and loudly, cease to deal with us (Australia) due to the very real possibility that all of you private and commercially sensitive communications will be monitored and recorded (Also given the five eyes agreement shared with other countries.) Australia already have a history of using their spy services for commercial gain. https://en.m.…

+1 block us. Apple if you are reading this stop selling us iPhones. Australians need to feel the pain of this otherwise nothing will change.

1 billion dollars wiped from Atlassian already. I’m hoping the markets react more and destroy the industry here.

Might want to assume that all Australian developers are now potentially compromised.

Re: Australian parliament passes encryption laws unamended

#46

This is another thing that adds to my deep sense of shame to live in this country (sadly, that list is long and growing). This bill does nothing to prevent the kinds of things it is intended to prevent. The apps this law targets were engineered specifically to prevent this kind of interference. The idea that passing legislation will suddenly change that, magically allowing decryption of messages is beyond idiotic. Th…

> This is another thing that adds to my deep sense of shame to live in this country (sadly, that list is long and growing). I don't support this legislation, but I have to ask, which country is doing a better job on human rights issues than Australia in your opinion? Surely not China or nearly any country in Asia, Africa, or South America? Surely not the US? Probably not much of Europe?

Iceland.

But yeah, “cryptonomicon” utopias are hard to get by, these days.

Re: Australian parliament passes encryption laws unamended

#48

Could an expat Australian dev be compelled to put backdoors in software even while overseas, under threat of being prosecuted when he returns? If so, Australians can't even be employed in foreign software companies.

The law as written applies to any company or person that does business or has customers in Australia. This includes websites. So they don’t need anyone Australian on your team as written. However yes.

Re: Australian parliament passes encryption laws unamended

#49

Literally zero percent chance I touch any software made in Australia now.

Isn't Atlassian Australian? Or did they move?

It looks like the cloud services are supplied by a company incorporated in the US [1] ‘Atlassian, Inc’. They probably needed to do this when they listed on the NASDAQ.

There is also an Australian entity `Atlassian Pty Ltd` but it’s not clear to me what role that has.

[1]: https://www.atlassian.com/legal/cloud-terms-of-service

Re: Australian parliament passes encryption laws unamended

#50
post #43

Some of the comments so far seem to suggest that this bill would require software to include backdoors. However, it looks like [the bill's PDF]( https://parlinfo.aph.gov.au/parlInfo/download/legislation/bi... ) includes: > Division 7—Limitations > 317ZG Designated communications provider must not be required to implement or build a systemic weakness or systemic vulnerability etc. > (1) A technical assistance notice o…

What does this mean for Zero-knowledge systems?
Post reply on HN