Live data from Hacker News

Australian parliament passes encryption laws unamended

abc.net.au

91–100 of 415 posts

Re: Australian parliament passes encryption laws unamended

#91
post #43

Some of the comments so far seem to suggest that this bill would require software to include backdoors. However, it looks like [the bill's PDF]( https://parlinfo.aph.gov.au/parlInfo/download/legislation/bi... ) includes: > Division 7—Limitations > 317ZG Designated communications provider must not be required to implement or build a systemic weakness or systemic vulnerability etc. > (1) A technical assistance notice o…

They were going to supply a definition of "systemic weakness", but I can't find one in the bill itself. I'm patiently waiting for their proposed method of reading end-to-end encrypted messages without introducing a systemic weakness. But the meaning of words don't seem to matter anymore in the reality distortion field that is the Australian government. This is all supposedly to somehow make us more secure for Christm…

Indeed, the laws of mathematics make this impossible. Count yourself lucky to be living in a country where the laws of mathematics don't apply.

Re: Australian parliament passes encryption laws unamended

#93
post #69

Earlier quoted context omitted.

Looks like a cool product. Realistically could we just setup all code to be hosted overseas and then pay a set of reviewers in Europe to check PR's for possible backdoors? Don't think the law let's them compell you to build the backdoor in a super secret and hidden way...

The way it’s written that could be 5 years in gaol because you let people know about it.

Not relevant, but I love the old-school spelling of "gaol". Is it still used anywhere or are you being whimsical?

Re: Australian parliament passes encryption laws unamended

#94
post #33
post #19

Earlier quoted context omitted.

This isn't quite true. The bill allows companies to provide statistics on how many TARs, TANs, and TCNs they've been served within a 6-month window. The obvious problem is that nothing stops them from lying or just omitting that information -- because why would you admit that your software is insecure?

Employees of a company may also be served, and required not to tell their employer. So a company may not know if they are compromised.

Right, but then the employee can publish statistics about how many TCNs they've received.

Re: Australian parliament passes encryption laws unamended

#95
post #55

Earlier quoted context omitted.

> This is another thing that adds to my deep sense of shame to live in this country (sadly, that list is long and growing). I don't support this legislation, but I have to ask, which country is doing a better job on human rights issues than Australia in your opinion? Surely not China or nearly any country in Asia, Africa, or South America? Surely not the US? Probably not much of Europe?

To paraphrase our PM, speaking on medical evacuation of children, "I will do whatever is possible to prevent it." Australia's government blocked legislation that would help kids not die. Because they came on a boat. Which has never been the primary way illegal immigrants get into this country. Nauru was declared a human rights travesty by the UN. The medical board that decides whether or not it is a medical emergency…

It is an absolute national shame. MSF recently likened the mental health of the people on Nauru to victims of torture.[1]

The most disturbing aspect is the strong bipartisan and public support for the ongoing abuse. Every Australian should wake up in the morning, take a long hard look in the mirror and ask themselves if they're proud of what they've become.

[1] https://www.msf.org.au/article/statements-opinion/indefinite...

Re: Australian parliament passes encryption laws unamended

#96

I am an Australian software developer and am currently getting https://www.lifepim.com ready for release which, funnily enough has the main selling point as "Your data is private, secure and free from adverts" - what a joke. The scary part is not knowing how the law is going to be implemented - I am hopeful that smart people work on the implementation of it in terms of practicality. If it is an on request thing "give…

Looks like a cool product. Realistically could we just setup all code to be hosted overseas and then pay a set of reviewers in Europe to check PR's for possible backdoors? Don't think the law let's them compell you to build the backdoor in a super secret and hidden way...

Thanks! I don't hosting overseas would work, but then again - who knows how it would be implemented.

Re: Australian parliament passes encryption laws unamended

#97
post #78

This is another thing that adds to my deep sense of shame to live in this country (sadly, that list is long and growing). This bill does nothing to prevent the kinds of things it is intended to prevent. The apps this law targets were engineered specifically to prevent this kind of interference. The idea that passing legislation will suddenly change that, magically allowing decryption of messages is beyond idiotic. Th…

> OpenVPN They'll probably want a backdoor in that too.

Careful criminals will surely be able to find a set of software that isn't affected. Australia isn't the US, only a small portion of software companies would have a large local presence here.

Re: Australian parliament passes encryption laws unamended

#98

Is there a (non-alarmist/non-defensive/non-partisan) summary available of what the bill actually contains and what its practical effects might be?

https://www.news.com.au/technology/online/security/inprincip...

The (autoplay! grr) video summary at the bottom is pretty good.

State police forces are getting these powers. So state police, federal police and ASIO can compel devs to break their security for the investigation of any crime that attracts a penalty of 3 years jail or more.

This is not an interim arrangement either.

God this whole thing is so idiotic and scary.

Re: Australian parliament passes encryption laws unamended

#99
post #40
post #21

Earlier quoted context omitted.

I'd recommend actually reading the bill to form your own conclusions. The main problem is that it mostly is a series of amendments, and many of them are quite unrelated. Most of the discussion is about the Technical Capability Notice section (which allows the government to compel a telecommunication provider, under threat of 5 years imprisonment, to create the ability to access communications otherwise inaccessible)…

The best discussion I've found in terms of the legislation is at [1]. The most insidious part to me as a programmer, is the definition of a "Designated Communications Provider" which (amongst others) includes (S317C, item 6): "the person develops, supplies or updates software used, for use, or likely to be used, in connection with: (a) a listed carriage service; or (b) an electronic service that has one or more end-u…

So australian software developers have become pretty much toxic now?

Re: Australian parliament passes encryption laws unamended

#100

Could an expat Australian dev be compelled to put backdoors in software even while overseas, under threat of being prosecuted when he returns? If so, Australians can't even be employed in foreign software companies.

Could any developer put backdoors in under promise of a suitcase of cash?

If your review system fails because your Aussie developer "may be compromised", it fails because your $good_country developer may also be compromised.

Post reply on HN