Live data from Hacker News

Australian parliament passes encryption laws unamended

abc.net.au

141–150 of 415 posts

Re: Australian parliament passes encryption laws unamended

#141
post #42

It's over. I may as well not be a programmer anymore. The government has effectively made it possible that anyone and everyone who develops software or hardware used by anyone in the country, or where they feel national security comes into play, must compromise their software, and tell no one. They can ask any intern to break the software, and not tell their employer. It's bad enough to have a gaping hole in your sec…

Remember that the Australian Government (whatever party happens to be in power at the time, it doesn't matter which) doesn't want technology or innovation in this country. They only want the value of dirt to remain high. So that buildings remain valuable and that we can export more natural resources.

Re: Australian parliament passes encryption laws unamended

#142
post #43

Some of the comments so far seem to suggest that this bill would require software to include backdoors. However, it looks like [the bill's PDF]( https://parlinfo.aph.gov.au/parlInfo/download/legislation/bi... ) includes: > Division 7—Limitations > 317ZG Designated communications provider must not be required to implement or build a systemic weakness or systemic vulnerability etc. > (1) A technical assistance notice o…

There are so many loopholes in this thing. One predominant thing to keep in mind is the legal onus that is put on a company that does not comply . The basic gems are that I got from reading the draft legislation was: - If you have server side encryption, & we want you to decrypt a particular person's data, then we expect you to do so - ad infinitum. - If you do client side encryption then we expect you to put into pl…

Does the legislation say they can do this without justification though? Can they just ask for anyones information or does there need to be some sort of warrant?

Re: Australian parliament passes encryption laws unamended

#143
post #95

Earlier quoted context omitted.

It is an absolute national shame. MSF recently likened the mental health of the people on Nauru to victims of torture.[1] The most disturbing aspect is the strong bipartisan and public support for the ongoing abuse. Every Australian should wake up in the morning, take a long hard look in the mirror and ask themselves if they're proud of what they've become. [1] https://www.msf.org.au/article/statements-opinion/indefi…

>The most disturbing aspect is the strong bipartisan and public support for the ongoing abuse. Is there really public support? Everyone I've talked to thinks it's a disgrace.

My personal social circle and Sydney Inner West socailly aware bubble all thinks it's a disgrace, but I'm not kidding myself into thinking I'd need to go very far before I bumped into people who'd justify it to themselves as "necessary for the country", and not a lot further to find people actively and vocally celebrating the cruelness...

Re: Australian parliament passes encryption laws unamended

#144
post #58

Earlier quoted context omitted.

Isn't Atlassian Australian? Or did they move?

There is still a substantial engineering team in Sydney

For now. I bet there's a lot of passports being dug out and resumes being polished up tonight...

Re: Australian parliament passes encryption laws unamended

#145
post #116

Ouch. Since I'm using Fastmail ... can anybody recommend a good alternative? I don't mind paying for a good and secure E-Mailprovider. Protonmail looks nice, but it does not seem to offer IMAP (because mails are end2end encrypted).

Paid Protonmail has a bridge to IMAP/SMTP. [0] [0] https://protonmail.com/bridge/

Yeah but not for mobile, which I assume means you have to use their own client? Ridiculous how much computing has regressed.

Re: Australian parliament passes encryption laws unamended

#146
post #123

Earlier quoted context omitted.

So now any of the Five Eyes intelligence agencies can have a chat with ASIO and get them to coerce companies and individuals within companies to put these back doors in. Then they can all use the same back doors, so everyone living in the USA, UK, Canada, and New Zealand can have their encryption compromised and communications intercepted. There's no way that companies will create back doors specifically just for Aus…

And then somebody from inside will get a guilty conscience, but remember what happened to Snowden, and just sell the backdoor straight to Huawei or NSO or Mohamad bin Salem (salving themselves by pretending they're going to donate hundreds of millions to "improving the world", but instead will by private islands and matching citizenships to Peter Thiel's...) :sigh:

Realistically, if you were a developer not in the chain of command and asked to do this: Would you? Could you?

You would be knowingly putting your name to a vulnerability, and if someone asks then you have to keep it a secret and feign incompetence. Then if they revert your change you'll have to re-implement it.

If you do tell your superiors (which would be most likely what would happen, even before writing the code) then you would be in violation and could be put in jail.

If you refuse you would be put in jail, or they would go to the next person in their list.

Re: Australian parliament passes encryption laws unamended

#148

Ouch. Since I'm using Fastmail ... can anybody recommend a good alternative? I don't mind paying for a good and secure E-Mailprovider. Protonmail looks nice, but it does not seem to offer IMAP (because mails are end2end encrypted).

From what I remember fastmail has always cooperated with law enforcement. It is not zero-knowledge so they always had access to the user data already.

Their promise has been to not use it for advertising purposes or share it with third parties. I don't see much changing here, but I would like to know if it is.

Re: Australian parliament passes encryption laws unamended

#149

Ouch. Since I'm using Fastmail ... can anybody recommend a good alternative? I don't mind paying for a good and secure E-Mailprovider. Protonmail looks nice, but it does not seem to offer IMAP (because mails are end2end encrypted).

ProtonMail costs 8€ per month, almost twice as much as Fastmail. I'm not sure yet if I'm willing to pay that much. I guess I'll check out the other mail services listed on privacytools.io

> I'm not sure yet if I'm willing to pay that much.

So what do you value your privacy at?

Re: Australian parliament passes encryption laws unamended

#150
post #33
post #19

Earlier quoted context omitted.

This isn't quite true. The bill allows companies to provide statistics on how many TARs, TANs, and TCNs they've been served within a 6-month window. The obvious problem is that nothing stops them from lying or just omitting that information -- because why would you admit that your software is insecure?

Employees of a company may also be served, and required not to tell their employer. So a company may not know if they are compromised.

I seriously wonder how that would work in practice?

"Hey Joey, will you work on the fizzibizzi feature that does xyz?"

I can't, I have other stuff to do?

"What kind of stuff? This feature is the top priority for the whole team?"

I JUST CAN'T TELL YOU OKAY!!!

Post reply on HN