Live data from Hacker News

Commandeering Australian citizens to become spies

twitter.com

1–10 of 71 posts

Re: Commandeering Australian citizens to become spies

#3
This is based on a false premise, that the Govt will ask developers, and that they would care if it is difficult/infeasible/impossible to actually complete.

In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.

Re: Commandeering Australian citizens to become spies

#5

This is based on a false premise, that the Govt will ask developers , and that they would care if it is difficult/infeasible/impossible to actually complete. In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.

But the problem remains the same: how do you keep it a secret? How does the backdoor not get leaked immediately to the press, to the customers of the software, etc?

Sure, this strategy may work in China but Australia is a Western nation where freedom is taken seriously.

Edit later: by 'freedom taken seriously I mean by the people, not by the government.'

Re: Commandeering Australian citizens to become spies

#6

This is based on a false premise, that the Govt will ask developers , and that they would care if it is difficult/infeasible/impossible to actually complete. In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.

Yeah you just go to the CEO or legal counsel, threaten loss of licenses, seizure of personal assets

Re: Commandeering Australian citizens to become spies

#7

This is based on a false premise, that the Govt will ask developers , and that they would care if it is difficult/infeasible/impossible to actually complete. In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.

The law explicitly allows them to target individuals. I don't believe that they gave themselves this power for no reason -- it's much easier to coerce an individual developer (who doesn't have fancy legal council) than force a company to do something. I'm sure they'll do it both ways of course, but I disagree that they'll only target companies.

Re: Commandeering Australian citizens to become spies

#8
post #6

This is based on a false premise, that the Govt will ask developers , and that they would care if it is difficult/infeasible/impossible to actually complete. In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.

Yeah you just go to the CEO or legal counsel, threaten loss of licenses, seizure of personal assets

CEO or legal counsel? They can directly compel current and former individual employees:

https://twitter.com/alfiedotwtf/status/1070658693409079296

Re: Commandeering Australian citizens to become spies

#9
post #5

This is based on a false premise, that the Govt will ask developers , and that they would care if it is difficult/infeasible/impossible to actually complete. In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.

But the problem remains the same: how do you keep it a secret? How does the backdoor not get leaked immediately to the press, to the customers of the software, etc? Sure, this strategy may work in China but Australia is a Western nation where freedom is taken seriously. Edit later: by 'freedom taken seriously I mean by the people, not by the government.'

> where freedom is taken seriously.

Ahahahahahahaha

Re: Commandeering Australian citizens to become spies

#10
Something interesting about this is that proper code management practices would mean there would have to be a chain-of-command having knowledge of the need for a specific code commit that targets a single user with a surveillance backdoor.

Could an approached employee say "I have to run this past software engineer X" before it will even be allowed to commit, so software engineer X is read-in, but he has to get auth from Middle Manager Y, and so on. The more people who are read-in, the more chance there is of a leak or someone overhearing a conversation or people questioning a stream of progressively higher-tiered employees being brought into a meeting with strange men wearing sunglasses, fedoras, with knife-sharp pleats in their slacks, and using company meeting rooms like they own the place.

This is making assumptions about the quality of company Z's code publishing process, but I'd be guessing that there would be a lot more "targets" using popular software from big vendors that have these QA processes in place.

The other interesting thing about this is that it may spur far more interest in both using and regularly auditing open source software. Proprietary software is far more at risk of losing reputation in this situation simply because of its opacity.

P.S.

https://blog.cryptoaustralia.org.au/2017/03/21/run-your-end-...

Post reply on HN