Live data from Hacker News

Australian parliament passes encryption laws unamended

abc.net.au

211–220 of 415 posts

Re: Australian parliament passes encryption laws unamended

#211

This is another thing that adds to my deep sense of shame to live in this country (sadly, that list is long and growing). This bill does nothing to prevent the kinds of things it is intended to prevent. The apps this law targets were engineered specifically to prevent this kind of interference. The idea that passing legislation will suddenly change that, magically allowing decryption of messages is beyond idiotic. Th…

When I was a kid I really wanted to see Australia. Kangaroos! Coral! Toilets that go backwards! Crocodile Dundee! (I was a kid, alright?)

It just seems like a hotter, drier America at this point.

New Zealand still looks lovely though. Maybe they could invade you?

Re: Australian parliament passes encryption laws unamended

#212
post #68

Earlier quoted context omitted.

I'm thinking about moving to NZ. How are they?

They are in Five Eyes, were instrumental in Echelon, illegally raided Dotcom... NZ is a beautiful country, but one of the weakest-willed in international terms. (Also, by all reports, internet connectivity sucks big time).

> Also, by all reports, internet connectivity sucks big time

If the poster is coming from Australia, NZ is not so bad.

Re: Australian parliament passes encryption laws unamended

#213
post #33

Earlier quoted context omitted.

Employees of a company may also be served, and required not to tell their employer. So a company may not know if they are compromised.

Can they quit? Or are they effectively being forced to perform labor for the government? This seems like an insanely impossible to enforce proposition.

That's something we'll have to wait and see on, see how the legal world interprets it. However, if it is interpreted that you quitting is not complying, it's fines and perhaps jail time.

Re: Australian parliament passes encryption laws unamended

#214
post #202

Earlier quoted context omitted.

You must build a custom made back door. eg. Something like ProtonMail would need to inject some extra javascript so that the government could obtain a copy before encryption, I expect. If I were to write some software of this nature these days, I'd make sure that the client would be aware of any changes in the api - sort of like a personal warrant canary. (Note that a warrant canary is legal in this legislation).

Warrant canaries are illegal in Australia, at least in the case of other kinds of secret warrants. I would be very surprised that a judge would (given the existing laws that have similar properties) consider a warrant canary legal. (For those wondering how they can be illegal, in Australia it's illegal to state the existence or non-existence of certain kinds of secret warrants. So a statement of a canary is, itself,…

There are allowances (from what I understand) in this bill. From "Section 6 - Unauthorised disclosure of information":

- A person who is: ...

...may, in the person’s capacity as such a provider or employee, disclose:

(e) the total number of technical assistance notices given to the provider during a period of at least 6 months; or

(f) the total number of technical capability notices given to the provider during a period of at least 6 months; or

(g) the total number of technical assistance requests given to the provider during a period of at least 6 months.

Note:

This subsection authorises the disclosure of aggregate statistical information. That information cannot be broken down:

(a) by agency; or

(b) in any other way. " [0]

[0] pp50-51, http://parlinfo.aph.gov.au/parlInfo/download/legislation/bil...

Re: Australian parliament passes encryption laws unamended

#215
post #127
post #56

Earlier quoted context omitted.

This immensely stupid law applies to any business that operates in Australia, which includes Google, Apple, Microsoft, Samsung, Facebook, Github, and every other major tech company on the planet. If they want to continue doing business in Australia (and they very much do) then they'll be forced to comply, which means everybody in the world is negatively affected by this insanity.

If they want to continue doing business in Australia (and they very much do) Meh. 25 million people, and not a top ten economy. Australia has a powerful reality distortion field that makes it seem more important than it is. Must be the tourist marketing and the fact that it punches above its weight in producing successful entertainers. It’s more likely that WhatsApp and other encrypted messaging apps will just get pu…

Of they don't get pulled, well, that tells you something too.

Re: Australian parliament passes encryption laws unamended

#216

Earlier quoted context omitted.

There are so many loopholes in this thing. One predominant thing to keep in mind is the legal onus that is put on a company that does not comply . The basic gems are that I got from reading the draft legislation was: - If you have server side encryption, & we want you to decrypt a particular person's data, then we expect you to do so - ad infinitum. - If you do client side encryption then we expect you to put into pl…

Does the legislation say they can do this without justification though? Can they just ask for anyones information or does there need to be some sort of warrant?

"The Director-General of Security, the Director-General of the Australian Secret Intelligence Service, the Director-General of the Australian Signals Directorate or the chief officer of an interception agency may give a technical assistance request to a designated communications provider. • A technical assistance request may ask the provider to do acts or things on a voluntary basis..."

Note that an interception agency also includes "the Police Force" p9

It later states that if a provider willingly complies:

"an officer, employee or agent of the provider is not subject to any civil liability for, or in relation to, an act or thing done by the officer, employee or agent in connection with the act or thing mentioned in paragraph (b)" p17

Meaning, you're up for civil charges if you fail to respond to a non-warrant request.

Re: Australian parliament passes encryption laws unamended

#217
post #202

Earlier quoted context omitted.

Warrant canaries are illegal in Australia, at least in the case of other kinds of secret warrants. I would be very surprised that a judge would (given the existing laws that have similar properties) consider a warrant canary legal. (For those wondering how they can be illegal, in Australia it's illegal to state the existence or non-existence of certain kinds of secret warrants. So a statement of a canary is, itself,…

There are allowances (from what I understand) in this bill. From "Section 6 - Unauthorised disclosure of information": - A person who is: ... ...may, in the person’s capacity as such a provider or employee, disclose: (e) the total number of technical assistance notices given to the provider during a period of at least 6 months; or (f) the total number of technical capability notices given to the provider during a per…

Right, I forgot to mention the statistics. Yes, you can publish statistics in 6-month windows -- which is kind of what warrant canaries are supposed to provide information about -- but I'd be surprised if the "cannot be broken down" might be used to restrict the usefulness of statistics...

I mean, a literal reading would allow you to provide minute-by-minute 6-month windows (or a new 6-month window each time you get a request) which could be used to get very detailed alerts each time a new request was given but obviously you'd get into hot water by doing that.

Re: Australian parliament passes encryption laws unamended

#218
post #94
post #33

Earlier quoted context omitted.

Employees of a company may also be served, and required not to tell their employer. So a company may not know if they are compromised.

Right, but then the employee can publish statistics about how many TCNs they've received.

They can't provide specifics only ranges. In Division 6, section 317ZF, Unauthorized Disclosure of Information, section 3) subsection 13) a person forced to do one of these TAN/TCN/TCR things can release a count of how many of these TAN/TCN/TCR things. BUT Note: This subsection authorises the disclosure of aggregate statistical information. That information cannot be broken down (a) by agency; or (b) in any other way.

So Division 6, section 317ZF (3) (13) is the ONLY way someone can tell the world what is happening.

Re: Australian parliament passes encryption laws unamended

#219

Earlier quoted context omitted.

> 1 billion Is that metaphorical or actual number? If latter, I am interested in the source.

Their stock is down 4.3% today and their market cap is around $20B

Thay may be unrelated - most stock markets went down about that much today (and I'm glaring at my own stocks at the moment - none in Atlassian, they're down an average of 4.23% as of now)

Re: Australian parliament passes encryption laws unamended

#220

Somebody over on Reddit [1] went through all the submissions (there was a consultation period) and summarised and tallied them [2]. Fully 99%+ of submissions were against the bill. A sad day for democracy indeed. A church in Tasmania was in favour, because child pornography. 1. https://www.reddit.com/r/australia/comments/a3j466/assistanc... 2. https://docs.google.com/spreadsheets/d/1dowpZ_Xtr1N_DgkHJN8i...

A sad day for democracy, but this fact restores some faith in humanity.
Post reply on HN