Live data from Hacker News

Australian parliament passes encryption laws unamended

abc.net.au

241–250 of 415 posts

Re: Australian parliament passes encryption laws unamended

#241

Earlier quoted context omitted.

the US has already been doing this stuff for a long time, without it being legal. They can always pressure you and threaten to ruin any engineer's life if they don't do what they want. and who do you think came up with this legislation? It's US Intelligence. Australia is their testing lab, just like Macca's does.

Apple stared down the FBI in a mass murder case, because it was possible for them to do so. They won't be able to do that in Australia. I don't like the US shonkiness any more than anyone else. But these situations are not precisely equivalent, especially since this bill passed.

I don't see how it's any different to the situations with NSLs in the US. There's a veil of secrecy and no real limits on the scope of request with very harsh penalties for non-compliance.

Re: Australian parliament passes encryption laws unamended

#242

Earlier quoted context omitted.

When I was a kid I really wanted to see Australia. Kangaroos! Coral! Toilets that go backwards! Crocodile Dundee! (I was a kid, alright?) It just seems like a hotter, drier America at this point. New Zealand still looks lovely though. Maybe they could invade you?

Bit harsh, compared to America it's still saner day-to-day with healthcare, gun control, and very liveable cities with public transport. And it isn't like other western countries aren't thinking of doing something similar. While this is a bad law, being smug about it is the wrong reaction.

Which other western and non-English-speaking countries are doing similar things? This democratic-authoritarianism seems to be unique to the Five Eyes nations.

Re: Australian parliament passes encryption laws unamended

#243
post #44

I live in Australia and this is the dumbest bill I have ever seen in parliament. Australian politicians have no clue what the fuck they have just done. Rushed through in less than four days so they can go on holidays. Bigots.

To quote our last PM (well, this week anyway): "The laws of Australia prevail in Australia, I can assure you of that. The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia."

Oh well. Please petition your local representative to outlaw irrational numbers. We don't want these hysterical numbers breaking rational Australian laws.

Re: Australian parliament passes encryption laws unamended

#244

Earlier quoted context omitted.

I'm thinking about moving to NZ. How are they?

if you're going to move you really should get out of the anglosphere because the US is dragging down everyone with it and there's just not enough sentiment amongst the populations to move away from the US, even now. Switzerland probably remains the best country in the world and has strong privacy laws and a culture of neutrality. As a plus you get to be in Europe. Tech salaries are high. The anglosphere nations lack…

While true, Switzerland now shares banking data with the EU and US when required for their respective nationals. So foreign governments can and do exert pressure on them successfully.

Re: Australian parliament passes encryption laws unamended

#245

If you are an Australian software engineer, you have one advantage that other nationalities do not: the E3 visa. It is a US working visa that is specifically reserved for Australians and consequently it is much easier to get than an H1B. My advice is that the Australian tech industry just got nuked from orbit, so come work in the USA. The pay is better, the work is more interesting and the tech companies actually hav…

I am not sure that migrating will help. If I read the bill right, it implies that every person providing any service used (or "likely to be used") in Australia is under legal obligation to insert these backdoors. I don't think it specifically mentions software developed in Australia.

The bill seems to be a nightmare - it even says that the technical assistance request can be given orally. What the bloody ....?

To me, it reads like this - if you're a Nigerian developer working in Germany and refuse to do this for some software (after all, every software is "likely to be used" in Australia), you are still breaking the Australian law. But you need not be prosecutable if Germany does not have an extradition agreement with Australia. If you are an Australian anywhere in the world however, then refusing this makes you a criminal, probably later a fugitive. This is my understanding. Can someone confirm?

Re: Australian parliament passes encryption laws unamended

#246
post #235

Earlier quoted context omitted.

"The Director-General of Security, the Director-General of the Australian Secret Intelligence Service, the Director-General of the Australian Signals Directorate or the chief officer of an interception agency may give a technical assistance request to a designated communications provider. • A technical assistance request may ask the provider to do acts or things on a voluntary basis..." Note that an interception agen…

I don't see how you're up for civil charges if you fail to respond. It's voluntary. The line about not being subject to civil liability sounds to me like your employer can't fire or sue you for undermining the security of their product if you're doing so in response to a request.

That's how I interpret it too. Though does that mean they can contact an employee directly, rather than going through the company to have the backdoor installed? That's how it sounds to me, since otherwise why would you bother with this provision.

And if that's the case, software really is dead in Australia. You can't trust an Australian company, even if their leadership says they've never received a request, because one of their employees may have.

Re: Australian parliament passes encryption laws unamended

#248

I live in Australia and this is the dumbest bill I have ever seen in parliament. Australian politicians have no clue what the fuck they have just done. Rushed through in less than four days so they can go on holidays. Bigots.

As far as stupid laws go, Australia defines "child pornography" to include drawings and stories of fictional characters, to the point where a man was convicted of possessing "child pornography" in the form of nude characters from The Simpsons, and a man in prison was convicted of producing "child pornography" for writing a story involving the rape of a young girl. England and Wales, Canada, NZ and France have similar laws on such imaginative artwork.

Re: Australian parliament passes encryption laws unamended

#249

Ouch. Since I'm using Fastmail ... can anybody recommend a good alternative? I don't mind paying for a good and secure E-Mailprovider. Protonmail looks nice, but it does not seem to offer IMAP (because mails are end2end encrypted).

From what I remember fastmail has always cooperated with law enforcement. It is not zero-knowledge so they always had access to the user data already. Their promise has been to not use it for advertising purposes or share it with third parties. I don't see much changing here, but I would like to know if it is.

Email is already insecure. Even if you use GPG, that's client side, and should be as safe/unsafe as it was before this law (unsafe b/c metadata or unknown vuln). So in terms of threat model, it hasn't changed much.

I'm not defending the Oz gov or companies here, but knee-jerk reactions just open you up to more mistakes. For me, the situation is still preferable to Google having my data/metadata.

Re: Australian parliament passes encryption laws unamended

#250

Earlier quoted context omitted.

Officially, they can’t, but you can be absolutely certain that iMessage, WhatsApp, Signal and Telegram are going to be immediately targeted with TCNs (technical capability notice), requiring them to bundle Australian government spyware and requiring that those apps send all conversations to the spyware.

I downvoted you because the bill explicitly says it excludes systemic changes that compromise security. Apps will not have systemic spyware, only specific users can be targeted. Open source apps like Signal would be extremely hard to compromise since no one is going to allow a backdoor commit.

Does this mean that they can only mandate the backdooring of a user's communication if they know who the user is? Doesn't that seem irrelevant to the concerns they've raised in the past of having apprehended a suspect but been unable to decrypt their previous communications?
Post reply on HN