Live data from Hacker News

Commandeering Australian citizens to become spies

twitter.com

51–60 of 71 posts

Re: Commandeering Australian citizens to become spies

#51
Atlassian's an AUS company. Let's say I store code on Bitbucket, or I use Atlassian's hosted Confluence service. Does this mean Atlassian might have to notify the AUS government when I change my code, or add something to my Confluence pages? Or that they might have to secretly change my code (which means I'd have to carefully check it all the time for changes)? What if I self-host Confluence? Could a software upgrade contain a backdoor that sends my Confluence data to the AUS gov?

Not that I give a damn if the AUS gov looks at my stuff, but that's completely beside the point. These appear to be real possibilities with this law, and I hope Atlassian and other AUS companies address them.

Re: Commandeering Australian citizens to become spies

#52
post #36

If you're wondering why this kind of thing happens all the time in Australia, the late Donald Horne summed it up beautifully in the 1960s: "Australia is a lucky country run mainly by second rate people who share its luck" [1] Australia has many intelligent, brilliant people. For some reason, the design of our political system results in almost none of them getting into Government. This awful, fundamentally flawed law…

Maybe. But I really-really wish we had Australia’s STV system here in the USA.

What is Australia's STV system? I went Googling a bit, and the only quick hit was https://en.wikipedia.org/wiki/STV_(TV_station) , which seems unlikely to be what you meant.

Re: Commandeering Australian citizens to become spies

#53
post #43
post #17

Earlier quoted context omitted.

Interesting comment on that thread. Since all Australian SSL certs are now compromised (we must assume that), shouldn't all Australian certifying authorities be de-trusted?

There are none. https://ccadb-public.secure.force.com/mozilla/IncludedCACert...

Now question is who with Australian passport work there and have access to keys.

Re: Commandeering Australian citizens to become spies

#54

If you're wondering why this kind of thing happens all the time in Australia, the late Donald Horne summed it up beautifully in the 1960s: "Australia is a lucky country run mainly by second rate people who share its luck" [1] Australia has many intelligent, brilliant people. For some reason, the design of our political system results in almost none of them getting into Government. This awful, fundamentally flawed law…

I'm from Italy originally, and visited Australia several times.

Your comment could be applied to Italy verbatim :(

Re: Commandeering Australian citizens to become spies

#55
post #52
post #36

Earlier quoted context omitted.

Maybe. But I really-really wish we had Australia’s STV system here in the USA.

What is Australia's STV system? I went Googling a bit, and the only quick hit was https://en.wikipedia.org/wiki/STV_(TV_station) , which seems unlikely to be what you meant.

erentz was probably referring to the single transferable vote system (https://en.wikipedia.org/wiki/Single_transferable_vote), which uses a ranked ballot in elections and results in relatively proportional representation. CGP grey explains it pretty well: https://www.youtube.com/watch?v=l8XOZJkozfI

Re: Commandeering Australian citizens to become spies

#56
post #34

Has anyone worked at a company where Change Management was so good that there was no possible backdoor? Every system change would have to be approved by at least one other engineer and there is no ssh/sudo access on production systems? So far my impression is that all that is required is to gain access to Jenkins one way or another and you have the keys of the whole infrastructure.

There's never no possible backdoor, but yes I think in order to effectively do this and not involve my whole company like the article described you may have to have to involve Intel (and AMD is coming back, so them too) to go all "trusting trust" on this problem. And even then people may notice that their FDO profiles seem to be broken, and other "huh, that's funny".

Also other shops that actually obey SOX, and actually care about two-key systems (or multi-key) will not be able to keep this a secret.

The same protections that work for SOX and "sysadmins kid was kidnapped and they demand a backdoor be inserted" will work for this.

Sure, companies that protect against none of these will fail. But if you actually have systems in place to protect against "rogue employee" then this kind of order requires breaking ALL of these systems. I expect most companies to have no such systems, but the important ones do.

Re: Commandeering Australian citizens to become spies

#57
post #55
post #52

Earlier quoted context omitted.

What is Australia's STV system? I went Googling a bit, and the only quick hit was https://en.wikipedia.org/wiki/STV_(TV_station) , which seems unlikely to be what you meant.

erentz was probably referring to the single transferable vote system ( https://en.wikipedia.org/wiki/Single_transferable_vote ), which uses a ranked ballot in elections and results in relatively proportional representation. CGP grey explains it pretty well: https://www.youtube.com/watch?v=l8XOZJkozfI

Thanks! That makes much more sense than a TV station.

Re: Commandeering Australian citizens to become spies

#58
post #5

This is based on a false premise, that the Govt will ask developers , and that they would care if it is difficult/infeasible/impossible to actually complete. In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.

But the problem remains the same: how do you keep it a secret? How does the backdoor not get leaked immediately to the press, to the customers of the software, etc? Sure, this strategy may work in China but Australia is a Western nation where freedom is taken seriously. Edit later: by 'freedom taken seriously I mean by the people, not by the government.'

Sure, this strategy may work in China but Australia is a Western nation where freedom is taken seriously.

That’s the carefully cultivated reality distortion field at work.

It may look that way from the outside, but it’s a tightly controlled, aging and fearful society. Anyone who steps out of line is dealt with harshly and swiftly. The government may loosen the leash on those who align with their political philosophy (so figures who vilify vulnerable groups are given a bit of freedom under the current government) but the jackboot of the state isn’t far away.

Re your edit: there is compulsory voting, so the people obviously like it that way.

Re: Commandeering Australian citizens to become spies

#59
post #44

This is based on a false premise, that the Govt will ask developers , and that they would care if it is difficult/infeasible/impossible to actually complete. In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.

You're "reality" doesn't match the historical record how FVEY agencies work. Programs like the NSA's BULLRUN[1] or GCHQ's EDGEHILL are well funded ($B/yr) target individuals, companies, standards committees[2], and anything else that serves the purpose of preventing or compromising encryption. One well documented[2] example where individuals were "tasked" (spy on) directly is the compromise of satellite ISP Stellar:…

I may have phrased it badly, but my point wasn't that they would/could not target individuals, but more that they don't really care about their capacity as developers; more that these people are simply government implants in the target org, and that whether they are unable to provide the capability through ordinary channels is simply irrelevant.

If the Govt strongarms a developer into implanting a backdoor, they won't care that they can't do it without breaking company policy or QA or workflow or even the law, because they cease to be primarily an employee, and become an asset of ASIO.

Re: Commandeering Australian citizens to become spies

#60
post #7

This is based on a false premise, that the Govt will ask developers , and that they would care if it is difficult/infeasible/impossible to actually complete. In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.

The law explicitly allows them to target individuals. I don't believe that they gave themselves this power for no reason -- it's much easier to coerce an individual developer (who doesn't have fancy legal council) than force a company to do something. I'm sure they'll do it both ways of course, but I disagree that they'll only target companies.

Which means that the developer will be asked to stick a USB stick on a server, or pick a certain RNG; not submit a PR on a dumb backdoor such as described in this ... rant I guess.

Companies, of course, are already cooperating. For petes sake, all you need to do is talk to a couple of admins in the Bay Area to know what alphabet soup are visiting what companies (pro tip: basically all of them).

Post reply on HN