Not that I give a damn if the AUS gov looks at my stuff, but that's completely beside the point. These appear to be real possibilities with this law, and I hope Atlassian and other AUS companies address them.
Commandeering Australian citizens to become spies
51–60 of 71 posts
Re: Commandeering Australian citizens to become spies
#52If you're wondering why this kind of thing happens all the time in Australia, the late Donald Horne summed it up beautifully in the 1960s: "Australia is a lucky country run mainly by second rate people who share its luck" [1] Australia has many intelligent, brilliant people. For some reason, the design of our political system results in almost none of them getting into Government. This awful, fundamentally flawed law…
Maybe. But I really-really wish we had Australia’s STV system here in the USA.
Re: Commandeering Australian citizens to become spies
#53Earlier quoted context omitted.
Interesting comment on that thread. Since all Australian SSL certs are now compromised (we must assume that), shouldn't all Australian certifying authorities be de-trusted?
There are none. https://ccadb-public.secure.force.com/mozilla/IncludedCACert...
Re: Commandeering Australian citizens to become spies
#54If you're wondering why this kind of thing happens all the time in Australia, the late Donald Horne summed it up beautifully in the 1960s: "Australia is a lucky country run mainly by second rate people who share its luck" [1] Australia has many intelligent, brilliant people. For some reason, the design of our political system results in almost none of them getting into Government. This awful, fundamentally flawed law…
Your comment could be applied to Italy verbatim :(
Re: Commandeering Australian citizens to become spies
#55Earlier quoted context omitted.
Maybe. But I really-really wish we had Australia’s STV system here in the USA.
What is Australia's STV system? I went Googling a bit, and the only quick hit was https://en.wikipedia.org/wiki/STV_(TV_station) , which seems unlikely to be what you meant.
Re: Commandeering Australian citizens to become spies
#56Has anyone worked at a company where Change Management was so good that there was no possible backdoor? Every system change would have to be approved by at least one other engineer and there is no ssh/sudo access on production systems? So far my impression is that all that is required is to gain access to Jenkins one way or another and you have the keys of the whole infrastructure.
Also other shops that actually obey SOX, and actually care about two-key systems (or multi-key) will not be able to keep this a secret.
The same protections that work for SOX and "sysadmins kid was kidnapped and they demand a backdoor be inserted" will work for this.
Sure, companies that protect against none of these will fail. But if you actually have systems in place to protect against "rogue employee" then this kind of order requires breaking ALL of these systems. I expect most companies to have no such systems, but the important ones do.
Re: Commandeering Australian citizens to become spies
#57Earlier quoted context omitted.
What is Australia's STV system? I went Googling a bit, and the only quick hit was https://en.wikipedia.org/wiki/STV_(TV_station) , which seems unlikely to be what you meant.
erentz was probably referring to the single transferable vote system ( https://en.wikipedia.org/wiki/Single_transferable_vote ), which uses a ranked ballot in elections and results in relatively proportional representation. CGP grey explains it pretty well: https://www.youtube.com/watch?v=l8XOZJkozfI
Re: Commandeering Australian citizens to become spies
#58This is based on a false premise, that the Govt will ask developers , and that they would care if it is difficult/infeasible/impossible to actually complete. In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.
But the problem remains the same: how do you keep it a secret? How does the backdoor not get leaked immediately to the press, to the customers of the software, etc? Sure, this strategy may work in China but Australia is a Western nation where freedom is taken seriously. Edit later: by 'freedom taken seriously I mean by the people, not by the government.'
That’s the carefully cultivated reality distortion field at work.
It may look that way from the outside, but it’s a tightly controlled, aging and fearful society. Anyone who steps out of line is dealt with harshly and swiftly. The government may loosen the leash on those who align with their political philosophy (so figures who vilify vulnerable groups are given a bit of freedom under the current government) but the jackboot of the state isn’t far away.
Re your edit: there is compulsory voting, so the people obviously like it that way.
Re: Commandeering Australian citizens to become spies
#59This is based on a false premise, that the Govt will ask developers , and that they would care if it is difficult/infeasible/impossible to actually complete. In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.
You're "reality" doesn't match the historical record how FVEY agencies work. Programs like the NSA's BULLRUN[1] or GCHQ's EDGEHILL are well funded ($B/yr) target individuals, companies, standards committees[2], and anything else that serves the purpose of preventing or compromising encryption. One well documented[2] example where individuals were "tasked" (spy on) directly is the compromise of satellite ISP Stellar:…
If the Govt strongarms a developer into implanting a backdoor, they won't care that they can't do it without breaking company policy or QA or workflow or even the law, because they cease to be primarily an employee, and become an asset of ASIO.
Re: Commandeering Australian citizens to become spies
#60This is based on a false premise, that the Govt will ask developers , and that they would care if it is difficult/infeasible/impossible to actually complete. In reality, they issue a notice to the company, give them a timeframe, and expect it to be done. They don’t care about the intricacies of git.
The law explicitly allows them to target individuals. I don't believe that they gave themselves this power for no reason -- it's much easier to coerce an individual developer (who doesn't have fancy legal council) than force a company to do something. I'm sure they'll do it both ways of course, but I disagree that they'll only target companies.
Companies, of course, are already cooperating. For petes sake, all you need to do is talk to a couple of admins in the Bay Area to know what alphabet soup are visiting what companies (pro tip: basically all of them).