Live data from Hacker News

Commandeering Australian citizens to become spies

twitter.com

61–70 of 71 posts

Re: Commandeering Australian citizens to become spies

#61

Something interesting about this is that proper code management practices would mean there would have to be a chain-of-command having knowledge of the need for a specific code commit that targets a single user with a surveillance backdoor. Could an approached employee say "I have to run this past software engineer X" before it will even be allowed to commit, so software engineer X is read-in, but he has to get auth f…

Also, what exactly happens if the code is worked on in teams and/or available for any people in the company (and it sure is), and if another developer questions the committed code or attempts to change or remove it? Does such code gets explicitly painted "don't remove, don't edit, don't ask any questions"? Suddenly we get code in our product that nobody cannot talk about, nobody should understand, and nobody can fix…

"Does such code gets explicitly painted "don't remove, don't edit, don't ask any questions"

This would flag the code as 'interesting' to any other members of the development team, and it would likely make it obvious which account is being specifically targeted, which works against the secrecy required of the whole thing.

Re: Commandeering Australian citizens to become spies

#62
post #45
post #24

As an Australian Dev living in the U.K. this is absolutely terrifying. I'm compelled to somehow deploy a backdoor at whatever company I'm working for if they have a single Australian user on threat of jail time???

You are not bound to the laws of Australia in the UK. Foreign nationals in Australia are. That being said, this is coming to the UK too.

Yes he is, and at risk of a felony charge waiting for him if he returns to Aus. Not sure about extradition but I assume that could be on the table too.

Re: Commandeering Australian citizens to become spies

#63

If you're wondering why this kind of thing happens all the time in Australia, the late Donald Horne summed it up beautifully in the 1960s: "Australia is a lucky country run mainly by second rate people who share its luck" [1] Australia has many intelligent, brilliant people. For some reason, the design of our political system results in almost none of them getting into Government. This awful, fundamentally flawed law…

From a selfish American-centric perspective, sometimes it feels like different west-aligned countries/regions use these attempts as test beds to gauge acceptableness in other countries/regions.

Isn't that exactly what has happened here? IIRC there was a Five Eyes get together not too long ago where they all decided this was the direction they should follow and Australia would take the lead.

https://www.arnnet.com.au/article/621107/australia-looks-lea...

https://www.itnews.com.au/news/five-eyes-nations-to-force-en...

Re: Commandeering Australian citizens to become spies

#64
post #16

Earlier quoted context omitted.

According to Sect 317C, a "designated communications provider" includes: A person is a designated communications provider if ... 6. the person develops, supplies or updates software used, for use, or likely to be used, in connection with: (a) a listed carriage service; or (b) an electronic service that has one or more end-users in Australia ... and the eligible activities of the person are ... (a) the development by…

The difference between can and will be is huge. Look at it from their point of view... they approach some developer and it's amateur hour. The dev might get stroppy, there's all sorts of infrastructure problems, they might not do it right... it's a mess. But if they approach the CEO, it gets done right. The CEO brings in Legal, who promptly shit themselves. They bring in the CTO, who is told to shut up, sign this NDA…

But now you have a dozen or more people who know what's happening and we all know, three people can keep a secret if two of them are dead.

Re: Commandeering Australian citizens to become spies

#65

Earlier quoted context omitted.

The difference between can and will be is huge. Look at it from their point of view... they approach some developer and it's amateur hour. The dev might get stroppy, there's all sorts of infrastructure problems, they might not do it right... it's a mess. But if they approach the CEO, it gets done right. The CEO brings in Legal, who promptly shit themselves. They bring in the CTO, who is told to shut up, sign this NDA…

But now you have a dozen or more people who know what's happening and we all know, three people can keep a secret if two of them are dead.

I'm not sure the point is actually to keep it secret, but (as with all government "services") to cover the arse.

Also, if you were an employee in a company in this situation, and you'd been told that the security of the nation depended on your silence, and more to the point, you'd be locked up and your career ruined if you went public, what would you do? Whistleblowers are pretty rare, because the consequences of doing that are huge.

Re: Commandeering Australian citizens to become spies

#66
post #7

Earlier quoted context omitted.

The law explicitly allows them to target individuals. I don't believe that they gave themselves this power for no reason -- it's much easier to coerce an individual developer (who doesn't have fancy legal council) than force a company to do something. I'm sure they'll do it both ways of course, but I disagree that they'll only target companies.

Which means that the developer will be asked to stick a USB stick on a server, or pick a certain RNG; not submit a PR on a dumb backdoor such as described in this ... rant I guess. Companies, of course, are already cooperating. For petes sake, all you need to do is talk to a couple of admins in the Bay Area to know what alphabet soup are visiting what companies (pro tip: basically all of them).

The most likely thing is going to be that Apple is going to be asked to allow police devices to be added to a user's iMessage account without alerting the user (but giving them access to their messages).

The real problem is that the law allows them to ask an individual to become a saboteur and it's unclear if you had a system that was explicitly resilient to such attacks (signed GPLv3 code with a threshold signing scheme with each key owned by people under different jurisdictions) whether you would be forced to dismantle such a system.

I think we'll need to start rethinking threat models.

Re: Commandeering Australian citizens to become spies

#67

Earlier quoted context omitted.

But now you have a dozen or more people who know what's happening and we all know, three people can keep a secret if two of them are dead.

I'm not sure the point is actually to keep it secret, but (as with all government "services") to cover the arse. Also, if you were an employee in a company in this situation, and you'd been told that the security of the nation depended on your silence, and more to the point, you'd be locked up and your career ruined if you went public, what would you do? Whistleblowers are pretty rare, because the consequences of doi…

It also applies to former employees. Yes, you can be asked to hack into previous job's systems

Re: Commandeering Australian citizens to become spies

#68
post #44

Earlier quoted context omitted.

You're "reality" doesn't match the historical record how FVEY agencies work. Programs like the NSA's BULLRUN[1] or GCHQ's EDGEHILL are well funded ($B/yr) target individuals, companies, standards committees[2], and anything else that serves the purpose of preventing or compromising encryption. One well documented[2] example where individuals were "tasked" (spy on) directly is the compromise of satellite ISP Stellar:…

I may have phrased it badly, but my point wasn't that they would/could not target individuals, but more that they don't really care about their capacity as developers; more that these people are simply government implants in the target org, and that whether they are unable to provide the capability through ordinary channels is simply irrelevant. If the Govt strongarms a developer into implanting a backdoor, they won'…

This is why I'm choosing to stick to the term commandeering

Re: Commandeering Australian citizens to become spies

#69
post #43
post #17

Earlier quoted context omitted.

Interesting comment on that thread. Since all Australian SSL certs are now compromised (we must assume that), shouldn't all Australian certifying authorities be de-trusted?

There are none. https://ccadb-public.secure.force.com/mozilla/IncludedCACert...

Not true. Symantec have offices in Australia

Re: Commandeering Australian citizens to become spies

#70

Earlier quoted context omitted.

Also, what exactly happens if the code is worked on in teams and/or available for any people in the company (and it sure is), and if another developer questions the committed code or attempts to change or remove it? Does such code gets explicitly painted "don't remove, don't edit, don't ask any questions"? Suddenly we get code in our product that nobody cannot talk about, nobody should understand, and nobody can fix…

"Does such code gets explicitly painted "don't remove, don't edit, don't ask any questions" This would flag the code as 'interesting' to any other members of the development team, and it would likely make it obvious which account is being specifically targeted, which works against the secrecy required of the whole thing.

[deleted]
Post reply on HN