Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

11–20 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#11
post #4

Do we trust Intel chips are free from gov backdoors? Or that Microsoft/FB arent in bed with the NSA? I would say the precedent has long since been set.

Not that this is any good, but at least in the US the state pays for the surveillance. Here the businesses have to foot the bill for who knows hoe many unending requests. If you thought it was hard to make a viable tech business in Australia before, well you can forget all about that now.

It's more like if Microsoft and FB were in bed with the NSA. And then they sent you the bill for your own surveillance. And if you didn't pay, then sent you to jail.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#12

The thing that makes me most despondent is, you just watch them all get voted back in next election.

ya and it will happen every year... those in power have been trying to take control of people's lives forever but so far they have been unable since it requires physically being present. but as technology becomes seamless and is woven into the fabric of society, eventually our thoughts too wont remain private. the only thing protecting us is we are just one data point in billions...

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#13
While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation.

It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has developed software that is likely to be used in an electronic service that has one end-user in Australia. This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. Now, there is an argument to be made that employees don't qualify (because they're acting on behalf of their employer), but that's not clear at the moment. It also includes sysadmins (or even ex-sysadmins) as people who can be "activated" as saboteurs.

It should be noted that it's very unlikely that this legislation would result in the Armageddon most people (including myself) are quite worried about. I imagine it's much more likely this power will be used against a few big players (Apple, Facebook, Google) in order to add features like being able to add additional devices to group chats (or something like that). But obviously the law gives them much more power than that, and that's a very big concern.

(And the fact that only 2 MPs voted against it tells me there's almost certainly some back-door dealings that resulted in this bill being passed.)

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#14
post #8

I am particularly concerned how this will affect Fastmail, an Australian company. I've hosted my mail there since 2002 and they've always been quite pro-privacy. But I fear that such a stance is now literally impossible for any Australian company.

TCNs (which is the primary thing this article is about) won't practically affect email providers, because email providers already have your plaintext emails -- they don't need to implement new capabilities to intercept them. (As an aside, I use Mailbox.org which has a feature to auto-encrypt incoming emails to a PGP public key -- which means that only new emails would be usable with interception.) However there is no…

maybe some people cannot get iPhones. Or use netflix or other items that depend on good encryption!

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#15
post #4

Do we trust Intel chips are free from gov backdoors? Or that Microsoft/FB arent in bed with the NSA? I would say the precedent has long since been set.

Not that this is any good, but at least in the US the state pays for the surveillance. Here the businesses have to foot the bill for who knows hoe many unending requests. If you thought it was hard to make a viable tech business in Australia before, well you can forget all about that now. It's more like if Microsoft and FB were in bed with the NSA. And then they sent you the bill for your own surveillance. And if you…

That's not necessarily true. For TCNs there is an explicit section that deals with compensating businesses, through an "Applicable costs negotiator". See s.317ZK(16).

And there is no criminal liability for non-compliance. "Just" very hefty civil fines.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#16
post #8

Earlier quoted context omitted.

TCNs (which is the primary thing this article is about) won't practically affect email providers, because email providers already have your plaintext emails -- they don't need to implement new capabilities to intercept them. (As an aside, I use Mailbox.org which has a feature to auto-encrypt incoming emails to a PGP public key -- which means that only new emails would be usable with interception.) However there is no…

maybe some people cannot get iPhones. Or use netflix or other items that depend on good encryption!

Sure, but the point is that warrants already allowed for access to services that are insecure.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#17
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company.

This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#18
post #17
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

It's an Australian law, so it can only affect people under Australian jurisdiction -- I didn't think that needed to be said. There are significant numbers of free software developers in Australia (I'm one of them).

The point is that all software engineers (in Australia) being able to be co-opted as saboteurs is a fairly "meaningful" problem and should be a concern to everyone...

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#20
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

Laws eventually get abused.

I think it’s very likely that this law will eventually lead to everything everybody is worrying about.

Post reply on HN