Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

21–30 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#21

The thing that makes me most despondent is, you just watch them all get voted back in next election.

Do you think that will just magically happen on its own?

The party that may win the next election already supports the bill. They claim they would update it with a few inconsequential changes, to make it look like they're "fixing it". But that's about it.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#22
post #18
post #17

Earlier quoted context omitted.

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

It's an Australian law, so it can only affect people under Australian jurisdiction -- I didn't think that needed to be said. There are significant numbers of free software developers in Australia (I'm one of them). The point is that all software engineers (in Australia) being able to be co-opted as saboteurs is a fairly "meaningful" problem and should be a concern to everyone...

Well, if it comes to it, we could always choose to just blacklist all Australian devs from writing software.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#23
post #8

I am particularly concerned how this will affect Fastmail, an Australian company. I've hosted my mail there since 2002 and they've always been quite pro-privacy. But I fear that such a stance is now literally impossible for any Australian company.

TCNs (which is the primary thing this article is about) won't practically affect email providers, because email providers already have your plaintext emails -- they don't need to implement new capabilities to intercept them. (As an aside, I use Mailbox.org which has a feature to auto-encrypt incoming emails to a PGP public key -- which means that only new emails would be usable with interception.) However there is no…

It’s not the same thing.

Don’t know Australian law, but for a warrant you need to demonstrate probable cause in front of a judge. And that’s a pretty high bar.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#24

warrant canaries, but for individuals

The law allows you to provide statistical information about how many of the relevant notices you've received within a 6-month-window. So there's no need for warrant canaries (which is a good thing, since they're not generally legal in Australia).

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#25
post #4

Do we trust Intel chips are free from gov backdoors? Or that Microsoft/FB arent in bed with the NSA? I would say the precedent has long since been set.

Actually we have yet to see any evidence that the government have forced Intel, Facebook, Amazon etc to insert backdoors. In fact the Snowden leaks kind of have evidence to the contrary - the NSA hacked Google's private network. They wouldn't need to bother if they had legally compelled them to add some kind of national security backdoor.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#26
post #8

Earlier quoted context omitted.

TCNs (which is the primary thing this article is about) won't practically affect email providers, because email providers already have your plaintext emails -- they don't need to implement new capabilities to intercept them. (As an aside, I use Mailbox.org which has a feature to auto-encrypt incoming emails to a PGP public key -- which means that only new emails would be usable with interception.) However there is no…

It’s not the same thing. Don’t know Australian law, but for a warrant you need to demonstrate probable cause in front of a judge. And that’s a pretty high bar.

I didn't say it was the same thing, and I agree that the lack of judicial oversight makes it incredibly rife for abuse as well as much easier to get.

I said that to you (a user who wouldn't be the target of a warrant) there isn't a practical difference if you're targeted. You wouldn't be able to mount a defence in court anyway.

But of course, it being easier is a very serious problem from a societal perspective.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#27
post #18

Earlier quoted context omitted.

It's an Australian law, so it can only affect people under Australian jurisdiction -- I didn't think that needed to be said. There are significant numbers of free software developers in Australia (I'm one of them). The point is that all software engineers (in Australia) being able to be co-opted as saboteurs is a fairly "meaningful" problem and should be a concern to everyone...

Well, if it comes to it, we could always choose to just blacklist all Australian devs from writing software.

That sounds like a reasonable outcome...

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#28
post #4

Do we trust Intel chips are free from gov backdoors? Or that Microsoft/FB arent in bed with the NSA? I would say the precedent has long since been set.

> Do we trust Intel chips are free from gov backdoors?

No. But there are people working hard on things like Power8-- which already exists-- and RISCV-- which don't include anything similar to Intel's ME.

Probably more to the point, Apple already designed and implemented a secure enclave that makes it much harder for them to turn over things to law enforcement like messaging content of its users. Signal similarly has a design that limits the amount of data it has to turn over.

Without a legal precedent that says you can't do such hardware/software designs, lots of companies do such designs. We've even seen a company fold rather than change their design on the request of the government to make it easier to spy on users.

Plus, if there is an Intel ME backdoor it is almost certainly only available directly to NSA-- not to FBI, not to the Treasury, definitely not to local law enforcement, and definitely not to other tech companies or politicians who have the sway to convince any of the above to give them access to some data they'd like to have.

A law that makes it possible for more government agencies to force a company to turn over data or serve up malware is a law for the worse. A law that makes it harder for companies to design secure protocols and systems in the first place is a law for the worse.

Or that Microsoft/FB arent in bed with the NSA? I would say the precedent has long since been set.

Well, Facebook isn't a very good example here. There were so many inputs/outputs into its user data that it's hard to imagine a type of inference that could not have been retrieved by an interested third party on any subset of its userbase.

If Facebook is supposed to be a metaphor for all modern general purpose computing software, your only serious conclusion is to stop using all modern general purpose computing software.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#30
post #17
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

This doesn't seem very meaningful? I live in the US.

How very Ameri-centric?

Post reply on HN