Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

31–40 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#31
post #18

Earlier quoted context omitted.

It's an Australian law, so it can only affect people under Australian jurisdiction -- I didn't think that needed to be said. There are significant numbers of free software developers in Australia (I'm one of them). The point is that all software engineers (in Australia) being able to be co-opted as saboteurs is a fairly "meaningful" problem and should be a concern to everyone...

Well, if it comes to it, we could always choose to just blacklist all Australian devs from writing software.

Which is why this bill is a complete disaster for the Australian tech industry. Every single software company in Australia just became blackmarked and could be "potentially compromised" by the government and whoever has figured out the governments likely hamfisted and boutique backdoor solutions.

Even someone's little SaaS can be asked to turn up dirt on someone. I literally couldn't comply. I don't write encryption algorithms for a living I just build websites. I can't not encrypt people's data and according to european laws I can't store most of it anyway. Here, gov, have a username, email address, and this blob of encrypted text. Enjoy the insight.

It's getting so hostile to do business in software. At least construction and engineering liabilities are clear cut. I don't even know what my risks factors are anymore and they change every month.

It took longer than expected, but the governments have finally decided it's time to ruin the internet. I am going to go be a carpenter or something.

What a shitshow.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#32

Earlier quoted context omitted.

Well, if it comes to it, we could always choose to just blacklist all Australian devs from writing software.

That sounds like a reasonable outcome...

No, not reasonable, but it's the will of the Australian people and we should respect their sovereignty.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#33
post #7
post #4

Do we trust Intel chips are free from gov backdoors? Or that Microsoft/FB arent in bed with the NSA? I would say the precedent has long since been set.

You're right, but this is the first time (I know of) that a government has explicitly required backdoors and forcing tech companies to download malware/spyware to their customers' devices. This new law brazenly makes encryption useless and sets a dangerous precedent.

There was an attempt to do this in the 90s in the US, but it failed. There's a paper titled "Keys Under Doormats" that outlines the debate of that era:

https://www.schneier.com/academic/paperfiles/paper-keys-unde...

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#34

The thing that makes me most despondent is, you just watch them all get voted back in next election.

It's exceptionally sad since Australia has order of preference, instant runoff and mandatory voting. Even with all those safeguards to prevent major parties and ensure equal representation, Australia still ends up with major parties and too many people who don't bother with the bottom of the ballot.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#35
post #30
post #17

Earlier quoted context omitted.

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

This doesn't seem very meaningful? I live in the US. How very Ameri-centric?

That wasn’t their point. These are global services and many of them are written and controlled by people who aren’t under the authority of Australian law.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#36
post #26

Earlier quoted context omitted.

It’s not the same thing. Don’t know Australian law, but for a warrant you need to demonstrate probable cause in front of a judge. And that’s a pretty high bar.

I didn't say it was the same thing, and I agree that the lack of judicial oversight makes it incredibly rife for abuse as well as much easier to get. I said that to you (a user who wouldn't be the target of a warrant) there isn't a practical difference if you're targeted. You wouldn't be able to mount a defence in court anyway. But of course, it being easier is a very serious problem from a societal perspective.

It depends. Australia is part of the 5 eyes countries. So now via cooperation between security agencies and due to no judicial oversight, I think more people are affected, whereas before this you would have to convince an Australian judge to give you a warrant.

IANAL.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#37
post #17
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

[deleted]

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#38

Earlier quoted context omitted.

That sounds like a reasonable outcome...

No, not reasonable, but it's the will of the Australian people and we should respect their sovereignty.

I honestly can’t tell if this is an honest comment, or a dark ironic reference to Trump, Brexit or current Italian politics.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#39
post #17
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

The demand would come directly from the US government, after it passes the same law in five years. You do realize this is ultimately FVEY doing a trial in Australia, yes?

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#40
post #8

Earlier quoted context omitted.

TCNs (which is the primary thing this article is about) won't practically affect email providers, because email providers already have your plaintext emails -- they don't need to implement new capabilities to intercept them. (As an aside, I use Mailbox.org which has a feature to auto-encrypt incoming emails to a PGP public key -- which means that only new emails would be usable with interception.) However there is no…

It’s not the same thing. Don’t know Australian law, but for a warrant you need to demonstrate probable cause in front of a judge. And that’s a pretty high bar.

The problem is that if a back door exists for government, it necessarily exists for anyone.

Here’s Tim Cook making that point: https://m.youtube.com/watch?v=rQebmygKq7A

Post reply on HN