Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

41–50 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#41

Earlier quoted context omitted.

No, not reasonable, but it's the will of the Australian people and we should respect their sovereignty.

I honestly can’t tell if this is an honest comment, or a dark ironic reference to Trump, Brexit or current Italian politics.

https://en.wikipedia.org/wiki/Poe%27s_law

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#42
post #31

Earlier quoted context omitted.

Well, if it comes to it, we could always choose to just blacklist all Australian devs from writing software.

Which is why this bill is a complete disaster for the Australian tech industry. Every single software company in Australia just became blackmarked and could be "potentially compromised" by the government and whoever has figured out the governments likely hamfisted and boutique backdoor solutions. Even someone's little SaaS can be asked to turn up dirt on someone. I literally couldn't comply. I don't write encryption…

> I literally couldn't comply. I don't write encryption algorithms for a living I just build websites.

I don't think you'd have to "break encryption" or do anything advanced, the main thing they're looking to ask is to circumvent encryption. For example sending the plaintext password for a specific user from the login form, or OS backdoor, etc., delivered through a special software update just for that user. Additionally the wording of the law does not allow for an inability for you to do it, I believe you would be compelled to hire someone that can.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#43
post #4

Do we trust Intel chips are free from gov backdoors? Or that Microsoft/FB arent in bed with the NSA? I would say the precedent has long since been set.

If intel does have a backdoor, would you think they were compelled to include it against their will by government, or that they willfully included it for their own use?

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#44
post #17
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

I am really not trying to be an alarmist but couldn't one be extradited to Australia for not complying?

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#45

Earlier quoted context omitted.

It’s not the same thing. Don’t know Australian law, but for a warrant you need to demonstrate probable cause in front of a judge. And that’s a pretty high bar.

The problem is that if a back door exists for government, it necessarily exists for anyone. Here’s Tim Cook making that point: https://m.youtube.com/watch?v=rQebmygKq7A

We aren't talking of back doors here.

With an email provider you don't need a back door to get somebody's emails.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#46
post #44
post #17

Earlier quoted context omitted.

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

I am really not trying to be an alarmist but couldn't one be extradited to Australia for not complying?

Definitely not in the case of the US. For other developed, liberal democracies, it'd be similarly very unlikely. It'd be equivalent to allowing China (or Turkey, etc) to extradite a citizen over speech that offends said foreign government.

The US is particularly aggressive about not ceding legal / constitutional sovereignty to other nations or entities.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#48
post #31

Earlier quoted context omitted.

Which is why this bill is a complete disaster for the Australian tech industry. Every single software company in Australia just became blackmarked and could be "potentially compromised" by the government and whoever has figured out the governments likely hamfisted and boutique backdoor solutions. Even someone's little SaaS can be asked to turn up dirt on someone. I literally couldn't comply. I don't write encryption…

> I literally couldn't comply. I don't write encryption algorithms for a living I just build websites. I don't think you'd have to "break encryption" or do anything advanced, the main thing they're looking to ask is to circumvent encryption. For example sending the plaintext password for a specific user from the login form, or OS backdoor, etc., delivered through a special software update just for that user. Addition…

I believe you are right. What an insane proposition though.

How do you advertise for the position? Lie about the job and then once they are on board the government hits them with the no-tell paperwork? What a shitty person I would have to become to make that happen, and I would have no choice at that point.

Perhaps they would have a saboteur on staff they would be willing to lend. Very hard position to hire for, no doubt.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#49
post #17

Earlier quoted context omitted.

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

The demand would come directly from the US government, after it passes the same law in five years. You do realize this is ultimately FVEY doing a trial in Australia, yes?

You could say that about any bad bill passed in any of the five eyes at any point in the past. The reality is, that's not how things work.

For example, in Britain you can be arrested for modestly offending someone on Twitter, due to their speech crime laws.[1] That's never going to commonly be the case in the US due to very strong speech protections.

Australia did away with its guns. The US is never going to follow that example. Australia's actions were not a trial for what would happen in the US.

The large counter examples to your premise are numerous.

[1] https://www.independent.co.uk/news/uk/arrests-for-offensive-...

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#50
post #30

Earlier quoted context omitted.

This doesn't seem very meaningful? I live in the US. How very Ameri-centric?

That wasn’t their point. These are global services and many of them are written and controlled by people who aren’t under the authority of Australian law.

I don't really follow these things much but isn't Julian Assange wanted for breaking American law while not under its authority? Wouldn't America need reciprocal deals?
Post reply on HN