Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

51–60 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#51
post #30
post #17

Earlier quoted context omitted.

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

This doesn't seem very meaningful? I live in the US. How very Ameri-centric?

"Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith."

https://news.ycombinator.com/newsguidelines.html

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#52
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

Personally I've been reading the text and trying to grasp the implications of this.

There appears to be two limitations on this power: 1. You cannot be compelled to do something in a foreign country that would be a crime in that country 2. In issuing the notice the relevant oversight authority must give weight to your 'legitimate' interests.

I think 1 is a huge point as it effectively constrains the jurisdiction of the law to Australia.

However, there is still significant ambiguity. For example, can I be compelled to commit a crime against a foreign country while in Australia, if I have a legitimate interest in not committing a crime against that country?

Would a company's legitimate interest in not compromising customer trust (more than the existence of this legislation doesn't already), act as a significant constraint on the issuing of TANs/TCNs?

There's also ambiguity as to whether I can reveal the existence of a TAN/TCN to my employer. The law makes certain exceptions, including the ability to publish the aggregate total of TAN/TCN received in a 6 month period and seek legal advice. So in order to seek legal advice or reasonably execute a TAN/TCN can I let my employer know?

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#53

Earlier quoted context omitted.

The demand would come directly from the US government, after it passes the same law in five years. You do realize this is ultimately FVEY doing a trial in Australia, yes?

You could say that about any bad bill passed in any of the five eyes at any point in the past. The reality is, that's not how things work. For example, in Britain you can be arrested for modestly offending someone on Twitter, due to their speech crime laws.[1] That's never going to commonly be the case in the US due to very strong speech protections. Australia did away with its guns. The US is never going to follow t…

Neither of the examples you gave have anything to do with signals intelligence.

But yes, FVEY isn't an overarching conspiracy that implements all digital authoritarianism, nor does it have a monopoly on promulgating such corruption - I doubt FVEY itself coordinated the attack on Kim Dotcom. Nor is it the only such conspiracy - Sweden isn't part of FVEY yet eagerly went after TPB and Assange.

But pointing to such agreements is a good analogy for the similar ratcheting totalitarian trends we observe across countries - how intertwined the governments are, and how willingly they give up their citizen-subjects to each other. This is the larger issue - regardless of the actual mechanics of pollination, we can be sure that after the bugs have been worked out in Australia, we'll be staring down the same exact bullshit in the US.

(And I do apologize for blowing up a thread about Australia with US centrism. The point is that we, the people, are ultimately all in this together. Looking to US-exceptionalism as a reason to write off what's happening in Australia as their own problem is a broken outlook)

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#54
post #8

I am particularly concerned how this will affect Fastmail, an Australian company. I've hosted my mail there since 2002 and they've always been quite pro-privacy. But I fear that such a stance is now literally impossible for any Australian company.

TCNs (which is the primary thing this article is about) won't practically affect email providers, because email providers already have your plaintext emails -- they don't need to implement new capabilities to intercept them. (As an aside, I use Mailbox.org which has a feature to auto-encrypt incoming emails to a PGP public key -- which means that only new emails would be usable with interception.) However there is no…

I think that section 317ZH specifies that a TAN/TRN/TCN is invalid if a warrant would be required to access the information.

Specifically:

A technical assistance request that relates to an agency, or a technical assistance notice that relates to an agency, or a technical capability notice that relates to an agency, has no effect to the extent (if any) to which it would request or require a designated communications provider to do an act or thing for which the agency, or an officer of the agency, would be required to have or obtain a warrant or authorisation under any of the following laws:

                     (a)  the Telecommunications (Interception and Access) Act 1979 ;

                     (b)  the Surveillance Devices Act 2004 ;

                     (c)  the Crimes Act 1914 ;

                     (d)  the Australian Security Intelligence Organisation Act 1979 ;

                      (f)  a law of the Commonwealth (other than this Part) that is not covered by paragraph (a), (b), (c) or (d);

                     (g)  a law of a State or Territory.*

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#56

Earlier quoted context omitted.

You could say that about any bad bill passed in any of the five eyes at any point in the past. The reality is, that's not how things work. For example, in Britain you can be arrested for modestly offending someone on Twitter, due to their speech crime laws.[1] That's never going to commonly be the case in the US due to very strong speech protections. Australia did away with its guns. The US is never going to follow t…

Neither of the examples you gave have anything to do with signals intelligence. But yes, FVEY isn't an overarching conspiracy that implements all digital authoritarianism, nor does it have a monopoly on promulgating such corruption - I doubt FVEY itself coordinated the attack on Kim Dotcom. Nor is it the only such conspiracy - Sweden isn't part of FVEY yet eagerly went after TPB and Assange. But pointing to such agre…

> Looking to US-exceptionalism

That's funny, the only exceptionalism I feel we've exhibited for a while is our exceptional ability to bury our heads in the sand and deny the existence of all the inconvenient problems we have to address in the future. :/

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#57
post #44
post #17

Earlier quoted context omitted.

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

I am really not trying to be an alarmist but couldn't one be extradited to Australia for not complying?

Non-compliance with a TAN/TCN is a civil mater and the law explicitly states that being required to do an act or thing in a foreign jurisdiction that would contravene the laws of that jurisdiction is a defence for non-compliance.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#58
post #31

Earlier quoted context omitted.

Well, if it comes to it, we could always choose to just blacklist all Australian devs from writing software.

Which is why this bill is a complete disaster for the Australian tech industry. Every single software company in Australia just became blackmarked and could be "potentially compromised" by the government and whoever has figured out the governments likely hamfisted and boutique backdoor solutions. Even someone's little SaaS can be asked to turn up dirt on someone. I literally couldn't comply. I don't write encryption…

Do we know of any organised groups who are opposing this? Both of our main political parties are in bed with this disaster so we can’t leave it to the opposition.

You’re clearly smart and lucid. Me perhaps less so but I have some spare time. Who else? Where are they gathering? What can I do?

I’m talking basic communications and publicity stuff, not anything anarchistic. Helping non-tech journalists. Writing articles to help the public understand this stuff. Lobbying MPs.

Maybe I just found a way to keep myself busy...

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#59
For free software, I wonder if reproducible builds plus a "certificate transparency"-style check in the updater (only allow an update once several build servers, preferentially located in separate jurisdictions, have validated the build and published the corresponding source code) could help. That is, make it impossible to push a backdoor to a single user without making it public to everyone. Making updates anonymous (that is, never sending any ID which could be used to target an update to a specific user) might also help.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#60

I am particularly concerned how this will affect Fastmail, an Australian company. I've hosted my mail there since 2002 and they've always been quite pro-privacy. But I fear that such a stance is now literally impossible for any Australian company.

Aww man. I've been a super happy user as well for quite some time. What should a privacy concerned customer do?
Post reply on HN