Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

71–80 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#71
post #17
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

Yeah, just remember not to go to Australia on holiday. It's more of an issue for companies that have a business presence in Australia, the usual suspects that sell proprietary software or advertising there. It also makes it hard to trust software developed in Australia.

Perhaps people outside Australia should also be wary of software from companies that do business in Australia, if there's any reason to think that the Australian government may want your data.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#73
post #31

Earlier quoted context omitted.

Well, if it comes to it, we could always choose to just blacklist all Australian devs from writing software.

Which is why this bill is a complete disaster for the Australian tech industry. Every single software company in Australia just became blackmarked and could be "potentially compromised" by the government and whoever has figured out the governments likely hamfisted and boutique backdoor solutions. Even someone's little SaaS can be asked to turn up dirt on someone. I literally couldn't comply. I don't write encryption…

> It took longer than expected, but the governments have finally decided it's time to ruin the internet. I am going to go be a carpenter or something.

Honestly, not bad advice.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#74

Earlier quoted context omitted.

Plus Australia is not part of the EU.

And? Any service that serves European customers needs to adhere to the GDPR.

It's possibly a good commercial decision given the size of the EU market, but a lot of people seem a bit delusional as to how much of an authority the EU is. They can't compel people outside their jurisdiction with the GDPR, anymore than Australia can with this law.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#75
post #48

Earlier quoted context omitted.

> I literally couldn't comply. I don't write encryption algorithms for a living I just build websites. I don't think you'd have to "break encryption" or do anything advanced, the main thing they're looking to ask is to circumvent encryption. For example sending the plaintext password for a specific user from the login form, or OS backdoor, etc., delivered through a special software update just for that user. Addition…

I believe you are right. What an insane proposition though. How do you advertise for the position? Lie about the job and then once they are on board the government hits them with the no-tell paperwork? What a shitty person I would have to become to make that happen, and I would have no choice at that point. Perhaps they would have a saboteur on staff they would be willing to lend. Very hard position to hire for, no d…

Yeah, and I guess most contractors would refuse to have anything to do with the project once they found out what was involved.

Actually I'm not sure you could hire a contractor, since you'd probably be under a secrecy constraint and wouldn't be able to tell them what needed to be done.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#76
post #57
post #44

Earlier quoted context omitted.

I am really not trying to be an alarmist but couldn't one be extradited to Australia for not complying?

Non-compliance with a TAN/TCN is a civil mater and the law explicitly states that being required to do an act or thing in a foreign jurisdiction that would contravene the laws of that jurisdiction is a defence for non-compliance.

> being required to do an act or thing in a foreign jurisdiction that would contravene the laws of that jurisdiction is a defense for non-compliance

There is no law in the US prohibiting me from creating an alternate login screen for one particular customer just in order to capture their login password. So as a US citizen I have no defense within Australian law against an Australian demand that I capture the password of one of my users... perhaps a parliament member of the Australian opposition.

I can choose to simply ignore the demand. The US will not extradite me for violating a foreign law that does not have an equivalent in US law. But I suppose I can never go on vacation to Australia.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#77
post #72

Apple should suspend selling any products into Australia and announce layoffs of all Australian employees for the day before the law goes into effect. The Australian market is small enough to make a stand without impacting the bottom line.

If only they did that. That would definitely have an impact. More non tech people will wake up and start asking questions locally in Oz. At the same time, Apple will show that they are really after people's privacy.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#78
post #66

What problem does Australia have that could possibly justify this? Gangs in Sidney? Drug traffickers from New Zealand? Terrorists from Vietnam?

Crime is pretty low in Australia, but that doesn't stop political parties trying to whip up paranoia about it to help their election chances.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#79
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

> only 2 MPs voted against it Have you got a source for this? I read (can’t remebemer where, sorry) that most Greens senators voted against it. From memory, Di Natali and SHY were in the list. The legislation was waved-through by Labor because there is an election coming up and they were afraid to be labelled as pro terrorists and child molesters. This site has sources: https://alp.fail

MP's are different from senators. MP's are in the house while senators are in the senate.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#80

Earlier quoted context omitted.

And? Any service that serves European customers needs to adhere to the GDPR.

It's possibly a good commercial decision given the size of the EU market, but a lot of people seem a bit delusional as to how much of an authority the EU is. They can't compel people outside their jurisdiction with the GDPR, anymore than Australia can with this law.

Actually they can - the second you place your foot on EU (or collaborating - extradition treaties) soil, and of course if you want to do business in EU then you need to have legal presence in the EU.
Post reply on HN