Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

101–110 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#101
post #60

I am particularly concerned how this will affect Fastmail, an Australian company. I've hosted my mail there since 2002 and they've always been quite pro-privacy. But I fear that such a stance is now literally impossible for any Australian company.

Aww man. I've been a super happy user as well for quite some time. What should a privacy concerned customer do?

Given that they store all of your data in plain text, probably run your own email server or use a different service. That's not really changed by this new law and was always the case.

I use fastmail as well, I like their ui a lot. I certainly treat it as the stockpile of plain text messages tied to my real life identity through my credit card that it is though.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#102
post #10

Earlier quoted context omitted.

It looks like Labor will win next election, but that really doesn't matter. Labor voted for the bill unanimously.

Shorten’s strategy to lose the battle/win the war has soured my view of him forever. He’s revealed himself to be a man of no principles.

Realistically, I don't think the majority of the Australian community is particularly aware of, let alone opposed to this legislation. The idea that law enforcement should be able to gain access to encrypted communications if they have a warrant doesn't seem particularly controversial in the wider community either.

Given this, I'd assume the law is here to stay. The question we need to ask is how can we constructively engage politicians to minimise the flaws in the law. On that front Labor has been much more open and were instrumental in addressing some of the deeper flaws in the original legislation.

So to be clear:

1. The law specifically forbids the government requiring weakening of encryption / authentication / authorisation mechanisms.

2. The law specifically forbids the government requiring systemic vulnerabilities be introduced.

3. The law defines a consultation, review and appeal process.

4. The law prevents the government requiring someone commit a crime in a foreign jurisdiction

5. The law allows publishing the number of aggregate TAN/TCN/TAR received in aggregate in a 6 month period.

The question is where should the law be fixed and how do we engage Labor / Liberals to fix those aspects.

Personally I would like to see:

1. Better protection for software exported for use outside Australia

2. Better definition of what defines a 'systemic' vulnerability

3. Greater protection for individuals. For if a TCN/TAN could be otherwise issued to a company, then the law should not allow a notice to be issued to an individual.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#103
post #17

Earlier quoted context omitted.

>This is a very wide net and immediately includes effectively every free software developer, and the employees of every tech company. This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.

Yeah, just remember not to go to Australia on holiday. It's more of an issue for companies that have a business presence in Australia, the usual suspects that sell proprietary software or advertising there. It also makes it hard to trust software developed in Australia. Perhaps people outside Australia should also be wary of software from companies that do business in Australia, if there's any reason to think that th…

That's a good point. There's no guarantee that compromised devices will stay within Australian jurisdiction. How are diplomats affected by this law?

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#104
post #52

Earlier quoted context omitted.

Personally I've been reading the text and trying to grasp the implications of this. There appears to be two limitations on this power: 1. You cannot be compelled to do something in a foreign country that would be a crime in that country 2. In issuing the notice the relevant oversight authority must give weight to your 'legitimate' interests. I think 1 is a huge point as it effectively constrains the jurisdiction of t…

I'm an Australian software developer, living in Europe and working for a European company (Austria) which has an Australian partner developing software for use in both the Australian and European markets. Can the Australian government compel me to sabotage the Australian software for their uses within Australia, and if so, can the Austrian government charge me with a crime for having done it while living in Austria?…

> I'm considering giving up my Australian citizenship over this

Then you never should have had it in the first place.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#105
post #99
post #96

Australia has an unstable federal political system, with elections every three years or less (this is baked into the constitution, so it will be hard to amend). Imagine the US House of Representatives with the equivalent of Speaker of the US House of Representatives as the Prime Minister of Australia as you won't be far off. Unlike the UK, there isn't a strong civil service, and unlike the US, the Senate, states and…

Do you live here? I do, and while tiny nuggets of truth are in individual sentence clauses, this is a very paranoid and over stated argument. We have a high court. They reverse bad federal and state laws. Lots of bad immigration decisions by ministers are being overturned. Mabo happened.

The jurisdiction of the court is largely granted by statute is it not? In fact, in the case of the bad immigration decisions you mention, the minister has tried to pass legislation to restrict judicial oversight.

EDIT: And he is also alleged to have used his already considerable discretionary powers to allow au pairs for politically connected individuals into Australia in violation of their visa conditions, with no consequences. Not exactly a ringing endorsement of the rule of law.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#106
post #94

Earlier quoted context omitted.

I'm an Australian software developer, living in Europe and working for a European company (Austria) which has an Australian partner developing software for use in both the Australian and European markets. Can the Australian government compel me to sabotage the Australian software for their uses within Australia, and if so, can the Austrian government charge me with a crime for having done it while living in Austria?…

I was worried about this as well which is why I read the law and commented above. The short answer is: 1. Non-compliance with a TAN/TCN is a civil not a criminal mater 2. As I stated above the law clearly says that it is a defence for non-compliance if a TAN/TCN would compel you to commit a crime in a foreign country. The issue is whether you can be compelled to commit an act in Australia, which would be a crime in a…

I thought a TAN/TCN also comes with a gag order.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#107
I'm grappling with what to do about this law. I develop software in Australia, for a company, separately as a private software vendor and separately again as an open source contributor. From what I can understand, this law can compel me to silently insert malware into any of these. Morally I feel like I need to modify the licenses, READMEs and terms of conditions for products I sell and the contracts under which I do commercial work to clearly state that I may at any time include malware into the software I supply, if directed to by my government.

However unlikely, the idea that I could be commandeered at any moment to betray the users of my software and ship malware to them sickens me. But I also know that the reality of this happening is almost vanishingly small. I genuinely don't know what to do.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#108
post #106
post #94

Earlier quoted context omitted.

I was worried about this as well which is why I read the law and commented above. The short answer is: 1. Non-compliance with a TAN/TCN is a civil not a criminal mater 2. As I stated above the law clearly says that it is a defence for non-compliance if a TAN/TCN would compel you to commit a crime in a foreign country. The issue is whether you can be compelled to commit an act in Australia, which would be a crime in a…

I thought a TAN/TCN also comes with a gag order.

There are exceptions to this, including for seeking legal advice.

If you think the law effects you then I highly recommend reading the entire text, as passed by parliament: https://parlinfo.aph.gov.au/parlInfo/search/display/display....

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#109
post #107

I'm grappling with what to do about this law. I develop software in Australia, for a company, separately as a private software vendor and separately again as an open source contributor. From what I can understand, this law can compel me to silently insert malware into any of these. Morally I feel like I need to modify the licenses, READMEs and terms of conditions for products I sell and the contracts under which I do…

> But I also know that the reality of this happening is almost vanishingly small.

Why do you think it’s vanishingly small?

You could somewhat trust the the current govt but you can’t trust the future. I’ve lived in Australia for a long time and the trend is clear. More surveillance is to come. Australia is very much a police state as it is.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#110
post #72

Apple should suspend selling any products into Australia and announce layoffs of all Australian employees for the day before the law goes into effect. The Australian market is small enough to make a stand without impacting the bottom line.

Layoff all Australian employees. That just looks weak.

Apple is only pro privacy when it makes them more money. They already do business in China. They have a fiduciary duty to their investors to not jump the gun like that.

Post reply on HN