Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

161–170 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#161
post #128
post #109

Earlier quoted context omitted.

> But I also know that the reality of this happening is almost vanishingly small. Why do you think it’s vanishingly small? You could somewhat trust the the current govt but you can’t trust the future. I’ve lived in Australia for a long time and the trend is clear. More surveillance is to come. Australia is very much a police state as it is.

I think it's vanishingly small because my software is pretty niche and the chance that anyone who is a target actually uses it is tiny just by pure laws of numbers. And then even if that happens they are much more likely to identify a bigger company that they can leverage before hitting me as the best vector into that person's devices. There simply isn't much value in getting my software backdoored compared to Google…

I think the govt will attack smaller companies first, the ones who don't have the means to refuse.

They'd be stupid to start with giants like Apple or Google.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#162
post #134

Earlier quoted context omitted.

Maybe something like a warrant canary makes more sense? An encryption canary? Would that even pass with the new laws though? Also you stating that you might have been forced to insert malware by the government surely breaks the rule that says you can't tell anyone too, if I'm understanding it correctly.

Warrant canaries aren't necessary (nor are they legal in Australia). The law allows you to provide aggregated statistics on how many requests you've received in a 6-month period.

Yes but a single request can include an unlimited number of targets.

They can literally ask for all communications of every one of your users.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#163
So the opposition party decided to pass this with no amendments on the understanding that it will be amended early next year. I doubt this will happen, they never go back and fix things. If they find out a piece of legislation has a loophole that is or will be abused, they never go back and fix it, it's hands up in the air - too hard.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#164

Earlier quoted context omitted.

Well, I'm working on software systems that are precisely the sort of thing that the Australian government will target with this law (transportation systems), and it is highly likely that these systems will be targeted with a TAN/TCN. In fact, I'm pretty sure that the software segment that I currently work on is going to be hit by this law, and hard, within the next year or so. If I don't get a TAN/TCN request, I'm al…

An easier option than 2 for most Australians: come help build the software industry in New Zealand. It's a 3 hour flight and requires zero paperwork for Aussies to work here (as long as you have no criminal record; so you probably can't move so easily after you disobey one of these requests...).

And hand over our phones and passwords at airport immigration and use the even worse than ours internet?

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#165
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

> I imagine it's much more likely this power will be used against a few big players (Apple, Facebook, Google)

Aussie market is not that big. Its gdp is less than a tenth of USA, smaller than Canada and a half of India. It is a good size but if a bunch of google employees stage a protest over this, google may just pull out of it because losing talent can be a bigger pain.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#166
post #94

Earlier quoted context omitted.

I'm an Australian software developer, living in Europe and working for a European company (Austria) which has an Australian partner developing software for use in both the Australian and European markets. Can the Australian government compel me to sabotage the Australian software for their uses within Australia, and if so, can the Austrian government charge me with a crime for having done it while living in Austria?…

I was worried about this as well which is why I read the law and commented above. The short answer is: 1. Non-compliance with a TAN/TCN is a civil not a criminal mater 2. As I stated above the law clearly says that it is a defence for non-compliance if a TAN/TCN would compel you to commit a crime in a foreign country. The issue is whether you can be compelled to commit an act in Australia, which would be a crime in a…

It seems like the fine for noncompliance for an individual is 238 "penalty units", which currently corresponds to nearly $50,000 (Australian), unless I misunderstand things. A $50,000 fine is quite serious even for a well-paid software engineer.

I agree that a lot of people seem to be catastrophizing this, but it still seems like a pretty big mess.

If I end up writing a little library and it gets popular, who's to say the spooks won't decide that's where they want the backdoor, and just send me a TAN to the email on my GitHub profile? Very likely not, but it is possible and would cost me at least several thousand dollars in legal bills to figure out how to respond.

Wonder if it will be possible to be insured against receiving such a request for foreigners (and maybe even Australians) who work on software that the Australian government would like to backdoor. To cover any possible fines for noncompliance but also, if you do want to use the "it's a crime in my country" defense, to deal with the complication and expense of hiring an Australian lawyer to represent you.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#167
post #24

warrant canaries, but for individuals

The law allows you to provide statistical information about how many of the relevant notices you've received within a 6-month-window. So there's no need for warrant canaries (which is a good thing, since they're not generally legal in Australia).

A single notice can request the data of every single one of your users.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#168
post #153
post #81

Earlier quoted context omitted.

Are you sure there is no law against this in the US? Isn't this potentially: 1. Circumventing an electronic protection 2. Unauthorised access (if your employer does not authorise the changes) .etc.

Yes, I am fairly sure. > Circumventing an electronic protection > Unauthorised access The company providing the protection cannot by definition circumvent it or be unauthorized. If a third party decides to deliver a payload to your browser to discover your Facebook password, then they are violating the DMCS in the US. But if Facebook decides to deliver a payload to your browser to discover your Facebook password that…

I'm obviously not an expert on US law but I find it very hard to believe that it is legal for an employee of a US company, without the permission of that company to put up a fake login page for particular users and then provide that information to a foreign government.

Now if the TAN/TCN was issued to a US based company that would be a different issue but then you as an individual would not be in violation of it.

Not that that makes it a better law, but I think for people not physically in Australia the risk of being issued an enforceable (under Australian law) TAN/TCN is quite low.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#169
post #134

Earlier quoted context omitted.

Warrant canaries aren't necessary (nor are they legal in Australia). The law allows you to provide aggregated statistics on how many requests you've received in a 6-month period.

Yes but a single request can include an unlimited number of targets. They can literally ask for all communications of every one of your users.

It would be very hard for that to pass the proportionality test in the law. I know it's tempting to go for the worst case dystopian scenarios but it's actually important not to go overboard. Politicians and other people with a say immediately stop listening once they hear that. This law is extremely problematic even with a conservative interpretation, so I think we should stick with that.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#170
post #169

Earlier quoted context omitted.

Yes but a single request can include an unlimited number of targets. They can literally ask for all communications of every one of your users.

It would be very hard for that to pass the proportionality test in the law. I know it's tempting to go for the worst case dystopian scenarios but it's actually important not to go overboard. Politicians and other people with a say immediately stop listening once they hear that. This law is extremely problematic even with a conservative interpretation, so I think we should stick with that.

What proportionality test?

Lets go with how the law is actually written.

Say they decide hn is a den for hackers. I mean, it's right there in the name!

Hacking attracts a >3yr sentence - hence, we need the data of all hn users, they're all potential hackers!

Post reply on HN