Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

181–190 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#182

Earlier quoted context omitted.

Actually they voted on the promise from the Libs that the amendments they proposed would be revisited in 2019, just to make Australia safe over Christmas. Which is somehow even more boneheaded than unanimously agreeing. https://www.abc.net.au/news/2018-12-07/bill-shorten-says-con...

Except the law doesn't kick in until the New Year.

No, it got royal ascent yesterday. It’s now law.

The actual implementation of any capabilities though would take months even if they started requesting them tomorrow.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#183
post #172

Earlier quoted context omitted.

What proportionality test? Lets go with how the law is actually written. Say they decide hn is a den for hackers. I mean, it's right there in the name! Hacking attracts a >3yr sentence - hence, we need the data of all hn users, they're all potential hackers!

The bill states: The Director General of Security or the chief officer of an interception agency must not give a technical assistance notice to a designated communications provider unless the Director General of Security or the chief officer, as the case requires, is satisfied that: (a) the requirements imposed by the notice are reasonable and proportionate; and (b) compliance with the notice is: (i) practicable; and…

Just to add to this, it is also a requirement to give consideration to the privacy expectations of the Australian community and the legitimate interests of the communications provider.

However, there is no guidelines on how these judgements should be made and what is / isn't acceptable. Effectively it will be left to the courts to decide through legal disputes.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#184

(essentially repeating a recent twitter thread here) Imagine you work in a modern software house and you get one of these ... and here I mean you, not your boss, not your coworkers, the govt knocks on your door and demands you put a back door in the thing you are working on at work ... So you write the code ... how do you write the unit test? how do you get it past the code review? the mandatory QA tests? ... all the…

For large oss projects, accept PRs from those contributers, and outright tell the Australian government to go fuck themselves. They have zero recourse.

I think they were trying to say "how do I know the Australians submitting PRs aren't secretly working for the govt?" Of course this raises (but does not beg) the question, "how do I ever know anybody submitting PRs isn't trying to sabatoge me?"

You just have to judge people by their fruits and hope they do the right thing or stop associating with Australians at all.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#185
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

If you think that this is a new thing, I recommend reading James Bamford's books about the NSA and its predecessors. It was not uncommon for technical staff to discreetly provide data to government intelligence agencies. Back in the telegraph days, that meant shlepping rolls of paper tape. Later, magnetic wire and tape. And this was often done without management knowledge. Because, you know, these were patriotic guys.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#186

Earlier quoted context omitted.

This is increasingly not true. SMTP-over-TLS is now the standard, and unless you are trying to imply that TLS is broken, email is far more secure than it used to be.

If it's not end-to-end encrypted, it's not secure in the sense OP clearly means.

Correct: if either mail server is compromised by the government then it may as well be plaintext.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#187
post #151

Earlier quoted context omitted.

Well, I'm working on software systems that are precisely the sort of thing that the Australian government will target with this law (transportation systems), and it is highly likely that these systems will be targeted with a TAN/TCN. In fact, I'm pretty sure that the software segment that I currently work on is going to be hit by this law, and hard, within the next year or so. If I don't get a TAN/TCN request, I'm al…

Now would be a good time to protest this by systematically denying Peter Dutton and the rest of these wankers access to any online service. Sorry, due to your part in voting for that bill, you're now in breach of our terms. Please return your devices as well.

But what would you deny? All .gov.au? All .au? Maybe a BGP suitable leak? Whatever, it wouldn't last.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#188
post #144

Earlier quoted context omitted.

Pretty simple: there are countries where these activities are highly illegal. I'll become a citizen of one of them instead.

As I said before: it is a defence for non-compliance if a TAN/TCN would compel you to commit a crime in a foreign country That has nothing to do with whether you are an Australian citizen or not. If you are a resident in Austria, these laws do not allow the government to compel you to commit a crime in Austria.

But they can compel my colleagues in Australia to do it, and that is still too close to the tyranny to me.

Keep this in mind: The Australian government is still ripping children from their parents.

If software that I am involved in is in any way responsible for assisting that, in any way, I would be more than furious to say the least.

Nope, its Option #2 for me. Australia can go to hell.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#189

Earlier quoted context omitted.

For large oss projects, accept PRs from those contributers, and outright tell the Australian government to go fuck themselves. They have zero recourse.

I think they were trying to say "how do I know the Australians submitting PRs aren't secretly working for the govt?" Of course this raises (but does not beg) the question, "how do I ever know anybody submitting PRs isn't trying to sabatoge me?" You just have to judge people by their fruits and hope they do the right thing or stop associating with Australians at all.

The problem is that Aussie contributors of good character may find themselves forced by their government to sabotage a project they are working on - I think at the very least we have to check their work closely

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#190
post #148

Earlier quoted context omitted.

> I'm considering giving up my Australian citizenship over this Then you never should have had it in the first place.

That crosses into incivility and you can't post like that here. More importantly, it looks like you've been using HN primarily for political and ideological arguments. That's an abuse of this site, because it destroys the intellectual curiosity that it exists for. So we ban accounts that do this. If you'd please review https://news.ycombinator.com/newsguidelines.html and use HN as intended from now on, we'd appreciat…

Thank you for this.

I've been subject to these site rules myself, and felt my ire rise when it happens that I've been on the wrong side of them (with political discussions), but this particular response absolutely infuriated me and I am grateful for the rules being applied in my favour, for once.

Post reply on HN