Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

211–220 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#211

Earlier quoted context omitted.

For large oss projects, accept PRs from those contributers, and outright tell the Australian government to go fuck themselves. They have zero recourse.

I think they were trying to say "how do I know the Australians submitting PRs aren't secretly working for the govt?" Of course this raises (but does not beg) the question, "how do I ever know anybody submitting PRs isn't trying to sabatoge me?" You just have to judge people by their fruits and hope they do the right thing or stop associating with Australians at all.

>or stop associating with Australians at all.

As an Australian, I hope people do this.

Internationally speaking, the tech community is not very good at drawing lines in the sand, we tend to want to please everyone.

I was really hoping that when it was shown how much the US was spying on traffic crossing it's borders, other countries would modify their routes to ensure their nations data didn't transit the US unless it was terminating there, but nope, didn't happen. Brazil talked about it but didn't do it.

Anyway, this is another rubicon moment. If we don't make this explode in the Australian governments face, then the US and UK will follow suit after the testing period is over. It's really important for the international software community to reject this utterly.

Start pulling out of Australia now and make it painful, or this will happen in countries it's impossible for you to pull out of.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#212
post #148

Earlier quoted context omitted.

> I'm considering giving up my Australian citizenship over this Then you never should have had it in the first place.

That crosses into incivility and you can't post like that here. More importantly, it looks like you've been using HN primarily for political and ideological arguments. That's an abuse of this site, because it destroys the intellectual curiosity that it exists for. So we ban accounts that do this. If you'd please review https://news.ycombinator.com/newsguidelines.html and use HN as intended from now on, we'd appreciat…

As a random HN reader, I just want to thank you for being our adult supervision.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#213

(essentially repeating a recent twitter thread here) Imagine you work in a modern software house and you get one of these ... and here I mean you, not your boss, not your coworkers, the govt knocks on your door and demands you put a back door in the thing you are working on at work ... So you write the code ... how do you write the unit test? how do you get it past the code review? the mandatory QA tests? ... all the…

There's another, perhaps more insidious perspective, on this.

After the emergence of these type of laws there's going to be potential backdoors explained away with "sorry, can't tell, wink wink" and nobody will ever know for sure. What's an employer to do? Or even end users?

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#214
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

(And the fact that only 2 MPs voted against it tells me there's almost certainly some back-door dealings that resulted in this bill being passed.)

Not really, that's just a consequence of the Australian Parliament's history of very strong party discipline. It is highly unusual for all the members of a parliamentary party not to vote the same way on a bill.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#217
post #138

Imagine you run a secure webmail provider where all data is truly encrypted and served up to the user that decrypts it using a 3rd party javascript library that isn't even hosted on your site. Based on the wording of this they could compel you to target that user and serve up a javascript decryption library of the governments choice. In a similar vein they could compel Android/MS/IOS system updates to include trojans…

Hasn't the FBI already done this years ago?

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#218
How about we take a bigger-picture view than the implementation flaws of this super-rushed law and ask what is to be done about encrypted messages that allow many serious criminals to circumvent traditional police powers of search & surveillance? I think society as a whole will not accept criminals having such an advantage. So I think alternative laws have to be suggested & promoted, otherwise potentially really bad ones are likely to get passed everywhere..

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#219
post #206

(essentially repeating a recent twitter thread here) Imagine you work in a modern software house and you get one of these ... and here I mean you, not your boss, not your coworkers, the govt knocks on your door and demands you put a back door in the thing you are working on at work ... So you write the code ... how do you write the unit test? how do you get it past the code review? the mandatory QA tests? ... all the…

Here's what I would do: send it back to them and tell them to send it to my employer's legal department.

This might not be legal, and is one of the large problems that needs to be resolved. You individually are listed in this law as a "designated service provider", and thus you can't really pass the buck to your employer.

There is a valid question as to whether you are listed as a "designated service provider" if the only time you ever developed the relevant software under s317C(6) was as part of a job. But software developers that have done free software work outside of their job definitely would be counted.

As always, I would suggest you get legal council before doing anything in response to a notice -- even throwing it back in the face of the AG.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#220
post #157
post #149

Earlier quoted context omitted.

Does that have much to do with the matter at hand?

"The jurisdiction of the court is largely granted by statute" is not an entirely accurate statement (though there are restrictions on what you can sue the Commonwealth for) . That was my point.

There are actually significant areas that are excluded from judicial review. https://www.alrc.gov.au/publications/laws-restrict-access-co...
Post reply on HN