Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

231–240 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#231
post #146

Earlier quoted context omitted.

It's exceptionally sad since Australia has order of preference, instant runoff and mandatory voting. Even with all those safeguards to prevent major parties and ensure equal representation, Australia still ends up with major parties and too many people who don't bother with the bottom of the ballot.

I think this is partly the fault of how electorates work. Imagine an election where every electorate votes 30% party A, and the remaining 70% of the vote split somehow between parties B and C. Then you get only members of parties B and C in office, and so you could argue that 30% of the population is not even represented. This is not so far off what happens with the Greens - in the last federal election they had abou…

> This is not so far off what happens with the Greens - in the last federal election they had about a 15% first-preference vote across Australia, but ended up with only 1/150 seats in parliament.

As someone who has lived in the US and Australia... the difference would be that in the US, the Greens would get nothing, zero. And due to gerrymandering, it's equally likely that even without party C in play, you can and do easily get situations where 30% votes for party A but win a majority.

Even in our recent mid terms here, whilst the House went back to Democratic control, in the Senate the Republican vote went down 20% but they didn't just keep the same number of seats, they _increased_ their majority.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#232
This is what happens when policy and law makers are essentially uneducated in the modern world. A law degree does not prepare on to understand technology, medicine, or even social issues.

Government needs lawyers in the body, but if as a whole it lacks a broad education, it essentially lacks an education.

If only we elected like we hired.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#233

(essentially repeating a recent twitter thread here) Imagine you work in a modern software house and you get one of these ... and here I mean you, not your boss, not your coworkers, the govt knocks on your door and demands you put a back door in the thing you are working on at work ... So you write the code ... how do you write the unit test? how do you get it past the code review? the mandatory QA tests? ... all the…

Why would the government ping you? Your boss can set a secondary build pipeline, that merges his brunch before producing a release build. Unless your company requires repeatable builds, you'll never notice this.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#234
post #66

What problem does Australia have that could possibly justify this? Gangs in Sidney? Drug traffickers from New Zealand? Terrorists from Vietnam?

The worst problem of all, a conservative government who are about to lose an election

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#235
post #183
post #172

Earlier quoted context omitted.

The bill states: The Director General of Security or the chief officer of an interception agency must not give a technical assistance notice to a designated communications provider unless the Director General of Security or the chief officer, as the case requires, is satisfied that: (a) the requirements imposed by the notice are reasonable and proportionate; and (b) compliance with the notice is: (i) practicable; and…

Just to add to this, it is also a requirement to give consideration to the privacy expectations of the Australian community and the legitimate interests of the communications provider. However, there is no guidelines on how these judgements should be made and what is / isn't acceptable. Effectively it will be left to the courts to decide through legal disputes.

I thought that decision was made by a "retired judge" and a "technology expert". Is that correct?

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#236
post #222

I am an Australian software developer. There is no way I am putting any backdoor into any software I write and I am willing to go to jail if needed. If all us Aussie developers tell the government to go jump this stupid law will fail.

The punishment for non-compliance is civil fines, not gaol time. However I believe it's technically possible for them to push you into bankruptcy by making many requests and revoking them after you refuse them (fining for each copy of the request they resend to you).

Well then bankruptcy it will have to be if it comes to this. A mass outbreak of civil disobedience is the only way to fight this.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#237
post #172

Earlier quoted context omitted.

What proportionality test? Lets go with how the law is actually written. Say they decide hn is a den for hackers. I mean, it's right there in the name! Hacking attracts a >3yr sentence - hence, we need the data of all hn users, they're all potential hackers!

The bill states: The Director General of Security or the chief officer of an interception agency must not give a technical assistance notice to a designated communications provider unless the Director General of Security or the chief officer, as the case requires, is satisfied that: (a) the requirements imposed by the notice are reasonable and proportionate; and (b) compliance with the notice is: (i) practicable; and…

When thinking about such unprecedented powers, I prefer to consider the worst-case scenario of the laws as written, rather than what seems currently acceptable.

Because even if the current government is harmless, the next regime might not be, and these powers are basically the equivalent of a nuclear bomb with respect to privacy. They move the pendulum far away from what many would consider reasonable for a free society.

These laws just seem so rife with loopholes and ambiguities that even as an honest law-abiding citizen with nothing of interest to hide, I find them honestly terrifying.

If they're doing these things for legitimate reasons then there would be little reason to be against having reasonable limits to scope, reasonable oversight, accountability, as well as real reporting on the actual number of citizens whose data has been accessed.

The fact these concerns and all the consultation submissions from experts in both legal and technology issues have been ignored makes me strongly fear the whole law has not taken citizens right to privacy into account at all, and that is a terrifying proposition.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#238
It will be interesting when we have our first outbreak of phishing, claiming to be ASIO and demanding backdoors to all IT infrastructure.

Literally any employee would be subject to these laws. They could just quote the laws and demand that any employee installs malware or creates a backdoor admin account.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#239

Earlier quoted context omitted.

Or you could just ensure that you don't have access to production systems in your job. Which you shouldn't have as a developer anyway. And that any code you write is reviewed before it is put into production. Which it should be anyway. And if they do try it, any of your non-Australian colleagues who review your code can immediately raise the alarm. The law is ridiculous not only because of all the points they're maki…

>Or you could just ensure that you don't have access to production systems in your job. Okay, so this just pushes the problem onto someone elses plate - the operator/sysadmin. I've known a few Australian operators. The law doesn't specifically target 'only people who can write code' - it applies to anyone who has access to the systems the Australian kooks and spooks want to infiltrate.

kinda, but the important bit is that it pushes the problem onto both of them. The dev has to write the code, and then the sysadmin has to deploy it. And they have to communicate to do that. The secret is not so secret any more. By the time everyone else is involved in deploying it, testing it, paying for the extra traffic, etc... it's not a secret any more.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#240
post #73

Earlier quoted context omitted.

> It took longer than expected, but the governments have finally decided it's time to ruin the internet. I am going to go be a carpenter or something. Honestly, not bad advice.

I recently had some electrician, plumbing and gas work done and the bill was around my contractor rate here in NZ. Given the politics and bs around the big corps and govt ministries my skillsets fit into (business analyst/pm) a trade has been something I've been considering seriously for a while now. The peace of mind and lack of toxic office cultures is really appealing. They're apprenticeships too, so you're paid a…

This law is so entirely bad, it's literally making highly-paid software engineers, who are essential to our way of life, seriously consider revoking their citizenship, leaving the country, working in another field, and encouraging other countries to boycott dealing with Australia entirely.

Just thought I'd note that. This is crazy.

Post reply on HN