Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

261–265 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#261
post #168
post #153

Earlier quoted context omitted.

Yes, I am fairly sure. > Circumventing an electronic protection > Unauthorised access The company providing the protection cannot by definition circumvent it or be unauthorized. If a third party decides to deliver a payload to your browser to discover your Facebook password, then they are violating the DMCS in the US. But if Facebook decides to deliver a payload to your browser to discover your Facebook password that…

I'm obviously not an expert on US law but I find it very hard to believe that it is legal for an employee of a US company, without the permission of that company to put up a fake login page for particular users and then provide that information to a foreign government. Now if the TAN/TCN was issued to a US based company that would be a different issue but then you as an individual would not be in violation of it. Not…

It is not legal. It would break so many laws that a prosecutor would have a difficult time sorting through them all.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#262
post #94

Earlier quoted context omitted.

I was worried about this as well which is why I read the law and commented above. The short answer is: 1. Non-compliance with a TAN/TCN is a civil not a criminal mater 2. As I stated above the law clearly says that it is a defence for non-compliance if a TAN/TCN would compel you to commit a crime in a foreign country. The issue is whether you can be compelled to commit an act in Australia, which would be a crime in a…

It seems like the fine for noncompliance for an individual is 238 "penalty units", which currently corresponds to nearly $50,000 (Australian), unless I misunderstand things. A $50,000 fine is quite serious even for a well-paid software engineer. I agree that a lot of people seem to be catastrophizing this, but it still seems like a pretty big mess. If I end up writing a little library and it gets popular, who's to sa…

Dumb idea here: Can you make a "not for use in Australia" license on free software and then claim that any Australian users are not your responsibility?

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#263
Creating and maintaining a large software project that "features" differing crypto strength depending on the country it's being shipped to is a HUGE PAIN IN THE ASS! I know because this was something I did for the Solaris implementation of Kerberos. What an excellent way to introduce bugs that never get tested. Crypto/security is hard enough to get right without added complications like this.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#265
post #52

Earlier quoted context omitted.

Personally I've been reading the text and trying to grasp the implications of this. There appears to be two limitations on this power: 1. You cannot be compelled to do something in a foreign country that would be a crime in that country 2. In issuing the notice the relevant oversight authority must give weight to your 'legitimate' interests. I think 1 is a huge point as it effectively constrains the jurisdiction of t…

I'm an Australian software developer, living in Europe and working for a European company (Austria) which has an Australian partner developing software for use in both the Australian and European markets. Can the Australian government compel me to sabotage the Australian software for their uses within Australia, and if so, can the Austrian government charge me with a crime for having done it while living in Austria?…

>Can the Australian government compel me to sabotage the Australian software for their uses within Australia, and if so, can the Austrian government charge me with a crime for having done it while living in Austria?

I know less about the law than other posters, but I don't think there's much of an inference in the legislation of these notices being contingent on nationality or citizenship when you're overseas. If the bill transcends borders like that then there's surely no end. Seeing as it's as broad a net as "software serving end users in Australia", it could literally affect millions of people/nationals/workers outside Aus borders, and have catastrophic economic consequences at which point the whole insane thing unravels and the absurdity of it becomes clear.

But yeah, you and me both man, as soon as I'm able I'll try and fall on my dual citizenship, if it's not too late by then. This is infuriating both in terms of ethics and logistics

Post reply on HN