Live data from Hacker News

Microsoft says encryption laws make companies wary of storing data in Australia

abc.net.au

171–180 of 294 posts

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#171
post #70

Earlier quoted context omitted.

I believe that is an incorrect interpretation of the law. The govt can compell an entity to assist in making encrypted information available. But the entity in question is not the individual employee, but the company who owns the product or service. If you're under the employment (i.e., not a contractor), you can't be an entity, and the employer will definitely know if they've been compelled. But I do agree the law i…

What if the entity is, say, an independent contractor, staffing agency, or consultancy that provides engineering support to Apple?

i believe an independent contractor is considered a service provider, and so they could be compelled to provide the gov't assistance.

I also believe that these service provider(s) are required to not disclose the fact they've provided assistance. Therefore, apple would do well to not hire any australian company for their contracting purposes (but instead, employ them as an employee).

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#172

Earlier quoted context omitted.

> We've also been around for longer than anyone else with a modern democracy No, we haven't. In fact, we copied it largely from the UK. (We didn't like the fact that as a colony we didn't get representation in the national legislature or the full range of rights citizens in the UK itself had, but, hey, the US does the same thing. Initially, and still partially, even to it's capital district . We've got the oldest sur…

The US has a very different system in a lot of ways. The UK doesn't have a formal constitution, its executive is subject to the legislature in a way it isn't in the US, one house, etc. The UK is a parliamentary democracy and the US is a republic. Also, the UK wasn't a democracy in any meaningful sense in 1776. The History Of Parliament Online is a very useful resource ( https://www.historyofparliamentonline.org/resea…

> Also, the UK wasn't a democracy in any meaningful sense in 1776

And the U.S. was? Much like the UK, the franchise was reserved to a subset of land freeholders. Only about 10-20% of the US population was eligible to vote. (http://www.crf-usa.org/bill-of-rights-in-action/bria-8-1-b-w...)

The UK did and still does have a written constitution, it's just not entirely written, and what's written is spread across multiple documents--the Magna Carta being one of the obvious ones. The US is not that different. Much of the US Constitution, especially the Bill of Rights, was copied verbatim from the written parts of the English constitution. And even conservative American jurists who reject Substantive Due Process regularly recognize unwritten constitutional rules and norms, especially those deriving from English constitutional norms.

Aside from federalism (where states maintained some sovereignty), the most fundamental constitutional differences between the US and the UK relate to judicial review and parliamentary supremacy. But it didn't become clear until 1803 in Marbury v. Madison that the US would follow a different path. If Congress was the final arbiter of legislative constitutionality (as many believed in 1789, and some conservatives argue to this day), there would be little if any functional difference between the US and UK constitutional systems. Indeed, now that US Senators are directly elected, but for Marbury v Madison even federalism would be little different than UK's so-called devolution. Japan nominally has judicial review, but their supreme court has zero inclination to strike down legislation so in practice the Japanese legislature has similar constitutional powers as the UK parliament.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#173
post #70

Earlier quoted context omitted.

I believe that is an incorrect interpretation of the law. The govt can compell an entity to assist in making encrypted information available. But the entity in question is not the individual employee, but the company who owns the product or service. If you're under the employment (i.e., not a contractor), you can't be an entity, and the employer will definitely know if they've been compelled. But I do agree the law i…

You are making the incorrect assumption that the people writing these laws are not idiots. They don't understand the technology. They don't listen to any of the people who advise them about this technology. They seem only to be listening to the police and other law enforcement crying about "paedophiles and terrorists GOING DARK". The Prime Minister at the time claimed the laws of Australia overrode the laws of mathem…

THe law provides a specific provision to say that there are limitations to what the assistance can be:

> 317ZG Designated communications provider must not be required

> to implement or build a systemic weakness or systemic

> vulnerability etc.

But the issue here is whether it's possible to perform the required "assistance" but not introduce systemic weakness or systemic vulnerability. I think it's a logical contradiction, so the law is pretty damn stupid...

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#174
post #30

I have migrated to Australia many years ago and I have recently become eligible to become a citizen. However I’ve heard stories of tech companies refusing to hire Australians because of the AA Bill, so I’m holding it off for now. The problem seems to be the provision that a tech worker can be coerced by the Australian Government into creating a backdoor, and they are not authorised to disclose it to their employer. I…

Do you mean tech companies in Australia refusing to hire Australian citizens? Or foreign companies? Because the first is very illegal.

If your home country allows dual citizenship, it doesn't seem like a problem for getting a job outside Australia. If it's not a government job where they'll do security checks, just don't disclose your dual citizenship. I hold dual citizenship, and not that my company has asked or would ask me if I am, I could easily say that I'm not and there isn't a lot they can do. Even governments struggle to determine if someone is a citizen of a foreign country, as we discovered with the dual citizenship debacle in parliament.

If your home country doesn't allow dual citizenship, depending on the risk you're willing to take, you can still become a dual citizen and not notify your home country.

Either way, the benefits of being legally entitled to live in Australia for eternity, as well as the right to participate in the democratic process, outweigh any potential downsides to becoming an Australian citizen, although I've still for a few more years to wait for that.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#175
post #4

That's one of the biggest things that lawmakers here couldn't seem to understand - tech companies have high mobility across borders. Even if a law has no teeth, why would Microsoft store data in Australia when the next country over can still serve data for the region? It just creates too much risk, from a privacy and PR standpoint. Startups will be more adverse to founding in Australia as well. It just creates a blac…

My understanding of the law is that the Australian government can demand assistance from Microsoft as long as Microsoft provides services to Australians. The location of the data is actually irrelevant.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#176
post #167

Earlier quoted context omitted.

IANAL, but sadly, the law does seem to target people rather than (or in addition to) corporations. https://parlinfo.aph.gov.au/parlInfo/download/legislation/bi... > 317C: > For the purposes of this Part, the following table defines: > (a) designated communications provider; > (b) the eligible activitiesof a designated communications provider > A person is a designated communications provider if... ... Actually, there…

in the definition part of the law: > contracted service provider, in relation to a designated > communications provider, means a person who performs services > for or on behalf of the provider, but does not include a person who > performs such services in the capacity of an employee of the > provider. The statute here is always talking about a contracted service provider who has to comply with the compelled "assistan…

I'm certainly not a lawyer, so absolutely may have misinterpreted.

However, what I've quoted above is referring to the definition for a designated communications provider, as opposed to a 'contracted service provider' - the latter of which makes sense not to include employees as they're not 'contractors'. However, technical assistance notices (which are compulsory, as opposed to 'technical assistance requests') can be served to designated communications providers, as covered by 317L.

So the fact employees aren't considered a 'contracted service provider' is therefore not relevant?

Again, just reiterating, not at all a lawyer, however at this moment in time, this is my interpretation of the legislation.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#177

Earlier quoted context omitted.

You opt into participating that process by accepting the job, though. So from Australia's perspective, the way to comply with their law is to not take such jobs, and to leave if the process changes prevent you from complying.

Unless you're an Australian lawyer I'm going to think this interpretation is a little far out by most Western legal traditions.

Can you explain why? It seems like a straightforward application of the law making some activity illegal, when its jurisdiction is explicitly defined as extending beyond the nation's borders. If you forget the border for a moment and just consider it all a single jurisdiction, aren't you basically saying that somebody can break the law and claim immunity from prosecution on the basis that their job requirements demanded that law to be broken?

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#178
post #167

Earlier quoted context omitted.

in the definition part of the law: > contracted service provider, in relation to a designated > communications provider, means a person who performs services > for or on behalf of the provider, but does not include a person who > performs such services in the capacity of an employee of the > provider. The statute here is always talking about a contracted service provider who has to comply with the compelled "assistan…

I'm certainly not a lawyer, so absolutely may have misinterpreted. However, what I've quoted above is referring to the definition for a designated communications provider , as opposed to a 'contracted service provider' - the latter of which makes sense not to include employees as they're not 'contractors'. However, technical assistance notices (which are compulsory, as opposed to 'technical assistance requests ') can…

It is completely relevant, since the OP mentions that you as an australian working for a company could be compelled directly as a communications provider.

I'm saying that if you are in the employ of a communications provider or a contracted service provider, you do not have to worry about being compelled directly. I take "the person" to mean an actual person, or a legal person, but the employee of the communications provider is not a person (IANAL, so don't use me as legal advice).

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#179

Earlier quoted context omitted.

Oh, and it's probably worth noting that you need not even be an Australian citizen to be covered, you simply need to have users in Australia. Of course, whether Australia can enforce these laws against non-citizens is another matter. However, this legislation was specifically put together with co-operation of all members of the five eyes, so there's a reasonable possibility of extradition. The Department of Home Affa…

>However, this legislation was specifically put together with co-operation of all members of the five eyes, so there's a reasonable possibility of extradition. The Department of Home Affairs even made a public statement confirming as much. It seems to have since been pulled from their website, but is available at: [PDF link] I read the PDF and didn't notice any mention of extradition. Am I missing something?

Don't know anything about extradition but the law specifically mentions putting in backdoors to aid foreign nations at their request.

It also notes that this can be for economic espionage too and isn't limited to national security (for the people who like to pretend that's not what their intelligence agencies are doing)

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#180

Earlier quoted context omitted.

There's so much ambiguity in this, though. Can't the complying Australian employee simply nudge his/her coworker and say "hey, patch this later" and then it's just a game of back and forth with the Australian government not having their way in the end?

I've had long discussions with techie friends about this, and none of us can see a way that the government could actually force a dev to do anything in a way that doesn't immediately tip off the rest of the team. I mean, your code is stored in a shared repo, right? So pushing a commit with the government-mandated changes to the shared repo is "informing others". But not pushing it means it'll never get to Prod. Most…

Really? It took me about 10 seconds to come up with this: "Hey tech dude, we need a version of iOS that unlocks the encryption on this device. Be a good boy and send us an IPSW that we can install on this nasty person's phone will you?"

You don't need to release it to the public. Build it on your local device and hand it to them. Nobody needs to know.

Post reply on HN