Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

121–130 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#121
post #107

I'm grappling with what to do about this law. I develop software in Australia, for a company, separately as a private software vendor and separately again as an open source contributor. From what I can understand, this law can compel me to silently insert malware into any of these. Morally I feel like I need to modify the licenses, READMEs and terms of conditions for products I sell and the contracts under which I do…

Maybe something like a warrant canary makes more sense? An encryption canary? Would that even pass with the new laws though? Also you stating that you might have been forced to insert malware by the government surely breaks the rule that says you can't tell anyone too, if I'm understanding it correctly.

I think me merely stating that I am subject to the laws of my country under which an individual can be compelled to ... etc. probably isn't illegal. It may be illegal if I modify that statement after being issued with an order and directed not to reveal the existence order.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#122

Earlier quoted context omitted.

I'm an Australian privacy-obsessed Fastmail user, and use them for my family domains and all our primary email. I'll keep using them, because email isn't private in the first place. Any more than snail mail is. Both can be intercepted and read by authorities without you knowing. For secure communications, you shouldn't be using email in the first place, so these new laws don't change much in that regard (in my unders…

This is increasingly not true. SMTP-over-TLS is now the standard, and unless you are trying to imply that TLS is broken, email is far more secure than it used to be.

If it's not end-to-end encrypted, it's not secure in the sense OP clearly means.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#123
post #99

Earlier quoted context omitted.

Do you live here? I do, and while tiny nuggets of truth are in individual sentence clauses, this is a very paranoid and over stated argument. We have a high court. They reverse bad federal and state laws. Lots of bad immigration decisions by ministers are being overturned. Mabo happened.

I do and while I am happy with 3 year terms, I don't disagree with much else. We Aussies are pretty proud of the various improvements we have over the UK and US systems. Our independent electoral commissions minimise gerrymandering. Our preferential voting system ensures more accurate representation. Mandatory voter turnout has a moderating influence on political campaigning and avoids voter disenfranchisement issues…

I do live in Australia (forgot to mention that in reply to GP). The primary problem with the terms is not their length, but the fact that they give the Prime Minister inordinate power to control the timing of elections.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#124
post #83

Earlier quoted context omitted.

Shorten’s strategy to lose the battle/win the war has soured my view of him forever. He’s revealed himself to be a man of no principles.

> soured my view of him forever. He’s revealed himself to be a man of no principles. I don't have a strong opinion of Shorten one way or the other, but I've read a lot of people express a similar POV and it strikes me as extremely naive. If you went into politics with a view to die on your sword rather than compromise any of your values you'd have a very short career. Losing the battle to win the war is the only way…

> The alternative would be for every man and his dog having our corrupt media ram the "Labor has made it easier for terrorists to kill you" story down their throat for the next few months.

In some ways that would be a good thing, because it would force a public debate about warrantless surveillance at a time when relatively few people trust the LNP government or its law-and-order rhetoric.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#125
post #83

Earlier quoted context omitted.

Shorten’s strategy to lose the battle/win the war has soured my view of him forever. He’s revealed himself to be a man of no principles.

> soured my view of him forever. He’s revealed himself to be a man of no principles. I don't have a strong opinion of Shorten one way or the other, but I've read a lot of people express a similar POV and it strikes me as extremely naive. If you went into politics with a view to die on your sword rather than compromise any of your values you'd have a very short career. Losing the battle to win the war is the only way…

If you sell out your principles to get that power, what's the purpose of having it? By the time you get there, you're no better than the person you ousted.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#126
post #94

Earlier quoted context omitted.

I'm an Australian software developer, living in Europe and working for a European company (Austria) which has an Australian partner developing software for use in both the Australian and European markets. Can the Australian government compel me to sabotage the Australian software for their uses within Australia, and if so, can the Austrian government charge me with a crime for having done it while living in Austria?…

I was worried about this as well which is why I read the law and commented above. The short answer is: 1. Non-compliance with a TAN/TCN is a civil not a criminal mater 2. As I stated above the law clearly says that it is a defence for non-compliance if a TAN/TCN would compel you to commit a crime in a foreign country. The issue is whether you can be compelled to commit an act in Australia, which would be a crime in a…

Well, I'm working on software systems that are precisely the sort of thing that the Australian government will target with this law (transportation systems), and it is highly likely that these systems will be targeted with a TAN/TCN. In fact, I'm pretty sure that the software segment that I currently work on is going to be hit by this law, and hard, within the next year or so. If I don't get a TAN/TCN request, I'm almost 100% sure that someone within the group of companies I am working, will. And I want none of that.

So I feel strongly enough about the tyranny and evil of the Australian government that it looks like I'm going to be giving up my Australian citizenship.

Oh, wait:

"We will not approve your application to renounce your citizenship if you do not have another foreign citizenship or it is not in Australia’s interests." [emphasis added]

What an extraordinarily evil thing for the Australian government to have done to its citizens.

Well then, some other options:

0. Do the typical Australian thing: "she'll be right mate!", and stick my head in the sand, hoping that ignoring the bad man will make him go away. This seems to work for a lot of Australians, so might work for me. Could be, I'll never be the subject of a TAN/TCN, but then again, why risk it.

1. I could change my profession. However, this would mean that over time, only the types of people who are willing to act as repressive agents of the Australian government would be found in the software industry. This is really a non-savoury outcome, as I have over 30 years in the software industry and am very proud of the good I have done in this field - I would hate to turn it over to such cunts who think its fine to spy for the Australian Fascist Overlords. I know they're out there - people like me are keeping them from taking over, completely.

(A brief moment of brevity for the poor Australians reading this: Fuck. The Australian Government is literally Auntie Jack. If I don't do what she tells me to, she's gonna jump out of my computer and rip my bloody arms off. [1])

2. Do the paperwork: get my second citizenship, abandon the Australian citizenship, do everything I can to protest Australia and never, ever, contribute to its well-being ever again - this means never going back, removing my assets and resources from the Australian economy, and so on. Hmmm.

3. Submit to a TAN/TCN when/if it happens, but somehow sabotage the work such that it doesn't quite work out. The True Aussie Way™.

4. Insist on working only on software that never tracks the user in any way, whatsoever. This would mean quitting my current job, which already involves tracking people (with their full approval) for productive (non-espionage/law-enforcement) purposes, and finding something with a strict no-data policy.

I guess I'm gonna go with #4. Well, #2 seems a bit more appealing, actually.

Please, I beg of you .. let me walk tall in Australia! [2]

--

[1] - https://www.youtube.com/watch?v=KnEOr1MgwTM

[2] - https://youtu.be/8PfDro1UGUo?t=158

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#127
post #107

I'm grappling with what to do about this law. I develop software in Australia, for a company, separately as a private software vendor and separately again as an open source contributor. From what I can understand, this law can compel me to silently insert malware into any of these. Morally I feel like I need to modify the licenses, READMEs and terms of conditions for products I sell and the contracts under which I do…

Maybe something like a warrant canary makes more sense? An encryption canary? Would that even pass with the new laws though? Also you stating that you might have been forced to insert malware by the government surely breaks the rule that says you can't tell anyone too, if I'm understanding it correctly.

Australia has a law that specifically bans warrant canaries.

https://arstechnica.com/tech-policy/2015/03/australian-gover...

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#128
post #109
post #107

I'm grappling with what to do about this law. I develop software in Australia, for a company, separately as a private software vendor and separately again as an open source contributor. From what I can understand, this law can compel me to silently insert malware into any of these. Morally I feel like I need to modify the licenses, READMEs and terms of conditions for products I sell and the contracts under which I do…

> But I also know that the reality of this happening is almost vanishingly small. Why do you think it’s vanishingly small? You could somewhat trust the the current govt but you can’t trust the future. I’ve lived in Australia for a long time and the trend is clear. More surveillance is to come. Australia is very much a police state as it is.

I think it's vanishingly small because my software is pretty niche and the chance that anyone who is a target actually uses it is tiny just by pure laws of numbers. And then even if that happens they are much more likely to identify a bigger company that they can leverage before hitting me as the best vector into that person's devices. There simply isn't much value in getting my software backdoored compared to Google, Apple, Facebook, Microsoft, etc.

But that doesn't help my on the other side of the equation where I need to sign contracts that directly prohibit things that I would be mandated to do under these laws (and do secretly). I will need to come up with some interesting boiler plate escape clauses that allow for it without sounding completely dodgy.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#129
(essentially repeating a recent twitter thread here)

Imagine you work in a modern software house and you get one of these ... and here I mean you, not your boss, not your coworkers, the govt knocks on your door and demands you put a back door in the thing you are working on at work ...

So you write the code ... how do you write the unit test? how do you get it past the code review? the mandatory QA tests? ... all these things are designed into our modern software design processes essentially designed to stop bad stuff like this happening ... what happens when you get caught? you lose your job, get blacklisted in the industry, after all you can't tell them the govt made you do it (on your CV/resume trying to explain why you were fired)

Equally say you run a big open source software project and you have valued contributors from Australia, people you trust and depend on ... what do you do? refuse them commit right? explicitly audit their every checkin? ask them to move on?

Suppose you buy closed source code from Australia .... you can't trust it in any way, even if you trust the company any one of their employees may have been asked to suborn the code you've paid good money for ... any smart purchaser is simply going to put Aussie software on the "do not purchase" list .....

So how do I find out which software on Android Play is written in Oz?

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#130
post #10

Earlier quoted context omitted.

It looks like Labor will win next election, but that really doesn't matter. Labor voted for the bill unanimously.

Shorten’s strategy to lose the battle/win the war has soured my view of him forever. He’s revealed himself to be a man of no principles.

I now call him Backdoor Bill.
Post reply on HN