Live data from Hacker News

Australian parliament passes encryption laws unamended

abc.net.au

161–170 of 415 posts

Re: Australian parliament passes encryption laws unamended

#161

Ouch. Since I'm using Fastmail ... can anybody recommend a good alternative? I don't mind paying for a good and secure E-Mailprovider. Protonmail looks nice, but it does not seem to offer IMAP (because mails are end2end encrypted).

From what I remember fastmail has always cooperated with law enforcement. It is not zero-knowledge so they always had access to the user data already. Their promise has been to not use it for advertising purposes or share it with third parties. I don't see much changing here, but I would like to know if it is.

Yep, we already blogged about this. It's shit legislation, but it is unlikely to affect our customers at all. Public perception on the other hand, it's going to hurt that plenty.

Like basically all of Australian tech right now, we're super disappointed in our politicians and their games. I spoke to a couple of senators' offices today, and they were sure it would die in amendment hell. Genius.

Re: Australian parliament passes encryption laws unamended

#162
If you are an Australian software engineer, you have one advantage that other nationalities do not: the E3 visa. It is a US working visa that is specifically reserved for Australians and consequently it is much easier to get than an H1B.

My advice is that the Australian tech industry just got nuked from orbit, so come work in the USA. The pay is better, the work is more interesting and the tech companies actually have sway over policy here.

Re: Australian parliament passes encryption laws unamended

#163
post #116

Ouch. Since I'm using Fastmail ... can anybody recommend a good alternative? I don't mind paying for a good and secure E-Mailprovider. Protonmail looks nice, but it does not seem to offer IMAP (because mails are end2end encrypted).

Paid Protonmail has a bridge to IMAP/SMTP. [0] [0] https://protonmail.com/bridge/

GNU/Linux support when?

Re: Australian parliament passes encryption laws unamended

#164

Earlier quoted context omitted.

There are so many loopholes in this thing. One predominant thing to keep in mind is the legal onus that is put on a company that does not comply . The basic gems are that I got from reading the draft legislation was: - If you have server side encryption, & we want you to decrypt a particular person's data, then we expect you to do so - ad infinitum. - If you do client side encryption then we expect you to put into pl…

Does the legislation say they can do this without justification though? Can they just ask for anyones information or does there need to be some sort of warrant?

Does it matter? The correct answer to "decrypt this person's data now" is "sorry, we can't". Not "won't", "can't".

Re: Australian parliament passes encryption laws unamended

#165

Earlier quoted context omitted.

I’m seriously considering moving from Australia to a country that isn’t part of the Five Eyes.

I'm thinking about moving to NZ. How are they?

if you're going to move you really should get out of the anglosphere because the US is dragging down everyone with it and there's just not enough sentiment amongst the populations to move away from the US, even now.

Switzerland probably remains the best country in the world and has strong privacy laws and a culture of neutrality. As a plus you get to be in Europe. Tech salaries are high. The anglosphere nations lack the intellectual capital amongst the population to remain critical of encroachments of privacy in the name of protection from terrorists.

Re: Australian parliament passes encryption laws unamended

#166

If you are an Australian software engineer, you have one advantage that other nationalities do not: the E3 visa. It is a US working visa that is specifically reserved for Australians and consequently it is much easier to get than an H1B. My advice is that the Australian tech industry just got nuked from orbit, so come work in the USA. The pay is better, the work is more interesting and the tech companies actually hav…

the US has already been doing this stuff for a long time, without it being legal. They can always pressure you and threaten to ruin any engineer's life if they don't do what they want. and who do you think came up with this legislation? It's US Intelligence. Australia is their testing lab, just like Macca's does.

Re: Australian parliament passes encryption laws unamended

#167
post #56

Literally zero percent chance I touch any software made in Australia now.

This immensely stupid law applies to any business that operates in Australia, which includes Google, Apple, Microsoft, Samsung, Facebook, Github, and every other major tech company on the planet. If they want to continue doing business in Australia (and they very much do) then they'll be forced to comply, which means everybody in the world is negatively affected by this insanity.

Fastmail, don't forget.

With a somewhat heavy heart, but I shall be cancelling my service there.

Re: Australian parliament passes encryption laws unamended

#168

Earlier quoted context omitted.

There are so many loopholes in this thing. One predominant thing to keep in mind is the legal onus that is put on a company that does not comply . The basic gems are that I got from reading the draft legislation was: - If you have server side encryption, & we want you to decrypt a particular person's data, then we expect you to do so - ad infinitum. - If you do client side encryption then we expect you to put into pl…

Does the legislation say they can do this without justification though? Can they just ask for anyones information or does there need to be some sort of warrant?

It has to be under suspicion of a crime that attracts over 3 years jail (which is almost anything).

They mentioned oversight of a "retired judge" and a "technology expert" in the autoplay video at the bottom of https://www.news.com.au/technology/online/security/inprincip...

Re: Australian parliament passes encryption laws unamended

#169

Earlier quoted context omitted.

Don't launch in Australia. Or don't launch in Europe. GDPR and this legislation are in direct conflict. Pick a market...

Can launches can be targeted (legally) to a country? The site is hosted in London and am already GDPR compliant - wonder if this is means it is not under Australian laws?

If you're not an Aussie company, and don't have any staff in Australia, then it's a long reach for them to do something to you.

If you specifically reject all customers attempting to sign up from an Aussie IP address, or with an Aussie physical address (if you have that), then you're on pretty firm ground to tell them to piss off if they come knocking.

But, y'know, I'm not a lawyer, and you might be subject to whatever whims any country cares to hit you with. Get some legal advice before trusting some random internet comment ;)

Post reply on HN