Live data from Hacker News

Australia’s vague anti-encryption law sets a dangerous new precedent

protonmail.com

171–180 of 265 posts

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#171
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

Laws eventually get abused. I think it’s very likely that this law will eventually lead to everything everybody is worrying about.

Even if it doesn't the unintended consequences and the Chilling Effect to public discourse is going to prove damaging.

I saw they were working in clauses to invoke Parliamentary Privilege so they can't be spied on.

Fuck that, there should be openness regarding discussions on any topic when they are there solely as their constituents' representatives. Had enough of them enacting laws that don't address the people's needs and serve no real purpose for the voters they clearly do not represent. Their inaction on climate change and continued embrace of the coal industry says it all.

And anything to do with security is clearly above these clowns pay grade.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#172
post #169

Earlier quoted context omitted.

It would be very hard for that to pass the proportionality test in the law. I know it's tempting to go for the worst case dystopian scenarios but it's actually important not to go overboard. Politicians and other people with a say immediately stop listening once they hear that. This law is extremely problematic even with a conservative interpretation, so I think we should stick with that.

What proportionality test? Lets go with how the law is actually written. Say they decide hn is a den for hackers. I mean, it's right there in the name! Hacking attracts a >3yr sentence - hence, we need the data of all hn users, they're all potential hackers!

The bill states:

The Director General of Security or the chief officer of an interception agency must not give a technical assistance notice to a designated communications provider unless the Director General of Security or the chief officer, as the case requires, is satisfied that:

    (a) the requirements imposed by the notice are reasonable and 
        proportionate; and
    (b) compliance with the notice is:
      (i) practicable; and
      (ii) technically feasible

So I don't believe intercepting en masse the communications of all the visitors to a web site purely based on its name would be seen as "reasonable and proportionate".

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#173
post #13

While I understand why they didn't mention this (because it's not clear if this interpretation of the bill is correct -- given there is currently no common law around it), I would like to point out what is the most concerning thing (to me) about this legislation. It potentially allows the government to turn employees into saboteurs. According to s.317C(6), a "designated service provider" can be someone who has develo…

> I imagine it's much more likely this power will be used against a few big players (Apple, Facebook, Google) Aussie market is not that big. Its gdp is less than a tenth of USA, smaller than Canada and a half of India. It is a good size but if a bunch of google employees stage a protest over this, google may just pull out of it because losing talent can be a bigger pain.

Note that Google, Apple, etc all have Australian employees and have subsidiaries incorporated in Australia. Google Maps came out of Google Australia, for instance. So you could argue they'd lose talent by pulling out.

Don't get me wrong, I want big tech companies to retaliate since that's the only way to get the attention of the Australian government (they stopped listening to the proletariat a long time ago). But it should be done as a retaliation, because that's the only justification that I believe would be consistent and might make a difference.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#174

Earlier quoted context omitted.

It’s not the same thing. Don’t know Australian law, but for a warrant you need to demonstrate probable cause in front of a judge. And that’s a pretty high bar.

The problem is that if a back door exists for government, it necessarily exists for anyone. Here’s Tim Cook making that point: https://m.youtube.com/watch?v=rQebmygKq7A

I'm aware of that, but in the case of email service providers there is no need for a backdoor. They have access to your emails on-disk since emails are plaintext (in general).

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#175
post #107

I'm grappling with what to do about this law. I develop software in Australia, for a company, separately as a private software vendor and separately again as an open source contributor. From what I can understand, this law can compel me to silently insert malware into any of these. Morally I feel like I need to modify the licenses, READMEs and terms of conditions for products I sell and the contracts under which I do…

The simplest solution is probably a harder one practically - leave Australia. Sadly one doesn't simply leave their country and immigrate to someplace else in addition to any personal concerns - it might not be an option, let alone a desirable one but it has its merits.

Come to Canada :) We'll hire you.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#176

Earlier quoted context omitted.

No, not reasonable, but it's the will of the Australian people and we should respect their sovereignty.

This was not the will of the Australian people. There was a "consultation period" and 99.7% of the submissions were against it. https://www.reddit.com/r/australia/comments/a3j466/assistanc... https://docs.google.com/spreadsheets/d/1dowpZ_Xtr1N_DgkHJN8i...

Put it this way: it was passed into law with bipartisan support by both democratically elected legislative chambers of the Commonwealth of Australia.

All it took to convince the representatives and senators was for a submission from the Australian Federal Police that it was necessary to investigate threats over Christmas.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#177
post #24

Earlier quoted context omitted.

The law allows you to provide statistical information about how many of the relevant notices you've received within a 6-month-window. So there's no need for warrant canaries (which is a good thing, since they're not generally legal in Australia).

A single notice can request the data of every single one of your users.

This is not necessarily true (as discussed elsewhere in this thread), but even if it was true you could still tell people that you've received 1 request. This fulfils the same properties as a warrant canary.

I'm currently talking to some lawyers about how flexible the 6-month window might be. (Can you give overlapping 6-month windows? What if you give a new 6-month window every day?)

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#178
I am an Australian software developer. There is no way I am putting any backdoor into any software I write and I am willing to go to jail if needed. If all us Aussie developers tell the government to go jump this stupid law will fail.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#179

(essentially repeating a recent twitter thread here) Imagine you work in a modern software house and you get one of these ... and here I mean you, not your boss, not your coworkers, the govt knocks on your door and demands you put a back door in the thing you are working on at work ... So you write the code ... how do you write the unit test? how do you get it past the code review? the mandatory QA tests? ... all the…

For large oss projects, accept PRs from those contributers, and outright tell the Australian government to go fuck themselves.

They have zero recourse.

Re: Australia’s vague anti-encryption law sets a dangerous new precedent

#180
post #95

One of the worst things about this bill is that the opposition knows it is full of problems and could have blocked it and forced a range of amendedments. The Labor party here though is afraid of creating any point of difference on anything that could in any way be considered “national security” legislation. So instead of risk a lengthy period over the summer break where they would be attacked if any kind of terrorist…

There is a bipartisan consensus on security and other matters in Australia. Most policy development in Australia is driven by the unelected agencies and departments that survive their political masters.

There is nothing in the values and philosophies of the ALP such that they would not have legislated this agenda were they in government rather than opposition.

There are so many other examples of this over history, such as the GST, Australia Card, refugee policy, copyright laws.

Post reply on HN