Live data from Hacker News

Microsoft says encryption laws make companies wary of storing data in Australia

abc.net.au

191–200 of 294 posts

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#191

Earlier quoted context omitted.

Is this true ? There is no way I am hiring an Australian citizen then.

1. You likely can't force someone to disclose all their citizenships. 2. In most countries you can't legally discriminate based on nationality. In practice publishing this comment here will likely cause you more trouble if you reject someone now, than Australian government. 3. If you apply this to all... what countries are you left with exactly where the government or LE can't force people to do something?

> 1. You likely can't force someone to disclose all their citizenships.

Yes you can, in some cases; as for instance in some cases, especially IT security, you cannot be a foreign national or have ties to some specific nationality if you do business with local governments. This requires you to know the nationality(ies) of your employees. You can still have them in your team but they cannot work on the project. The Australian law would make this a very good argument to not hire them as they cannot work on any project as they are a possibly compromised. An example would be SpaceX which only hires US citizens due to DoD contracts.

> 2. In most countries you can't legally discriminate based on nationality. In practice publishing this comment here will likely cause you more trouble if you reject someone now, than Australian government.

I'm pretty sure that in the cryptography and IT security business the value of not having to comply with this law outweighs the cost of any discrimination lawsuits.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#192
post #13

Earlier quoted context omitted.

Australians have very few constitutionally guaranteed rights (compared to countries such as the US). The Constitution only gives us the right to vote, the right to a trial by jury, and freedom of religion (and a few others). But many more rights, including extensive privacy rights, exist in statute law and elsewhere. The main argument against adding more rights to the Constitution, is: "we don't want to end up with o…

You can't protect rights and freedoms from intrusion by the government by statute, which is kinda the whole point of having a constitution. If it's just a law saying the government can't do something, then it'll do that by first repealing that law - if all you need is a simple majority, the votes are always there. The reason why the US constitution is so hard to amend is because of how high the bars are for the proce…

I think it's the splitting of government power that secures people's rights, not the fact that the Constitution needs many votes to amend. Because someone still has to enforce the Constitution; of course it's going to be the government. Your rights are just words if the government doesn't care.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#193

Earlier quoted context omitted.

Oh, and it's probably worth noting that you need not even be an Australian citizen to be covered, you simply need to have users in Australia. Of course, whether Australia can enforce these laws against non-citizens is another matter. However, this legislation was specifically put together with co-operation of all members of the five eyes, so there's a reasonable possibility of extradition. The Department of Home Affa…

You can't force non-citizens, obviously, since non-citizens are not under Australian jurisdiction. If they could, then this would create a problem of national security for other countries. But yes, the Five Eyes countries can use Australia for their wiretapping.

It wouldn't be the first time someone would be extradited to a country they've never even visited.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#194
post #189

Earlier quoted context omitted.

The obfuscated C coding contest shows that you probably won't catch backdoors with code reviews

Obfuscated code shouldn't pass code review.

Maybe the poster above was referring to the Underhanded C Contest

> The Underhanded C Contest is an annual contest to write innocent-looking C code implementing malicious behavior. In this contest you must write C code that is as readable, clear, innocent and straightforward as possible, and yet it must fail to perform at its apparent function. To be more specific, it should perform some specific underhanded task that will not be detected by examining the source code.

Source: http://www.underhanded-c.org/_page_id_2.html

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#195
post #191

Earlier quoted context omitted.

1. You likely can't force someone to disclose all their citizenships. 2. In most countries you can't legally discriminate based on nationality. In practice publishing this comment here will likely cause you more trouble if you reject someone now, than Australian government. 3. If you apply this to all... what countries are you left with exactly where the government or LE can't force people to do something?

> 1. You likely can't force someone to disclose all their citizenships. Yes you can, in some cases; as for instance in some cases, especially IT security, you cannot be a foreign national or have ties to some specific nationality if you do business with local governments. This requires you to know the nationality(ies) of your employees. You can still have them in your team but they cannot work on the project. The Aus…

Government/DoD security is much different than any random company's it security. Even large corps don't care about nationality for security team, just visa status / employment rules for most projects. (Again, when not related to gov projects)

I honestly don't know how SpaceX does what it does. (Update: they are regulated as working on military stuff so it's the same as DoD rules)

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#196

Earlier quoted context omitted.

The Australian tech sector is not that large, an ill-conceived law like this one could potentially worsen the job prospects here, to the point that one may consider working overseas. I'm not saying that it's likely, but at the same time it's not impossible. So, yes, I was thinking primarily about foreign companies; (by the way, your argument in relation to Australian companies, "Because the first is very illegal", is…

> I believe it's not that unlikely that a prospective employer may ask about my citizenship status I guess that depends on whether you want to lie to a potential employer then, or alternatively renounce your citizenship. The difference between a PR and a citizenship though is that you have the privilege to live and work in Australia, your PR visa can technically be cancelled on good character grounds, whereas with ci…

Yes, good point about the difference between PR and citizenship.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#197

Earlier quoted context omitted.

It is not cheaper than getting sued for discrimination. Which would be easily proven in many cases, seeing how many people are more afraid of a potential issue with another country's intelligence agencies then of publicly posting about their plans to violate their own employment laws.

That's absurd, not hiring a foreign national on security concerns is a daily event, can you name one discrimination case won for that?

You're bringing up an valid exception validated by law. It's not the default and does not apply to almost all jobs out there. It's also usually applied as "only our nationals" rather than "not those specific other nationals" which would be the case for non-Australian.

I'm not linking specific cases. (partially because you didn't specify which country you're taking any) A quick Google will bring you the specific laws, cases and lots of lawyers specifically advertising themselves to handle those cases.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#198
It's incredible to watch the degree to which intelligence wants and needs are dictating the coming regulatory environment of internet & tech generally.

Losing access to an information stream due to routing or encryption. Matching allies' and rivals' levels of information access (a la prism). Denying them access... From the perspective of the spooks (asio, in this case) these are equivalents to exposing a microphone in Bin Laden's proverbial cave.

Meanwhile, FB & Google's revenue streams are, at this point so big and so tightly coupled with creepy ad-tech/spyware that the economy depends on privacy intiatives failing. Narrowing down a list of FB users who are >n% likely to sign up to a new candy subscription is a lot like producing a list of >n% likely to march in charlottesville or support some specific jihad. Colaboration is inevitable.

Lets not underestimate where these roads are leading.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#199

Earlier quoted context omitted.

I've had long discussions with techie friends about this, and none of us can see a way that the government could actually force a dev to do anything in a way that doesn't immediately tip off the rest of the team. I mean, your code is stored in a shared repo, right? So pushing a commit with the government-mandated changes to the shared repo is "informing others". But not pushing it means it'll never get to Prod. Most…

Really? It took me about 10 seconds to come up with this: "Hey tech dude, we need a version of iOS that unlocks the encryption on this device. Be a good boy and send us an IPSW that we can install on this nasty person's phone will you?" You don't need to release it to the public. Build it on your local device and hand it to them. Nobody needs to know.

The number of people with access to the private keys that sign iOS updates must be very limited - I wouldn't be surprised if you needed at least two people actively involved in signing every update.

On top of that, Apple is heavily siloed, and somebody working on the Calendar app won't have information on the operation of Secure Enclave, the chip that deals with authenticating fingerprints, passcodes, Apple Pay etc.

So it would be more like "Hey tech dude, can you sneak a change to the compiler your company uses to build iOS, to have it compile a backdoor into iOS, then surreptitiously login to the relevant machines and place your new compiler?"

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#200

Earlier quoted context omitted.

> We've also been around for longer than anyone else with a modern democracy No, we haven't. In fact, we copied it largely from the UK. (We didn't like the fact that as a colony we didn't get representation in the national legislature or the full range of rights citizens in the UK itself had, but, hey, the US does the same thing. Initially, and still partially, even to it's capital district . We've got the oldest sur…

The US has a very different system in a lot of ways. The UK doesn't have a formal constitution, its executive is subject to the legislature in a way it isn't in the US, one house, etc. The UK is a parliamentary democracy and the US is a republic. Also, the UK wasn't a democracy in any meaningful sense in 1776. The History Of Parliament Online is a very useful resource ( https://www.historyofparliamentonline.org/resea…

> Also, the UK wasn't a democracy in any meaningful sense in 1776.

One could argue that UK is still not a democracy now. House of lords, Queen's hard and soft power, traditions, no legally binding referendum that can be done without government or parliament.

Post reply on HN