Live data from Hacker News

Microsoft says encryption laws make companies wary of storing data in Australia

abc.net.au

231–240 of 294 posts

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#231
post #156

Earlier quoted context omitted.

The problem seems to be the provision that a tech worker can be coerced by the Australian Government into creating a backdoor, and they are not authorised to disclose it to their employer. As I read it, the law requires warrants and court enforcement. I don't think you can be required to backdoor code in secret or held to account by the security agencies not to inform your employer. I would be very surprised if tat w…

> I don't think you can be required to backdoor code in secret or held to account by the security agencies not to inform your employer. This law gave the government the power to do just that. Details of implementing a backdoor in secret is close to impossible, as any developer would know. There was a post[1] made by "Alfie John" (alfiedotwtf) that outlines a scenario in which a developer is presented with a Technical…

Australian citizens, regardless of their location are obliged to comply with these requests.

Extra-territorial law application is very complex. KP is one of the few places where you can routinely expect to be prosecuted in Australia for breaches overseas. or FGM. Or, more recently the war in Syria but bear with me: do you not also recognize that there is a huge reluctance to try and enforce the law in that last regard? because it turns out simply being somewhere is not neccessarily a good basis to declare you broke the law, noting that few if any of the people seeking to come home took up arms, and specifically took up arms against Australia or her allies.

They also have to serve the request on you. Simply issuing it doesn't make it binding surely? You have to be formally notified.

Lastly, since you can reveal it to your lawyer, I would argue that it implies they believe it could be mis-applied, or you can have a case in law to contest its applicability.

And, included in the notice begs the question: do we have any indication aside from hypothetically speaking, that a TAR/TAN/TCN has or can be drafted which doesn't include the employer and IPR holder in the notice?

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#232
post #189

Earlier quoted context omitted.

Obfuscated code shouldn't pass code review.

Maybe the poster above was referring to the Underhanded C Contest > The Underhanded C Contest is an annual contest to write innocent-looking C code implementing malicious behavior. In this contest you must write C code that is as readable, clear, innocent and straightforward as possible, and yet it must fail to perform at its apparent function. To be more specific, it should perform some specific underhanded task tha…

I highly encourage everyone to go look at the hall of fame, it was extremely eye opening when I first did!

Even knowing there is an exploit in the code, I probably would never be able to find most of them. My favorite is 2008's winner who's goal is to write a redaction program to redact text. It doesn't use any buffer/array hacks, the code is very straightforward and simple and small, and it would work in languages other than C. It's a terrifying example of how easy it is to write malicious code that would pass multiple code reviews but still has a backdoor!

http://www.underhanded-c.org/_page_id_17.html

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#233
post #215

Earlier quoted context omitted.

> We elect the government to serve the people Quit making me laugh, buddy. Unfortunately, I think we all know that once they get their office, they do very little to serve the people. Not sure about the case with Australia, but you can't sue the American government unless it lets you. Otherwise, it just claims sovereign immunity. Wrong as that is, it's a very good defense as it keeps them out of court. This might lea…

That could lead to some interesting court cases. Employee gets fired for introducing a backdoor, but "may or may not have been" subject to one of these assistance notes (the Government won't comment either way, the employee insists they had a Technical Assistance Note). Employee sues the employer for wrongful dismissal because of the alleged unprovable TAN. I wonder which way that court case would go... sounds like a…

Another possible concern is that the employee sues for wrongful termination, alleging they were "just following the law" (which they would have been). The employee shouldn't lose his job for following the law, the company shouldn't have such problems for trying to protect its users, and this whole mess was caused by government intervention.

But yes, it will be interesting to see how the courts rule. Not familiar with Australian law, so if anybody has thoughts about this, please feel free to enlighten me.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#234

Earlier quoted context omitted.

> well-established democratic and legal systems Given the topic at hand, this doesn't seem like a distinct strength of Australia, unless you're coming from a despotic regime or recently New Zealand.

I think it's important to have some context here though. I can't speak for the parent commenter, but I am Australian and how I interpreted it was that our democratic system is reasonably mature, functional, and relatively free from large scale corruption. I think the last point is the big one. Political lobbying, while still a thing, isn't as rampant as in the US for example. Bad power-grab legislation like the bill…

> Bad power-grab legislation like the bill being discussed still happen, as do bad laws as a result of general incompetence, but in my experience there are far less laws that happen as a result of corporate lobbying.

I think I care a bit less about corporate welfare lobbying than infringements on my civil rights. You can fix corporate lobbying if you have real civil rights, but if you don't have the right to communicate privately, the corporations can literally just stop you from organizing, with the littlest nudges (just make the messages of dissent mysteriously not deliver). It might not even be illegal.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#235
post #45

I was about ready to move all my email over to Fastmail before this happened. But not now.

I recently moved to Fastmail and couldn't be happier. Like others have said, you really should never count on email being a private medium. I switched mainly to remove my email from Google's sources of data collection on me: this is the level of privacy that is important to me. If I wanted to hide from state sponsored actors I wouldn't be using email at all. A nice side effect of moving to Fastmail is being able to u…

[deleted]

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#237
post #215

Earlier quoted context omitted.

> We elect the government to serve the people Quit making me laugh, buddy. Unfortunately, I think we all know that once they get their office, they do very little to serve the people. Not sure about the case with Australia, but you can't sue the American government unless it lets you. Otherwise, it just claims sovereign immunity. Wrong as that is, it's a very good defense as it keeps them out of court. This might lea…

That could lead to some interesting court cases. Employee gets fired for introducing a backdoor, but "may or may not have been" subject to one of these assistance notes (the Government won't comment either way, the employee insists they had a Technical Assistance Note). Employee sues the employer for wrongful dismissal because of the alleged unprovable TAN. I wonder which way that court case would go... sounds like a…

Even better: employee gets criminally prosecuted in a (slightly) more sensible jurisdiction for having intentionally introduced the backdoor.

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#238
post #25
post #12

Earlier quoted context omitted.

> ProtonMail’s inability to support standard clients without an awkward bridge app Isn't that one of the pros of Protonmail? All the data is encrypted and decrypted on the client. There is no way to have mail apps access the data without a piece of software that handles the encryption.

I guess it’s just the way you look at it, and maybe even what your priorities are in choosing an email service. To me at least, I’m thoroughly disinterested in an email service which doesn’t implement IMAPS.

Which ones do?

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#239
post #236

Good thing those folks in Australia have retained the ability to fight their govt via the right to bear arms.... right ?

> Good thing those folks in Australia have retained the ability to fight their govt via the right to bear arms.... right ?

Why would violence be an appropriate response by Australians to disagreements with their country's laws?

For that matter, given how many Americans disagree with their own country's governance, shouldn't the Tree of Liberty be soaked in the blood of tyrants and patriots by now?

Or is the 2A crowd just too busy shooting at schools, mosques and watermelons to fit it into their agenda?

Re: Microsoft says encryption laws make companies wary of storing data in Australia

#240
post #70

Earlier quoted context omitted.

I believe that is an incorrect interpretation of the law. The govt can compell an entity to assist in making encrypted information available. But the entity in question is not the individual employee, but the company who owns the product or service. If you're under the employment (i.e., not a contractor), you can't be an entity, and the employer will definitely know if they've been compelled. But I do agree the law i…

You are making the incorrect assumption that the people writing these laws are not idiots. They don't understand the technology. They don't listen to any of the people who advise them about this technology. They seem only to be listening to the police and other law enforcement crying about "paedophiles and terrorists GOING DARK". The Prime Minister at the time claimed the laws of Australia overrode the laws of mathem…

No. The people who wrote the law (and handed it over to the elected politician) knows quite a lot about it. The politicians who put their face on it are mostly ignorant, if not idiots.

Politicians don't generally come home in the evening and sit down to write their own bills. They rely on "experts" to do it for them. The more we rely on a central regulatory apparatus, the more essential this is. And this is where we run into problem like this, as well as regulatory capture. But the fact remains that they've got to rely on somebody with expertise, yet where can you find such people, and how much can you trust them when they're not publicly responsible (or even known).

Post reply on HN