Live data from Hacker News

Advocating for privacy in Australia

fastmail.blog

81–90 of 112 posts

Re: Advocating for privacy in Australia

#81

Earlier quoted context omitted.

We never offered, and never claimed to offer, a safe haven for people who have broken the law in both Australia and their own country to hide from the police. We don't place ourselves above law enforcement. We don't have data trading agreements with anybody, and we don't sell or provide backdoor channels - we only provide data in response to lawful warrants. That's the right amount of privacy and the right tradeoff w…

> We don't place ourselves above law enforcement. Of course this is reasonable, but I'm curious what you think of companies who do put themselves above law enforcement when it's the right thing to do. i.e. lawmakers do not always make laws that are right and law enforcement does not always do the right thing when interpreting and enforcing laws. A case to cite might be Apple vs. FBI in 2016. The company placed itself…

Apple did not place themselves about the law, they went to a properly constituted court and asked the judge to rule on whether what the FBI was asking was lawful.

During those proceedings, they also explained how complying with the FBI's request would lead to a highly damaging corruption of the privacy of their users data.

They asked the judge to make a judgement which was that Apple were right in saying that the FBI had over-reached in their warrant.

The case was headed to appeals when the FBI withdrew after finding another way to get the information they needed. Notably they did so without Apple having to compromise security or user data privacy.

Re: Advocating for privacy in Australia

#82
post #13

So the article's tl;dr is basically: "We're advocating for privacy, but we aren't going to try to offer you any. We never did, and we certainly won't now that this law passed. You're on your own." Is this supposed to be a PR-positive announcement from FastMail, because I can't quite tell?!

We never offered, and never claimed to offer, a safe haven for people who have broken the law in both Australia and their own country to hide from the police. We don't place ourselves above law enforcement. We don't have data trading agreements with anybody, and we don't sell or provide backdoor channels - we only provide data in response to lawful warrants. That's the right amount of privacy and the right tradeoff w…

> We never offered, and never claimed to offer, a safe haven for people who have broken the law in both Australia and their own country to hide from the police.

You seem to be conflating the concept of "I don't want my emails read" with "I am a criminal".

Why?

Re: Advocating for privacy in Australia

#83
[disclaimer: happy fastmail user, 30+ year Aussie programmer]

What I really really like about this blog entry and the Fastmail service in general is that it is practical and clear.

Fastmail does not and has not ever offered data privacy from properly constituted legal requests. Within the service they offer of email (and calendaring and contacts), they protect their user data by having it encrypted at rest and in transit.

Email protocols are not suited to E2E encryption because of the historical evolution of those protocols. So if you want E2E, there are appropriate solutions.

In terms of people who want access to your data, there are two types, bad/illegal actors and those operating under the judicial system. Under the judicial system in place in Australia, as has been explained, warrants (and the equivalent for non-law enforcement security services) are still required for access to an identified person's information.

Fastmail has always been clear that they would respond to a properly constitued legal request.

In terms of lobbying, it is up to all Australian tech people to respond to this legislation and its ill-considered requirements.

I've already written to Mark Dreyfus as Shadow Attorney General and also the senior ALP person on the PJCIS which is responsible for this legislation.

I intend to engage further in the new year with all those relevant MPs, ministers and shadow ministers, with the primary goal of clarifying that the tradeoff between security and privacy is not a zero-sum game, that invading privacy in such a ham-fisted manner as defined in the legislation is more damaging to both our industry and our community than the stated objectives of our security services to avoid bad actors "going dark".

Re: Advocating for privacy in Australia

#84
post #10

The ability to use standard protocols (IMAP and SMTP) is much more important to me than end-to-end encryption. I won't even touch an email service that doesn't support IMAP with a 10-foot pole no matter how secure they claim it is. I know some people are developing self-hosted gateways that can speak IMAP on the local side and a more secure protocol on the public side, and I think it shows promise. But the whole setu…

My work email has disabled imap in the name of security. My understanding is it's easier to lock down email entirely than to get doctors not to email patient data around, so I kind of understand, but it's annoying to have to read my email either using the terrible outlook web all or by giving my employer a lot of permissions on my personal phone. For context I'm in the US, where HIPAA fines can be quite high (not that that's a bad thing).

Re: Advocating for privacy in Australia

#85

> FastMail won’t be making changes to our technology or policies in response to this bill. Law enforcement has always been able to request information from us through the Telecommunications Act with a lawful warrant. Because we have the ability to decrypt all data, there is no need to make changes that circumvent encryption. Isn't this, "No need to force us to install a backdoor, we've already got one!" Kind of disap…

It's not a backdoor. It's a front door, and clearly marked and prominently documented as such.

Re: Advocating for privacy in Australia

#86

EDIT: note that I'm probably wrong, see reply below by @brongondwana! --- One problem not being addressed is that via #AABill data access requests can now be submitting without warrants issued by a judge, so it removes the judicial oversight. Also this law says that all such requests need to be "reasonable", but it doesn't define what that means. For example is blanket surveillance reasonable? AFAIK this law doesn't…

> One problem not being addressed is that via #AABill data access requests can now be submitting without warrants issued by a judge, so it removes the judicial oversight.

TANs require a warrant (or rather, a TAN is unenforceable if it would require the agency to get a warrant -- but a TAN instead is a method to give force to a warrant). The restrictions on notices are in s317ZH (which is a while after the definitions of the notices so people might be forgiven for misunderstanding the limitations).

> And companies like FastMail cannot report abuse publicly, or the people responsible risk 10 years in jail.

5 years in gaol is the limit. There are also processes for them to provide statistical information about how many notices they've received, as well as provisions for courts and the Commonwealth Ombudsman to make public notice information.

> Couple this with the fact that Australia is part of the "Five Eyes", being the only country without a "Bill of Rights", it means that agencies like the NSA could use Australia for their dirty work.

This is definitely true, and GCHQ has already started requesting similar powers in the UK (not that they need to, since they can just use the Australian powers). There are several provisions in the act which specify that it can be used for investigations into "serious foreign crimes".

> Please correct me if I'm wrong, I haven't read the actual bill, just random commentary on the net.

I would recommend reading it, a lot of people haven't.

Re: Advocating for privacy in Australia

#87

EDIT: note that I'm probably wrong, see reply below by @brongondwana! --- One problem not being addressed is that via #AABill data access requests can now be submitting without warrants issued by a judge, so it removes the judicial oversight. Also this law says that all such requests need to be "reasonable", but it doesn't define what that means. For example is blanket surveillance reasonable? AFAIK this law doesn't…

We've never done blanket surveillance, and specifically mention "individual users" in the blog post. There's been a lot of FUD about warrants not being needed - I think the ZDNet article we linked covers that very well: "[a judge doesn't have to sign off on the specific method by which data is requested] However there must be an underlying warrant to access communications under the Telecommunications (Interception an…

> There's been a lot of FUD about warrants not being needed - I think the ZDNet article we linked covers that very well

There is definitely a lot of FUD, though I think the ZDNet article is underplaying several quite reasonable concerns about the legislation.

In addition, I've not seen any concrete explanation of how you could make use of the Commonwealth Ombudsman to effectively appeal the decision of assessors for a TCN.

Re: Advocating for privacy in Australia

#88
post #15

Their "Actions we are taking" section is almost entirely composed of a political lobbying strategy. Given the outcome of the vote, 44 votes for and only 12 against, their plan doesn't exude much confidence. I would have expected plans to move data and key technologists out of Australia at the very least. The company I work for uses Fastmail but our CEO has already decided to switch mail providers sometime in 2019. I…

> The company I work for uses Fastmail but our CEO has already decided to switch mail providers sometime in 2019. I don't know what other service they'll choose. If the reason for switching is because of such laws, your company could look at providers outside the: * Five Eyes (Australia, Canada, New Zealand, the United Kingdom and the United States) * Nine Eyes (Five Eyes plus Denmark, France, the Netherlands and Nor…

This. I've been trying to find both web and email hosting outside of the 14 eyes, and it's not easy. It's very frustrating. I'm trying to figure out the best way to keep my user's data safe from these kind of legislations (within reason of course). The site I run isn't even that large, but I'm still concerned about these kinds of things stifling my business.

Re: Advocating for privacy in Australia

#89

> FastMail won’t be making changes to our technology or policies in response to this bill. Law enforcement has always been able to request information from us through the Telecommunications Act with a lawful warrant. Because we have the ability to decrypt all data, there is no need to make changes that circumvent encryption. Isn't this, "No need to force us to install a backdoor, we've already got one!" Kind of disap…

> Isn't this, "No need to force us to install a backdoor, we've already got one!"

Fundamentally there is no need for a backdoor for emails. The entire protocol results in plaintext being received on the server, and so there is no need to add a backdoor. Email isn't end-to-end encrypted -- you've always had to use PGP if you wanted that.

Lavabit had the same problem when the US sent and NSL that asked for the TLS keys of his server to decrypt the email traffic that Snowden had sent.

Re: Advocating for privacy in Australia

#90

Earlier quoted context omitted.

Damn, I just lost $100. Thanks. We had a bet on how long it would take for somebody to say "just relocate your entire company and all your staff's lives to another jurisdiction".

Slightly off topic: you have a broken link in your blog post titled 'Submission regarding “The Assistance And Access Bill 2018”'. The link [2] in the line "For more information around this submission, see our about the bill" leads to a 404 page not found. [1]: https://fastmail.blog/accessbill-submission/ [2]: https://fastmail.blog/access-and-assistance-bill/

Hey, thanks! We've updated that to link to both the relevant blog posts.
Post reply on HN