Live data from Hacker News

Australia ranked 61/63 countries for entrepreneurship

ceda.com.au

81–85 of 85 posts

Re: Australia ranked 61/63 countries for entrepreneurship

#81
post #79

Earlier quoted context omitted.

Have you read the whole legislation? It's not FUD... the Australian government has the powers for full commandeering of it's citizens via TOLA

I've given you a factual basis for my claim that backdoor powers are FUD: section 317ZG puts clear limitations in place that forbid backdoors or any other kind of systemic weakness. If you want to argue that backdoor powers are real and not FUD, please back up your statement with facts (e.g. a limitation on 317ZG or a case where it does not apply).

> Designated communications provider must not be requested or required to implement or build a systemic weakness or systemic vulnerability

The key words here being systemic.

Sure, they can't create a backdoor that will allow weaken everyone's protections, but the way the whole 317ZG is written is that between the lines a "communications provider" can be compelled to provide targeted access to individuals.

For example, let's say all our phones have e2e encryption and cannot be unencrypted unless you have a password. There is scope within the act to commandeer Google/Apple (who both have offices in Australia) to push targeted updates to a specific user and save targeted plaintext data or even install a keylogger etc.

In other words, this would then give authorities access to plaintext data on the phone without a user's consent, all without being systemic weakness.

And I'm writing this based on many discussions with lawyers. I was very vocal about the AABill when most people Australian tech people didn't care, but I can tell you know that a lot of lawers were concerned and reached out.

It is commandeering Full. Stop. Want to disobey a TAR, TAN, or TCN? Go right ahead given that you say it's not FUD... but be my guest arguing with:

    9  Subsection 3LA(5)

    Repeal the subsection, substitute:

    Offences

             (5)  A person commits an offence if:

                     (a)  the person is subject to an order under this section; and

                     (b)  the person is capable of complying with a requirement in the order; and

                     (c)  the person omits to do an act; and

                     (d)  the omission contravenes the requirement.

    Penalty:  Imprisonment for 5 years or 300 penalty units, or both.

Re: Australia ranked 61/63 countries for entrepreneurship

#82
post #79

Earlier quoted context omitted.

I've given you a factual basis for my claim that backdoor powers are FUD: section 317ZG puts clear limitations in place that forbid backdoors or any other kind of systemic weakness. If you want to argue that backdoor powers are real and not FUD, please back up your statement with facts (e.g. a limitation on 317ZG or a case where it does not apply).

> Designated communications provider must not be requested or required to implement or build a systemic weakness or systemic vulnerability The key words here being systemic . Sure, they can't create a backdoor that will allow weaken everyone 's protections, but the way the whole 317ZG is written is that between the lines a "communications provider" can be compelled to provide targeted access to individuals. For examp…

I'm not saying TARs, TANs or TCNs are FUD and you can ignore them, I'm saying the suggestion that they can compel the introduction of a backdoor is FUD.

The example you give, if it's possible, is an example of an existing systemic weakness. Yes, the government is free to exploit it but the government can't compel its existence.

Apple and Google are free to eliminate it, if they so choose.

FWIW, I'd consider the possibility of such a mechanism to be a problem in itself. And I don't believe it is possible today. Android, at the OS level, will only install updates with the same signature as the currently-installed version.

Re: Australia ranked 61/63 countries for entrepreneurship

#83
post #72

Earlier quoted context omitted.

This is FUD. The law has always had limitations built-in to ensure that this isn't true [0]. The government can only force you to use backdoors you already have, for example if you don't use end-to-end encryption and already have the keys. [0]: http://classic.austlii.edu.au/au/legis/cth/consol_act/ta1997...

Yes, it's FUD. But it's only FUD because they don't need a new backdoor. They already have one. It's the automatic update system, which ironically has to be there for security updates. The automatic update system means on devices that identify their customers, the act demands any software provider not only provide access to the device via that mechanism, they must also provide assistance such as writing software the…

True that an update system could be used maliciously.

I wonder though: if the keys needed to sign an update are stored in say an American or Korean HSM and no person located in Australia has access, can the Australian government still compel their use?

Re: Australia ranked 61/63 countries for entrepreneurship

#84
post #82

Earlier quoted context omitted.

> Designated communications provider must not be requested or required to implement or build a systemic weakness or systemic vulnerability The key words here being systemic . Sure, they can't create a backdoor that will allow weaken everyone 's protections, but the way the whole 317ZG is written is that between the lines a "communications provider" can be compelled to provide targeted access to individuals. For examp…

I'm not saying TARs, TANs or TCNs are FUD and you can ignore them, I'm saying the suggestion that they can compel the introduction of a backdoor is FUD. The example you give, if it's possible, is an example of an existing systemic weakness. Yes, the government is free to exploit it but the government can't compel its existence. Apple and Google are free to eliminate it, if they so choose. FWIW, I'd consider the possi…

> I'm not saying TARs, TANs or TCNs are FUD and you can ignore them

> Apple and Google are free to eliminate it, if they so choose.

Pick one.

Again, a TCN compels a provider to develop a targeted capability, or face jail time.

Re: Australia ranked 61/63 countries for entrepreneurship

#85
post #82

Earlier quoted context omitted.

I'm not saying TARs, TANs or TCNs are FUD and you can ignore them, I'm saying the suggestion that they can compel the introduction of a backdoor is FUD. The example you give, if it's possible, is an example of an existing systemic weakness. Yes, the government is free to exploit it but the government can't compel its existence. Apple and Google are free to eliminate it, if they so choose. FWIW, I'd consider the possi…

> I'm not saying TARs, TANs or TCNs are FUD and you can ignore them > Apple and Google are free to eliminate it, if they so choose. Pick one. Again, a TCN compels a provider to develop a targeted capability, or face jail time.

A TCN can only compel a targeted capability where doing so does not require introduction of a systemic weakness.

If the system is secured in such a way that the targeted capability isn't possible (e.g. open-source project with e2e encryption and verifiable builds), the government cannot compel introduction of a systemic weakness (e.g. stop using verifiable builds) to make it possible.

My suggestion is that Apple/Google build their software such that it is systemically secure against targeted attacks.

Post reply on HN