3 ms·
Is this even technically possible? What happens to all the businesses in Australia that built products around crypto where it’s impossible to go backwards.
by aetherspawn 8y ago
Is this even technically possible? What happens to all the businesses in Australia that built products around crypto where it’s impossible to go backwards.
- clouddrover 8y agoThey'll lose business: https://www.abc.net.au/news/science/2018-11-30/encryption-bill-tech-business-damage-international-reputation/10570316 https://www.abc.net.au/news/science/2018-11-30/encryption-bi... I suppose they could always go offshore.
- cyphar 8y agoThey will get fined very heavily and thus will be forced to add backdoors or go out of business. The government claims that what they want aren't backdoors (they use the term "backdoor" to refer to a 0-day in possibly the most disgusting Orwellian doublespeak I've seen come out of this government in an attempt to avoid criticism) but that's simply false.
- caf 8y agoThe meat of the bill is the ability to issue three sorts of notices to service providers (which only need have some incidental presence in Australia to be served, like for example a company owned storefront): Technical Assistance Request - a non-compulsory request to provide requested information they have access to; Technical Assistance Notice - a compulsory version of a Technical Assistance Request, to use a capability that the recipient already has to obtain data; Technical Capability Notice - a compulsory instruction to develop a new interception capability. So it doesn't constrain the way you can build products (now or in the past), they're instead just going to require your assistance to attack the targeted endpoints if that's the only way in.
- aetherspawn 8y agoSo the government can now ask you to do specialised software development to retardify your own systems and if you refuse then they can fine you? I didn’t think there was any basis whatsoever to be able to make a law that assumes a company is capable of maintaining or modifying their systems or infrastructure. That seems too generalised.. what if they’re running on a system that they don’t have the source code for?
- NoPicklez 8y agoThat's exactly one of the things they can do yes. One of the stupid things about it is that they say that what they ask you to do cannot create a systematic weakness. Which is exactly what they're asking you to do, create a weakness that is only for them.
- caf 8y agoPretty much. Maybe they'll just ask you to sign a binary they've built themselves. They obviously won't be able to ask you to do something you technically can't. If you sell, say, IoT devices that don't phone home for updates then you'll probably be safe.
- brokenmachine 8y ago>If you sell, say, IoT devices that don't phone home for updates then you'll probably be safe. They can demand source code to find vulnerabilities in those IoT devices however.
- BLKNSLVR 8y agoMike Cannon-Brookes (co-founder of Atlassian) has been fairly outspoken against it: https://twitter.com/mcannonbrookes https://twitter.com/mcannonbrookes