2 ms·
Suppose there is an Australian who works on important and widely used open source infrastructural software, has commit rights, and is compelled to insert a back
by macdice 8y ago
Suppose there is an Australian who works on important and widely used open source infrastructural software, has commit rights, and is compelled to insert a back door by this new law. Well, obviously that would be really bad. But it seems unlikely to succeed; too many eyeballs. Something closed like a mobile communications app in an app store seems like a more plausible target, but we should already have no faith in apps in app stores in the first place, with or without such laws in existence, wherever they come from. Even with "open source" apps, there is no way to know that you're running the same code. More generally, I have no faith at all that a person or company that develops such apps in (insert other country here) is not similarly compromised, even if they don't have an explicit law like that. For example, some countries have secret courts and secret court orders, so who knows? So as an end user I wouldn't personally feel any more secure if Australian developers were banned from participating in projects I care about, and of course that'd be terrible for those developers.
On the other hand, if I were a global company developing proprietary software with development offices in Australia I'd be pretty concerned... and complain loudly and publicly and lay down what the consequences will be. Maybe there could already have been court orders and ways to compel companies to assist at the management level (in probably any country), and maybe there could potentially be moles (from any country) hiding anywhere, but if the more tinfoil hat interpretations are correct this turns every employee on that continent into a mole, and even worse, risks accidental compromises through incompetence (beyond the specific target of a warrant/order/whatever). Right?
In the late 90s I recall hearing of crypto work being done in Australia to avoid the crypto export laws of certain other countries. If I'm remembering that correctly, its software development economy may have benefited in the past from other countries making choices like these, and I suppose it will now suffer. Why would a bank or whatever want to expose itself to that? Australian offices could totally finish up blacklisted for certain software projects.