3 ms·
Or, alternatively, maybe it's just not true that you need to do this, because maybe the law doesn't work how most software engineers automatically assume it doe
by ajdlinux 8y ago
Or, alternatively, maybe it's just not true that you need to do this, because maybe the law doesn't work how most software engineers automatically assume it does, and maybe it doesn't apply based on citizenship...
(It's still a really bad law, but for different reasons, and the ridiculous rhetoric from all sides is ridiculous. There's been a few good people like Stilgherrian writing decent commentary.)
- askmike 8y agoThe article states that the law is too vague to know how it will be used: > There is a great deal of vagueness in the law in its current form, and we do not know how it will be interpreted and used when it goes into effect in March. When dealing with security issues, you are dealing with worst case scenarios. If a law can be abused I am happy my password manager has thought about how to best protect me from this scenario. Same as with software vulnerabilities: if 1password detects one that doesn't mean that someone read my passwords, but I expect them to work on it nonetheless for the slight change someone might.
- ajdlinux 8y agoYes, it's a bad law. Yes, in large part that's because it's vague. No, it's not so vague that it's impossible to figure out any limits to the implications for service providers. The worst vagueness is in specific areas (e.g. what does the prohibition on "systemic weaknesses" in mandated technical capabilities actually mean - lots of expert opinion says that the definition of that particular safeguard doesn't actually protect us against very much). The final section of their post discusses a common idea that interception agencies can request individual employees to do things without their employers' knowledge. I'm pretty confident this is bogus, and appears to be based on a misunderstanding of statutory interpretation that some organisations have encouraged (see the thread at https://twitter.com/stilgherrian/status/1072666031963979777 https://twitter.com/stilgherrian/status/1072666031963979777, which includes at least one actual lawyer), and at least one representative of the Australian Government who was involved in drafting the legislation has explicitly denied this (towards the end of the recording at https://www.lawfareblog.com/lawfare-podcast-global-developments-encryption-and-surveillance-law https://www.lawfareblog.com/lawfare-podcast-global-developme..., there may be better and more formal written sources for this). Also, they're wrong about the start date of this legislation - it's already commenced. So, yes, the law is very bad and vague (in parts), and yes, you need to think about worst case scenarios, but that doesn't excuse poor analysis. edit: I should also add that apart from the badness of the law itself, the Government primarily has itself to blame for not communicating with industry and community and allowing wild speculation to go around unchecked - they have really lost control of the narrative here, and that's bad for their own desired outcomes more than anything else.