4 ms·
Well, any software that gets written here can be legally forced to have secret backdoors in it by the government, so I'm not surprised people perhaps don't want
by Rodeoclash 4y ago
Well, any software that gets written here can be legally forced to have secret backdoors in it by the government, so I'm not surprised people perhaps don't want to build products here.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- Youden 4y agoThis is FUD. The law has always had limitations built-in to ensure that this isn't true [0]. The government can only force you to use backdoors you already have, for example if you don't use end-to-end encryption and already have the keys. [0]: http://classic.austlii.edu.au/au/legis/cth/consol_act/ta1997214/s317zg.html http://classic.austlii.edu.au/au/legis/cth/consol_act/ta1997...
- Enderboi 4y agoYou can't be forced to introduce a "systemic" weakness. On the other hand, a certain four-letter agency can certainly craft a TAN requesting you to, say, weaken your key negotiation for a specific client. That's targetted, not systemic. And hey, you're not removing the encryption your just making it slightly less secure. Neatly sidesteps a whole bunch of restrictions in 317ZG. It's only FUD until the policy makers decide it's the norm :P
- Youden 4y agoA "back door" would by definition be systemic, so the initial comment's statement that the government could compel backdoors is FUD. But yes, targeted attacks are permitted, but only so long as they don't cause any collateral damage. Making encryption systemically less secure is forbidden by 317ZG paragraph 3.
- alfiedotwtf 4y agoHave you read the whole legislation? It's not FUD... the Australian government has the powers for full commandeering of it's citizens via TOLA
- Youden 4y agoI've given you a factual basis for my claim that backdoor powers are FUD: section 317ZG puts clear limitations in place that forbid backdoors or any other kind of systemic weakness. If you want to argue that backdoor powers are real and not FUD, please back up your statement with facts (e.g. a limitation on 317ZG or a case where it does not apply).
- alfiedotwtf 4y ago> Designated communications provider must not be requested or required to implement or build a systemic weakness or systemic vulnerability The key words here being systemic. Sure, they can't create a backdoor that will allow weaken everyone's protections, but the way the whole 317ZG is written is that between the lines a "communications provider" can be compelled to provide targeted access to individuals. For example, let's say all our phones have e2e encryption and cannot be unencrypted unless you have a password. There is scope within the act to commandeer Google/Apple (who both have offices in Australia) to push targeted updates to a specific user and save targeted plaintext data or even install a keylogger etc. In other words, this would then give authorities access to plaintext data on the phone without a user's consent, all without being systemic weakness. And I'm writing this based on many discussions with lawyers. I was very vocal about the AABill when most people Australian tech people didn't care, but I can tell you know that a lot of lawers were concerned and reached out. It is commandeering Full. Stop. Want to disobey a TAR, TAN, or TCN? Go right ahead given that you say it's not FUD... but be my guest arguing with: 9 Subsection 3LA(5) Repeal the subsection, substitute: Offences (5) A person commits an offence if: (a) the person is subject to an order under this section; and (b) the person is capable of complying with a requirement in the order; and (c) the person omits to do an act; and (d) the omission contravenes the requirement. Penalty: Imprisonment for 5 years or 300 penalty units, or both.
- rstuart4133 4y agoYes, it's FUD. But it's only FUD because they don't need a new backdoor. They already have one. It's the automatic update system, which ironically has to be there for security updates. The automatic update system means on devices that identify their customers, the act demands any software provider not only provide access to the device via that mechanism, they must also provide assistance such as writing software the host OS won't complain about when it is downloaded using the mechanism. That is why it's called the Assistance and Access act, 2018. It provides access to just about any device, and forces the manufacturer to any and all assistance required to get that access. Devices that identify their users are ubiquitous. Anybody that sells you something in anticipation of getting an ongoing revenue stream from it will have to identify you. That includes Android, Windows, iOS, your Samsung TV, ... Any device that asks you to register with an email address or phone number can be targeted exactly. The act does devote many words to saying all bugs and spying devices must be targeted very specifically like it's some huge restriction, while never going out of it's way to make it plain just about all devices can now be targeted specifically. And yes, security updates are systemic weakness. In fact I refuse to own stuff that is supposed to be highly secure that does allow security updates. Think security tokens, SIMs, credit cards, ... If it's broken I'll go down to the store and anonymously buy a new one thank you. And because security updates are a systemic weakness - the long and flowing waffle in the act about no introducing systemic vulnerabilities is there purely as a smoke screen. They don't need to introduce new systemic vulnerabilities - they already have a perfectly good one.
- Youden 4y agoTrue that an update system could be used maliciously. I wonder though: if the keys needed to sign an update are stored in say an American or Korean HSM and no person located in Australia has access, can the Australian government still compel their use?