5 ms·
It's disappointing that this has had very little coverage and/or discussion in the tech community outside Australia. I realise it's at a national level and the
by coffeecheque 12y ago
It's disappointing that this has had very little coverage and/or discussion in the tech community outside Australia.
I realise it's at a national level and therefore a domestic piece of legislation, but that doesn't stop internet users the world over rallying together on issues like net neutrality and SOPA.
For days, the SOPA campaign was everywhere. It too was a domestic (US) piece of legislation, but it's "forced" on other uses (through sites like Reddit, etc.) in countries where it doesn't specifically apply.
The data retention scheme proposed by the Australian Government is draconian. It has very little public oversight, it costs consumers money and inhibits the free ideal of the internet. At a basic level, the spooks want every IP address of every consumer for every connection to be kept (by the ISP) for two years.
My name, address (subscriber information) will be tied to my IP by the ISP. I connect at 5:43am to Facebook. That's logged. I leave Facebook and log onto Reddit at 5:55am, that's logged. For two years. I send an email to Activists-R-US at 6am, that's logged. Not the "content", just the fact that I did it.
And, best of all, it's all classified as "metadata", so accessing the records doesn't even need a warrant. In fact, any agency in the country with "investigative powers" can request the records from the ISP. That includes, and is not limited to, councils who are investigating lost dogs or parking infringements.
The Attorney-General in Australia, George Brandis, couldn't even describe or explain what he wanted to be retained: https://www.youtube.com/watch?v=EbtgULCY5zk https://www.youtube.com/watch?v=EbtgULCY5zk
We already have fairly tight rules when it comes to internet spying. Every ISP - to get a carrier licence - needs to submit a Interception Capability Plan (ICP) with the Government, explaining how it can - if necessary - tap that connection for spying. If you change your network and it changes the way the lines are tapped, you have to let the Government know straight away.
We also have mandatory retention orders, which can be applied to a subscriber account if a court sees fit. This orders the ISP to keep the information on the user for a limited time.
If the authorities have their suspicions, they have ample opportunity to get what they want under the current laws.
Data retention is, as I said, draconian. It turns presumption of innocence on its head, and it will be used - one day - to track down to prosecute and jail journalists and whistleblowers.
It will eventually be used to track down and prosecute copyright infringers and "trolls".
I realise that's a slippery slope argument, but legislation - once it's on the books - is often used for things it wasn't intended for.
- csirac2 12y agoBut wait a minute - didn't risky.biz' Patrick Gray originally report that the AFP clarified that the "Metadata retention" amounts to merely formalizing the retention of DHCP logs? I mean, there's heaps of shitty things to complain about here (Eg. illegal intelligence activities could send an ASIO officer to gaol for 2 years but a journalist reporting such a thing could go to gaol for 10 years). However I can totally get why authorities should be able to match up an IP address + datetime = ISP user.
- coffeecheque 12y agoThere are many, many different takes on what is wanted. The Government's Communications Minister, the Attorney-General's Department, the Attorney-General himself and the police/spies have all said different things on what will be required. The ISP iiNet has also said that an internal document it received from the AG's Department a year or so back has very, very different requirements on what should be kept than what anyone is saying publicly. Also, I see why authorities want it, but I don't think they should have it. As mentioned, there is already more than enough ways to get the information on targets if they want it. What they are doing is a dragnet style surveillance approach in a democratic country.
- csirac2 12y agoI was under the impression they would continue to use the existing channels of obtaining DHCP logs from ISPs as before (i.e. subpoenas), but the changes were aimed at some ISPs not retaining more than eg. last 7 days logs, or last 30 days/billing period, etc. The RB guys made it sound so simple...