Talk on HN is comparatively cheap, and I suspect most people would reconsider their position when facing down the very real prospect of serving 5 years in HM Prison Belmarsh.
[1] https://en.wikipedia.org/wiki/Key_disclosure_law#United_King... [2] http://arstechnica.com/tech-policy/2007/10/uk-can-now-demand... [3] https://www.schneier.com/blog/archives/2007/10/uk_police_can...
Principled idiots are of more use to mankind when they're on the loose.
My understanding of s49 is that to convict you, the government has to prove that you had the ability to decrypt at _any time in the past_. If they do that, you can make a defence by showing that you _no longer do_. In other words, if the government shows you ever had the ability to decrypt, the burden of proof changes to you to show you no longer do. Pretty ridiculous.
It does mean that if you can make it patently obvious that you can't decrypt something, you have a good defence. One option therefore is to place control of decryption in the hands of not yourself, but a trusted agent outside the UK (or both, with both required to decrypt).
There may also be grounds for appeal in the ECourtHR, as there is precedent that the 'right to a fair trial' in the EConventionHR includes the right to remain silent, etc.
Perhaps even more importantly, it's the people that care deeply about privacy there, too, and would protest obvious authoritarian moves by the government, while in the UK they seem to care almost as little about it as the Americans do.
Yes the German Government has been caught doing some nefarious stuff but if you compare the totality of what the UK government has been doing against what the German government has been doing, I'll take the German government every single time.
I say that as a UK citizen, also this is one of the areas where the EU has actually been really useful and I have a feeling we might leave in the referendum.
It is frightening how fast a government can eviscerate the very foundations of democracy. This is even more appaling when you look at the fastest growing political power in Germany: The rightists from the AFD. I have no doubt that, what is happening right now in poland can happen in germany too, given enough time.
For example, I am part owner of a Canadian company that sells an online service. If we hire US employees (developers), then we must collect sales tax and pay income tax for sales originating within the governing municipality.
Obviously, I am talking about US tax law, and your question is of a different nature, so the best thing to do is to contact a lawyer who has expertise in that area. I only offer my experience as evidence that the location of employees can impact the legal responsibilities of a foreign business.
As long as you need to live in the UK, you're at their mercy.
If only there was a bigger power that looked a bit more after people's privacy and could stop local governments from doing this...
"7.14 Section 217(8) provides that obligations may be imposed on, and technical capability notices given to, CSPs located outside the UK and may require things to be done or not done outside the UK. Where a notice is to be given to a person outside the UK, the notice may (in addition to electronic or other means of service) be given to the CSP:
-- By delivering it to the person’s principal office within the UK or, if the person does not have an office in the UK, to any place in the UK where the person carries on business or conducts activities; or
-- At an address in the UK specified by the person."
https://www.gov.uk/government/uploads/system/uploads/attachm... -- page 59
I also don't think it's a safe assumption in any jurisdiction nowadays that the person who gets served with a notice will be an executive. It seems quite plausible to me that a front-line engineer could get served with a notice, and not even be allowed to tell an executive. Thus, even if your employees in the UK don't appear to have been coerced, this appearance could be deceiving.
There may be some limited countermeasures to this sort of thing, like regular audits of system configurations, etc. performed by a different group of people, and who will thus cry murder if they find any anomalies. This should work because the second group of people will not be the target of a notice, and thus not bound by its secrecy provisions. Possibly this group could do their auditing remotely, from outside the UK. Of course the in-UK group could, under coercion, rootkit the system to hide these changes, probably by being told to install government-issued software. Hmm...
Even more interesting is how this would work regarding open-source software. You can't keep such a backdoor secret in GPL'ed software and comply with the license, but a UK company couldn't release changes they'd made to comply with the law either. So if you suddenly see UK companies move away from GPL'ed software for no obvious reason, that may be a clue.
(a) Disclosure would likely result in liability for the executive officers and/or Company Directors, which might be contempt of court, or something more serious;
(b) Software developers working for Apple (an example) are likely under strict Non-Disclosure Agreements as part of their employment contracts, so the company served with such a request will likely make it clear to those responsible for technical implementation that it's covered by NDA.
Even in the case of (b) if a developer quits rather than implement the functionality, in many jurisdictions, the employer would have grounds to pursue a gag order.
If I quit a job at Apple over this, Apple might have to sue me for appearances sake, but my GoFundMe account would be quite fattened by the experience.