I am quite worried about free software that implements encryption. As an Australian, I'm quite concerned that software I've written and is free software will be asked to be backdoored by the Australian government. I'm small fish, but if I was a GnuPG developer I'd be more worried -- will GnuPG even accept my patches anymore given my nationality?
I don't believe this is a significant risk, at least for the case of source code. The proposed legislation doesn't allow them to ask for "systemic weaknesses" - so a sneaky change in the source that leaks few bits of key material or something should be out. And a big part of this is secrecy - they don't want those targeted to know they're under surveillance - so it would be self-defeating to ask you to put an "if (user == osama_bin_laden) { send_to_ausgov(msg); }" line in the public source.
If you distribute your free software through an app store or something there could be more risk, in that you might be asked to distribute a binary with code to target certain users - but even there I'd say there's still too much chance that people analysing the binary would discover the backdoor code, so it's doubtful they'd go that way either.
It seems to me that the most likely use of the TCN power would be to ask the OS vendor to deploy some Game Over malware to a targeted endpoint (using their existing update or app store mechanism). We already know what that malware looks like, the hardest part is getting it onto the device.
I find it hard to credit that Apple would stomach this, after they were seemingly prepared to go to the mat with the FBI in the All Writs Act case over a very similar issue. Would they withdraw entirely from the Australian market? You'd have to think that is a live possibility.
My problem with this argument is that the whole "systemic weaknesses" restriction is just a word-game so that the bill can escape certain criticism.
As a hypothetical, if I implement an e2e system which is "entirely secure" and as a provider I have no method of attacking it (and let's imagine it's free software and uses reproducible builds, so users can trivially verify if their binary is backdoored) -- how can I respond to a Technical Assistance Notice? I simply cannot, without taking my existing program and making it insecure. Without creating a weakness which, by the nature of the problem, is systemic.
Do you see what happened? The government hasn't asked me to create a systemic weakness but because of the very situation I've now been forced to make one -- it's just a word-game. They can't ask you to create a systemic weakness, but they sure as hell can put you in a situation where (in order to fulfill a "completely reasonable request" under threat of exceptionally large fines and civil prosecution) you must create a systemic weakness.
Now of course, most programs are insecure and so this hypothetical isn't entirely practical. But the principle stands that there will be many situations where (in order to avoid exceptionally large fines and civil prosecution) companies will opt into creating a systemic weakness out of fear of not being able to comply with future Technical Assistance Notices.
My reading of that is that the authorities would have to ask you for some specific technical solution. You lay out how your e2e system with reproducible builds works, and they ask you for something specific - like a backdoored build. It's up to them to figure out how to deal with issues like the reproducible build one.
The only requirement applied to a Technical Assistance Notice is that "the Director General of Security or the chief officer of an interception agency [...] is satisfied that [...] compliance with the notice is practicable and technically feasible" (317P). So if the case officer is "satisfied" it doesn't really matter whether you can practically follow it -- and it's not clear to me what recourse someone has if they are given such a notice.
Now, Technical Capability Notice restrictions are quite odd. I'm not a lawyer, so 317T.8 is pretty obfuscated to me but it appears to support the argument that they cannot require you to modify a telecommunications system so that it "has the capability to enable a communication passing over the system to be intercepted in accordance with an interception warrant". But I simply must not be reading that part of the bill correctly, because that would imply that e2e couldn't be subverted at all -- which obviously is false because that's precisely what the government wants to do. Technical Capability Notices do have review periods (which can be waived if the Attorney-General says it's urgent) and so on, but I'd be quite worried about how much of a say you really have in those situations...
The 317ZG limitations sound good in theory, but as above it feels like it's just word-games to try to avoid criticism.
Given the criminal penalties for disclosure of "technical capability notice information", I wonder how this situation would work if you were the maintainer of a GPLv3 project where not providing the source code would be a violation of copyright law.
IANAL, but I'm fairly certain that essentially means "anything we require you to introduce is specifically defined to not be a systemic weakness". What do we need reality for when we've got doublespeak?
Apple have already essentially stated they will not make use of Aus tech products if this goes through, as have a few other big players. I'm not sure if EU companies will be able to use Aus tech products and also comply with the GDPR, so there's a rather large chance that our nascent tech industry immediately implodes.
Honestly I pray that's what happens. Maybe the lobotomized masses will then actually start caring about their (lack of) privacy and stop these dimwits from putting everyone at risk.
This question is in light of Huwaei's CFO being extradited from Canada. I know this law isn't something like the Iran sanctions, but I imagine extradition would still be a possibility.