This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.
This doesn't seem very meaningful? I live in the US. If the Australian government goes to me and tells me to sabotage my employer, I can tell them to pound sand.
The point is that all software engineers (in Australia) being able to be co-opted as saboteurs is a fairly "meaningful" problem and should be a concern to everyone...
There was a "consultation period" and 99.7% of the submissions were against it.
https://www.reddit.com/r/australia/comments/a3j466/assistanc... https://docs.google.com/spreadsheets/d/1dowpZ_Xtr1N_DgkHJN8i...
All it took to convince the representatives and senators was for a submission from the Australian Federal Police that it was necessary to investigate threats over Christmas.
Even someone's little SaaS can be asked to turn up dirt on someone. I literally couldn't comply. I don't write encryption algorithms for a living I just build websites. I can't not encrypt people's data and according to european laws I can't store most of it anyway. Here, gov, have a username, email address, and this blob of encrypted text. Enjoy the insight.
It's getting so hostile to do business in software. At least construction and engineering liabilities are clear cut. I don't even know what my risks factors are anymore and they change every month.
It took longer than expected, but the governments have finally decided it's time to ruin the internet. I am going to go be a carpenter or something.
What a shitshow.
I don't think you'd have to "break encryption" or do anything advanced, the main thing they're looking to ask is to circumvent encryption. For example sending the plaintext password for a specific user from the login form, or OS backdoor, etc., delivered through a special software update just for that user. Additionally the wording of the law does not allow for an inability for you to do it, I believe you would be compelled to hire someone that can.
How do you advertise for the position? Lie about the job and then once they are on board the government hits them with the no-tell paperwork? What a shitty person I would have to become to make that happen, and I would have no choice at that point.
Perhaps they would have a saboteur on staff they would be willing to lend. Very hard position to hire for, no doubt.
Actually I'm not sure you could hire a contractor, since you'd probably be under a secrecy constraint and wouldn't be able to tell them what needed to be done.
You’re clearly smart and lucid. Me perhaps less so but I have some spare time. Who else? Where are they gathering? What can I do?
I’m talking basic communications and publicity stuff, not anything anarchistic. Helping non-tech journalists. Writing articles to help the public understand this stuff. Lobbying MPs.
Maybe I just found a way to keep myself busy...
Honestly, not bad advice.
Given the politics and bs around the big corps and govt ministries my skillsets fit into (business analyst/pm) a trade has been something I've been considering seriously for a while now. The peace of mind and lack of toxic office cultures is really appealing. They're apprenticeships too, so you're paid as you learn.
Being in NZ, I wonder: do you know Mike Rowe, from the American TV show 'Dirty Jobs'? If not I encourage you to research him and the TV show. It's not very often I recommend television.
Just thought I'd note that. This is crazy.
This is something I'm seriously considering. I live in Europe anyway, and at this rate I have zero interest in ever living in Australia again. I won't return, and I won't do anything to support Australia in any way, if I have to go down this path.
The Australian government has truly committed a hostile act against its own citizens.
On the other hand, if I were a global company developing proprietary software with development offices in Australia I'd be pretty concerned... and complain loudly and publicly and lay down what the consequences will be. Maybe there could already have been court orders and ways to compel companies to assist at the management level (in probably any country), and maybe there could potentially be moles (from any country) hiding anywhere, but if the more tinfoil hat interpretations are correct this turns every employee on that continent into a mole, and even worse, risks accidental compromises through incompetence (beyond the specific target of a warrant/order/whatever). Right?
In the late 90s I recall hearing of crypto work being done in Australia to avoid the crypto export laws of certain other countries. If I'm remembering that correctly, its software development economy may have benefited in the past from other countries making choices like these, and I suppose it will now suffer. Why would a bank or whatever want to expose itself to that? Australian offices could totally finish up blacklisted for certain software projects.
For example, in Britain you can be arrested for modestly offending someone on Twitter, due to their speech crime laws.[1] That's never going to commonly be the case in the US due to very strong speech protections.
Australia did away with its guns. The US is never going to follow that example. Australia's actions were not a trial for what would happen in the US.
The large counter examples to your premise are numerous.
[1] https://www.independent.co.uk/news/uk/arrests-for-offensive-...
But yes, FVEY isn't an overarching conspiracy that implements all digital authoritarianism, nor does it have a monopoly on promulgating such corruption - I doubt FVEY itself coordinated the attack on Kim Dotcom. Nor is it the only such conspiracy - Sweden isn't part of FVEY yet eagerly went after TPB and Assange.
But pointing to such agreements is a good analogy for the similar ratcheting totalitarian trends we observe across countries - how intertwined the governments are, and how willingly they give up their citizen-subjects to each other. This is the larger issue - regardless of the actual mechanics of pollination, we can be sure that after the bugs have been worked out in Australia, we'll be staring down the same exact bullshit in the US.
(And I do apologize for blowing up a thread about Australia with US centrism. The point is that we, the people, are ultimately all in this together. Looking to US-exceptionalism as a reason to write off what's happening in Australia as their own problem is a broken outlook)
That's funny, the only exceptionalism I feel we've exhibited for a while is our exceptional ability to bury our heads in the sand and deny the existence of all the inconvenient problems we have to address in the future. :/
Each nation in question has different protections, or lack thereof, when it comes to privacy, speech, property rights, et al. One size will not fit all, each country would see a different response to the same attempted legislation. The US Government has tried for two decades - with very little success - to reach for something equivalent to what Australia just rushed through in no time at all. What would completely rewrite so much US law and interpretation so rapidly as to make such a drastic change possible in the US anytime soon? Nuclear terrorism, as a society shaking event, is about the only thing that comes to mind as plausible and that's far-fetched.
USG basically tried once to mandate backdooring encryption itself - in the 90s, when the entire topic was only relevant to a small community, there was basically no low level "street crime" involving encryption, and doing so required restricting individuals' distribution of software.
The renewed push is based on telling commercial companies that they have to setup their systems to assist the police, completely in line with precedents like CALEA. The much more diffuse tech-using community is already primed for heavy handed authoritarianism based on how these companies already operate, and also in general due to being pumped full of the terrorism by the 24/7 "news" cycle. I'd hope you're right that the US has constitutional protections to backstop this, but from my perspective those "protections" serve more as coping mechanisms rather than as effective restraints on government power.
I can perhaps see a legal exception for US Free software devs who aren't working commercially, but I can just as well see a malinterpretation declaring them as engaging in commercial activity ala Wickard v. Filburn.
No it didn't. Saying it did helps prevent the US implement similar measures.
Perhaps people outside Australia should also be wary of software from companies that do business in Australia, if there's any reason to think that the Australian government may want your data.
They are so the US and other 5 eyes members can spy on their own citizens in ways that are illegal under their own laws.
These laws are terrifying for everyone, not only Australians.
The US is particularly aggressive about not ceding legal / constitutional sovereignty to other nations or entities.
There is no law in the US prohibiting me from creating an alternate login screen for one particular customer just in order to capture their login password. So as a US citizen I have no defense within Australian law against an Australian demand that I capture the password of one of my users... perhaps a parliament member of the Australian opposition.
I can choose to simply ignore the demand. The US will not extradite me for violating a foreign law that does not have an equivalent in US law. But I suppose I can never go on vacation to Australia.
> Circumventing an electronic protection
> Unauthorised access
The company providing the protection cannot by definition circumvent it or be unauthorized. If a third party decides to deliver a payload to your browser to discover your Facebook password, then they are violating the DMCS in the US. But if Facebook decides to deliver a payload to your browser to discover your Facebook password that is simply them doing business in a different fashion. This isn't a violation of US law, so refusing it do it would be a violation of Australia's very poorly-considered new law.
Now if the TAN/TCN was issued to a US based company that would be a different issue but then you as an individual would not be in violation of it.
Not that that makes it a better law, but I think for people not physically in Australia the risk of being issued an enforceable (under Australian law) TAN/TCN is quite low.