If the idea was for Australia to lead by example on all the ways to NOT regulate an increasingly digital world, we're doing a bloody good job.
I worked for Atlassian in Sydney. I know there's a pretty decent tech culture that is thriving in Sydney + Melbourne (and elsewhere, I'm sure). I really hope more of my colleagues find a passion for politics and get to a position where they can steer our clearly incompetent government in governance issues pertaining to technology.
In the meantime, does anyone have a clear idea of how this Act will even work? Lets talk in specific terms for something like Signal. I'm assuming Signal has no legal footprint in Australia. How/can Australia compel Signal to allow Australian enforcement agencies to snoop on conversations?
If they can't, won't one of the worst outcomes of this legislation be that any kind of technology company that needs to deal with encryption (which these days should be basically 100% of them) be forced to move overseas? How could a single Australian-based tech company have even the slightest scrap of credibility for data security when a law like this exists?
Final note - is anyone from Fastmail around here? I'm a Fastmail customer and this has me extremely concerned.
Signal: The employee is required to intentionally alter the app to no longer provide security, such that some communication may be intercepted. They are not permitted to publicly disclose that they have done this.
Unfortunately, this goes deeper. The law may be capable of compelling Google or Apple of Australia to force deploy to your phone a malicious version of the Signal app with the "technical assistance notice".
Don't be fooled by the narrative on the amendment.
The truth is that such interception is normal, in Australia, in other countries.
AA is two things. 1st, the government there legalizing an already existing practise to cover their own liability in the event that the grey practise is eventually exposed. Especially amid the current public awareness of privacy.
Next, more importantly, AA is to get around recent security patches that rendered previous vectors now impossible to use, since these collections were often done covertly. It's law compensating for where a much relied on covert method no longer works. Thus, the 11th hour urgency.
The cover story that it is this huge privacy catastophe is just more noise, to distract from the big story; how interceptions like this have been going on for more than a decade.
Will your phone accept an app upgrade which has been signed by Google or Apple instead of by Signal?
If not, is the law capable of compelling your telephone vendor to ship you an upgrade that weakens its upgrade testing enough that Apple/Google can ship you such an upgrade?
Apple controls the root CA on iOS devices. I guess that Google controls the root CA on Android too. Therefore it is within their technical ability to issue a certificate that bears the name of Signal and is trusted by almost all devices. They wouldn’t need to ship any OS upgrades to forge the signature of Signal, as they are already the ultimate authority of who is Signal. I won’t speculate on whether they or their Australian employees will actually do so in the future.
AFAIK, that's not how Android works. Each apk is signed by a standalone certificate (which does not have to be signed by any CA), and the operating system will only allow an upgrade if the same certificate is used. Which means a developer must carefully guard the certificate's private key; if it's lost, the application can no longer be updated, but it must instead be released as a new application with a separate name. And since AFAIK this mechanism is part of the operating system (not the constantly-updated Google Play store), to bypass it would require a full OS update.
(This has other consequences: if a developer releases the same apk to several stores, but it's signed by different certificates on each store, a user who installed the apk from one store will not be able to upgrade it using the other store.)
My understanding is that it would not due to the different app signing certificate. This would be a new application unless Apple or Google signs the app using certificate forgery or similar.
The Australian government could just force Google or Apple to make updates to their OS to not enforce signatures for some apps, or put in vulnerabilities that could be used by them to bypass signature checking at all.
I'm not a lawyer, but from what I hear any Australian employees can be compelled to change code and be threatened with prison if they tell anyone. Any companies with any presence in Aus can be given demands and gag orders to ensure they can't talk about what is happening.
And if this article is trustworthy, this isn't hypothetical, it's already happening right now. Right now people are being served with orders to do things like this and if they tell anyone (including the company they work for and are in essence "attacking"), they can kiss their life goodbye.
That's what makes it so scary. A programmer that is living in Aus that works for Google or Apple could one day get a notice that they are now mandated to modify code for an unknown reason with the threat of prison if they don't or if they tell anyone. Technically even programmers that don't work for those companies can be compelled to make contributions to open source software to introduce vulnerabilities or exploits, and again there is literally nothing the person can do except follow orders or go to jail forever.
If they are ever forced to do that and it becomes public knowledge, I think it will finally be enough for a critical mass of security-conscious people to buy phones with user-controlled platforms where it becomes impossible.
Figuring out people's easy passwords and password recovery methods isn't a weakness in iCloud, and shouldn't be counted as hacking iCloud. And if you were concerned with security, and had to buy a smartphone, what device is better than an iPhone?
Analogies are useful for illustrating a thought, not for supporting arguments. And identity theft (where the victim can do nothing to protect themselves) is not analogous in the first place.
Using multi factor authentication, using long, difficult passwords, and don’t let your security questions be obvious. If someone knocks me out, uses my finger to TouchID into my bank’s app and transfer money, that’s the price I pay for the convenience of not wanting to login with my password. Same with using weak passwords and questions.
You can't seriously say that a multi-million dollar company can't enforce those security features by default.
This is the same as having a car recall and having people dying before the letters reach their homes and saying 'they should have known this company's cars could explode'
I don't understand the purpose of using analogies (valid or not) in this discussion.
Apple could have forced people to use multi factor authentication, and whether or not they should have forced it is a separate discussion that can be had. But I was claiming that your original comment was that iCloud was "hacked" is incorrect, since it implies there was some weakness on Apple's technical backend.
Not forcing secure by default practices in your secure devices is a weakness on Apple's technical backend.
Maybe they should take a couple of notes for their broken cloud implementation from another phone manufacturer in the space that takes security seriously:
The celebgate phishing attacks involved more Google accounts than Apple accounts.
>According to court filings, Collins stole photos, videos and sometimes entire iPhone backups from at least 50 iCloud accounts and 72 Gmail accounts, “mostly belonging to celebrities,” between November 2012 and September 2014, when the photos were posted online.
> Signal: The employee is required to intentionally alter the app to no longer provide security, such that some communication may be intercepted. They are not permitted to publicly disclose that they have done this.
Replace "Signal" with "OpenBSD" and watch the freaking fireworks.
(Why OpenBSD? De Raadt hasn't promised to be "nicer" recently. Linus has.)
Seems like a fair summary would be that since they don't offer any truly secure services (e.g. e2e encryption), there's nothing that this law could require them to subvert. Turning over an individual's account data pursuant to an Australian issued warrant was something they were already doing, and nothing about that has changed under the new law.
There's no reason to be concerned about fastmail like there's any kind of uncertainty, your account is comprised and you were given warning it was going to happen.
Meta-question: Obviously, the whole thing is rotten because of the secrecy. But is is better to do what Australia is doing, by making it a law which can at least be talked about, or doing it anyway, but covertly, like certain other five eyes countries (and beyond)? I don't really have an opinion or answer, just curious.
What Australia is doing is worse, because the actions can’t be talked about.
What the five eyes do is normal espionage. They often get away with it, but when they are uncovered their illegal actions aren’t covered by gag orders.
I worked for Atlassian in Sydney. I know there's a pretty decent tech culture that is thriving in Sydney + Melbourne (and elsewhere, I'm sure). I really hope more of my colleagues find a passion for politics and get to a position where they can steer our clearly incompetent government in governance issues pertaining to technology.
In the meantime, does anyone have a clear idea of how this Act will even work? Lets talk in specific terms for something like Signal. I'm assuming Signal has no legal footprint in Australia. How/can Australia compel Signal to allow Australian enforcement agencies to snoop on conversations?
If they can't, won't one of the worst outcomes of this legislation be that any kind of technology company that needs to deal with encryption (which these days should be basically 100% of them) be forced to move overseas? How could a single Australian-based tech company have even the slightest scrap of credibility for data security when a law like this exists?
Final note - is anyone from Fastmail around here? I'm a Fastmail customer and this has me extremely concerned.