Submission to the Department of Home Affairs on the Exposure Draft of the Telecommunications and Other Legislation Amendment (Assistance and Access) Bill 2018
Ádám Molnár, Elizabeth O'Shea, Monique Mann, Angus Murray, P Tonoli, Bruno Watt, Suelette Dreyfus · QUT ePrints (Queensland University of Technology) · 2018
On 14 August 2018, the Department of Home Affairs released an exposure draft of the Telecommunications and Other Legislation Amendment (Assistance and Access) Bill 2018 (“the Bill”). By gaining access to an exceedingly broadly defined class of 'designated communication providers’ and encrypted data, the Bill aims to limit the exploitation of communications technology by terrorist organisations, child sex offenders and criminal organisations. Whilst the protection of the Australian community is obviously important, it is incumbent on Government to ensure that this is achieved in a manner which is necessary and proportionate. This Bill creates extremely broad powers with almost no oversight without any substantive justification. The possibility that such powers might be needed in future is not a proper basis for the making of laws. Among other things, the Bill effectively enacts insecurity by design, which will almost certainly create additional obstacles and exclusions for Australian companies seeking to operate in EU markets. We recommend that members of the Australian Parliament reject the Bill wholesale, as this is the most appropriate response to the exposure draft in the opinion of the authors of this submission. The remainder of this submission should be read with this recommendation in mind. We have numerous serious concerns with this Bill, in particular that it: 1. Introduces a seemingly scopeless definition of “designated communication providers”; 2. Increases the obligations on communication providers to assist with law enforcement agencies; 3. Introduces covert computer access warrants enabling law enforcement to search computers and electronic devices without an individual’s knowledge; and 4. Increases the powers of law enforcement to use and apply the currently available search and seizure warrants. The Bill grants the Director-General of Security, the chief officer of an interception agency and the Attorney-General additional powers to issue new types of orders. These include, directly and indirectly, forcing communications and technology companies to provide information about how networks are built and how information is stored, or to directly access encrypted data if they have a key. Taking this further, the Bill also grants the power to compel companies to engage in actively building new tools and mechanisms at the request of law enforcement agencies. There is no warrant or oversight process proposed other than that these orders must be “reasonable and proportionate.” While the government has pointed to the potential for people to challenge in the courts, there is no outline of what this process will be or how the courts will be equipped to handle them. Indeed, this would require knowledge of the use and deployment of these new powers and, within the ambit of the Bill, it seems unlikely that this would be possible for end-users affected by the operation of this Bill. The powers within the Bill prevent people from revealing any information about any order they receive – with fines and jail time for those who do speak out. The legislation also does not seem to be limited by what “assistance” organisations can be ordered to do. The government claims the legislation specifically forbids activities that would provide a ‘systemic weakness or vulnerability’ into an encrypted system. However, the kind of operation that the government is planning doesn’t require an active creation of a weakness, instead opting for an end-point activation. Most encrypted services allow you to have multiple devices such as a phone and a computer, which can be end-to-end encrypted between all endpoints. If the government could secretly add a new device to that conversation without your knowledge, it would be building a new door into that encrypted communication. An organization, whether Australian or not, that fails to comply with a notice can be fined $10,000,000. An individual can be fined up to $50,000 and, depending on the circumstances, can face up to 10 years in prison. The Bill’s wide remit means companies with even minimal connection to Australia could be subject to notices and the corresponding punishment. This submission contains 35 recommendations pertaining to specific measures in schedules 1, 2 and 3 of the Telecommunications and Other Legislation Amendment (Assistance and Access) Bill 2018.