Australia to force tech firms to hand over encryption keys
PM Turnbull declares laws of Australia trump laws of mathematics
The Australian government wants to introduce new cyber security laws that would force technology companies to give law enforcement agencies access to encrypted messages, in an effort to clamp down on criminal activity.
Australian prime minister Malcolm Turnbull said on Friday that a law modelled on the UK's Investigatory Powers Act would be necessary in order to curb the growing use of social media a means for terrorists and criminals to communicate.
The proposed law would oblige technology companies to assist security forces in their investigations, although warrants would still be needed to access communications. This includes social media companies such as Facebook and Google, but also device manufacturers like Apple and Samsung.
"We need to ensure that the internet is not used as a dark place for bad people to hide their criminal activities from the law," said Turnbull, speaking to Guardian reporters on Friday.
"The reality is, however, that these encrypted messaging applications and voice applications are being used obviously by all of us, but they're also being used by people who seek to do us harm."
When asked how the new law would prevent users opting for third-party encryption software, such as virtual private networks, Turnbull said: "The laws of Australia prevail in Australia, I can assure you of that. The laws of mathematics are very commendable, but the only laws that apply in Australia is the law of Australia."
Australia faces the same criticism levied at the UK government following the London terrorist attack, when Home Secretary Amber Rudd demanded that WhatsApp give police agencies access to user messages that forcing social media giants to create encryption back doors for law enforcement would in effect create back doors for cyber criminals as well. Turnbull denied that the proposed law would involve the use of these, however.
"A back door is typically a flaw in a software program that perhaps the developer of the software program is not aware of, and that somebody who knows about it can exploit," said Turnbull. "We're not talking about that. We're talking about lawful access."
Facebook has criticised the news, saying that it already has a system for cooperating with security forces, and that the proposed law would be impossible to impose on individual users.
"Weakening encrypted systems for them would mean weakening it for everyone," said Facebook spokesperson Antonia Sanda, speaking to Reuters.
Yet Australia's stance is shared by a number of other countries, including France and Britain, which have expressed a commitment to ensuring security agencies are able to access encrypted messages.
However, proposed legislation from the European Union seeks to take the opposite approach, by making end-to-end encryption compulsory for all forms of digital communication. The draft proposal would prevent service providers from accessing encryption keys, and would render it impossible for companies to 'hand over' messages to security forces.
What you need to know about migrating to SAP S/4HANA
Factors to assess how and when to begin migrationDownload now
Your enterprise cloud solutions guide
Infrastructure designed to meet your company's IT needs for next-generation cloud applicationsDownload now
Testing for compliance just became easier
How you can use technology to ensure compliance in your organisationDownload now
Best practices for implementing security awareness training
How to develop a security awareness programme that will actually change behaviourDownload now