iTnews

Mozilla may treat Aussie staff as 'insider threats' to code base

By Ry Crozier on Feb 25, 2019 5:12PM
Mozilla may treat Aussie staff as 'insider threats' to code base

Seeds of mistrust sewn by anti-encryption laws.

Mozilla - maker of the Firefox browser - and hosted email provider FastMail are worried that individual employees will be put in untenable positions by law enforcement exercising new anti-encryption laws.

In separate submissions to a senate inquiry examining the now-passed laws, the two technology companies raised concerns about how they could trust their workers.

Both Mozilla [pdf] and FastMail [pdf] worry that individual employees could be targeted by law enforcement to make secret changes to systems.

The employee would then be under secrecy provisions that prevented them from even informing their own employer about what they had done.

Mozilla warned that if the laws weren’t clarified, that it may need to treat any Australian workers as potentially “insider threats” to its code base.

“Serving an order on an individual employee rather than a provider itself would fail to allow a provider to avail itself fully of the protections afforded under this legislation in regards to consultations, assessments, and legal challenges,” Mozilla said.

“Further, this potential would force providers to treat Australia-based employees as potential insider threats, introducing another vector for compromise that could undermine trust in critical products and incentivising companies to move critical roles to other localities.”

FastMail, which is based in Australia, said its staff had already “expressed concerns that they may be forced to attempt to secretly add backdoors or security holes in our services - actions that would be just cause for dismissal - and be unable to tell us why they have made these changes.”

CEO Bron Gondwana believed that organisations - rather than individuals - were most likely to be targeted. Still, he said, it would be nice if the laws reflected that, if indeed it is the intent.

“By far the biggest concern for our staff is that they would inadvertently leak information about a capability that we had built in response to a [law enforcement notice], possibly not even knowing that it was built for [that purpose],” he said.

“Any secret capability only known to some people causes “bus factor” headaches for management and is more likely to lead to process breakdowns and a lack of trust within teams.”

Gondwana said he was not only concerned about staff at his immediate organisation.

“This is not just a matter of looking after our own staff’s mental health, it also makes it harder for Australians looking to work for overseas companies if there is any risk that they will be compelled to act against their employer’s interests,” he said.

Mozilla said that secrecy “should not be the default” in any case that law enforcement demands a “capability” be built into someone’s products or services.

“The government should have to periodically justify to the court why the continuation of a restriction on disclosure is warranted, and all orders should become public eventually,” Mozilla said.

The browser maker cited the 2016 San Bernardino iPhone cracking case as an important example of why surveillance capability discussions should play out in public.

It warned that secrecy provisions in Australia’s laws “effectively prohibits the much-needed conversation about the appropriate limits of government surveillance as well as use of exploits that undermine the security of internet users, products, and services.”

Mozilla also sought, among other things, the addition of judicial approvals and a better definition of what constitutes “systemic weaknesses and vulnerabilities”, a key term that is still poorly-defined in the laws.

However, it said that changes to the laws should only be a reserve option, undertaken in the absence of political will to kill the laws entirely.

Mozilla said that it did “not believe that this law should have been passed in the first place”.

“We believe the best possible path is to repeal this legislation in its entirety and begin afresh with a proper, public consultation,” it said.

“This law represents an unprecedented and unchecked threat to the privacy and security of users in Australia and abroad.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
aabill australia encryption security

Partner Content

MSI shows first laptops with Wi-Fi 6E, Nvidia RTX 30 graphics
Partner Content MSI shows first laptops with Wi-Fi 6E, Nvidia RTX 30 graphics
MSI launches innovative new laptops
Partner Content MSI launches innovative new laptops
Improving returns from SD-WAN spending
Sponsored Content Improving returns from SD-WAN spending
NCS expands into Australia in partnership with Optus Enterprise
Sponsored Content NCS expands into Australia in partnership with Optus Enterprise

Sponsored Whitepapers

The risky business of open source
The risky business of open source
Ensure your e-signatures are legally binding
Ensure your e-signatures are legally binding
Mitigating open source risk in your organisation
Mitigating open source risk in your organisation
How to choose a WAF that's right for you
How to choose a WAF that's right for you
The global telco 5G cloud gaming opportunity
The global telco 5G cloud gaming opportunity

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
  • Beat the DDoS blackmailers in 2021
By Ry Crozier
Feb 25 2019
5:12PM
0 Comments

Related Articles

  • India and Japan join Five-Eyes push to break end-to-end encryption
  • Australia's anti-encryption laws need judicial oversight: INSLM
  • Australia's anti-encryption laws stay unchanged
  • Australia's anti-encryption laws ridiculed on world stage
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Telstra blasts plan to 'set aside' mobile spectrum for Optus and TPG, but not it

Telstra blasts plan to 'set aside' mobile spectrum for Optus and TPG, but not it

Accellion hack behind Reserve Bank of NZ data breach

Accellion hack behind Reserve Bank of NZ data breach

Google unravels state-of-art Android and Windows exploit chains

Google unravels state-of-art Android and Windows exploit chains

Tyro halts trading following week-long outage

Tyro halts trading following week-long outage

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.