Hacker News new | past | comments | ask | show | jobs | submit login

My understanding is that it would not due to the different app signing certificate. This would be a new application unless Apple or Google signs the app using certificate forgery or similar.



The Australian government could just force Google or Apple to make updates to their OS to not enforce signatures for some apps, or put in vulnerabilities that could be used by them to bypass signature checking at all.


Good luck with that. How do you have any idea its running in Australia or belongs to an Australian?


I'm not a lawyer, but from what I hear any Australian employees can be compelled to change code and be threatened with prison if they tell anyone. Any companies with any presence in Aus can be given demands and gag orders to ensure they can't talk about what is happening.

And if this article is trustworthy, this isn't hypothetical, it's already happening right now. Right now people are being served with orders to do things like this and if they tell anyone (including the company they work for and are in essence "attacking"), they can kiss their life goodbye.

That's what makes it so scary. A programmer that is living in Aus that works for Google or Apple could one day get a notice that they are now mandated to modify code for an unknown reason with the threat of prison if they don't or if they tell anyone. Technically even programmers that don't work for those companies can be compelled to make contributions to open source software to introduce vulnerabilities or exploits, and again there is literally nothing the person can do except follow orders or go to jail forever.


and if the change is caught in a code-review, then what?


I don't know, and I'm not sure if anyone outside of the person who gets the order can know, because these laws are so vague anything can be required.


Maybe Australia would even force Samsung to issue OS updates for as long as an Australian uses the device in question?

Put that way, it sounds like a feature, doesn't it? But perhaps a little implausible?


Good luck with that.


This would be a new application unless Apple or Google signs the app using certificate forgery or similar.

What if Apple or Google changes the OS security mechanism itself?




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: