“Harvest now, decrypt later” — why your encrypted data is already being stolen for a computer that doesn’t exist yet
Sep 17, 2026
Australia has set the world’s most aggressive post-quantum deadline, and the first milestone falls in three months. Here is what the threat actually is — and what it means for anyone holding data with a long shelf life. In 1943, a small US Army codebreaking unit began quietly copying Soviet diplomatic cables it could not read. The cipher was considered unbreakable, and by the standards of the day it was. They kept the intercepts anyway. Three years later a mistake at the Soviet end gave th...
Smart devices now have to be secure by law — what Australia’s new IoT rules mean for you
Sep 10, 2026
From March 2026, smart devices sold in Australia must meet mandatory minimum security standards under the Cyber Security Act 2024 — starting with a ban on the universal default passwords behind countless botnet takeovers. Here’s what the standard requires, what it doesn’t cover, and how to vet the connected gear already on your network. Take a moment to count the things in your home or office that are quietly connected to the internet. Not the laptops and phones — the other things. The doo...
Where the road ends — what total surveillance looks like in practice
Sep 03, 2026
Ubiquitous cameras, facial recognition, data fusion and social scoring already exist at national scale in one country. Australia is not that country — but much of the technology is the same, and it is worth looking honestly at where the infrastructure leads. Every debate about surveillance in Australia eventually runs into the same objection: you're being paranoid — nobody is building a police state here. And the objection is right, as far as it goes. Nobody is. But the argument was never ...
Nobody changed the password — misconfiguration as the quiet breach
Aug 28, 2026
Exposed databases, public cloud buckets and factory passwords cause more damage than exotic exploits ever will. In 2025, a key copied from old documentation proved the point — and Australia has now written a law aimed squarely at the worst offender. When a serious breach makes the news, the mental image is always the same: a hooded figure, exotic malware, a flaw so obscure only a nation-state could have found it. Sometimes that is the story. More often it is not. A large share of the incid...
This fight is thirty years old — from the Clipper Chip to Chat Control
Aug 24, 2026
Every attempt to build lawful access into encryption since 1993 has made the same promise and run into the same wall. The mechanisms change. The mathematics doesn't. On 16 April 1993, three months into the Clinton administration, the White House announced a new encryption standard for American telephones. It arrived on a tamper-resistant chip, used a cipher the National Security Agency refused to publish, and had one distinguishing feature: a copy of every key it generated would be held by...
The board is personally on the hook now — how cyber became a directors' duty in Australia
Aug 21, 2026
Picture the standing agenda of a mid-sized Australian company. Finance gets forty minutes and an argument. Cyber gets a slide — usually green, occasionally amber — presented by whoever manages the IT contract, and everyone nods. The working theory is that cyber is a technical matter, technical matters get delegated, and delegation is what good governance looks like. Australia's regulators no longer subscribe to that theory. Across three regimes — corporate law, prudential standards and pri...
Your router is quietly working for someone else — SOHO botnets in 2026
Aug 17, 2026
There is a small plastic box somewhere in your office. Under a desk, on a storeroom shelf, or bolted to the wall near the meter box. Someone installed it years ago. Nobody has logged into it since. It has no screen, no alerts, and it appears on no asset register you have ever seen. It is also, by some distance, one of the most attacked devices you own. The uncomfortable part is not that routers get compromised — that has been true for a decade. It is what compromise looks like from the ...
The internet took the wrong turn - BGP hijacking and route leaks
Aug 13, 2026
The day YouTube vanished On a Sunday afternoon in February 2008, YouTube disappeared. Not slowed down, not glitchy — gone, for most of the planet, for around two hours. There was no army of hackers behind it, no malware, no ransom note. The cause was almost embarrassingly mundane. Pakistan's government had ordered local providers to block YouTube inside the country, so Pakistan Telecom set up a routing rule to send YouTube-bound traffic into a digital black hole. Then it accidentally annou...
The master key: how child safety became the argument for watching everyone
Aug 07, 2026
Australia’s metadata scheme, its encryption laws, the UK Online Safety Act and the EU’s Chat Control were all argued for on the same ground. Here is what happened to each of them afterwards. There is a rhythm to the way sweeping surveillance powers arrive in a democracy. They almost never begin with a plain claim that the state should be able to see inside everyone’s phone. They begin with the worst thing you can imagine happening to a child. Once you notice the pattern, it is difficult...
The silent extra participant — the "ghost" backdoor, explained
Aug 03, 2026
Most attacks on encrypted messaging arrive wearing boots. Ban the apps. Break the maths. Scan every message before it's sealed. The "ghost" proposal arrived wearing slippers — which is exactly why it's worth unpacking. Nobody breaks your encryption. Nobody cracks an algorithm. Law enforcement simply joins your conversation, invisibly, like crocodile clips on the copper phone lines of old. The padlock on your chat stays closed the whole time. It sounds surgical. It's actually a demolition —...