[Linux-aus] Grant Application from Fraser Tweedale for Support the myGov Code Generator source code FOI review
Jonathan Oxer
jon at oxer.com.au
Thu Jul 16 22:23:13 AEST 2026
I fully support this initiative by Fraser and would like to see the grant
approved for the full amount.
Linux Australia is generally seen as having a primary role within the Open
Source community as a facilitator of conferences and events. However, it
has also undertaken other roles in the past including lobbying, such as
during the period of the introduction of the Australia-United States Free
Trade Agreement (AUSFTA) way back in 2004/5. I believe that supporting
initiatives such as Fraser's are directly in line with the values and
mission of the organisation:
https://linux.org.au/about-us/values/
It's easy to let issues like this slide. When someone is willing to step up
and take a stand, we as a community should support them.
Regards,
Jonathan Oxer
On Thu, 16 Jul 2026 at 21:08, Linux Australia Website via linux-aus <
linux-aus at lists.linux.org.au> wrote:
> Your Email Address: frase at frase.id.au
> Project name: Support the myGov Code Generator source code FOI review
> Grant Type: Project Grant
> Aim of the project: I am applying for a grant of $5,000 to help cover
> litigation costs in a Freedom of Information review at the Administrative
> Review Tribunal. The matter is *Tweedale and CEO, Services Australia*, file
> 2025/4916. I applied for review of Services Australia’s access refusal
> decision in relation to my request for access to the source code of the
> myGov Code Generator app, a (now retired) mobile app published by Services
> Australia for myGov login MFA (TOTP). The case involves critical questions
> about government transparency and software security, the validity of
> “security by obscurity” arguments in this context, and the benefits and
> consequences of governments granting access to the source code of
> applications they develop and expect citizens to run on their devices.
> Much more detail about this matter, and regular updates, are available at
> https://openmygov.au.
> The outcomes of this legal proceeding and my associated efforts will
> include:
> * Precedent: A binding or persuasive administrative law decision regarding
> the accessibility of government-developed source code under Australian law,
> and the validity of “security by obscurity” arguments for refusing access.
> * openmygov.au: continued free, unhindered public access to all
> disclosable submissions, evidence, expert witness reports, decisions and
> other documents, and a chronicle of the conduct of this case—in other
> words, a legal toolkit for future open-source FOI litigation in Australia
> (and possibly useful elsewhere)
> I am happy to answer any questions or provide further information to
> Council and/or the Linux Australia membership in support of this
> application.
> ## Risks and disclosures
> ### Impact on LA funding and government relations
> Impact: Actively financing public-interest litigation against a major
> Federal Government agency may have a chilling effect on future sponsorship
> opportunities for LA-auspiced events, or otherwise introduce friction in
> LA’s interactions with Government.
> Mitigation: Contributing to the costs of this litigation does not enjoin
> LA as a party or subject LA to any risks of further direct costs. Also, the
> matter and the purpose of the review is aligned with Linux Australia’s
> values and purpose and is being pursued in the public interest; it is
> unlikely to be perceived as frivilous or vexatious.
> ### The Tribunal decides against transparency
> Impact: Should the Tribunal agree with the Respondent’s “security by
> obscurity” arguments and refuses access, it sets an unfortunate precedent.
> Mitigation: This is barely worse than the status quo, where agencies
> refuse access for these reasons anyway, but those decisions are not
> challenged. Grounds for appeal (judicial review) in Federal Court will be
> considered, although costs would be in another order of magnitude and may
> be prohibitive. Win or lose, the community will have an extensive and
> durable record of and playbook for FOI litigation involving open source and
> cybersecurity matters.
> ### Disclosure of EO2027 treasurer role
> I am a core organising team member and the appointed Treasurer for the
> Everything Open 2027 conference, which is an official subcommittee of Linux
> Australia. I have no influence over grant funding decisions, and conference
> money is managed in complete separate accounts.
> Estimated cost breakdown of the project: Through a successful Pozible
> crowdfunding campaign early in 2026, and an ongoing Chuffed campaign, I
> raised approximately $20,000 to help with the costs of this litigation.
> Though I always expected costs to exceed this amount, procedural battles
> over Services Australia’s national security claims and applications for
> confidentiality orders over critical evidence have depleted these funds
> sooner than expected. We are now in an intense phase, finalising the
> evidence and submissions. The substantive hearing is listed for 3 days from
> 2–4 September in Melbourne.
> Cumulative costs by the end of this proceeding will certainly exceed
> $30,000, and could end up in the range of $40,000–$50,000. The shortfall
> between funds raised (so far) through crowdfunding campaigns and the
> eventual costs is therefore at least $10,000 and possibly much more. In
> addition to Wise Law’s fees (the biggest expense by far), my costs include
> travel to and accommodation in Melbourne for the hearing, and for a one-day
> strategy meeting back in February. (Wise Law and both expert witnesses are
> based in Melbourne.)
> I am applying for a **$5,000** grant to help close this gap. I would
> gratefully accept any lesser amount the Linux Australia Council deems
> appropriate, as I recognise that the requested amount is a significant
> proportion of the 2026 grants program budget, and I do not want to
> disadvantage or preclude other worthwhile grant opportunities.
> Project team details: I (Fraser) am a free software developer and active
> member of the Australian open source community. Most of my work over the
> last decade has been on open source PKI, authentication and identity
> management solutions, and supply chain security. I will give evidence in
> this proceeding on open source public policy and law in Australia and
> around the world, and on cybersecurity matters.
> I have engaged two expert witnesses to assist the Tribunal, both known to
> the LA membership and Australian open source community: cryptographer and
> electoral security researcher Dr Vanessa Teague; and Dr Peter Serwylo for
> his Android expertise and involvement in the F-Droid project. Vanessa and
> Peter are providing their services free of charge.
> My legal representative in this proceeding is Jason Bosland of Wise Law, a
> boutique cyber law firm based in Melbourne. Jason is an expert in
> administrative law, and he has a good grasp on the technical aspects of the
> case. Wise Law are generously providing their services at a 50% discount,
> in recognition of the public interest nature of this case. Jason has also
> employed a paralegal to help with preparation of my case; this will reduce
> costs because the volume of evidence and submissions is significant.
> First Name: Fraser
> Last Name: Tweedale
> Email Address: frase at frase.id.au
> A statement including a willingness to provide regular project updates on
> the project: I publish detailed information and updates about this case at
> https://openmygov.au/. All information I can publish, I do, including
> submissions, evidence, and Tribunal decisions and orders. It will form a
> significant and valuable artifact for Freedom of Information applicants or
> litigants, and people interested in the intersection of free/open source
> software, public policy, and administrative law.
> I am committed to absolute transparency with respect to all funds received
> (from all sources) and all expenditure, including publication of invoices
> and bank statements (I have a dedicated bank account for this purpose).
> _______________________________________________
> linux-aus mailing list
> linux-aus at lists.linux.org.au
> https://lists.linux.org.au/mailman/listinfo/linux-aus
>
> To unsubscribe from this list, send a blank email to
> linux-aus-unsubscribe at lists.linux.org.au
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.linux.org.au/pipermail/linux-aus/attachments/20260716/179686b9/attachment-0001.htm>
More information about the linux-aus
mailing list