Live data from Hacker News

Luca App: CCC calls for a moratorium

ccc.de

151–160 of 169 posts

Re: Luca App: CCC calls for a moratorium

#151

Earlier quoted context omitted.

I only have positive things to say about our contact tracing application. It’s open source https://github.com/immuni-app . It’s simple: contact tracing only, easy for non technical people. And has minimal tracking (I only see a periodic ping to get.immuni.gov.it)

Yeah. Too bad nobody downloaded it

Immuni is the official contact tracing app for Italy with 10mm downloads.

Re: Luca App: CCC calls for a moratorium

#152
> Mecklenburg-Western Pomerania even wants to make installation of the app a prerequisite for participating in public life.

This is the trajectory for everything essential it seems. Want to function in the modern world? You need a pocket computer with approved applications on it to do increasingly important, but basic tasks. Banking, health, transportation, etc. are all sitting on the pocket computer that can watch where you go and track what you do to the minute.

Re: Luca App: CCC calls for a moratorium

#153
post #29

There is so much incompetency in governmental IT/software decisions and software it's actually sad. Is it a product of smart people simply not working in this sector or corruption?. It seems from the outside to be filled with imbeciles masquerading as administrators. We need to somehow make the government way more accountable, if only there was an organization that could do that, we could call it the media.

Due to various reasons, government IT jobs pay a fraction of private sector jobs. So they tend to have slim pickings when it comes to hiring skilled people.

Re: Luca App: CCC calls for a moratorium

#154

Earlier quoted context omitted.

Yeah. Too bad nobody downloaded it

Immuni is the official contact tracing app for Italy with 10mm downloads.

Which is not "nobody", but it is not even close to the statistical threshold of "enough use, helps prevent the spread of the disease"

Re: Luca App: CCC calls for a moratorium

#155

Earlier quoted context omitted.

Exhibit B: Ubirch and their 5 Blockchains https://www.heise.de/news/Digitaler-Corona-Impfpass-IBM-Ubir...

An issue with the reporting is that the ubirch standard solution is confused all the time with the actual project. Especially since it is mostly guessing, not knowledge of the actual technology behind it.

Can't really blame the reporting there imho. At the time that article was written they actively marketed towards the blockchain solution and the government side wasn't really forthcoming with public information. Luckily that changed a few days ago but this article in particular is from March 9th.

Re: Luca App: CCC calls for a moratorium

#156
post #131

Earlier quoted context omitted.

> Unfortunately, nobody's really come up with any reliable process for having the flexibility to get good products for good value, while reliably preventing corruption. I've seen one approach work, but it struggles to scale, as it needs technical people on the client side. Buying "outcomes" rather than services can work well - rather than procuring a specific "specification", you buy a solution. The standard contract…

Problem with that is government is worst customer: don't know what they want, what they have and how to get anything done. It is very hard for companies to commit to deliverables, when incompetent department they need to integrate with doesn't play the ball.

Indeed, however this approach effectively offers them a carrot - if you understand your problem, you can use this (very effective and well regarded) route to getting your problem fixed.

The end result, as you'd expect, is mission-focused solutions to problems with minimal external dependencies. That means the problem gets solved in the simplest way possible, with the least overlap with incompetency possible.

It doesn't work for every problem, but it does show that forcing government to understand the problem before spending money can actually work, at least at some scale.

Re: Luca App: CCC calls for a moratorium

#157

Earlier quoted context omitted.

CCC isn't a hacker space as I understand the term. CCC is a club of security experts. hacker spaces are communal spaces where you can tinker with peers using provided tools.

In Germany the CCC has a lot of physical clubs where people hang out. They have some specialised equipment, but are from my limited experience more social spaces for cohacking, giving talks, etc. There's also the chaos communication congress, with is a big hacker festival/conference (by the same group of people), run by I think the same org, and I've never fully understood how one navigates the identical acronyms...

Typically, the Chaos Communication Congress is referred to by its number and the abbreviation C3. So it's 36C3 for the last regular installment.

Re: Luca App: CCC calls for a moratorium

#158
post #132

Earlier quoted context omitted.

Of course it doesn't! I've yet to meet a procurement team that actually understands what they are buying. Companies like Microsoft focus heavily on "training" and "awareness" of their products and solutions - pure slideware, but speaking the right language. At enterprise-scale, I must concede that Microsoft have a really sleek sales pitch. Group Policy in AD offers a level of "managed desktop" that a low-pay, mid-ski…

Oh my, your post reads like a bureaucracy horror story, but I fear it is not a work of fiction! Regarding client-side restrictions: I doubt I'll ever understand why many organizations appear to be so focused on restricting their employees' computers, some even going for full-blown surveillance. Maybe I'm just a little naive, but is intercepting and filtering all network traffic really the only way to notice whether a…

> Oh my, your post reads like a bureaucracy horror story, but I fear it is not a work of fiction!

Afraid it's not fiction. I see it pretty regularly.

> Regarding client-side restrictions: I doubt I'll ever understand why many organizations appear to be so focused on restricting their employees' computers, some even going for full-blown surveillance.

Several reasons I've seen. Firstly, don't underestimate the importance of protecting people's data at scale. If staff can use their Gmail on a computer, someone will email themselves someone's personal data. Maybe it won't be malicious, but it's still a breach. Maybe it was some software running on the computer (malware) that got in via an ad or game, that simply emails out information.

Governments (and large enterprise) operate at a scale where you need to be careful of data exfiltration by malicious users or software. While you might be able to trust people in a team of 5, it's very hard to scale that trust up to 5000 people.

> Maybe I'm just a little naive, but is intercepting and filtering all network traffic really the only way to notice whether an employee is playing browser games all day (instead of, you know, noticing the employee's productivity dropping)?

This implies that the person's manager is competent enough to actually notice this, and has enough understanding of what they do to act.

Filtering network traffic is often more about preventing data egress of other people's personal information than it is about spotting someone playing candy crush.

> My primary concern that those enterprise firewalls intercepting all traffic (including MitM-ing TLS traffic) regularly prevent adoption of new Internet standards. At the same time, the idea of total communication surveillance seems surreal. Image the equivalent situation 20-30 years ago: What would you have said if your employer hired a team in order to eavesdrop on every single telephone call and open every single letter entering or leaving the office?

In financial services and other regulated sectors, they pretty much did/do that, albeit recorded rather than having someone listen all day long. I agree with you that these kinds of active MITM firewalls likely introduce more issues than they solve - many don't themselves validate the certificate of the site they're MITM'ing properly, therefore introducing a whole new attack vector if you can convince the MITM box to serve up a valid certificate for your site's invalid certificate.

Unfortunately though, for as long as the goal is to make it possible to work at big scale and minimise the risk posed by individual employees, you'll continue to see this be the default way of working, I reckon.

Re: Luca App: CCC calls for a moratorium

#159
post #135

Earlier quoted context omitted.

> The reason it doesn't exist in the private sector The same problem absolutely does exist in the private sector. Many of the same big government contractors are running almost the same scam on big companies. I think this problem is more a function of the size of the organization than public vs. private.

I was referring to the problem of corruption and kickbacks. I'm certainly not saying companies can't overpay for things, but there is an inherent pressure from competition to incentivize companies to try to pay less, whereas taxpayer-funded government often doesn't experience similarly direct pressure.

Corrupt businessmen are a thing.

Re: Luca App: CCC calls for a moratorium

#160

What was wrong with Corona-Warn-App? Looked amazing compared to ‎TousAntiCovid last year yet I'm learning here that it isn't improved anymore and I haven't seen ads for it anywhere. The differences between German states and the way news are communicated is so complicated, and it's been more than a year that it's like that now. As a French citizen living in Germany I can get vaccinated if I go back to France soon (the…

The CWA is developed under extreme scrutiny wrt privacy. It's really good at what it does, so good that even the CCC gave it it's blessing (despite being made by companies that would traditionally be considered evil empire in CCC, which really puts CCC in a very favorable light for objectivity). But that strength makes it the absolute opposite of move fast and break things.
Post reply on HN