Live data from Hacker News

BundesMessenger, a secure messenger for Germany’s public administration

element.io

81–90 of 278 posts

Re: BundesMessenger, a secure messenger for Germany’s public administration

#81

I really like the idea. But I am skeptic - digitalisation of Germany's public services and offices in the past hasn't exactly been a success story.

It hasn’t but it’s on the right track. I am working as a developer in one of the federal agencies and have direct contact with the efforts. It helps a lot that public agencies can now offer a so called IT Zulage of a few hundred euros to 1000 per months that brings salaries on par with the private sector. In my team, this worked wonders and we managed to get some really good people. On the other hand, the task is eno…

As a user of some public sector German IT Services (provided by dataport to be specific) I have to say that I wouldn't work on them for double my current wage.

The jank was incredible and just using them you could feel the spaghetti code, incompetence and age. My advice would be to stay away as far as possible. As a user and as a developer.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#82
post #75

Hasn't Element/Matrix been problematic in the past?

It certainly hasn't been w/o growing pains or detractors.

I still occasionally get rooms or spaces borked, and that frequency increases if E2EE is enabled.

The current server implementation is not svelte in the least, but that's a problem that's being solved with new server implementations that are already 90% of the way there (look-up Dendrite and Conduit if you haven't heard of them).

Re: BundesMessenger, a secure messenger for Germany’s public administration

#83
post #73
post #38

Germany was quite advanced when it came to technology but then the drive to make more of it somehow stopped. It has always been incredibly sad to me that the German ID card (Personalausweis) has an RFID chip inside with trust zones, certificates, authorization features, and much more and just never had been used. Like at all except for getting cigarettes at vending machines. 12 years after the first RFID Personalausw…

A couple of years ago, I would have concurred. But for some time already you have the possibility to use the e-ID through Postident ( https://www.deutschepost.de/de/p/postident/privatkunden/iden... ) which is kind of well integrated in many businesses. Moreover you have private / corporate solutions like Verimi ( https://verimi.de/ ) that incorporate functionalities of the e-ID. There is even an alternative ( https:/…

The official app is already open-source:

https://github.com/Governikus/AusweisApp2

Re: BundesMessenger, a secure messenger for Germany’s public administration

#84
post #79

Earlier quoted context omitted.

It doesn’t take a religious nut or a conspiracy theorist to see the catastrophically enormous downsides of universally mandated, centrally managed, and cryptographically-backed state identification cards, complete with RFID. Imagine, for example, that upon declaring a protest unlawful, the police could simply scan all the RFID-enabled ID cards in the area and issue everyone a court summons. Not carrying an ID card? N…

There is quite a lot of slipper slope going on here. > centrally managed, and cryptographically-backed state identification cards, complete with RFID. Does not necessitate: > universally mandated > No access to anything > felony to do so intentionally > Your 2FA and disk encryption is mandatorily tied to your ID card All the latter things are awful, but we can have the first thing without any of the latter things.

Believe me if you have the first thing the latter things will eventually follow. At least in the EU "universally mandated" has been a reality for a very long time.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#85

I think messaging is an area where Europe could have an impact. The basic problem with messaging and voice/video comm applications is that clients are not interoperable. It is easy to think that: we've had CUSeeMe, IRC, ICU, AOL Instant Messenger, Tivejo, MSN Messenger, I think more than 10 kinds of Google Chat, Facebook Messenger, Skype, Zoom, Paltalk, Yahoo Messenger, Signal, Telegram, Go2Meeting, Discord, WhatsApp…

Curiously many of the messengers you mentioned are or were at least initially based on the same protocol, XMPP, some of them even were interoperable for a time[0]. There are still attempts at realising interoperability, notably libpurple[1], but they are fighting a constant uphill battle. Sadly companies usually just have more incentives to either keep their services walled off or extend only theirs in functionality, rather then keeping them interoperable. This would only change through regulation, or I suppose if a federated service gains enough traction to become the de-facto standard, but given the fate of XMPP that seems unlikely.

[0]: https://en.wikipedia.org/wiki/XMPP#Non-native_deployments

[1]: https://en.wikipedia.org/wiki/Pidgin_(software)

Re: BundesMessenger, a secure messenger for Germany’s public administration

#87
post #61

Earlier quoted context omitted.

It is always puzzling to me with how Germany has many cultural similarities with us Nordics and is an advanced science nation, yet is always so much slower in adopting new technologies. In Norway we have used electronic receipts since 2013. That is like a decade. But I suspect it is a difference in attitude. I think in Scandinavia we are generally far more enthusiastic about new things.

Germans have diffuse fears of new technology. Many of us are skeptical whenever it comes to new gadgets, especially if the risk of being tracked or spied on plays a role. Eventually most people level out and get it anyway, like the cell phone, the smart phone, credit cards, Google/Apple pay, etc. Not sure if our history has something to do with it so that many feel uneasy about giving away too much control about our…

> Not sure if our history has something to do with it so that many feel uneasy about giving away too much control about our personal data, but maybe it does.

Germany has seen two dictatorships in the last century. The first one was more brutal, but the second one maintained a gigantic spying apparatus on its citizens, that took a large fraction of the state's budget.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#88
post #73

Earlier quoted context omitted.

A couple of years ago, I would have concurred. But for some time already you have the possibility to use the e-ID through Postident ( https://www.deutschepost.de/de/p/postident/privatkunden/iden... ) which is kind of well integrated in many businesses. Moreover you have private / corporate solutions like Verimi ( https://verimi.de/ ) that incorporate functionalities of the e-ID. There is even an alternative ( https:/…

The official app is already open-source: https://github.com/Governikus/AusweisApp2

True, that wasn't well formulated.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#89

Another virtue signal from good 'ol Deutschland. Where 75% of the population prefer cash. "Do what we say, just don't do what we do", as the old adage goes. How painful.

I prefer cash and would at the same time use an encrypted messenger to communicate with the government. While cards are certainly convenient, they have failed me at very inopportune moments. I’ve also recently witnessed how someone could not book a ticket for a ferry in one of the mostly cashless European states - cash wasn’t an option and they didn’t have a card. This was at the official counter at the harbor. A few…

I am not a young person anymore & card payments have almost never failed for me (unless it was for a specific/resolvable reason).

> A few month ago, card terminals of a widely used type failed hard in Germany, only cash payment was possible.

This exactly is part of my point.

> or my medical provider is entirely orthogonal to that.

I prefer a medical provider that does a good job & shares my data, rather than incompetent medical staff that adhere to privacy policies. I expect my doctor to be a good doctor, not a good data policy keeper.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#90
post #75

Hasn't Element/Matrix been problematic in the past?

It certainly hasn't been w/o growing pains or detractors. I still occasionally get rooms or spaces borked, and that frequency increases if E2EE is enabled. The current server implementation is not svelte in the least, but that's a problem that's being solved with new server implementations that are already 90% of the way there (look-up Dendrite and Conduit if you haven't heard of them).

getting borked?
Post reply on HN