Live data from Hacker News

BundesMessenger, a secure messenger for Germany’s public administration

element.io

251–260 of 278 posts

Re: BundesMessenger, a secure messenger for Germany’s public administration

#251
post #227
post #168

Earlier quoted context omitted.

In The Netherlands, they are implementing a thing which gives the same advantages (i.e. disclose some attributes about yourself without disclosing unneeded data), but uses different technologies. It's called IRMA, you can find an overview here [1]. It can be combined with other applications to do cool stuff, e.g. with PostGuard [2] you can use identity-based encryption to be able to send an encrypted email to someone…

I'm a little surprised we haven't seen governments try offering identity-based encryption as a way to head off encryption that's harder for them to wire-tap. For the unfamiliar, with identity-based encryption, the recipient's public key is a function of the key authority's public key and some "identity", such as a national ID number or email address. Their private key is a one-way function of their identity and the k…

[deleted]

Re: BundesMessenger, a secure messenger for Germany’s public administration

#253
post #196

Earlier quoted context omitted.

I actually like the idea of becoming a public servant and bringing innovation to places that really matter for basically everyone around me, but salaries are not even in the same ballpark even with IT-Zulage.

It's not the IT salaries that are the problem, it's that many places working on government IT projects in Germany range from slow, backwards and incompetent to outright toxic. These are not environments that attract the best people but usually clueless YES men.

It bears repeating: this is not the case everywhere and the same principle applies to the private sector. You can usually tell from the job description and the interview

Re: BundesMessenger, a secure messenger for Germany’s public administration

#254
post #54
post #46

Earlier quoted context omitted.

I don't speak german, but by video identification do you mean the system in which you turn in the webcam and it checks your face? If so, that is highly vulnerable to real time face swapping attacks (and possibly just recorded webcam footage). I'm sure you're aware, but these systems need to change.

For banking a fairly well known identification provider is "Postident", a service offered by Deutsche Post. They offer plenty of ways to actually authenticate. The classic one is that you receive a voucher, go to a post shop, the employee there checks your ID and prints you a verification code (iirc). They also added video calls for identification and from my experience, it seems as if they are aware of the potential…

> They ask you a bunch of questions and require you to do different things (for example hold your ID card right in front of your face, cover one side of your face, etc) presumably to counter this attack vector.

Give them a little while and the AI will be able to do all that so you can finally prove to the government that you are indeed a panda bear.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#255
post #77
post #38

Germany was quite advanced when it came to technology but then the drive to make more of it somehow stopped. It has always been incredibly sad to me that the German ID card (Personalausweis) has an RFID chip inside with trust zones, certificates, authorization features, and much more and just never had been used. Like at all except for getting cigarettes at vending machines. 12 years after the first RFID Personalausw…

Makes a lot of sense with German culture IMO. There's a culture of doing your job very well, but not much of a culture of thinking outside of the box or shaking things up. Some Herr Doktor probably followed all the best practices to implement "trust zones, certificates, authorization features, and much more" in the ID, doing their job really well. But actually changing the processes to use those features is not anyon…

Wow, after living in Germany for 5 years.. I think I agree with you completely. That last sentence is the best description of the problem I have read.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#256

Given that the protocol is E2EE, how do they handle data retention / transparency requests? Does each agency centrally store copies of their employees' encryption keys?

Funny you ask this, I remember actually having a discussion about doing this, but for another reason - to avoid users losing their messages because they lost their keys. We ended up not doing it of course, it makes no sense to have e2ee if you're going to bypass it anyway... If you need to be able to access the data I think you should probably force your users to not use e2ee rooms...

Re: BundesMessenger, a secure messenger for Germany’s public administration

#257
post #77
post #38

Germany was quite advanced when it came to technology but then the drive to make more of it somehow stopped. It has always been incredibly sad to me that the German ID card (Personalausweis) has an RFID chip inside with trust zones, certificates, authorization features, and much more and just never had been used. Like at all except for getting cigarettes at vending machines. 12 years after the first RFID Personalausw…

Makes a lot of sense with German culture IMO. There's a culture of doing your job very well, but not much of a culture of thinking outside of the box or shaking things up. Some Herr Doktor probably followed all the best practices to implement "trust zones, certificates, authorization features, and much more" in the ID, doing their job really well. But actually changing the processes to use those features is not anyon…

Absolutely spot on

Re: BundesMessenger, a secure messenger for Germany’s public administration

#258

Cute. A secure messenger for the state. And "Chatkontrolle", i.e. client-side inspection and surveillance of every message, for the unwashed masses.

Especially considering that the most recent arrested terrorists targeted police and military employees as conspirators.

But honestly all much better than the NSA listening into German state traffic. The big fives are not friends just allies.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#259
post #216
post #110

I'm happy to see this. I came out embarrassingly that Germany was spied on by the "ally" US. They already did not trust MS Exchange, probably for good reasons. So they either trust the Swiss (Signal), the Russians (Telegram, prolly not), the ..., or they roll their own, or they use open source. I'm stoked to see they seem (yes: seem) to be doing the latter. Why do I emphasize "seem". Well there have been several Germ…

I don't know why the person who was first to respond to you is "dead" but set aside his value judgement; all he wrote is factually correct. The embarrassment you speak of lies in the fact that it became public knowledge, not in the act itself, depending on the perspective of specific institutions. Furthermore, disregarding the fact that signal is in Israeli hands, i'm fairly certain they don't even trust themselves a…

> [The] Munich example, the most significant factors for the outcome of that debacle where at one end incompetent people backed by powerless competent people and on the other end Microsoft with millions of lobby money backed by a powerful state actor.

How is that different when it comes to Matrix/Elements vs proprietary apps? Maybe this time there's not so much lobbying and more "user just choosing a different communication channel" than they are told to use (as it's UX is so much worse).

Re: BundesMessenger, a secure messenger for Germany’s public administration

#260

Given that the protocol is E2EE, how do they handle data retention / transparency requests? Does each agency centrally store copies of their employees' encryption keys?

Honestly, chat is the equivalent of a person to person regular mouth to ear communication. Some stuff needs to be off record. Which effectively means, nothing in chat and not on a formal document is just coordination. Like it was for centuries.
Post reply on HN