Live data from Hacker News

BundesMessenger, a secure messenger for Germany’s public administration

element.io

101–110 of 278 posts

Re: BundesMessenger, a secure messenger for Germany’s public administration

#101

Earlier quoted context omitted.

It hasn’t but it’s on the right track. I am working as a developer in one of the federal agencies and have direct contact with the efforts. It helps a lot that public agencies can now offer a so called IT Zulage of a few hundred euros to 1000 per months that brings salaries on par with the private sector. In my team, this worked wonders and we managed to get some really good people. On the other hand, the task is eno…

As a user of some public sector German IT Services (provided by dataport to be specific) I have to say that I wouldn't work on them for double my current wage. The jank was incredible and just using them you could feel the spaghetti code, incompetence and age. My advice would be to stay away as far as possible. As a user and as a developer.

I wouldn’t generalize it. In our agency, we keep everything very modern, especially the tools and infrastructure, but also processes. We go to workshops and conferences and then implement what we learned.

Yes, I’ve seen some creepy stuff like 100kb of information on one line and a definition file saying from which column to each column one can find information, but we don’t do that.

Like I said, it’s getting better.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#102

Earlier quoted context omitted.

It hasn’t but it’s on the right track. I am working as a developer in one of the federal agencies and have direct contact with the efforts. It helps a lot that public agencies can now offer a so called IT Zulage of a few hundred euros to 1000 per months that brings salaries on par with the private sector. In my team, this worked wonders and we managed to get some really good people. On the other hand, the task is eno…

As a user of some public sector German IT Services (provided by dataport to be specific) I have to say that I wouldn't work on them for double my current wage. The jank was incredible and just using them you could feel the spaghetti code, incompetence and age. My advice would be to stay away as far as possible. As a user and as a developer.

With this approach, it's not likely to ever improve. If they can't get good talent to come in and "fix" things, it will probably only continue to get worse

Re: BundesMessenger, a secure messenger for Germany’s public administration

#103

These guys keep pushing the idea that if it's not federated, it's closed and proprietary. In at least the cases of Signal and Threema that's just not true.

Signal clients may be open source, but as far as I know the network is very much closed and proprietary.

Correct me if I am wrong, but as far as I understand you can't make any changes to the Signal client, compile it yourself, and connect to the Signal network. You have to use the binaries from the app store.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#104

These guys keep pushing the idea that if it's not federated, it's closed and proprietary. In at least the cases of Signal and Threema that's just not true.

Signal clients may be open source, but as far as I know the network is very much closed and proprietary. Correct me if I am wrong, but as far as I understand you can't make any changes to the Signal client, compile it yourself, and connect to the Signal network. You have to use the binaries from the app store.

IIRC you are allowed to get the Signal client from the git master branch and install it yourself, but not sure if that extends to local modifications of the client. They don't want you to distribute binaries however that are connecting to the official Signal network, even if those binaries are the official ones. You are not supposed to find Signal anywhere else than on Google play and the app store.

The server is open source technically, but it's not federated. They have also not published updates in the past for months while deploying them on the server (probably to prevent people from finding out that they were testing some feature).

Re: BundesMessenger, a secure messenger for Germany’s public administration

#105

"Real time collaboration systems such as Microsoft Teams, Slack, Mattermost, Wire, Threema, WhatsApp and Signal are currently all closed proprietary systems - meaning they are walled gardens whereby all parties have to use the same vendor." Signal is in this list. Isn't this false? The server and clients are here: https://github.com/signalapp

Signal is (as far as I know) single-vendor, which they are confusingly calling “closed proprietary”

Re: BundesMessenger, a secure messenger for Germany’s public administration

#106
post #58

Quoted post unavailable.

It doesn’t take a religious nut or a conspiracy theorist to see the catastrophically enormous downsides of universally mandated, centrally managed, and cryptographically-backed state identification cards, complete with RFID. Imagine, for example, that upon declaring a protest unlawful, the police could simply scan all the RFID-enabled ID cards in the area and issue everyone a court summons. Not carrying an ID card? N…

We have many of those things already, but using flaky inconsistent ID forms like drivers' licenses and social numbers.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#107
post #84
post #79

Earlier quoted context omitted.

There is quite a lot of slipper slope going on here. > centrally managed, and cryptographically-backed state identification cards, complete with RFID. Does not necessitate: > universally mandated > No access to anything > felony to do so intentionally > Your 2FA and disk encryption is mandatorily tied to your ID card All the latter things are awful, but we can have the first thing without any of the latter things.

Believe me if you have the first thing the latter things will eventually follow. At least in the EU "universally mandated" has been a reality for a very long time.

Then why haven't they done that already? "Hold your encryption key in escrow" is perfectly feasible without a national ID system.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#108
post #38

Germany was quite advanced when it came to technology but then the drive to make more of it somehow stopped. It has always been incredibly sad to me that the German ID card (Personalausweis) has an RFID chip inside with trust zones, certificates, authorization features, and much more and just never had been used. Like at all except for getting cigarettes at vending machines. 12 years after the first RFID Personalausw…

It's almost as if the spirit of the people was broken as Germany drifted more and more leftward.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#109
post #108
post #38

Germany was quite advanced when it came to technology but then the drive to make more of it somehow stopped. It has always been incredibly sad to me that the German ID card (Personalausweis) has an RFID chip inside with trust zones, certificates, authorization features, and much more and just never had been used. Like at all except for getting cigarettes at vending machines. 12 years after the first RFID Personalausw…

It's almost as if the spirit of the people was broken as Germany drifted more and more leftward.

wow. You won the award of the most stupid comment on this post.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#110
I'm happy to see this. I came out embarrassingly that Germany was spied on by the "ally" US. They already did not trust MS Exchange, probably for good reasons. So they either trust the Swiss (Signal), the Russians (Telegram, prolly not), the ..., or they roll their own, or they use open source. I'm stoked to see they seem (yes: seem) to be doing the latter.

Why do I emphasize "seem". Well there have been several German initiatives for using open source, but non of them stuck very well. Munich's going Linux comes to mind, but there were others. And I'm afraid that this may be another such "attempt", while I hope it this time different as their national security is a at stake.

Telling everyone to communicate with GPG-encrypted emails has shown to be too hard on users, who then simply use one of the many less-secure channels. You have to do something, or you know they --the US mostly (WhatsApp, Twitter, GMail/Chat) -- will listen along with everything.

Post reply on HN