Live data from Hacker News

BundesMessenger, a secure messenger for Germany’s public administration

element.io

181–190 of 278 posts

Re: BundesMessenger, a secure messenger for Germany’s public administration

#181
post #108
post #38

Germany was quite advanced when it came to technology but then the drive to make more of it somehow stopped. It has always been incredibly sad to me that the German ID card (Personalausweis) has an RFID chip inside with trust zones, certificates, authorization features, and much more and just never had been used. Like at all except for getting cigarettes at vending machines. 12 years after the first RFID Personalausw…

It's almost as if the spirit of the people was broken as Germany drifted more and more leftward.

Oh dear. Please don't take HN threads into ideological flamewar. It's predictable, nasty, and not what this site is for.

https://news.ycombinator.com/newsguidelines.html

Re: BundesMessenger, a secure messenger for Germany’s public administration

#182
post #109
post #108

Earlier quoted context omitted.

It's almost as if the spirit of the people was broken as Germany drifted more and more leftward.

wow. You won the award of the most stupid comment on this post.

Please don't respond to a bad comment by breaking the site guidelines yourself. That only makes everything worse.

https://news.ycombinator.com/newsguidelines.html

Re: BundesMessenger, a secure messenger for Germany’s public administration

#183
post #129

Earlier quoted context omitted.

In Germany at least there are several measures in place to make this slippery slope a fallacy (as it usually is) and not realistic. You can pick whether you want to have an ID card or a passport or both. You are not required to carry your ID card with you. In general the actually existing surveillance of mobile phones that were in a certain area at a certain time is much more worrisome to me.

How does that prevent anything? An empty promise today is easily broken tomorrow. The best defense-in-depth against future abuse is not building the abusable system in the first place. Adoption might start as a voluntary choice, but pervasive integration with other technology and services result in it becoming effectively mandatory. > In general the actually existing surveillance of mobile phones that were in a certa…

If you want to argue for a slippery slope you actually have to argue for causal connecting links. You have to demonstrate how you get from A to B. That why slippery slopes are usually logical fallacies. They do not demonstrate anything. It‘s just empty handwaving.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#184
"Matrix is the secure real time alternative to SMTP" I stopped reading there.

I used Element in the past and Matrix is a clusterfuck.

Python server slow, Go server not feature complete. Channels available uninteresting, mostly cryptocurrency. A few porn channels, that's it.

I wish it wasn't so. If anything Matrix is a replacement for IRC, absolutely not email.

Then, I am absolutely NOT installing a Bundes-anything on any of my devices. I can't trust a state that has multiple state Trojans.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#185
post #146

Earlier quoted context omitted.

I actually use my German ID card to communicate with the Elster service of the German tax offices. My old USB signing stick would need to be replaced next year, but using my ID card was the cheaper option.

You can also generate a certificate. Registering it requires receiving a letter by snail mail and it expires every X years (5 maybe?), but otherwise it's just like your certificate for your server you use to SSH in.

2 years

Re: BundesMessenger, a secure messenger for Germany’s public administration

#186

Since Matrix (and thus BundesMessenger?) currently doesn't provide standard security guarantees for its end-to-end encryption (the mitigation to the "Simple confidentiality break" from https://nebuchadnezzar-megolm.github.io/ is still in the design phase; same for the IND-CCA break, but that doesn't seem exploitable in practice) I wonder how much the German government cares about E2EE for its civil servants? The blog…

Gematik co-funded the most recent Matrix audit of vodozemac[1], and is poised to fund 3 more (of matrix-rust-sdk-crypto, matrix-rust-sdk and the whole stack end-to-end) to ensure the E2EE is where it needs to be. So I'd say that the German government definitely cares about E2EE for its civil servants, and we're very grateful for them funding security research. Meanwhile, BWI is helping fund the work needed to address…

> BWI.. also funding work to provide MLS as an option for E2EE in Matrix, https://www.golem.de/news/bwmessenger-vom-messenger-der-bund...

Good news that BWI is funding a Matrix implementation of the multi-vendor IETF standard MLS group messaging E2EE protocol.

The (translated to English) linked reference doesn't mention MLS, is it correct?

Re: BundesMessenger, a secure messenger for Germany’s public administration

#187
post #79

Earlier quoted context omitted.

There is quite a lot of slipper slope going on here. > centrally managed, and cryptographically-backed state identification cards, complete with RFID. Does not necessitate: > universally mandated > No access to anything > felony to do so intentionally > Your 2FA and disk encryption is mandatorily tied to your ID card All the latter things are awful, but we can have the first thing without any of the latter things.

Yet. It's not slippery slope, it's looking ahead. Is the ice on the lake cracked? No. Therefore there is no chance of it cracking? Setup, then execute, not necessarily immediately.

I’m not a Lawyer, but between the 4th, 5th and 14th amendments it seems pretty clear that it’s not a slippery slope, more like a craggily rocky one. Necessitating searchable papers to use the public commons is going to be a pretty difficult argument, between the protection against unreasonable search, guarantee of due process, necessity for search warrants and extention of these rights under state law, it seems pretty far fetched.

The opening of the 4th seems just about tailor made for this(because it was I believe?)

Emphasis mine, obviously.

> The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#188
post #94

This is great "Matrix is the equivalent to SMTP". Goodbye Microsoft or Slack -specific chat services. Welcome them to compete with their Matrix client-apps. And hey, we're in the Matrix finally.

Now I'm just waiting for the Matrix app that I don't hate. And for that matter, the SMTP app that I don't hate.

@Hamuko I have been on matrix several years, and lately I've been really liking Schildi Chat [https://schildi.chat]. Also, many other users that i know really like Fluffy Chat [https://fluffychat.im/]. In any case, there are several more options nowadays.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#189

I think messaging is an area where Europe could have an impact. The basic problem with messaging and voice/video comm applications is that clients are not interoperable. It is easy to think that: we've had CUSeeMe, IRC, ICU, AOL Instant Messenger, Tivejo, MSN Messenger, I think more than 10 kinds of Google Chat, Facebook Messenger, Skype, Zoom, Paltalk, Yahoo Messenger, Signal, Telegram, Go2Meeting, Discord, WhatsApp…

The impact is not likely to be positive. Nearly every government in Europe will want access to the comms happening, particularly if it's within their borders or with their citizens. Europe is not likely to introduce an end-user-to-end-user encryption. It will be encrypted from end user to the government to the next end user.

The EU's DMA regulation, which is the one that will enforce interoperability, explicitly requires end-to-end encryption to be preserved.

Re: BundesMessenger, a secure messenger for Germany’s public administration

#190
post #163

Using open protocols and open source solutions: great idea. Letting some random company operate your army's IT infrastructure: what could possibly go wrong?

Random is pretty load bearing here. The BWI GmbH was literally created to operate the armies non-military IT infrastructure.

They also operate military infrastructure, ie operation planning software and battle management systems [1, from the German Wikipedia article].

[1] https://esut.de/2020/05/meldungen/cyber-it/20897/digitales-g...

Post reply on HN