21 ms·
BundesMessenger, a secure messenger for Germany’s public administration
- raybb 4y agoCongrats to the folks running the Element project! I hope this means more development/funding/documentation of the project :)
- Arathorn 4y agoIt does sponsor some development, although we still have a big gap on overall Matrix funding currently (hence trying to drum up additional sponsors and support via https://matrix.org/blog/2022/12/01/funding-matrix-via-the-matrix-org-foundation https://matrix.org/blog/2022/12/01/funding-matrix-via-the-ma...).
- Traubenfuchs 4y agoWhy not use / invest in Mattermost?
- royjacobs 4y agoPerhaps you could provide some initial arguments why they should?
- Arathorn 4y agoMattermost is great, but it's not decentralised, it doesn't federate, it's not end-to-end encrypted, it's not based on an open standard, it's vendor-locked to Mattermost, only has one usable client implementation, and is rather aggressively open core (unlike the BundesMessenger distribution which is entirely apache-licensed FOSS). I'm also not sure that whether deployments easily scale up to million+ users like a big Matrix deployment can. It's worth noting that if Mattermost adopted Matrix, like Rocket.Chat has[1][2], the vast majority of these limitations would fall away :) [1] https://www.rocket.chat/press-releases/rocket-chat-leverages-matrix-protocol-for-decentralized-and-interoperable-communications https://www.rocket.chat/press-releases/rocket-chat-leverages... [2] https://matrix.org/blog/2022/05/30/welcoming-rocket-chat-to-matrix https://matrix.org/blog/2022/05/30/welcoming-rocket-chat-to-...
- jansan 4y agoAh, that's why they did not invest in mattermost.
- Traubenfuchs 4y agoThank you, explains everything! I thought it was completely open source.
- PurpleRamen 4y ago[..]Real time collaboration systems such as Microsoft Teams, Slack, Mattermost, Wire, Threema, WhatsApp and Signal are currently all closed proprietary systems - meaning they are walled gardens whereby all parties have to use the same vendor. That’s impractical, creates vendor lock-in and stifles innovation. There’s simply no way that a government entity using, say, Microsoft Teams would be able to have secure real time communication with another government entity using, for example, Slack, Mattermost or Wire.[..]
- mhd 4y agoAs mentioned in the article, the German health services already adopted Matrix for their "TI-Messenger", which is supposed to make secure communication between health care professionals easier. Or, well, possible at all. Right now this is a morass of "don't mention anything private" emails, letters and faxes. I'm surprised that ticker tape isn't involved somehow. But don't worry, if German health services doing something right is triggering your "the end is nigh!" response: As far as I know, the rollout for patients is still a long way coming and they still don't even have a date set for video chat (right now a cottage industry of anyone involved in HC doing their own WebRTC thing).
- pimeys 4y agoAnd we still have to walk to the doctor's office to get that prescription for the same Asthma medicine you always get every three months. Instead of just getting it electronically to the nearest pharmacy. Now we have to queue up in the doctor's office with sick people, wait for them to print and sign a red piece of paper and then walk to the pharmacy. Maybe this changes too in the future?
- kapep 4y ago> Maybe this changes too in the future? E-Rezept was supposed to launch in 2022 but has been postponed until mid 2023. Some regions already tested it. It didn't work out well, so some regions dropped out of the testing phase. I'm pretty sure it won't work well at launch and we will have to rely on printed prescriptions for quite some time until all pharmacies and doctors use the new system.
- RicoElectrico 4y agoGreetings from Poland, e-Recepta here launched in 2019.
- krzyk 4y agoAnd was given prime time thanks to covid, same as remote call with doctor, which allowed getting electronically recipe without coming into doctors office. Covid accelerated a lot of remote services.
- jansan 4y agoThis is interesting. Being German, when I read the headline I had a "not another public IT project destined to fail" moment. But this actually makes sense. The government and military need a secure communication tool, it is not a pie in the sky, but built on existing software, and they start with a well defined user base. My guts feeling is that this will be a successful project.
- socialdemocrat 4y agoThat is sad to hear. You hear criticism of public IT stuff here in Norway too, but it mostly works. Like I got e-receipt since 2013. Can order new prescriptions, book appointments , look at test results online online. Well the latter doesn’t always work. But everything with taxes and banking had long been all electronic and working fine.
- f1shy 4y agoIt is based in French software... so... maybe?!
- MoSattler 4y agoI really like the idea. But I am skeptic - digitalisation of Germany's public services and offices in the past hasn't exactly been a success story.
- gillesjacobs 4y agoIn this case, the slow digitisation had a good side-effect of allowing a open, decentralized encrypted messaging protocol to be maturely adopted. Not much consolance for the German people, who still have to deal with a lot of paper administration but a happy accident nonetheless.
- ehvatum 4y agoFrom my experiences with DMG Mori and Siemens employees servicing my equipment and managed by a 100% electronic appointment booking and part ordering systems, German society is wholly and irrevocably doomed by the move away from physical paperwork. All German productivity will end and even German language itself will be replaced by grunts and shrugs. In the end, I got rid of my DMG Mori machine with its Siemens control and replaced it with a Taiwanese machine that functions reliably.
- kioleanu 4y agoIt hasn’t but it’s on the right track. I am working as a developer in one of the federal agencies and have direct contact with the efforts. It helps a lot that public agencies can now offer a so called IT Zulage of a few hundred euros to 1000 per months that brings salaries on par with the private sector. In my team, this worked wonders and we managed to get some really good people. On the other hand, the task is enormous, we were discussing last week that if we had double the man power, we would still have the same workload, because we push back on a lot of things. We have about 70 projects that we wrote and maintain and a backlog of another 12 waiting to be started. BWI has the same problem, I’ve been approached multiple times by them for this project, which from my knowledge is being intensely worked since many years.
- codethief 4y ago
- aliqot 4y ago
- schipplock 4y agoIt's probably Element with a different logo and different colors.
- AstixAndBelix 4y agowhy would you want to see the screenshots of an application used by the German military which is basically a fork of another app with plenty of screenshots on its own webpage? this is just a blog announcement of something cool they're doing behind the scenes and that you will never use in a trillion years, not an Apple product launch
- Arathorn 4y agoyou can see screenies on the app stores: https://play.google.com/store/apps/details?id=de.bwi.messenger https://play.google.com/store/apps/details?id=de.bwi.messeng... etc
- gsatic 4y agoSo people who need to chat with German govt entities have to do what now?
- gillesjacobs 4y agoThat's the advantage of choosing Matrix: it is compatible with a multitude of clients and servers, so take your pick. No need to install the BundesMessenger frontend. No need to trust the government, how very un-German.
- jonas-w 4y agoCurrently the best way is via fax or post
- wongarsu 4y ago*most convenient. The best option is obviously coming in person, with a ring binder containing all relevant documents as well as written records of all previous communication
- LeonidasXIV 4y agoBe sure to queue up 2h before opening time of the office you want to visit because everyone else is also dropping by in person too and the office closes for public service at 12:00.
- oaiey 4y agoAnd not to forget: in German :)
- martinralbrecht 4y agoSince Matrix (and thus BundesMessenger?) currently doesn't provide standard security guarantees for its end-to-end encryption (the mitigation to the "Simple confidentiality break" from https://nebuchadnezzar-megolm.github.io/ https://nebuchadnezzar-megolm.github.io/ is still in the design phase; same for the IND-CCA break, but that doesn't seem exploitable in practice) I wonder how much the German government cares about E2EE for its civil servants? The blog post mentions E2EE prominently, but any insights to share on whether that mattered for this particular adoption?
- Arathorn 4y agoGematik co-funded the most recent Matrix audit of vodozemac[1], and is poised to fund 3 more (of matrix-rust-sdk-crypto, matrix-rust-sdk and the whole stack end-to-end) to ensure the E2EE is where it needs to be. So I'd say that the German government definitely cares about E2EE for its civil servants, and we're very grateful for them funding security research. Meanwhile, BWI is helping fund the work needed to address clientside controlled room membership (https://github.com/matrix-org/matrix-spec-proposals/pull/3917 https://github.com/matrix-org/matrix-spec-proposals/pull/391...) as highlighted in your paper, as well as TOFU... and they're also funding work to provide MLS as an option for E2EE in Matrix too[2]. Unsure why you're talking about the unexploitable IND-CCA break :) [1] https://matrix.org/blog/2022/05/16/independent-public-audit-of-vodozemac-a-native-rust-reference-implementation-of-matrix-end-to-end-encryption https://matrix.org/blog/2022/05/16/independent-public-audit-... [2] https://www.golem.de/news/bwmessenger-vom-messenger-der-bundeswehr-zum-bundesmessenger-2211-169472-2.html https://www.golem.de/news/bwmessenger-vom-messenger-der-bund...
- martinralbrecht 4y agoCool, thanks! That's interesting to know. Do you know how they deal with FOI and auditable communications in this case? PS: I talked about the seemingly unexploitable IND-CCA vulnerability because it means Matrix can't give you some security guarantees: It should be fine - we don't have an exploit, only a vulnerability - but it is not clear how to reason to arrive at "there cannot be an exploit". If you care about security guarantees, you care about it.
- ho_schi 4y agoMakes me happy to read that. One of the bright lights on horizon is that the Bundeswehr opted for a open-source, federated, multi-platform and secure messaging framework. Instead of some proprietary, closed-source piece of crap from a Big-IT vendor which make same depending in a negative way.
- miroljub 4y agoThis was possible only because Ursula vdL is not in charge of Bundeswehr any more. That being said, god save the EU, since these walking tax-money black hole is now leading the whole EU.
- ho_schi 4y agoAs hanikesn pointed out the decision got for Matrix was made back in 2019, probably under VdL and/or AKK.
- hanikesn 4y agoThe bwmessenger pilot started already in December 2019.
- jjsinai 4y agoSinking tax-money destined for the military into consulting contracts could have been her plan towards the Nobel Peace Prize.
- SSJPython 4y agoIt's really awesome to see the public sector being able to experiment with new technologies to see what works. Rather than a top-down approach imposed on everyone all at once, the trial-and-error approach seems to work better. If it succeeds, then try to scale it up. If it doesn't, then it doesn't bring everyone else down with them.
- foepys 4y agoGermany was quite advanced when it came to technology but then the drive to make more of it somehow stopped. It has always been incredibly sad to me that the German ID card (Personalausweis) has an RFID chip inside with trust zones, certificates, authorization features, and much more and just never had been used. Like at all except for getting cigarettes at vending machines. 12 years after the first RFID Personalausweis had been issued it is only possible to register your car in some cities. Maybe there are other minor uses but it's negligible. It's a very cool technology with a certificate authority and cryptographically secured claims for various things (proving you are over 18 without revealing your DOB, only giving out the name and address, authenticating as a German citizen, pseudonymity with separate identities for each service you use etc.). All functionality is also available for use over the internet. The German Wikipedia has a good overview: https://de.m.wikipedia.org/wiki/Personalausweis_(Deutschland)#Der_elektronische_Personalausweis_(nPA) https://de.m.wikipedia.org/wiki/Personalausweis_(Deutschland...
- hatenberg 4y ago25 years of intentionally slowing down digitalization to protect local SMEs (which make 70-80% of the economy) against US tech companies leveraging economies of scale. Yes there’s plenty corruption and disastrous bets (ISDN…), but let’s not pretend the situation isn’t intentionally created.
- jlelse 4y agoYou can use the "Online-Personalausweis" for quite some things actually. For example to authenticate at banks, so you don't have to do Video-Ident. Or to do taxes etc. I wrote a post about it earlier this year: https://b.jlel.se/s/59c https://b.jlel.se/s/59c
- derac 4y agoI don't speak german, but by video identification do you mean the system in which you turn in the webcam and it checks your face? If so, that is highly vulnerable to real time face swapping attacks (and possibly just recorded webcam footage). I'm sure you're aware, but these systems need to change.
- TEP_Kim_Il_Sung 4y agoComes with free BundesTrojaner so someone is always reading your messages. Never feel alone again!
- cf141q5325 4y agoIts indeed a brave new world. With governments getting ever more interested in what you do online, some not quite so mentally stable people have an audience for their mental diarrhea for the first time. If you ever asked yourself the famous "who is supposed to read that", well now somebody is payed to. I hope they do the nice thing and upvote
- Sporktacular 4y agoThese guys keep pushing the idea that if it's not federated, it's closed and proprietary. In at least the cases of Signal and Threema that's just not true.
- Arathorn 4y agoSignal and Threema are proprietary, in that the protocol they speak is vendor-specific and not openly standardised. You are literally locked to that system, and neither of them allow 3rd party clients to connect. Moreover, Threema's server is closed-source and so completely proprietary - and you could argue that Signal's server is often closed-source too, given years occasionally go by without public code releases. This is the rationale.
- Sporktacular 4y agoSignal publishes its protocol spec and allows other applications to use it. Not on their network, but again, that's an issue of federation, not openness. The license allows you to modify it, so you could roll out your own implementation. So you are literally not locked into that system and that's not proprietary. As for Threema, true enough as it's useless without a server. But again, federation isn't a necessary condition for being open.
- newaccount74 4y agoSignal clients may be open source, but as far as I know the network is very much closed and proprietary. Correct me if I am wrong, but as far as I understand you can't make any changes to the Signal client, compile it yourself, and connect to the Signal network. You have to use the binaries from the app store.
- Sporktacular 4y agoSo, you can't just make your own signal network? Sounds pretty open if you can and hardly proprietary if the license allows for that.
- est31 4y ago
- theptip 4y agoVery cool. I’ve long thought that global government spend should be more than sufficient to build robust open source solutions. But it requires some degree of technical expertise on the ground to weave together solutions, instead of just buying the Microsoft package with AD and Office.
- PaulHoule 4y agoI think messaging is an area where Europe could have an impact. The basic problem with messaging and voice/video comm applications is that clients are not interoperable. It is easy to think that: we've had CUSeeMe, IRC, ICU, AOL Instant Messenger, Tivejo, MSN Messenger, I think more than 10 kinds of Google Chat, Facebook Messenger, Skype, Zoom, Paltalk, Yahoo Messenger, Signal, Telegram, Go2Meeting, Discord, WhatsApp, WeChat, etc. The average person would be hard pressed to tell the difference between these applications, a cynic would say "Facebook Messenger is no different from AOL Instance|MSN|Yahoo messenger except it is integrated with Facebook". The average person doesn't question that chat programs don't interoperate but because they don't we see a pattern of "try out the new shiny, it's just as good as the old cruddy was back in the day", the new application rides high for a while, then it rots and it is it the new old cruddy before long. The one constant is that you may need to install 10 chat applications to talk to everybody you talk to. As it is, two-sided markets let applications coast and generally rot without losing market share until things get catastrophically bad. If chat applications interoperated there would be a robust market for better applications and better servers and you'd see developers of old apps to have a reason to keep them working over time and more chances for new apps to get established.
- Muehe 4y agoCuriously many of the messengers you mentioned are or were at least initially based on the same protocol, XMPP, some of them even were interoperable for a time[0]. There are still attempts at realising interoperability, notably libpurple[1], but they are fighting a constant uphill battle. Sadly companies usually just have more incentives to either keep their services walled off or extend only theirs in functionality, rather then keeping them interoperable. This would only change through regulation, or I suppose if a federated service gains enough traction to become the de-facto standard, but given the fate of XMPP that seems unlikely. [0]: https://en.wikipedia.org/wiki/XMPP#Non-native_deployments https://en.wikipedia.org/wiki/XMPP#Non-native_deployments [1]: https://en.wikipedia.org/wiki/Pidgin_(software) https://en.wikipedia.org/wiki/Pidgin_(software)
- stevehawk 4y agoThe impact is not likely to be positive. Nearly every government in Europe will want access to the comms happening, particularly if it's within their borders or with their citizens. Europe is not likely to introduce an end-user-to-end-user encryption. It will be encrypted from end user to the government to the next end user.
- Pxtl 4y ago
- catiopatio 4y agoIt doesn’t take a religious nut or a conspiracy theorist to see the catastrophically enormous downsides of universally mandated, centrally managed, and cryptographically-backed state identification cards, complete with RFID. Imagine, for example, that upon declaring a protest unlawful, the police could simply scan all the RFID-enabled ID cards in the area and issue everyone a court summons. Not carrying an ID card? No access to anything - public transportation, payments, and can’t even authorize your car to start. Also, it’s a felony to do so intentionally and with intent to evade law enforcement monitoring. State wants to search your laptop? Your 2FA and disk encryption is mandatorily tied to your ID card, and the state holds keys in escrow. Some things should be onerous for the state and decentralized. This is absolutely one of those things.
- getcrunk 4y agoIt sucks that this seems to be the only way. Why can’t we support both. Given how QR codes are forcefully replacing menus with no paper fallback options seems to be the only way
- jszymborski 4y agoSee, I totally agree that you shouldn't require identification for most services. But, for things like banking, car registration, etc... we require strong ID'ing, and it behooves society to make it secure. I still think municipalities should own their own data rather than have it stored at a central federal level, but we need municipalities to rely on something better than a serially-issued social insurance/security number which I have stored in a million databases that can pop at any second. It's easy to dream of the future dystopia and ignore the one we live in now, where identity theft is trivial.
- shortstuffsushi 4y agoWorth calling out imo, in our current world you have recourse and an ability to "recover" from identity theft (to some extent). If the government controls your identity and revokes some piece, what can you do?
- moooo99 4y agoGerman officials have had a whole lot of groundbreaking visions for as long as I can remember. The visions were never the issue but the delivery. I remember Peter Altmaier claiming in 2017 that in 2021 any government service will be accessible online lmoa. To this day I regularly have to print out PDFs and send them via registered snail mail or fax (yes, I actually have a fax)
- oaiey 4y agoIn the 2000/2001 the defense minister (Rudi something) wanted to have a direct communication channel to all officers of the army. They contracted the Telekom (aka T-Mobile). The result was a parallel modem line network with extra PCs next to the well established communication network of the army. It was called Rudiphone and a the most stupid project ever. So yes, visions where always there but the implementation was indeed always a story
- deleted 4y ago[deleted]
- beardedman 4y agoAnother virtue signal from good 'ol Deutschland. Where 75% of the population prefer cash. "Do what we say, just don't do what we do", as the old adage goes. How painful.
- Xylakant 4y agoI prefer cash and would at the same time use an encrypted messenger to communicate with the government. While cards are certainly convenient, they have failed me at very inopportune moments. I’ve also recently witnessed how someone could not book a ticket for a ferry in one of the mostly cashless European states - cash wasn’t an option and they didn’t have a card. This was at the official counter at the harbor. A few month ago, card terminals of a widely used type failed hard in Germany, only cash payment was possible. Being able to do some purchases anonymously is also a good thing - even if it’s only my wife’s birthday present. I prefer a society where cash is an option for all (in-person) transactions. And preserving that requires exercising the use of cash. Encrypted secure communication with (and within) the government, or my medical provider is entirely orthogonal to that.
- beardedman 4y agoI am not a young person anymore & card payments have almost never failed for me (unless it was for a specific/resolvable reason). > A few month ago, card terminals of a widely used type failed hard in Germany, only cash payment was possible. This exactly is part of my point. > or my medical provider is entirely orthogonal to that. I prefer a medical provider that does a good job & shares my data, rather than incompetent medical staff that adhere to privacy policies. I expect my doctor to be a good doctor, not a good data policy keeper.
- Xylakant 4y agoI have had cards expire and the new cards sent to an outdated address, and when that was discovered, the bank blocked all cards since they could have fallen into the wrong hands. I happened to be traveling at that time. I’ve had cards be blocked due to random fluctuations in the usage pattern. Calling usually helps a to resolve this, though it usually takes time. I’ve had an ATM eat my card and not return it. I have entered the wrong pin once too many. I’ve had my bank replay all transactions from at the beginning of the month twice, debiting the rent and all payments twice, and overdrawing my account, blocking my cards. Shit happens. Cash was always an option to solve this. > > A few month ago, card terminals of a widely used type failed hard in Germany, only cash payment was possible. > This exactly is part of my point. I don’t understand how this is part of your point. It was a bug that required exchanging the terminals - either some kind of hardware or a borked software update that left the terminals unable to function. Shit happens, in hardware, too. It’s not like other countries are magically exempt from failures of their digital infrastructure.
- k__ 4y agoHasn't Element/Matrix been problematic in the past?
- jszymborski 4y agoIt certainly hasn't been w/o growing pains or detractors. I still occasionally get rooms or spaces borked, and that frequency increases if E2EE is enabled. The current server implementation is not svelte in the least, but that's a problem that's being solved with new server implementations that are already 90% of the way there (look-up Dendrite and Conduit if you haven't heard of them).
- k__ 4y agogetting borked?
- jszymborski 4y agoThe most recent instance I experienced was the GrapheneOS rooms which suddenly just stopped working. https://grapheneos.social/@GrapheneOS/109510405342409074 https://grapheneos.social/@GrapheneOS/109510405342409074
- eredengrin 4y agoTo be clear, GrapheneOS was running on much older matrix room versions and the bugs that were causing the issues have (to my understanding) largely been mitigated in the later room versions. Of course it's not ideal it happened, but I wouldn't expect the same set of issues to persist after the upgrade, the mitigation has already existed it's just GrapheneOS (understandably) wanted to avoid the disruption of an upgrade if possible.
- jszymborski 4y agoThat makes sense... I was having trouble with E2EE rooms with my friends back when Element was (regrettably) called Riot, but we also chalked that up to being (somewhat) early adopters. That didn't stop us from migrating to Discord, sadly. It's why I characterised them as growing pains... I'm sure it'll all work out eventually and I've no doubt it's more stable than it has been.
- sgt101 4y agoI wonder where they get their prime numbers...
- galaxyLogic 4y agoThis is great "Matrix is the equivalent to SMTP". Goodbye Microsoft or Slack -specific chat services. Welcome them to compete with their Matrix client-apps. And hey, we're in the Matrix finally.
- Hamuko 4y agoNow I'm just waiting for the Matrix app that I don't hate. And for that matter, the SMTP app that I don't hate.
- galaxyLogic 4y agoI wonder if Matrix could be used for social media
- mxuribe 4y agoYes, i remember there have been early experiments leveraging the matrix protocol for many scenarios including blog platforms and social media...But i don;t think its popular to do so. Most people interested in federated social media tend to use ActivityPub (protocol), and use servers and clients already optimized for such a social media use case on the Fediverse (mastodon is a recent popular software stack, but there are many, many others).
- mxuribe 4y ago@Hamuko I have been on matrix several years, and lately I've been really liking Schildi Chat [https://schildi.chat https://schildi.chat]. Also, many other users that i know really like Fluffy Chat [https://fluffychat.im/ https://fluffychat.im/]. In any case, there are several more options nowadays.
- Klonoar 4y agoThere are really no options outside of Element, unless you're a Linux user - then maybe you have a few ones. All alternative clients on iOS, macOS, and arguably Windows are an absolute clusterfuck of UI/UX, broken features, and varying stages of completion. I say this as someone who wants Matrix to work: people need to demand more from client apps, and client apps need to stop being okay with barely hitting the bar. Element also needs to set the bar, which I frankly don't think it currently does - but that's supposedly being rewritten, so I'm hopeful for what they produce.
- Pr0ject217 4y ago"Real time collaboration systems such as Microsoft Teams, Slack, Mattermost, Wire, Threema, WhatsApp and Signal are currently all closed proprietary systems - meaning they are walled gardens whereby all parties have to use the same vendor." Signal is in this list. Isn't this false? The server and clients are here: https://github.com/signalapp https://github.com/signalapp
- msgilligan 4y agoSignal is (as far as I know) single-vendor, which they are confusingly calling “closed proprietary”
- Arathorn 4y agoI wrote this sentence. “closed proprietary” here means that it’s not an open standard, and it’s not an open network you can connect your own clients to, and so it’s vendor-locked, and in the case of Signal there are gaps of years when they don’t release opensource code on the server.
- IshKebab 4y agoI guess it's a bit debatable. It's more or less open source - apparently there have been long periods when it was closed source (I think when they added cryptocurrency nonsense) and also it's centralised so you have to use their servers. I would say it's a bit disingenuous to put it in the same list as Teams, Slack and WhatsApp though.
- cies 4y agoI'm happy to see this. I came out embarrassingly that Germany was spied on by the "ally" US. They already did not trust MS Exchange, probably for good reasons. So they either trust the Swiss (Signal), the Russians (Telegram, prolly not), the ..., or they roll their own, or they use open source. I'm stoked to see they seem (yes: seem) to be doing the latter. Why do I emphasize "seem". Well there have been several German initiatives for using open source, but non of them stuck very well. Munich's going Linux comes to mind, but there were others. And I'm afraid that this may be another such "attempt", while I hope it this time different as their national security is a at stake. Telling everyone to communicate with GPG-encrypted emails has shown to be too hard on users, who then simply use one of the many less-secure channels. You have to do something, or you know they --the US mostly (WhatsApp, Twitter, GMail/Chat) -- will listen along with everything.
- offlinenative 4y ago
- fuoqi 4y ago>the Russians (Telegram, prolly not) I wouldn't call it a "Russian" system. Just consider where Durov currently resides and has his wealth.
- coretx 4y agoThe power of any State regarding such things usually works by exercising control & influence over entire networks of people. Not so much by brute (legal) force applied at who or whatever holds the formal power. Quite often, such firms / owners / networks of people don't even fully realize what is going on if at all. Often it's even more than one State trying to achieve the same without it being "visible". TL;DR We don't know shit by just observing media reports & firm/executive behavior. But if you did a actual "Follow the Money" on Durov, i'd love to see it ! ( Although I do like what he seems to be doing. )
- coretx 4y agoI don't know why the person who was first to respond to you is "dead" but set aside his value judgement; all he wrote is factually correct. The embarrassment you speak of lies in the fact that it became public knowledge, not in the act itself, depending on the perspective of specific institutions. Furthermore, disregarding the fact that signal is in Israeli hands, i'm fairly certain they don't even trust themselves and simply calculate and spread risks as they see fit. Regarding your Munich example, the most significant factors for the outcome of that debacle where at one end incompetent people backed by powerless competent people and on the other end Microsoft with millions of lobby money backed by a powerful state actor. Both can easily be regarded as both a risk and opportunity for state security. Your closing statement is of course indisputable, never the less we should not forget that despite the fact that times change; old adagia such as "Something you have, something you are, something you know" are not only easily understood by everyone but we are also getting there with for example the advent of cheap FIDO2 keys, fairly invisible network access control & encryption at device enrollment, infrared cameras, privacy respecting / agnostic AI driven real-time analytics & heuristics at scale and so on. In other words, we are slowly getting there but not due things such as "having a BundesMessenger" unless it's weaknesses contribute to the drive for improvement ~ including replacing American cloud services ~ ; something it's open source nature definitely does.
- hrdwdmrbl 4y agoIs this more of a teams app (Slack, Teams) or more of a chat app (Whatsapp, Signal, Messenger)?
- farhaven 4y agoElement feels a lot like Slack/Teams/Discord. It has a few distinct features (federation and such), and a few are, as far as I'm aware, missing or "different enough" such as Slack's whole "We'll replace Email, why don't you write your longer documents in here as well"-thing.
- olivierduval 4y agoI find really nice that Europe "as a whole" is starting to share the same solutions to the same problems !!! Remember "Tchap" (https://www.tchap.fr/ https://www.tchap.fr/), the French Gov messenger system based on Matrix ? ;-)
- sharperguy 4y ago> secure messenger > built on electron Hmm
- Arathorn 4y agoElement X is a native app, and will replace Element Desktop for many purposes, fwiw (and will be also adopted by BundesMessenger)
- archsurface 4y agoI know someone who works in the digital id space, and the businesses pushing this stuff at the governments are far more interested in their business than your rights. And governments have a habit of slipping in things they find convenient. With some insider insight I'd suggest pushing back very hard against this sort of thing.
- jupp0r 4y agoUsing open protocols and open source solutions: great idea. Letting some random company operate your army's IT infrastructure: what could possibly go wrong?
- comte7092 4y agoThe infrastructure is managed by Germanys public administration. The French utilize matrix for military operations as well. This isn’t “some random company”.
- Xylakant 4y agoRandom is pretty load bearing here. The BWI GmbH was literally created to operate the armies non-military IT infrastructure.
- jupp0r 4y agoThey also operate military infrastructure, ie operation planning software and battle management systems [1, from the German Wikipedia article]. [1] https://esut.de/2020/05/meldungen/cyber-it/20897/digitales-gefechtsleitsystem-in-die-truppe-eingefuehrt/ https://esut.de/2020/05/meldungen/cyber-it/20897/digitales-g...
- oaiey 4y agoThe article is pretty explicit in that BWI are not running but packaging a reference software. And aside how do you think that anywhere in the world software for the army is created. It is called military industrial complex for a reason.
- lakomen 4y ago"Matrix is the secure real time alternative to SMTP" I stopped reading there. I used Element in the past and Matrix is a clusterfuck. Python server slow, Go server not feature complete. Channels available uninteresting, mostly cryptocurrency. A few porn channels, that's it. I wish it wasn't so. If anything Matrix is a replacement for IRC, absolutely not email. Then, I am absolutely NOT installing a Bundes-anything on any of my devices. I can't trust a state that has multiple state Trojans.
- Arathorn 4y agowe’ll miss you :’(
- LAC-Tech 4y agoDid the German language ever have a 'proper' German word for messenger? I seem to recall a computer message was a "nachricht", but I have forgotten so much...
- coretx 4y agoThe classic obligation of the state to testify who someone is -empowering citizens- ( by whatever means, including passports ) seems to be silently converted into the obligation of the citizen to proof who they are, taking power from them without their consent and potentially causing future abuse on a scale larger than the 1933 Reichstag fire.
- iepathos 4y agolol they're reinventing the wheel and calling it "ground-breaking"
- jasonzemos 4y agoWhere can I find information about how the German government came to this decision? Does this involve contracts to outside companies for development and consulting or will that all be done by the government? If the former, when and where did the bidding process take place? What alternatives were considered? I don't speak German, so I need some help understanding this. Precise links would be appreciated.
- oaiey 4y agoWhat angle is in your question? Matrix is the best choice i could imagine. And the lobbyists of Google, Microsoft and Apple surely had better funding than anyone touching matrix. If your ask whether a consulting agency earned something between 10 and 100 million on that decision you are most likely right. But I guess overall it was probably the CCC influence on the politics and the population. The club and their members are much more influential than you would expect.
- julian_sark 4y agoCute. A secure messenger for the state. And "Chatkontrolle", i.e. client-side inspection and surveillance of every message, for the unwashed masses.
- oaiey 4y agoEspecially considering that the most recent arrested terrorists targeted police and military employees as conspirators. But honestly all much better than the NSA listening into German state traffic. The big fives are not friends just allies.
- TheHappyOddish 4y agoIt's incredibly cool to see New Vector finding revenue streams working with governments and large companies on frontend and integration etc, whilst still maintaning open source, federated software. It must be a very hard slog to get there whilst also upholding your ideals, so kudos to you!
- aborsy 4y agoSome of these EU governments are authoritarian, will capture captive citizens and intercept communications. In addition to surveillance, the quality of the government services has been often low.
- letmeinhere 4y agoGiven that the protocol is E2EE, how do they handle data retention / transparency requests? Does each agency centrally store copies of their employees' encryption keys?
- chagaif 4y agoFunny you ask this, I remember actually having a discussion about doing this, but for another reason - to avoid users losing their messages because they lost their keys. We ended up not doing it of course, it makes no sense to have e2ee if you're going to bypass it anyway... If you need to be able to access the data I think you should probably force your users to not use e2ee rooms...
- oaiey 4y agoHonestly, chat is the equivalent of a person to person regular mouth to ear communication. Some stuff needs to be off record. Which effectively means, nothing in chat and not on a formal document is just coordination. Like it was for centuries.