[HN Gopher] Teleguard: Swiss Made Safe Messaging
       ___________________________________________________________________
        
       Teleguard: Swiss Made Safe Messaging
        
       Author : 0x10c0fe11ce
       Score  : 45 points
       Date   : 2021-01-23 14:10 UTC (8 hours ago)
        
 (HTM) web link (teleguard.com)
 (TXT) w3m dump (teleguard.com)
        
       | motohagiography wrote:
       | Raises the more interesting question of what is sufficient
       | collateral for a developer to make a secure messenger.
       | 
       | Before Snowden/Poitras/Greewald, we trusted Moxie Marlinspike
       | mostly because of his dreadlocks and some conference appearances.
       | Very, very, few people understood what a ratchet was, let alone
       | read the code. We trusted founders Jan and Brian of WhatsApp I
       | think because they wrote t-filez. Security is in many ways
       | cultural and aesthetic as it is technical. SILC was a thing for
       | people legitimately being spied on by their governments in the
       | pre-occupy anti-globalization movement - and then suddenly it
       | wasn't.
       | 
       | I want a product like this to succeed, so why snark about these
       | perfectly nice seeming people's new tool? Because security has
       | serious consequences. We don't need to tell anyone what we need
       | privacy for, but I think we're still lacking a clear "for what,"
       | to evaluate privacy technologies against.
       | 
       | The threat we need to build privacy tools against is essentially
       | suburban-bourgeois and mob governance. When you look at old
       | "alternative" culture, or why people still go to things like
       | burning man today, it's to engage in what are essentially
       | aesthetic communities of desire and to be free of political
       | oversight and surveillance. The criteria I would propose for a
       | secure messenger is that it can create a private perimeter to
       | facilitate the freedom of something like burning man for a
       | community of users. If it isn't designed to create that kind of
       | growth, it's a reaction with a limited horizon and just
       | bargaining with the inevitable.
       | 
       | Personally I think a privacy product that is for everyone is
       | necessarily for no one. Maybe this is the one that gets used by
       | the next burner-level community to emerge, but the conversation
       | about what-for will be the thing that drives the adoption of it.
        
         | clairity wrote:
         | > "The threat we need to build privacy tools against is
         | essentially suburban-bourgeois and mob governance"
         | 
         | no, that's exactly wrong in ways that really matter,
         | distracting us from real threats to free and fair living, which
         | are exertions of power by large organizations (including
         | governments) and wealthy (influential) people (including
         | politicians).
         | 
         | the focus on the capitol disturbance is exactly this kind of
         | distraction as well, trying to vilify the relatively powerless
         | while the real 'villains' (to satirize) ratchet up their hold
         | on power and insulate themselves further from consequences and
         | answerability to their constituent stakeholders.
         | 
         | we should not be looking askance at each other, but rather
         | askance at anyone trying to garner power and influence. the
         | balance of power has no lasting stable mode so we as citizens
         | must keep tabs on power. the last 50+ years has been a slow
         | neglect of that duty, allowing ourselves to be distracted by
         | all the new shinies.
        
         | tgsovlerkhgsel wrote:
         | > we trusted Moxie Marlinspike mostly because of his dreadlocks
         | and some conference appearances.
         | 
         | Not because experts had reviewed the design and found it good?
         | (Serious question, I don't know what the exact timeline looked
         | like, i.e. when people were trusting the apps vs. when reviews
         | became public)
        
       | tgsovlerkhgsel wrote:
       | "The" Swiss made secure messaging app (which already has brand
       | recognition and some meaningful adoption within Switzerland) is
       | Threema (no affiliation, and I'm using Signal - just comparing to
       | Threema because "Swiss made" seems to be what this app is trying
       | to make their main selling point).
       | 
       | This app has "1,000+" installs on the Play store (Threema:
       | "1,000,000+"), and doesn't use phone numbers as IDs, i.e. it's
       | only useful if you for some reason want to migrate all your
       | friends to a brand new chat app that nobody else has heard about,
       | and that has no really unique selling points, and thus little
       | chance of building meaningful network effect (which is critical
       | for chat apps, because a chat app without people to talk to is
       | useless). As a result, it seems unlikely to be successful and
       | thus unlikely to be supported (or exist) long term.
       | 
       | It seems to be a poorly thought out attempt to jump onto the
       | wagon train far too late and get users trying to flee WhatsApp.
       | Due to the network effect, adding choice is likely to help only
       | the incumbent (WhatsApp) by making it harder for any of the
       | alternatives to reach critical mass.
       | 
       | The crypto design is also highly questionable: They say they're
       | using "SALSA 20", which is a low level primitive (comparable to
       | e.g. AES), not a complete protocol. Advertising primitives shows
       | little understanding of the actual problems in cryptographic
       | practice, and thus a significant risk that not enough work went
       | into designing the protocol around it, resulting in something
       | that is insecure overall.
        
       | aleken wrote:
       | Let's throw this in the mix! https://www.secuwine.com/ Under
       | Norwegian and European laws and regulations
        
       | dbrgn wrote:
       | Does this app have _any_ USP?
        
       | lvs wrote:
       | That famous swiss encryption...
        
         | tgragnato wrote:
         | oh come on! Switzerland is neutral!
        
           | outside1234 wrote:
           | Especially if you are German and need banking during a world
           | war.
        
         | rich_sasha wrote:
         | Surely lots of holes in it then?
        
       | outside1234 wrote:
       | Why is Swiss Made better for ethics?
       | 
       | These are the same folks that looked the other way on Hitler (and
       | in fact were his preferred banking location) and recently sold a
       | phone with a backdoor while claiming it was private.
       | 
       | The Swiss are extremely systematic, which makes them great at
       | banking, but ethical? Not sure about that.
        
         | krsdcbl wrote:
         | I think the "swiss made" plays onto two ideas in this context:
         | on the one side, Switzerland having a very advanced industry
         | when it comes to precision technology / on the other side
         | Switzerland being a neutral country of high diplomatic esteem.
         | 
         | But both of those tropes might very well be a little stuck in
         | the last century imho.
        
         | Rochus wrote:
         | It's just about a messenger, not saving humanity.
        
       | egberts wrote:
       | someone needs to update https://www.securemessagingapps.com/
        
       | [deleted]
        
       | newscracker wrote:
       | I'm constantly on the lookout for newer and/or different
       | messaging applications. This one is good because it doesn't rely
       | on a phone number. But it's still yet another centralized system.
       | There isn't enough information on how this service doesn't store
       | user data (or metadata) and still manages to connect them (in
       | contrast, Signal has many blog posts and documentation about how
       | it minimizes data collection).
       | 
       | In the FAQ, there's this:
       | 
       |  _> Which operating systems are supported?
       | 
       | > TeleGuard supports all Android devices with version OS 5.0.3+
       | and all iPhone devices with at least iOS 9.0+._
       | 
       | It's good to support a few older versions of operating systems,
       | but I don't think a messenger can promise security or privacy if
       | it supports operating systems that are quite old by mobile
       | standards and aren't getting security updates for a long time.
       | Wikipedia says that Android 5's latest release was nearly six
       | years ago (April 21, 2015) and that of iOS 9 as 17 months ago
       | (July 22, 2019). Supporting iOS seems kinda ok, but supporting
       | that Android version looks quite bad.
       | 
       | I also judge websites by what they say and how they say it. In
       | the FAQ, after the answer for "07. Edit Profile", there's a list
       | of bullet points that looks like a to do list for additional FAQs
       | that haven't been completed:
       | 
       | * Send media
       | 
       | * Forgot password?
       | 
       | * How is TeleGuard financed?
       | 
       | * Registration
       | 
       | * Add contacts from the phone list
       | 
       | * What kind of encryption does TeleGuard use?
       | 
       | I don't think this is ready for prime time yet.
        
       | tao_oat wrote:
       | This website is awfully light on details. Is it open source? Is
       | there a whitepaper on the encryption used? Does it have e.g.
       | forward secrecy? At the moment there's no reason why you might
       | want to use this over e.g. Signal or Wire, both of which use
       | well-studied encryption schemes.
       | 
       | Also -- "Complex encryption system for all transmitted data" does
       | not seem like a particularly good thing.
        
       | 1cvmask wrote:
       | I think the Swiss Made Safe Messaging is suspect to those who
       | know about backdoors. In fact the Swiss sold "encrytped" crypto
       | phones with backdoors baked in as a business model. You paid to
       | get spied on:
       | 
       | https://en.wikipedia.org/wiki/Crypto_AG
        
         | nabla9 wrote:
         | You seem to associate two completely separate things only
         | because they are both incorporated in Switzerland.
         | 
         | Crypto_AG (founded in 1952) was part of secret US/West German
         | government project.
         | 
         | Are you claiming that Andreas Wiebe, Hulbee AG, Swisscows AG
         | are also working for the US government?
        
           | 3327 wrote:
           | I think his association is not far fetched, did you read the
           | post and the Narrative?
           | 
           | Are they not using the "Swiss" brand as a pretext to convey
           | safety and imply security?
           | 
           | OP is pointing out a clear and recent example that the "Hey
           | this is Swiss" therefore must be "safe, secure, reliable" is
           | no longer the truth.
        
           | eganist wrote:
           | The Swiss Government was (at the latter part of the
           | operation) aware and complicit.
           | 
           | https://www.swissinfo.ch/eng/business/no-official-outcry-
           | in-...
           | 
           | Given this precedent, there's good reason to believe it would
           | happen again. There is _not_ reason to believe that the
           | people behind Teleguard today would be in favor, but there
           | _is_ good reason not to become wedded to the service given
           | the risk that it may change hands or be operated similarly to
           | Crypto AG down the road.
        
             | nabla9 wrote:
             | There is no indication that Swiss Government at the high
             | level was aware. Intelligence agencies were aware.
             | 
             | It's important to understand that the was violation of
             | Swiss neutrality law, and it was not started by Swiss
             | government or government agency.
        
               | eganist wrote:
               | > There is no indication that Swiss Government at the
               | high level was aware. _Intelligence agencies were aware._
               | 
               | I'm not seeing how
               | 
               | 1. Swiss intelligence is somehow distinct from the Swiss
               | government.
               | 
               | 2. this mitigates the risk I described.
        
           | paulryanrogers wrote:
           | Well if they are leaning on the reputation the Swiss as being
           | neutral or otherwise more trustworthy, then it's relevant.
        
             | nabla9 wrote:
             | They are neutral and trustworthy. Significantly so.
             | 
             | Nobody is absolutely neutral or always trustworthy. It's
             | argumentation error to move from is not completely neutral
             | and has had some issues to saying "it's all bullshit".
        
               | paulryanrogers wrote:
               | Didn't mean to dismiss them out right. Rather that
               | banking on 'Swiss' as a shortcut isn't wise. Obviously if
               | one does the work to audit those involved or the
               | product/service itself then they can trust it regardless
               | of the marketing.
        
               | saiya-jin wrote:
               | What does banking has to do with secure messaging? That's
               | pretty basic strawman argument. For example US does
               | Blackwater and did MK Ultra on its own citizens, so what?
               | 
               | Banking en Suisse adheres to Swiss laws, which are
               | heavily influenced by EU and US laws these days. If some
               | private company decides to break the law, they will be
               | handled accordingly.
        
               | paulryanrogers wrote:
               | Banking as is depending upon, not financial services.
        
         | idlewords wrote:
         | We all know Swiss products are full of holes.
        
           | Rochus wrote:
           | Only the cheese.
        
         | tptacek wrote:
         | A peeve of mine: pretty much all "made outside the US"
         | messaging is sketchy, because one of the most important
         | differences between stuff run in the US and stuff run outside
         | the US is that NSA doesn't need special permission to hack
         | stuff run outside the US --- in fact, hacking stuff outside of
         | the US is basically their whole charter.
         | 
         | I'm not saying you should purposefully select US technology in
         | order to avoid surveillance, just that "hosted or made in
         | Switzerland" messaging in privacy tools isn't very meaningful,
         | and takes advantage of an emotional reaction in prospective
         | customers, not a rational one.
        
           | saiya-jin wrote:
           | That might be true if you are US person. If you're not, like
           | 95% of the mankind, using non-US hosted services lowers the
           | threat. Nobody knows how much since the answer lies in NSA
           | capabilities.
           | 
           | But as a smart approach, for folks ie in Europe, US is a big
           | no-no if security is a concern.
        
             | tptacek wrote:
             | I don't see how it does; if you're a non-US person using a
             | non-US service, you have essentially no formal legal
             | protections whatsoever from NSA surveillance. A non-US
             | person using a US service at least inherits whatever
             | procedural protections US companies have. I'm not saying
             | it's a meaningful barrier, just that going overseas
             | logically can't _gain_ you protection (unless you 're more
             | worried about the Swiss or EU's sigint agencies than you
             | are the NSA).
        
               | Barrin92 wrote:
               | As a non-US person I'm not concerned about the NSA, it
               | doesn't have a material impact on me, it's not like the
               | NSA orders a black helicopter to snatch me from Germany.
               | I'm worried about corporate use of my data because that
               | stuff can actually realistically leak or be used for ads
               | or whatever else and in this case I have probably better
               | default protections with a Swiss company than with a US
               | based one. (with some exceptions of course, Signal and so
               | on seem trustworthy).
        
           | Youden wrote:
           | I think you're missing a bigger issue: if the data is in
           | America, _nothing needs to be hacked_. Your data can be
           | obtained through legal means.
           | 
           | Plus, if you're not an American citizen, you have no rights
           | so far as three-letter agencies are concerned, whether your
           | data is stored in the US or elsewhere.
           | 
           | The choice is between data stored in the US, where data can
           | be obtained through legal means or hacking, and data stored
           | elsewhere, where it can only be obtained through hacking.
        
             | tptacek wrote:
             | That's true. You do have to make a decision about which
             | protection you feel is stronger: the American legal system,
             | or the current commercial state of the art in computer
             | security lined up against the world's largest consumer of
             | offensive security technology.
        
               | Youden wrote:
               | That could be true but only applies to people subject to
               | the American legal system, i.e. those with American
               | citizenship or living on American soil.
               | 
               | For the other 96% of us, the American legal system offers
               | no protection whatsoever, as far as I'm aware.
               | 
               | This deficiency is not true of all jurisdictions. As far
               | as I can tell from reading articles 1-3 GDPR, the GDPR
               | applies to all processing that takes place within the EU
               | or on behalf of an EU entity, regardless of whether the
               | subject of the data is a citizen or resident of the EU.
               | Same goes for the Swiss data protection act [0].
               | 
               | So as a non-American, I have a choice between services
               | located in a country where I have no legal rights and
               | services located in countries where I do.
               | 
               | This is also all from a security point of view. From a
               | privacy point of view, I know that American companies
               | have essentially free reign over the data I give them.
               | They can monetize it, sell it, train machine learning
               | models with it or do whatever else they please,
               | regardless of whether they have my explicit consent.
               | 
               | Other jurisdictions have privacy protections, so I know I
               | have some basic level of privacy if I choose say a German
               | email provider, while I know I have essentially none if I
               | choose an American one.
               | 
               | Really, as a non-American, I see no reason why I should
               | treat American services as being any better than say
               | Russian or Chinese services. I'm happy to listen if you
               | have any compelling arguments though.
               | 
               | [0]:
               | https://www.fedlex.admin.ch/eli/cc/1993/1945_1945_1945/en
        
         | systemvoltage wrote:
         | There is also this:
         | https://en.wikipedia.org/wiki/Onyx_(interception_system)
         | 
         | > The goal of the system is to monitor both civil and military
         | communications, such as telephone, fax or Internet traffic,
         | carried by satellite.
        
         | WanderPanda wrote:
         | I think people underestimate how much of a blow this is for
         | Switzerland
        
           | ur-whale wrote:
           | That and the fact that they sold "banking secrecy" to the
           | whole of Europe for the better part of a century only to
           | betray all those promises in the 21st century.
        
             | saiya-jin wrote:
             | Banking secrecy was removed due to peer pressure from EU
             | and US, which together form a majority of exports for
             | Switzerland. They just did make keeping the secrecy
             | extremely costly in form of import tariffs on Swiss goods.
             | 
             | Originally intended as a fine example of government
             | actually caring about privacy of its own citizens, then
             | heavily misused by local and international banks, it just
             | stopped making sense anymore at one point. Its still
             | somewhat valid for its own citizens and AFAIK residents.
             | 
             | Banking together is cca 12% of Swiss economy, so the
             | fantasy of some folks who read let's say alternative news
             | about Switzerland ruining itself by losing banking secrecy
             | didn't pan out. Swiss economy is much more reliant on tons
             | of small/medium high quality manufacturing companies, or
             | tourism rather than banking.
        
         | dgellow wrote:
         | Though it was a CIA ops. That doesn't make everything "swiss
         | made" suspect (but it clearly impacted the "Swiss made" brand
         | and Zug's reputation).
         | 
         | Switzerland has strict data protection laws, that's why some
         | companies are established there and pushing that branding
         | (also, low taxes).
        
           | fmajid wrote:
           | CIA and BND (Bundesnachrichtendienst, the German intelligence
           | service). They actually owned the CryptoAG company. It's
           | become a big political scandal there, with accusations that
           | the Swiss intelligence services knew and deliberately misled
           | their parliament.
        
             | acct776 wrote:
             | Of course some of them knew.
        
           | nix23 wrote:
           | If your intelligence service let the biggest bank of
           | Switzerland (UBS) buy those product, there is no excuse, and
           | later being proud of the whole thing (as a neutral country)
           | it's a shame and a shit stain on our integrity (which is/was
           | more or less the only real quality of Swiss services)
        
       | bergstromm466 wrote:
       | After Crypto AG [1], does 'Swiss made' really still have the same
       | positive connotations it used to?
       | 
       | I'm so over any sort of branding that proclaims the superiority
       | of one nation over others. [2]
       | 
       | If we really wanna give credit, why not list the actual names of
       | the engineers that came up with the encryption mechanisms?
       | 
       | Same goes for Apple's _' Designed in California'_ etc.
       | 
       | [1] https://news.ycombinator.com/item?id=22297963
       | 
       | [2] https://www.youtube.com/watch?v=VRh925Is_1U
        
       | sobriquet9 wrote:
       | Closed source, unclear what protocol is used. They mention SALSA
       | 20 which is good, but that's probably just channel encryption. No
       | details on how session keys are derived.
        
       | nix23 wrote:
       | Wow those peoples completely missed Crypto Ag and Opensource.
       | 
       | DONT trust Swiss enc. Products
       | 
       | BTW: I'm Swiss
        
       | 1_player wrote:
       | People from Switzerland are probably the most patriotic in the
       | world after those from USA. If it's made in Switzerland, you can
       | be sure "Swiss-made" is prominent and there's a white-on-red
       | cross somewhere visible.
       | 
       | But, honest question, is there such thing as the "Swiss
       | guarantee" in tech?
       | 
       | What have the Swiss ever done for us, in computer science, to
       | demand such respect just by mentioning the place of origin as
       | certificate of trust?
        
         | [deleted]
        
         | polymeris wrote:
         | It's only partially patriotism. More importantly, I suspect,
         | just a brand that sells well, no matter what you are selling.
         | That said, EPFL/ETH and CERN have done some important things in
         | computer science.
        
           | T-A wrote:
           | CERN is an international laboratory which happens to be
           | located on the border between Switzerland and France. I
           | wouldn't call it Swiss.
        
           | bergstromm466 wrote:
           | CERN is made possible by shared European funding, hardly
           | 'Swiss'.
        
             | polymeris wrote:
             | True. And much of the work at ETH is conducted by
             | foreigners, but the marketing association is still there.
        
               | tdudzik wrote:
               | And much of the work in the USA is done by foreigners or
               | even outsourced to other countries.;)
        
         | [deleted]
        
         | vinay427 wrote:
         | There's definitely more Swiss-made signage and emphasis in
         | Switzerland than anywhere in the US I've been, having lived in
         | both countries. You'd have a hard time finding broccoli, dish
         | soap, or wheat flour labeled with a made-in-US or made-
         | in-[state] insignia in the US, for instance.
         | 
         | In general flag-bearing, however, the US might just beat out
         | Switzerland but I doubt either are at the top of that list.
        
           | systemvoltage wrote:
           | It also depends on which cantons in Switzerland. You're
           | hardly going to see flag bearers in Zurich canton for
           | example.
           | 
           | There are parts of Switzerland that are extremely
           | conservative - think deep American south but more. Women's
           | right issues are far backwards than the deepest of US south.
           | Women in gained the right to vote in federal elections in
           | 1971 in Switzerland.
           | 
           | Switzerland is also small, the size of SF Bay Area (~ 7
           | million people). Most people don't realize how small
           | Switzerland is - not in land area, but in many other aspects.
           | 
           | There is also some friction with Germany when it comes to
           | culture and customs. The Swiss pride themselves to speak
           | Swiss-German. Never suggest buying a German watch or you're
           | going to get nasty reactions :-)
           | 
           | Last but not the least, Switzerland has declined to be part
           | of the EU and majority of the people are against joining it.
           | There are a lot of parallels than differences between Brexit
           | philosophy and Swiss sovereignty.
        
         | T-A wrote:
         | > What have the Swiss ever done for us, in computer science
         | 
         | https://en.wikipedia.org/wiki/Niklaus_Wirth
        
         | fmajid wrote:
         | The Pascal programming language. Whether this is a feature or a
         | bug is left to the reader...
        
         | [deleted]
        
         | thinkloop wrote:
         | The trust is supposed to be in their legal system and politics.
        
       | mstef wrote:
       | Crypto AG. https://archive.is/d6z6l
        
       | rascul wrote:
       | Took me a minute to realize this wasn't related to the Telegard
       | BBS. I didn't see the "u" in the name at first, and I was
       | wondering what the Swiss had to do with old BBS software.
       | 
       | https://en.wikipedia.org/wiki/Telegard
       | 
       | https://en.wikipedia.org/wiki/OpenTG
        
         | exogeny wrote:
         | This is the first thought that I had too. Lots of good
         | memories, although I was on the latter end of the era and
         | mostly played around with heavily-modded Renegade and Iniquity
         | boards.
        
         | Mountain_Skies wrote:
         | Same here though my brain may have been primed in that
         | direction due to reading the Associated Press Tandy Model 100
         | article right before this. Telengard, a Rouge like game for
         | many 8-bit computers also came to mind.
        
       | tamentis wrote:
       | Thank God. I had 39 messaging systems on my phone, I didn't like
       | the odd number. Now we're good. Until next week.
        
       | sneak wrote:
       | No links to source code, no mention of open source, even in the
       | FAQ.
       | 
       | Did I miss it, or is this a wholly proprietary thing?
        
         | pelasaco wrote:
         | Switzerland is neutral. You should trust them. You must trust
         | them. /s
         | 
         | https://www.washingtonpost.com/graphics/2020/world/national-...
        
         | tgsovlerkhgsel wrote:
         | Seems proprietary, and simply name-dropping a low level
         | symmetric primitive (SALSA 20) to explain how their encryption
         | works is a serious red flag.
        
       | traceroute66 wrote:
       | Can someone give me a TL;DR 30,000ft view of why Teleguard is
       | better than what are arguably the "market leading" Swiss
       | alternatives, namely Threema and Wire ?
        
       | chovybizzass wrote:
       | This looks good. Just sent you my resume.
        
       ___________________________________________________________________
       (page generated 2021-01-23 23:01 UTC)