[HN Gopher] Teleguard: Swiss Made Safe Messaging
___________________________________________________________________
Teleguard: Swiss Made Safe Messaging
Author : 0x10c0fe11ce
Score : 45 points
Date : 2021-01-23 14:10 UTC (8 hours ago)
(HTM) web link (teleguard.com)
(TXT) w3m dump (teleguard.com)
| motohagiography wrote:
| Raises the more interesting question of what is sufficient
| collateral for a developer to make a secure messenger.
|
| Before Snowden/Poitras/Greewald, we trusted Moxie Marlinspike
| mostly because of his dreadlocks and some conference appearances.
| Very, very, few people understood what a ratchet was, let alone
| read the code. We trusted founders Jan and Brian of WhatsApp I
| think because they wrote t-filez. Security is in many ways
| cultural and aesthetic as it is technical. SILC was a thing for
| people legitimately being spied on by their governments in the
| pre-occupy anti-globalization movement - and then suddenly it
| wasn't.
|
| I want a product like this to succeed, so why snark about these
| perfectly nice seeming people's new tool? Because security has
| serious consequences. We don't need to tell anyone what we need
| privacy for, but I think we're still lacking a clear "for what,"
| to evaluate privacy technologies against.
|
| The threat we need to build privacy tools against is essentially
| suburban-bourgeois and mob governance. When you look at old
| "alternative" culture, or why people still go to things like
| burning man today, it's to engage in what are essentially
| aesthetic communities of desire and to be free of political
| oversight and surveillance. The criteria I would propose for a
| secure messenger is that it can create a private perimeter to
| facilitate the freedom of something like burning man for a
| community of users. If it isn't designed to create that kind of
| growth, it's a reaction with a limited horizon and just
| bargaining with the inevitable.
|
| Personally I think a privacy product that is for everyone is
| necessarily for no one. Maybe this is the one that gets used by
| the next burner-level community to emerge, but the conversation
| about what-for will be the thing that drives the adoption of it.
| clairity wrote:
| > "The threat we need to build privacy tools against is
| essentially suburban-bourgeois and mob governance"
|
| no, that's exactly wrong in ways that really matter,
| distracting us from real threats to free and fair living, which
| are exertions of power by large organizations (including
| governments) and wealthy (influential) people (including
| politicians).
|
| the focus on the capitol disturbance is exactly this kind of
| distraction as well, trying to vilify the relatively powerless
| while the real 'villains' (to satirize) ratchet up their hold
| on power and insulate themselves further from consequences and
| answerability to their constituent stakeholders.
|
| we should not be looking askance at each other, but rather
| askance at anyone trying to garner power and influence. the
| balance of power has no lasting stable mode so we as citizens
| must keep tabs on power. the last 50+ years has been a slow
| neglect of that duty, allowing ourselves to be distracted by
| all the new shinies.
| tgsovlerkhgsel wrote:
| > we trusted Moxie Marlinspike mostly because of his dreadlocks
| and some conference appearances.
|
| Not because experts had reviewed the design and found it good?
| (Serious question, I don't know what the exact timeline looked
| like, i.e. when people were trusting the apps vs. when reviews
| became public)
| tgsovlerkhgsel wrote:
| "The" Swiss made secure messaging app (which already has brand
| recognition and some meaningful adoption within Switzerland) is
| Threema (no affiliation, and I'm using Signal - just comparing to
| Threema because "Swiss made" seems to be what this app is trying
| to make their main selling point).
|
| This app has "1,000+" installs on the Play store (Threema:
| "1,000,000+"), and doesn't use phone numbers as IDs, i.e. it's
| only useful if you for some reason want to migrate all your
| friends to a brand new chat app that nobody else has heard about,
| and that has no really unique selling points, and thus little
| chance of building meaningful network effect (which is critical
| for chat apps, because a chat app without people to talk to is
| useless). As a result, it seems unlikely to be successful and
| thus unlikely to be supported (or exist) long term.
|
| It seems to be a poorly thought out attempt to jump onto the
| wagon train far too late and get users trying to flee WhatsApp.
| Due to the network effect, adding choice is likely to help only
| the incumbent (WhatsApp) by making it harder for any of the
| alternatives to reach critical mass.
|
| The crypto design is also highly questionable: They say they're
| using "SALSA 20", which is a low level primitive (comparable to
| e.g. AES), not a complete protocol. Advertising primitives shows
| little understanding of the actual problems in cryptographic
| practice, and thus a significant risk that not enough work went
| into designing the protocol around it, resulting in something
| that is insecure overall.
| aleken wrote:
| Let's throw this in the mix! https://www.secuwine.com/ Under
| Norwegian and European laws and regulations
| dbrgn wrote:
| Does this app have _any_ USP?
| lvs wrote:
| That famous swiss encryption...
| tgragnato wrote:
| oh come on! Switzerland is neutral!
| outside1234 wrote:
| Especially if you are German and need banking during a world
| war.
| rich_sasha wrote:
| Surely lots of holes in it then?
| outside1234 wrote:
| Why is Swiss Made better for ethics?
|
| These are the same folks that looked the other way on Hitler (and
| in fact were his preferred banking location) and recently sold a
| phone with a backdoor while claiming it was private.
|
| The Swiss are extremely systematic, which makes them great at
| banking, but ethical? Not sure about that.
| krsdcbl wrote:
| I think the "swiss made" plays onto two ideas in this context:
| on the one side, Switzerland having a very advanced industry
| when it comes to precision technology / on the other side
| Switzerland being a neutral country of high diplomatic esteem.
|
| But both of those tropes might very well be a little stuck in
| the last century imho.
| Rochus wrote:
| It's just about a messenger, not saving humanity.
| egberts wrote:
| someone needs to update https://www.securemessagingapps.com/
| [deleted]
| newscracker wrote:
| I'm constantly on the lookout for newer and/or different
| messaging applications. This one is good because it doesn't rely
| on a phone number. But it's still yet another centralized system.
| There isn't enough information on how this service doesn't store
| user data (or metadata) and still manages to connect them (in
| contrast, Signal has many blog posts and documentation about how
| it minimizes data collection).
|
| In the FAQ, there's this:
|
| _> Which operating systems are supported?
|
| > TeleGuard supports all Android devices with version OS 5.0.3+
| and all iPhone devices with at least iOS 9.0+._
|
| It's good to support a few older versions of operating systems,
| but I don't think a messenger can promise security or privacy if
| it supports operating systems that are quite old by mobile
| standards and aren't getting security updates for a long time.
| Wikipedia says that Android 5's latest release was nearly six
| years ago (April 21, 2015) and that of iOS 9 as 17 months ago
| (July 22, 2019). Supporting iOS seems kinda ok, but supporting
| that Android version looks quite bad.
|
| I also judge websites by what they say and how they say it. In
| the FAQ, after the answer for "07. Edit Profile", there's a list
| of bullet points that looks like a to do list for additional FAQs
| that haven't been completed:
|
| * Send media
|
| * Forgot password?
|
| * How is TeleGuard financed?
|
| * Registration
|
| * Add contacts from the phone list
|
| * What kind of encryption does TeleGuard use?
|
| I don't think this is ready for prime time yet.
| tao_oat wrote:
| This website is awfully light on details. Is it open source? Is
| there a whitepaper on the encryption used? Does it have e.g.
| forward secrecy? At the moment there's no reason why you might
| want to use this over e.g. Signal or Wire, both of which use
| well-studied encryption schemes.
|
| Also -- "Complex encryption system for all transmitted data" does
| not seem like a particularly good thing.
| 1cvmask wrote:
| I think the Swiss Made Safe Messaging is suspect to those who
| know about backdoors. In fact the Swiss sold "encrytped" crypto
| phones with backdoors baked in as a business model. You paid to
| get spied on:
|
| https://en.wikipedia.org/wiki/Crypto_AG
| nabla9 wrote:
| You seem to associate two completely separate things only
| because they are both incorporated in Switzerland.
|
| Crypto_AG (founded in 1952) was part of secret US/West German
| government project.
|
| Are you claiming that Andreas Wiebe, Hulbee AG, Swisscows AG
| are also working for the US government?
| 3327 wrote:
| I think his association is not far fetched, did you read the
| post and the Narrative?
|
| Are they not using the "Swiss" brand as a pretext to convey
| safety and imply security?
|
| OP is pointing out a clear and recent example that the "Hey
| this is Swiss" therefore must be "safe, secure, reliable" is
| no longer the truth.
| eganist wrote:
| The Swiss Government was (at the latter part of the
| operation) aware and complicit.
|
| https://www.swissinfo.ch/eng/business/no-official-outcry-
| in-...
|
| Given this precedent, there's good reason to believe it would
| happen again. There is _not_ reason to believe that the
| people behind Teleguard today would be in favor, but there
| _is_ good reason not to become wedded to the service given
| the risk that it may change hands or be operated similarly to
| Crypto AG down the road.
| nabla9 wrote:
| There is no indication that Swiss Government at the high
| level was aware. Intelligence agencies were aware.
|
| It's important to understand that the was violation of
| Swiss neutrality law, and it was not started by Swiss
| government or government agency.
| eganist wrote:
| > There is no indication that Swiss Government at the
| high level was aware. _Intelligence agencies were aware._
|
| I'm not seeing how
|
| 1. Swiss intelligence is somehow distinct from the Swiss
| government.
|
| 2. this mitigates the risk I described.
| paulryanrogers wrote:
| Well if they are leaning on the reputation the Swiss as being
| neutral or otherwise more trustworthy, then it's relevant.
| nabla9 wrote:
| They are neutral and trustworthy. Significantly so.
|
| Nobody is absolutely neutral or always trustworthy. It's
| argumentation error to move from is not completely neutral
| and has had some issues to saying "it's all bullshit".
| paulryanrogers wrote:
| Didn't mean to dismiss them out right. Rather that
| banking on 'Swiss' as a shortcut isn't wise. Obviously if
| one does the work to audit those involved or the
| product/service itself then they can trust it regardless
| of the marketing.
| saiya-jin wrote:
| What does banking has to do with secure messaging? That's
| pretty basic strawman argument. For example US does
| Blackwater and did MK Ultra on its own citizens, so what?
|
| Banking en Suisse adheres to Swiss laws, which are
| heavily influenced by EU and US laws these days. If some
| private company decides to break the law, they will be
| handled accordingly.
| paulryanrogers wrote:
| Banking as is depending upon, not financial services.
| idlewords wrote:
| We all know Swiss products are full of holes.
| Rochus wrote:
| Only the cheese.
| tptacek wrote:
| A peeve of mine: pretty much all "made outside the US"
| messaging is sketchy, because one of the most important
| differences between stuff run in the US and stuff run outside
| the US is that NSA doesn't need special permission to hack
| stuff run outside the US --- in fact, hacking stuff outside of
| the US is basically their whole charter.
|
| I'm not saying you should purposefully select US technology in
| order to avoid surveillance, just that "hosted or made in
| Switzerland" messaging in privacy tools isn't very meaningful,
| and takes advantage of an emotional reaction in prospective
| customers, not a rational one.
| saiya-jin wrote:
| That might be true if you are US person. If you're not, like
| 95% of the mankind, using non-US hosted services lowers the
| threat. Nobody knows how much since the answer lies in NSA
| capabilities.
|
| But as a smart approach, for folks ie in Europe, US is a big
| no-no if security is a concern.
| tptacek wrote:
| I don't see how it does; if you're a non-US person using a
| non-US service, you have essentially no formal legal
| protections whatsoever from NSA surveillance. A non-US
| person using a US service at least inherits whatever
| procedural protections US companies have. I'm not saying
| it's a meaningful barrier, just that going overseas
| logically can't _gain_ you protection (unless you 're more
| worried about the Swiss or EU's sigint agencies than you
| are the NSA).
| Barrin92 wrote:
| As a non-US person I'm not concerned about the NSA, it
| doesn't have a material impact on me, it's not like the
| NSA orders a black helicopter to snatch me from Germany.
| I'm worried about corporate use of my data because that
| stuff can actually realistically leak or be used for ads
| or whatever else and in this case I have probably better
| default protections with a Swiss company than with a US
| based one. (with some exceptions of course, Signal and so
| on seem trustworthy).
| Youden wrote:
| I think you're missing a bigger issue: if the data is in
| America, _nothing needs to be hacked_. Your data can be
| obtained through legal means.
|
| Plus, if you're not an American citizen, you have no rights
| so far as three-letter agencies are concerned, whether your
| data is stored in the US or elsewhere.
|
| The choice is between data stored in the US, where data can
| be obtained through legal means or hacking, and data stored
| elsewhere, where it can only be obtained through hacking.
| tptacek wrote:
| That's true. You do have to make a decision about which
| protection you feel is stronger: the American legal system,
| or the current commercial state of the art in computer
| security lined up against the world's largest consumer of
| offensive security technology.
| Youden wrote:
| That could be true but only applies to people subject to
| the American legal system, i.e. those with American
| citizenship or living on American soil.
|
| For the other 96% of us, the American legal system offers
| no protection whatsoever, as far as I'm aware.
|
| This deficiency is not true of all jurisdictions. As far
| as I can tell from reading articles 1-3 GDPR, the GDPR
| applies to all processing that takes place within the EU
| or on behalf of an EU entity, regardless of whether the
| subject of the data is a citizen or resident of the EU.
| Same goes for the Swiss data protection act [0].
|
| So as a non-American, I have a choice between services
| located in a country where I have no legal rights and
| services located in countries where I do.
|
| This is also all from a security point of view. From a
| privacy point of view, I know that American companies
| have essentially free reign over the data I give them.
| They can monetize it, sell it, train machine learning
| models with it or do whatever else they please,
| regardless of whether they have my explicit consent.
|
| Other jurisdictions have privacy protections, so I know I
| have some basic level of privacy if I choose say a German
| email provider, while I know I have essentially none if I
| choose an American one.
|
| Really, as a non-American, I see no reason why I should
| treat American services as being any better than say
| Russian or Chinese services. I'm happy to listen if you
| have any compelling arguments though.
|
| [0]:
| https://www.fedlex.admin.ch/eli/cc/1993/1945_1945_1945/en
| systemvoltage wrote:
| There is also this:
| https://en.wikipedia.org/wiki/Onyx_(interception_system)
|
| > The goal of the system is to monitor both civil and military
| communications, such as telephone, fax or Internet traffic,
| carried by satellite.
| WanderPanda wrote:
| I think people underestimate how much of a blow this is for
| Switzerland
| ur-whale wrote:
| That and the fact that they sold "banking secrecy" to the
| whole of Europe for the better part of a century only to
| betray all those promises in the 21st century.
| saiya-jin wrote:
| Banking secrecy was removed due to peer pressure from EU
| and US, which together form a majority of exports for
| Switzerland. They just did make keeping the secrecy
| extremely costly in form of import tariffs on Swiss goods.
|
| Originally intended as a fine example of government
| actually caring about privacy of its own citizens, then
| heavily misused by local and international banks, it just
| stopped making sense anymore at one point. Its still
| somewhat valid for its own citizens and AFAIK residents.
|
| Banking together is cca 12% of Swiss economy, so the
| fantasy of some folks who read let's say alternative news
| about Switzerland ruining itself by losing banking secrecy
| didn't pan out. Swiss economy is much more reliant on tons
| of small/medium high quality manufacturing companies, or
| tourism rather than banking.
| dgellow wrote:
| Though it was a CIA ops. That doesn't make everything "swiss
| made" suspect (but it clearly impacted the "Swiss made" brand
| and Zug's reputation).
|
| Switzerland has strict data protection laws, that's why some
| companies are established there and pushing that branding
| (also, low taxes).
| fmajid wrote:
| CIA and BND (Bundesnachrichtendienst, the German intelligence
| service). They actually owned the CryptoAG company. It's
| become a big political scandal there, with accusations that
| the Swiss intelligence services knew and deliberately misled
| their parliament.
| acct776 wrote:
| Of course some of them knew.
| nix23 wrote:
| If your intelligence service let the biggest bank of
| Switzerland (UBS) buy those product, there is no excuse, and
| later being proud of the whole thing (as a neutral country)
| it's a shame and a shit stain on our integrity (which is/was
| more or less the only real quality of Swiss services)
| bergstromm466 wrote:
| After Crypto AG [1], does 'Swiss made' really still have the same
| positive connotations it used to?
|
| I'm so over any sort of branding that proclaims the superiority
| of one nation over others. [2]
|
| If we really wanna give credit, why not list the actual names of
| the engineers that came up with the encryption mechanisms?
|
| Same goes for Apple's _' Designed in California'_ etc.
|
| [1] https://news.ycombinator.com/item?id=22297963
|
| [2] https://www.youtube.com/watch?v=VRh925Is_1U
| sobriquet9 wrote:
| Closed source, unclear what protocol is used. They mention SALSA
| 20 which is good, but that's probably just channel encryption. No
| details on how session keys are derived.
| nix23 wrote:
| Wow those peoples completely missed Crypto Ag and Opensource.
|
| DONT trust Swiss enc. Products
|
| BTW: I'm Swiss
| 1_player wrote:
| People from Switzerland are probably the most patriotic in the
| world after those from USA. If it's made in Switzerland, you can
| be sure "Swiss-made" is prominent and there's a white-on-red
| cross somewhere visible.
|
| But, honest question, is there such thing as the "Swiss
| guarantee" in tech?
|
| What have the Swiss ever done for us, in computer science, to
| demand such respect just by mentioning the place of origin as
| certificate of trust?
| [deleted]
| polymeris wrote:
| It's only partially patriotism. More importantly, I suspect,
| just a brand that sells well, no matter what you are selling.
| That said, EPFL/ETH and CERN have done some important things in
| computer science.
| T-A wrote:
| CERN is an international laboratory which happens to be
| located on the border between Switzerland and France. I
| wouldn't call it Swiss.
| bergstromm466 wrote:
| CERN is made possible by shared European funding, hardly
| 'Swiss'.
| polymeris wrote:
| True. And much of the work at ETH is conducted by
| foreigners, but the marketing association is still there.
| tdudzik wrote:
| And much of the work in the USA is done by foreigners or
| even outsourced to other countries.;)
| [deleted]
| vinay427 wrote:
| There's definitely more Swiss-made signage and emphasis in
| Switzerland than anywhere in the US I've been, having lived in
| both countries. You'd have a hard time finding broccoli, dish
| soap, or wheat flour labeled with a made-in-US or made-
| in-[state] insignia in the US, for instance.
|
| In general flag-bearing, however, the US might just beat out
| Switzerland but I doubt either are at the top of that list.
| systemvoltage wrote:
| It also depends on which cantons in Switzerland. You're
| hardly going to see flag bearers in Zurich canton for
| example.
|
| There are parts of Switzerland that are extremely
| conservative - think deep American south but more. Women's
| right issues are far backwards than the deepest of US south.
| Women in gained the right to vote in federal elections in
| 1971 in Switzerland.
|
| Switzerland is also small, the size of SF Bay Area (~ 7
| million people). Most people don't realize how small
| Switzerland is - not in land area, but in many other aspects.
|
| There is also some friction with Germany when it comes to
| culture and customs. The Swiss pride themselves to speak
| Swiss-German. Never suggest buying a German watch or you're
| going to get nasty reactions :-)
|
| Last but not the least, Switzerland has declined to be part
| of the EU and majority of the people are against joining it.
| There are a lot of parallels than differences between Brexit
| philosophy and Swiss sovereignty.
| T-A wrote:
| > What have the Swiss ever done for us, in computer science
|
| https://en.wikipedia.org/wiki/Niklaus_Wirth
| fmajid wrote:
| The Pascal programming language. Whether this is a feature or a
| bug is left to the reader...
| [deleted]
| thinkloop wrote:
| The trust is supposed to be in their legal system and politics.
| mstef wrote:
| Crypto AG. https://archive.is/d6z6l
| rascul wrote:
| Took me a minute to realize this wasn't related to the Telegard
| BBS. I didn't see the "u" in the name at first, and I was
| wondering what the Swiss had to do with old BBS software.
|
| https://en.wikipedia.org/wiki/Telegard
|
| https://en.wikipedia.org/wiki/OpenTG
| exogeny wrote:
| This is the first thought that I had too. Lots of good
| memories, although I was on the latter end of the era and
| mostly played around with heavily-modded Renegade and Iniquity
| boards.
| Mountain_Skies wrote:
| Same here though my brain may have been primed in that
| direction due to reading the Associated Press Tandy Model 100
| article right before this. Telengard, a Rouge like game for
| many 8-bit computers also came to mind.
| tamentis wrote:
| Thank God. I had 39 messaging systems on my phone, I didn't like
| the odd number. Now we're good. Until next week.
| sneak wrote:
| No links to source code, no mention of open source, even in the
| FAQ.
|
| Did I miss it, or is this a wholly proprietary thing?
| pelasaco wrote:
| Switzerland is neutral. You should trust them. You must trust
| them. /s
|
| https://www.washingtonpost.com/graphics/2020/world/national-...
| tgsovlerkhgsel wrote:
| Seems proprietary, and simply name-dropping a low level
| symmetric primitive (SALSA 20) to explain how their encryption
| works is a serious red flag.
| traceroute66 wrote:
| Can someone give me a TL;DR 30,000ft view of why Teleguard is
| better than what are arguably the "market leading" Swiss
| alternatives, namely Threema and Wire ?
| chovybizzass wrote:
| This looks good. Just sent you my resume.
___________________________________________________________________
(page generated 2021-01-23 23:01 UTC)