this post was submitted on 01 Dec 2023
108 points (97.4% liked)

Privacy

80 readers
2 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 1 year ago
MODERATORS
 

After the Tchap project based on Matrix, the French Prime Minister asks anyone in the gouvernement to use Olvid, the only app validated by the ANSSI, with metadata encryption and no centralised architecture nor contacts discovery. But only the front-ends are open source, not the back-end.

Source: https://www.politico.eu/article/france-requires-ministers-to-swap-whatsapp-signal-for-french-alternatives/

all 48 comments
sorted by: hot top controversial new old
[–] joelimgu 28 points 9 months ago (3 children)

I can understand the WhatsApp part, its a closed source app but it makes no sense to ban an open source app bc of security concerns, just order a study of the source code to validate it

[–] plz1 43 points 9 months ago (2 children)

France wants backdoors into these apps, it's not a lack of trust thing.

[–] [email protected] 3 points 9 months ago (1 children)

France wants backdoors into these apps, it’s not a lack of trust thing.

If it's trivial for a host nation to add backdoors to instant messaging services, you'd be agreeing with the government of France and you'd be pressing to migrate your communication out of the hand of third parties.

[–] plz1 1 points 9 months ago (1 children)

I’m not a proponent of any backdoors like this. I use Signal because it puts privacy first.

[–] [email protected] 1 points 9 months ago (1 children)

I’m not a proponent of any backdoors like this.

I'm not sure you got the gist of what I said. The point I made was that if being the host nation of an organization meant that their government can add backdoors at will, using any foreign service would automatically mean you'd be snooped by external actors.

Regardless of where you stand on whether you want to add your own backdoor or not, by your own logic using a foreign service means your services are already compromised.

If that's the case, wouldn't it make sense to simply run your own stuff?

[–] plz1 1 points 9 months ago

I agree. The challenge in running your own stuff is adoption. Having my item chat platform is kind of outlets if no one else is willing to switch to it for me. That’s the same problem I have with Signal when I decided to stop using anything Meta owns.

[–] [email protected] 3 points 9 months ago

Darmanin's dream.

[–] [email protected] 20 points 9 months ago (1 children)

A far better reason not to use WhatsApp is that it is run by Facebook. It was also a primary vector for Pegasus.

[–] [email protected] 1 points 9 months ago (1 children)

A far better reason not to use WhatsApp is that it is run by Facebook. It was also a primary vector for Pegasus.

Aren't you doubling down on the government of France's position?

I mean, the french minister did explicitly stated that "[you] cannot guarantee the security of conversations and information shared via them".

[–] [email protected] 2 points 9 months ago (1 children)

For WhatsApp, sure. For Signal, no.

[–] [email protected] 2 points 9 months ago (1 children)

For Signal, no.

There is an argument to make about using custom versions of Signal that route their traffic through your own infrastructure.

This would count as France running their own service.

Given that Signal relies on centralized servers to route traffic, and if I'm not mistaken they use AWS in US instances, this means that your Signal traffic is being fed straight into the US security services' infrastructure. France might be a staunch ally of the US, but they do go through great lengths to preserve their independence.

[–] [email protected] 1 points 9 months ago

Sure, I'd be the last person to say that Signal is perfect and secure. But it's a damn sight more secure than WhatsApp.

[–] [email protected] 3 points 9 months ago (2 children)

Indeed. However we can think the Olvid company, a private company, was very pushy to promote its product and made people think the other apps are worse. In fact it seems Olvid, compared to Signal, encrypt metadata and does not rely on contacts nor identity server. And because it’s a French app, “sovereignty matters” (even of ministers use Microsoft Office solutions 🤡)

[–] [email protected] 2 points 9 months ago (2 children)

Western countries got 'lobbying', Eastern countries got 'corruption' amirite? If they really cared, they would've certified Tox, that I2P IM or Simplex...

[–] [email protected] 2 points 9 months ago

If your solution had been chosen, it’s lobbying. If not, call corruption 😂

[–] [email protected] 1 points 9 months ago* (last edited 9 months ago) (1 children)

Western countries got ‘lobbying’

The term "lobbying" doesn't mean corruption. It means basically have meetings with stakeholders to discuss issues regarding policy and agenda.

If you hold a meeting with your local city council asking for a crosswalk, you're engaged in lobbying. If you chat with the local police chief asking for more patrols in some part or another of town, you're engaged in lobbying.

Now, lobbying might set the stage for corruption. If you're talking to your city council about the need for a crosswalk and you show a video of cars speeding by an intersection, that's ok. If instead you tell your city councilman that if he hires your construction company to build that crosswalk then you'll pay him a wad of cash, that's corruption.

Lobbying is not corruption. It's weird how the basis of any democratic system is attacked for being "corruption" to try to justify corruption in corrupt hellholes.

[–] [email protected] 1 points 9 months ago* (last edited 9 months ago) (1 children)

Yeah yeah all is great. But we often hear about 'corporate lobbying' and you've described things mostly carried out by individuals or nonprofits. Now I'm not saying that some corporate entities cannot convince politicians to do anything without bribing them. But the purpose of any private company is creating profits for the shareholders. If they fund a biased research or fabricate evidence to prove their point in talks with governmental bodies that can result in securing more profits, but do not hand money to any politician then is it corruption or lobbying? Or what if they offer their software in exchange for providing backdoors for the government? Or if they engage in price dumping to win a government tender just so that they can overcharge elsewhere?

[–] [email protected] 1 points 9 months ago

But we often hear about ‘corporate lobbying’ and you’ve described things mostly carried out by individuals or nonprofits.

No, I'm describing lobbying. The definition of lobbying doesn't depend on your market capitalization or revenue. A corporation does lobbying, just like unions do and industry representatives and community groups. If you have personal interests and want to raise awareness with stakeholders then you reach out to them.

I mean, Wikipedia's article on lobbying also refers to it as advocacy. From Wikipedia;

In politics, lobbying or advocacy, is the act of lawfully attempting to influence the actions, policies, or decisions of government officials, most often legislators or members of regulatory agencies, but also judges of the judiciary.

"Attempting to influence" is the operative principle.

And so is "lawfully". Which is not the same as the corruption you pinned on "Eastern countries".

[–] [email protected] 2 points 9 months ago

That shouldn't be a job for the French administration ? How can they give credit to a private company for such sensible informations ?

[–] [email protected] 17 points 9 months ago (1 children)

To start Europe should have secure phones made in EU.

[–] [email protected] 8 points 9 months ago (1 children)

To start Europe should have secure phones made in EU.

Doesn't switching instant messaging services count as a start? Switching hardware is far harder than switching software.

Also, local messaging systems also determine where your traffic goes and who controls that data. If you have a french messaging service with data centers in france routing traffic between people in France, you are in a far better shape.

[–] [email protected] 1 points 9 months ago (1 children)

When Real-Time Bidding allows foreign states and non-state actors to obtain compromising sensitive personal data about key European personnel and leaders to get location data, time-stamps, websites and apps activities; switching to a local messaging service appears to be a weak patch. You can get an overview of the actual situation here : https://www.iccl.ie/digital-data/europes-hidden-security-crisis/

[–] [email protected] 2 points 9 months ago (1 children)

appears to be a weak patch.

It's not a patch. It's eliminating an attack vector, and the one which is more pervasive and easier to exploit.

Security-minded people pay far more attention to what software you run than what hardware you have.

[–] [email protected] 1 points 9 months ago

You didn't read the article apparently.

[–] [email protected] 16 points 9 months ago (1 children)

Can't wait to hear how this gets hacked!

[–] [email protected] -4 points 9 months ago (2 children)

Olvid is the only messaging application today certified by the ANSSI (the French security agency), I doubt this one will be hacked.

[–] FutileRecipe 17 points 9 months ago (1 children)

Olvid is the only messaging application today certified by the ANSSI

Is there a list of those they've tested, and why they didn't meet criteria? Has Signal been tested?

Without that info, just seems coincidental that the French government has bestowed this cert on only a French app.

[–] [email protected] -5 points 9 months ago

Same point of view 🙃

[–] [email protected] 4 points 9 months ago (1 children)

It's only a matter of time.

[–] [email protected] -4 points 9 months ago (3 children)

A matter of time, resources, knowledge, tools, energy, intels. With the ANSSI credit, good luck.

[–] [email protected] 3 points 9 months ago (1 children)

Just because everything checks out in principle doesn't mean it's actually secure. First off, we have no certainty of the client code running; it's open source, sure, but unless they ensure reproducible builds - which, given it's on the Play store (and I assume Apple app store), they can't be, since the binaries must be signed - we have no way of knowing whether the code actually being downloaded and run is actually the same as the FOSS version. Further, even if it is, it may have intentional subtle vulnerabilities meant to be used by the French govt (so would easily pass certification by having the ANSSI be instructed top-down to overlook certain things), or it may be that the server can trigger a known bug resulting in leakage of data. At an even more paranoid level, it's possible that the encryption itself is faulty; the specification says it uses aes256 and ed25519 which is about as battle-tested as it gets, but the PRNG seems to be mostly their own innovation. It specifies a minimum of 32 bytes of entropy, which (though cryptography is not my expertise, so at this point I'm wildly speculating) is probably trivial to send or embed in some other communication with the server e.g. by ensuring the PRNG is deterministic after the first keygen and faulty in some known way and sending over a future result.

I wouldn't trust the French government.

[–] [email protected] 5 points 9 months ago (1 children)

Seeing as the French government was going after a group of people for using Signal and other 'clandestine' behaviors, I'm with you in distrusting them.

[–] [email protected] 1 points 8 months ago (1 children)

Wasn't also France behind a lawsuit in Switzerland that got Protonmail to start spying on its users?

[–] [email protected] 1 points 8 months ago

I hadn't heard about that one but I'm not surprised.

[–] [email protected] 1 points 9 months ago

You ever hear of nation-state actors?

[–] [email protected] 12 points 9 months ago* (last edited 9 months ago) (1 children)

I downloaded and scanned it with App Manager. Google play billing, another Google something, and telemetry from someone else. Also has the Google maps api. Pass

Edit: I use SimpleX which has many of the same features (no phone number, ETEE, lots more) but is FOSS, has no trackers, has been audited by Trail of Bits, and can be self hosted if you wish. I am very happy with it after leaving Signal.

[–] [email protected] 6 points 9 months ago (1 children)

Don’t know App Manager. What is it? The report from Exodus Privacy is interesting: https://reports.exodus-privacy.eu.org/fr/reports/io.olvid.messenger/latest/

[–] [email protected] 7 points 9 months ago (1 children)

It's an Android app that can 'Scan for trackers and libraries in apps and list (all or only) tracking classes (and their code dump)' as well as many other functions

https://github.com/MuntashirAkon/AppManager

[–] [email protected] 4 points 9 months ago

Thank your for sharing 🙂

[–] [email protected] 12 points 9 months ago (1 children)

i rather doubt a government would push people out of signal-protocol apps and into Some Other App if they didn't already have a backdoor into the designated substitute

[–] [email protected] 2 points 9 months ago

Servers are private, so we can conclude anything…

[–] slazer2au 11 points 9 months ago (1 children)

Ah yes, politicians making technical decisions about technology they won't understand.

[–] FutileRecipe 5 points 9 months ago

To be fair, their job is not to 100% understand the technology, but to govern (they are politicians, not IT or SysAdmins)...and listen to subject matter experts as they make those decisions.

[–] [email protected] 3 points 9 months ago

Minitel 2 let's go

[–] [email protected] 2 points 9 months ago

Olvid seems okay, but I find it weird that they advertise the fact that they don't need to trust their servers as a feature somehow unique to them. Yeah, their "lack of centralized user directory" USP is a good feature (or lack thereof), but in the end it's "yet another secure messenger", even tough their github specificially says it's not.

If it were federated (as far as I can tell it's not), then it would be a different matter. That would be a great USP. Kind of like Tox, but federated instead of P2P.

[–] [email protected] 2 points 9 months ago

This is the best summary I could come up with:


French Prime Minister Élisabeth Borne has banned widely used messaging applications WhatsApp, Telegram and Signal for ministers and their teams due to security vulnerabilities, according to a memo seen by POLITICO.

Borne set a deadline of December 8 for the government to switch to using the French app Olvid instead, which is certified by France's cybersecurity agency ANSSI.

Tchap, the government-developed secure messaging and collaboration app, launched in 2019, is also allowed.

In December, the entire government will be using [Olvid], the world's most secure instant messaging system," French digital minister Jean-Noël Barrot confirmed on X.

The government previously ordered civil servants to remove all types of social media platforms, gaming and video-streaming apps — including TikTok, CandyCrush and Netflix — from their work devices over cybersecurity and privacy concerns.

This article was updated to include details on the memo seen by POLITICO.


The original article contains 193 words, the summary contains 143 words. Saved 26%. I'm a bot and I'm open source!

[–] [email protected] 1 points 9 months ago* (last edited 9 months ago)

Is berty still around?

Edit: they are https://berty.tech/