• CosmoNova@lemmy.world
    link
    fedilink
    English
    arrow-up
    29
    ·
    4 months ago

    I‘m a little bit confused because all of this is moving so quickly (and badly) when the EU is known to work slow. How do they even have an app ready so quickly? Even when it‘s trash. It‘s almost as if they act on the ‚wisdom‘: „Apologizing later is easier than asking for permission first.“ I get the impression they started working on this before any legislation was even proposed.

  • gsv@programming.dev
    link
    fedilink
    English
    arrow-up
    15
    ·
    4 months ago

    Maybe the security expert could read the readmes in the repos first. From the iOS app repo:

    The initial development release has reduced security, privacy, availability, and reliability standards relative to future releases. This could make the software slower, less reliable, or more vulnerable to attacks than mature software.

    And further:

    If you’re planning to use this application in production, we recommend reviewing the following steps: […] The Pin storage configuration matches your security requirements, or provide your own by following this guide Pin Storage Configuration […]

    So the text hints not at design flaws but at facts that are already stated in the readme. <irony> Plus, the major source for the article is Pavel Durov, who’s messenger is of course a standard in security and privacy. </irony>

    So there seems to be no news but a lot of speculation by Durov instead.

  • linule@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    4 months ago

    What’s the official stage of it? was it already intended to be released? If not it might be less of an issue.

    Anyway it’s good that it’s open source. At the very least it encourages public discussion and in this case noticing the flaws.

      • linule@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        ·
        edit-2
        4 months ago

        That “ready” is just typical political advertising speech. Could have been worded more carefully, but it’s forgivable. As long as the git repo and website correctly identify it as a demo/prototype, it seems fine to me. E.g. not using the security enclave is totally fine for a demo. It doesn’t affect the general protocol design. There’s a lot of hostility both to these initiatives as well as to the EU (often by different actors, there’s e.g other countries pushing for less privacy respecting mechanisms), so the clever criticism tends towards nitpicking. There’s actually merit in releasing such an ambitious project as open source and so early, which even with the nitpicking and negativity, is a good thing.

        • Twongo [she/her]@lemmy.ml
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 months ago

          that is a very pessimistic outlook.

          there covid app for example was also something that could be misused in terrible ways and they managed to even get it approved by the ccc.

          defeatism just makes things worse.

            • Twongo [she/her]@lemmy.ml
              link
              fedilink
              English
              arrow-up
              2
              ·
              4 months ago

              you are missing the point: this measure is a steaming pile of dogshit. but it’ll be forced on us anyway - the least we can do is make sure it’s at least secure because even a hardliner can’t defend this security issue