India reportedly wants to build its own WhatsApp for government communications
techcrunch.com
techcrunch.com
https://techcrunch.com/2019/04/19/security-flaw-in-french-go...
The only time we hear about bugs with non OS software is when there is a masssive breach, FB initially reveals it only affects a small number of people, a few weeks later quietly revised that to a few 10s of million, and then a couple of months later buried somewhere that it was actually hundreds of millions of users affected.
Also you do not seem to understand that bugs and resulting security problems are something that happen every day - and get fixed quickly, usually, after discovery. This is what they mean when domain experts say things like "security is a process".
Also here we see a perfect example of why you want to use open source software for all governmental software: after a bug was found your admins can see the code changes and understand, if the bug still exists or not. Even more, only with open source software your admins and developers can read the code and search for bugs, too! This is what makes open source software a very good idea!
You are welcome to the world of free and open software, and after some reading about the basic principles I am sure you will understand why open source software is used by so many companies and organizations around the world.
BTW re the website you pointed to: I see a very annoying, totally absurd cookie dialog that makes me click at least five times and still does not give me a choice to not accept cookies at all. Please do not link to that website until they wake up and stop insulting visitors with this UI nightmare and learned that nobody needs to set cookies to publish content. Also this is not a website a pro developer would ever read or point to - always prefer to point to the primary source of information.
They failed the "secure" part - nothing else matters, and that does not mean that rolling your own should be discouraged - it means that these things are hard, and chances are your pet project will be less secure than established systems.
> Please do not link to that website until they wake up and stop insulting visitors with this UI nightmare
Had I known that this happend for your UA, I would not have - worked like a charm on my side.
Thank the French for that, who are the main reason behind the EU legislation about Cookies.
> Also this is not a website a pro developer would ever read or point to
Gatekeeping, are we? "Pro developers" don't waste time searching for some obscure original source for a meaningless online discussion - they pick the first result of their favorite search engine.
This again is wrong. The problem originated by publishers who track users and disrespect their privacy for many years.
The regulation that happened after a very long time of people urging governments to do something about that, makes this initial problem better visible.
Still it is important to understand: no cookies are needed at all for publishing content.
Cookie regulation is one of the best examples of how governments meddling into tech has backfired.
It would have been a much better idea to launch a public awareness campaign about cookies and their client-side blocking, or even provide patches to open source browsers to have a better UX for blocking cookies by default. The only regulation that should have been passed (if any), would have been to allow access (to static content) despite blocking of cookies client-side.
Publishers can show a cookie-free site to all visitors and offer a cookie opt-in for some kind of added value, e.g. "more information for membership".
There is no governmental force pushing anybody to produce a website that diplays a "cookie dialog" even before you see what that site is about or if you like it. You are producing a false and absurd story of "governments meddling into tech produces cookie dialogs".
Had the regulation at least forbade this behavior, we most likely wouldn't be in this situation.
However, thinking back, I guess it's fair to say that publishers might have implemented this blocking behavior if the governments would only have done a public awareness campaign. In this case, only a minimum set of regulations (ban force acceptance of cookies for static content) would suffice as well.
I'm not saying that Matrix is bad, or that XMPP is definitely better, but the facts are there and we'd better stick to that than hold on how we feel about each piece of technology.
I hope they go for Matrix, like France did, but I get a feeling they'll be hit hard by NIH.
One relatively low effort path for a government might be to simply adopt something like Chatsecure and fix it.
But it's a good idea nonetheless. A lot of confidential data is sent over WhatsApp.
Imagine the data that PM/FM has!
I can't find a source but I do remember that IE used to ship with reduced encryption. Perhaps we have learnt some lessons since then :-)
With government support and financial support, india could easily have an indian "whatsapp". WhatsApp isn't technological sophisticated. It's simply a large network. With government/business "tweaking", india could help their own "whatsapp" company take over much of that market from facebook.
Why hand the entire indian market over to facebook and zuckerburg?
There is no reason why large and significant markets shouldn't be dominated by local businesses. Not to say whatsapp should be banned from india, but it's only the incompetence of government/business that cedes their market to foreign companies. This also applies to the EU. It's insane to me that the EU doesn't have their own google, facebook, etc.
On the other hand ,Wouldn’t some other govt sub-org like CDAC etc might get to build this via NIC or whomsoever supervises this?
Our beloved PM sending messages via 'Raamdoot' messenger on Aakash tablet will set the tone for entire bureaucracy.
That aside, it's a bit of a mystery why anyone would choose a proprietary app whose owner could be in cahoots with anybody and you would never know over an open source app, given the entire point of the exercise to ensure your communications private. Facebook is even talking about monetising WhatsApp chats, and governments are talking about forcing Facebook to store the chats so they can be retrieved with a suitable warrant. Yet people still choose use these apps for private communications. Such is the power of the marketing dollar, I guess.
The pathetic Indian Government websites would show you what they are capable of when designing a product that is supposed to work for Millions/Billions of people. They are just going to line up TCS or Wipro's pockets because that's the cheapest and also the crappiest.
India has a very large base of software engineers, security researchers and local cloud builders that would love to contribute to such a project.
Hopefully it inspired a bit of innovation.
China has learned a lot from not adopting all the US products and implementing their own product and in some ways we see things they did, that our products had not done yet.
The monoculture that the digital hegemony of a few multi national corporations creating the only viable solutions is not healthy.
Making something like a government chat system, might be the seed for creating a public system.
The interesting parts for any potential implementation only pertain to things like workflow, integrations to existing applications and services and regulatory requirements (export, backup etc) - from that end, Erlang is not a great option.
There are several alternatives where both sides are, though.
Internal communication is usually great source for historians and posterity. Not to mention parliamentary investigative bodies.
This is the kind of dangerous statement that has done more damage to privacy and security conversation than anything else. Please stop.
Stop expecting transparent and accountable politics? Yeh, sure. It's India.