What I meant is that Tresorit is NOT a Swiss government project. It is a project of a PRIVATE company that belongs to the government.
If it is under the government’s control, what practical difference does it make?
There is a company between Tresorit and the government. Decisions are not taken by the Federal Department of the Environment, Transport, Energy and Communications (DETEC) but by the executives of the Post.
Who presumably are obligated to listen to the Government because they oversee it all even when disagreements occur.
I still fail to understand your POV.
The government is not running the day by day operations so it is different from most government programs.
And you can prove that?
Can’t you see the Swiss government and Tresorit are two different things, even when the first owns the latter?
They have their own offices, they don’t work in Swiss government offices, there is zero branding of the Swiss government in Tresorit, nor does the Swiss government speak anywhere of Tresorit. They have their own press office, their own recruiting teams, their own budget, teams, domain name, etc. (Yes the money comes from the Swiss State (100℅ shareholder) but THEY manage it, apart from the budget of the rest of the Swiss administration.
Even if they depend from the government and that the DETEC can take decisions impacting Tresorit, this is obviously not an official project offered and managed by the Swiss government!
There is several levels between Tresorit and the State:
- The Swiss state
- Swiss Post LTD
- Post CH Digital Services Ltd
- Tresorit
That is entirely on Tuta, Proton uses PGP and already is interoperable with other email PGP setups.
Tutas encryption is not interoperable.
The bureaucracy exists for plebs like you and I, not for when the powers-that-be want to get things done.
I’m always wary of these providers selling jurisdictions (as Jonah points out above, Signal, for example, has no trouble being in the US even though it has state actors like the US in its threat model, but of course, Signal is an outlier; folks like Joshua Lund know what they’re doing). For instance, iVPN’s “legal strategy” is selling the fact that they’re based in Gibraltar (most UK laws apply anyway), but their Google Developer entity[1] is based in Switzerland. So, are they or are they not subject to Swiss laws like Proton VPN is?
Privatus GmbH, Baarerstrasse 82, 6300 Zug, Switzerland. ↩︎
5 posts were split to a new topic: Signal escrowed app signing keys