this post was submitted on 26 Feb 2025
289 points (99.0% liked)

Cybersecurity

6418 readers
183 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 20 points 3 days ago (3 children)

I don't believe a bill will be introduced.

The Swedish Armed Forces (Försvarsmakten) have decided to standardize the use of the encrypted messaging app Signal for non-classified communications via mobile phones.

The Swedish military would likely have to reevaluate their use.

[–] [email protected] 12 points 3 days ago (3 children)

Frankly the military should re-evaluate.

As good as Signal is for the average non-technical person, organizations with resources would be far better served by hosting their own, using something like XMPP with encryption, with servers only permitting connection from their own compiled clients, run in a container on the phone, which have been available since at least 2010.

No business I've worked for would accept Signal as a solution, in part because you have little control over it.

[–] [email protected] 4 points 3 days ago (1 children)

It's only for non classified information. Sweden has other encryption schemes for communication.

[–] [email protected] 1 points 2 days ago (1 children)

Still, they don't control it. Which means support is a real problem.

They're not even paying for a service, which would give you contractual commitments.

[–] [email protected] 1 points 2 days ago

Sure, but it's not like the security of the state is at stakes.

[–] [email protected] 1 points 2 days ago

I mean signal is used for non-secret non-sensitive communications.

It's like hey we have a formation here at this time.

Hey we have inventories here.

It's good enough for basic stuff. No one will be using signal for anything higher than unclassified.

Also phones are often not issued to soldiers so I doubt most are going to install a military related/developed app onto it.

[–] [email protected] 1 points 2 days ago

Wire (https://wire.com/) uses the same OTR / double-ratchet encryption primitives as Signal, but focuses more on self-hosting, and supporting organizations that want to self-host (for whatever reason).

I believe GNU Jami, well-deployed is capable of Signal's level of security while being self-hosted.

[–] [email protected] 2 points 2 days ago

SAF is really not happy about this. Most people in the military used and recommend Signal for most communication (both personal and non-confidential) until they standardized it, and most people I have contacted facepalmed at the proposal. Hopefully, the dipshit that got this stupid fucking idea (pardon my french) will meet the same storm of critisim as Ylva Johansson got.

[–] [email protected] 4 points 3 days ago

Nato and some Swedish agencies already use Matrix, Försvarsmakten should help standardize.