this post was submitted on 26 Feb 2025
291 points (99.0% liked)

Cybersecurity

6847 readers
9 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] zephorah@lemm.ee 43 points 1 month ago (15 children)

She talks a good game now, let’s hope she sticks with that stance after the bill is introduced.

[–] anon@lemmus.org 20 points 1 month ago (8 children)

I don't believe a bill will be introduced.

The Swedish Armed Forces (Försvarsmakten) have decided to standardize the use of the encrypted messaging app Signal for non-classified communications via mobile phones.

The Swedish military would likely have to reevaluate their use.

[–] Onomatopoeia@lemmy.cafe 12 points 1 month ago (3 children)

Frankly the military should re-evaluate.

As good as Signal is for the average non-technical person, organizations with resources would be far better served by hosting their own, using something like XMPP with encryption, with servers only permitting connection from their own compiled clients, run in a container on the phone, which have been available since at least 2010.

No business I've worked for would accept Signal as a solution, in part because you have little control over it.

[–] Valmond@lemmy.world 4 points 1 month ago (1 children)

It's only for non classified information. Sweden has other encryption schemes for communication.

[–] Onomatopoeia@lemmy.cafe 1 points 1 month ago (1 children)

Still, they don't control it. Which means support is a real problem.

They're not even paying for a service, which would give you contractual commitments.

[–] Valmond@lemmy.world 1 points 1 month ago

Sure, but it's not like the security of the state is at stakes.

[–] bss03@infosec.pub 1 points 1 month ago

Wire (https://wire.com/) uses the same OTR / double-ratchet encryption primitives as Signal, but focuses more on self-hosting, and supporting organizations that want to self-host (for whatever reason).

I believe GNU Jami, well-deployed is capable of Signal's level of security while being self-hosted.

[–] randombullet@programming.dev 1 points 1 month ago

I mean signal is used for non-secret non-sensitive communications.

It's like hey we have a formation here at this time.

Hey we have inventories here.

It's good enough for basic stuff. No one will be using signal for anything higher than unclassified.

Also phones are often not issued to soldiers so I doubt most are going to install a military related/developed app onto it.

load more comments (4 replies)
load more comments (10 replies)