Swiss army restricts use of messenger apps for military purposes
swissinfo.ch
swissinfo.ch
Key part being "for military purposes". To me it is bizarre that these apps were being used in the first place. Does a national military really not have better/more secure ways to communicate internally than off-the-shelf messaging apps?
Their annual defense budget is $5B+.
"Switzerland to Spend $2.5 Billion in Military Upgrades" (https://www.thedefensepost.com/2021/06/15/switzerland-invest...). Just last year they allocated $284 million towards "command and communication systems". You can build a hundred Whatsapps from scratch with that money. Where exactly did it all go?
On hardened physical crypto radios I presume - rather than on consumer-grade apps.
Source: https://en.wikipedia.org/wiki/Conscription_in_Switzerland
You get your orders for your once a year repetition course about 3 months before, then show them to your HR department, who arranges for you to have paid time off, paid by the unemployment insurance or something. Then you go do it and come back to work. Your colleagues pick up your tasks while you are gone because you'll do the same for them later (and good teams value cross training anyway). Source: I was a team lead on a team with active Swiss army soldiers.
While you are doing exercises, you have access to all the normal army comms stuff, including presumably encrypted digital HF radio for voice and data, satellite days, VHF radios, etc.
This order is saying, "don't use commercial products, use the military comms systems we give you".
Kind of too bad they didn't give an exception for Signal though... :)
Especially if in response to some claimed attack on the public logs the company would say, "hah, hah, JK, the stream has been xor'd with /dev/random all along anyway".
Whereas these would never (usually) be used 'in the field'
For example, to an adversary able to see the direct one to one social messages between a platoon of soldiers can probably easily figure out social dynamics, who might be most easily bribed, etc.
Hence why they put a limit on the usable chat systems.
The worry also should extend to private conversations between to military members.
But you can't really or them all the time to use military controlled apps, that in practice just doesn't work out. So limiting them to commercial but reasonable secure solutions which are under a local jurisdiction is a reasonable good solution.
A public accessible Swiss military payed Signal fork probably would be an better solution tbh., but Threema isn't bad either. Just not quite as good as Signal.
You don't want people to get into bad habits.
By military purposes they probably don't mean to message buddies to break the door during an operation, for this they will use proper military gear. However you can imagine military personel discussing military stuff on WhatsApp etc. Stuff like scheduling things, clarifying information, discussing classified stuff to form an opinion or make a decision.
A few years back, US bases could be spotted using a fitness trackers heat map: https://www.theguardian.com/world/2018/jan/28/fitness-tracki...
Some of the better of the shelf apps are as or more secure then many of the military internal developed solutions of many militaries. At lest when applied to use-cases outside of war zones and similar.
I mean there are top of the line security experts all around the world directly and indirectly contributing to apps like Signal. On the other hand the amount of scrutiny a proprietary military app will receive is limited.
But more important "for military purposes" includes a lot of situations you might not have considered.
Like more or less all communication done between two active members of the military, even if of duty, as long as work content might pop up in the conversation.
Or like they sending a member on break a message that due to weather forecast there is a good chance they will have to interrupt your brake for helping with "disaster relive" (which can e.g. include removing snow after some unusual heavy snow fall, or helping with cleanup after a avalanche). To just name some situations.
while i support the use of swiss secure solutions for critical stuff, it should be noted our beautiful militia is mostly there for a reason: allow male teenagers to become men, namely 1) play with explosives, 2) get drunk and 3) loose their virginity with prostitutes.
they will probably allow back these apps for military operations when they discover these are more secure than their proprietary communication systems.
can't wait they get their F35..
In practice the swiss army is a giant live action role-play, where young males go to be paid for playing with firearms and be drunk together.
Note that you can be very professional while larping, it's not contradictory.
You're completely right, unfortunately. For a country that prides itself with its neutrality, we sure do like our armed boy scout club.
I do have hopes though that their F35 plans won't work out; the last vote was extremely tight, if it was already clear back then that they'd go for the F35, I'd wager they would have lost.
being CIA's back office and being "neutral" is a quite interesting standpoint..
regarding F35 it's quite possible this get canceled, indeed it was close.
this plane choice seems also really bad. it doesn't turns well due to low lift (perfect in mountains ranges, especially when you already crash a jet every few years on a cliff), "hi-tech" sensors platform with a little less than a million bugs (perfect for the reasons above) and probably a maintenance nightmare due to stealth and other gimmicks.
wouldn't be surprised F35 maintenance double our army budget.
oh yeah and badly negotiated contracts so peanuts for our beautiful local weapons manufacturers (not that i like them btw).
I don't blame them one second for going local, but then if security and ownership of your comms is what you're after, why not set up your own Matrix server for comms for your military personnel like every European country (I think), and instead purchase Threema licenses?
I feel this is basically a form of corporate sponsorship/handouts from the government/defense sector in disguise, to support a local champion (basically how the US defense sector propped up Silicon Valley in its inception).
In the event of war you want complete control of comms systems for your military.
This makes sense to me! I think it would be foolish of any army to use a comms system another country controls.
Most government and military employees (especially in countries that at least want to have the appearance of opposing corruption) have specific record keeping requirements. If you use unofficial channels for official communications, you are almost certainly violating those rules and laws. "Where's lunch today?", not an issue. "Let's discuss these budget items and make a decision", that's an issue.
I don't know Swiss laws and rules, but I'd be surprised if they permitted, say, coordination of movement of military assets (in country, peace time) via unofficial, unrecorded methods.
This is not only identifies you through Google/Apple services, but is also fundamentally incompatible with software freedom, as few can audit the binaries they receive.
Unless you build your own binaries from the open source project (which has its issue tracker disabled for the public), you are out of luck.
Was software freedom a goal?
It’s not as if auditing source code is something that most people can do.
In the same way that war is just politics by other means, yes.
Wars are about logistics. If you think business is hard with the current disruption of our just-in-time economy when most actors are actually trying to cooperate, think about your competitor subverting, buying or bombing your third party communications service providers.
Keep the data and money local!
Signal may not exactly be proprietary, but they won't put it on F-Droid, so... Telegram has a free-ish client but not a server
Omnisec AG was a swiss company with (hidden) ties to US intelligence services [1] that produced manipulated encryption devices. Switzerland's military was also using Omnisec hardware and I doubt they received the "proper" ones.
[1] https://www.swissinfo.ch/eng/second-swiss-firm-allegedly-sol...
I ask because it's not trivial to clone the memory of a phone and have a network of simulators capable of simultaneously enumerating each combination, to stave off slowed-next-attempt policies etc.
If a serious attacker is set on getting your stuff, it's just a matter of time and money. It's down to how much the data is worth for the attacker.
like the first iteration of the for loop runs at time 0, fails;
second iteration gets to start 10 seconds later, fails;
third iteration gets to start 1 minute later, fails;
fourth iteration gets to start 1 hour later, fails;
and so on.
Signal has no end point security past the phone so they would want the phone security to be as good a possible.
That doesn't sound like they've banned it at all.
I also heard all three of these messengers WhatsApp [0], Signal [1] and Telegram [2] have a cryptocurrency projects too for their users. So now they are automatically involved in promoting ponzi scam-coins as well, which Threema has none of that.
Great choice for the Swiss Army to use Threema then.
[0] https://www.theverge.com/2021/12/9/22825766/whatsapp-novi-di...
[1] https://www.wired.com/story/signal-mobilecoin-cryptocurrency...
[2] https://cointelegraph.com/news/telegram-verified-payments-bo...
Note that we have mandatory military service. Every year thousands of new recruits will perform military service for around half a year. After that, they have to attend three weeks of military service yearly (refresher). This always requires organization; when to arrive in the barracks, equipment to bring, request for leave, corona updates etc. Also coordination at which McDonalds to stop at the freeway.
Same for professional army members. They need to communicate somehow, without using super encrypted email or radios (schtichwort "fill guns", super). Military IT is also as you expect (old and cumbersome).
First, all developed-nation military forces have internal, "secure" tactical and strategic communication networks for classified (e.g. Secret, Top Secret) data. So something like WhatsApp, Signal, Telegram, or Threema would only be used for unclassified, administrative communications as others have already mentioned.
But there are still controls required for unclassified, administrative communications. Speaking as a US military officer who works in IT, we have to think about data ownership and retention for things like investigations and compliance with FOIA requests. It's impossible to do that if everyone is using personal accounts on communications services that we don't control. I'm not sure how much control the Swiss government can exert over Threema, but it's presumably more than they can control services hosted outside of their borders. This article from last summer explains why the US Defense Digital Service Director got in trouble for using the Signal app for official business: https://www.nextgov.com/cio-briefing/2021/06/defense-digital...
WhatsApp and Telegram I can understand but Signal is a bit strange, they probably could just have setup some way to have "Swiss army compiled" version of Signal which IMHO would be more safe then Threema.
While I do use Threema and like it's decoupling from phone numbers it has problems including Salamander attacks on their group chats and a very easily DDOS able account creation system.
Furthermore most other users I meet did for a long time not know about the importance of Threema Id backups, often until they switched phones and lost their Threema Id...
Generally from what I can tell it _seems_ (i.e. speculation) to be developed from experienced software engineers, but missing some "full-on security experts/researchers(1)" and there is in my experience a subtle but for this kind of things important gap between a senior engineer with a lot of security expertise and a non-junior full-on security expert/researcher.
(1): What I mean hear is a bit tricky to define. First security experts and researchers are not necessary the same then different people have different field of expertise and skill level, so just doing it full time isn't necessary enough.
Every scandal over the last few years always seems to either start or end with screenshots of WhatsApp conversations.
The title is a bit misleading, at first glance it seems as if the military banned encrypted communications for soldiers' personal communication. No, this only applies to mile Gary communications, and is to allow swiss sovereignty over the services they use.
https://www.wired.com/story/strava-heat-map-military-bases-f...
I don’t think anyone has been expecting a paid-for device for the past two years just because to work you have to install Zoom, even in the US.
Most employees have to buy their own work tech devices outside of the US?
There are companies that provide some budget for work equipment, but unless it is mandatory by law the budget and quality of equipment varies a lot, from good to terrible or none.
We (big employer in the UK) can order paid-for devices on the corporate purchasing system. It works out best for everyone: they can control the device, I can turn it off at the end of the day, and nobody has to see my reaction when they say "oh yeah, now we can remote-brick your personal phone."
When WFH became more widespread at the office in 2020, the local mgmt team told everyone to enter all sorts of information into a spreadsheet like their IMEI number, etc. Then people discovered after the fact that their personal devices were now managed devices. Cue surprised faces.
MDM rejects bootloader unlocked devices, so even if you have extra devices you might not be able to use them because of that or the OS version being too low to please them. A good alternative if available, is to use Citrix Receiver instead, it doesn't require MDM and doesn't require permissions. It does require an RSA keyfob.