Maybe the DoD should work on developing some internal Android and Signal forks that focus on adding additional critical security controls without impacting usability. There's an obvious desire path here.
Maybe the DoD should work on developing some internal Android and Signal forks that focus on adding additional critical security controls without impacting usability. There's an obvious desire path here.
I know personally that given the choice I'd probably rather use Signal than whatever messaging system the DoD contractors managed to come up with. And private conversations between senior military officials over encrypted DoD communication channels probably aren't FOIAable anyway.
Both are fairly "meh" WRT to usability, but neither are so awful people should be breaking the law over it.
They have a completely sepearate internet for TS/SCI (JWICS https://en.wikipedia.org/wiki/Joint_Worldwide_Intelligence_C...)
Yes, in the chat where a reporter was accidentally present, many of the messages were set to be disappearing. I don't know why anyone would do that if not to avoid recordkeeping laws.
> The images of the text chain show that the messages were set to disappear in one week.
https://apnews.com/article/war-plans-hegseth-signal-chat-inv...
Further, Project 2025 suggests bypassing federal record keeping legislation by simply holding in-person meetings without record.
https://www.youtube.com/watch?v=xxe55mU4DA8
Oddly, the Project 2025 training videos that presumably the members of the executive cabinet have seen say _not_ to delete messages or set messages to auto-deleting _because_ that would be in violation of federal record keeping legislation.
It's not just this. Security involves compromises and trade-offs. Humans will be stupid humans and re-use passwords, install better but insecure software, not ever update, etc. It's an old story.
In the year 2025, if communication with any other human on the globe isn't as simple as opening and app and typing, then people will find another way because there are about a thousand better ways.
So I doubt they are trying to get away with anything. They're just preferring the trivial option over the option that probably involves a physical token or slow biometrics or 15-second logout or whatever arduous security features the government comms probably have. Just like any human would.
Perhaps this will force the government COMSEC people to re-evaluate their practices.
Updated to add: I'm not defending their practices, just giving a likely explanation. Blaming the users is not always the best way to evaluate a security failure.
https://www.google.com/search?q=computer+security+human+natu...
I think big companies' influence on purchasing decisions (aka corruption) drives a lot of this.