Showing posts with label Secure voice. Show all posts
Showing posts with label Secure voice. Show all posts

January 8, 2026

Trump risked a compromise of his strike against Venezuela

(Updated: January 14, 2026)

On January 3, 2026, the United States conducted a remarkable strike against Venezuela, during which president Maduro and his wife were captured and exfiltrated to New York.

At his private residence Mar-a-Lago, US president Trump monitored this operation from a room that looks hardly secure enough to prevent adversaries from eavesdropping.


Left to right: Hegseth, Ratcliffe, Rubio and Trump at Mar-a-Lago, January 3, 2026
(White House photo - click to enlarge)


Right after the strike had been absolved, Trump's team released several photos via X (formerly Twitter) and their own social media platform Truth Social. The images show how the US president and his national security team monitored the operation and the communications equipment they used.

Present were president Donald Trump, Secretary of Defense Pete Hegseth, Secretary of State Marco Rubio, CIA Director John Ratcliffe, Chairman of the Joint Chiefs of Staff general Dan Caine, White House Deputy Chief of Staff Stephen Miller, as well as some other staff members.



The communications equipment

Among the communications equipment in the photos we see a Cisco 8832 IP Conference Phone and at least two Cisco 8841 IP phones with a black box attached to their back. All these phones were modified by Advanced Programs, Inc. (API) in order to provide some TEMPEST protection and appliance to the TSG Standards.


However, those technical measures are of little use when a phone is off hook or when the speakerphone is enabled and all kind of people (and antennas) can simply listen in to what is said.


Left to right: Ratcliffe, Trump and Rubio at Mar-a-Lago, January 3, 2026
(White House photo - click to enlarge)


In the photo below we see Chairman of the Joint Chiefs of Staff working on a laptop which has two yellow labels and is connected with cables that are yellow as well. Yellow is the color code for the classification level Top Secret/Sensitive Compartmented Information (TS/SCI), which indicates that the device is connected to JWICS, the highly secured network for intelligence information and communication.

In another photo we can see that at his right hand, Cain also has another laptop. That one had a red label and was connected with a red cable. Red is the color code for the classification level Secret, which means that laptop was connected to the SIPRNet, which is the primary network for classified military communications.


Left to right: Caine, Ratcliffe and Hegseth at Mar-a-Lago, January 3, 2026
(White House photo - click to enlarge)


On the wall behind defense secretary Hegseth is a large videoscreen. The bright green bar along the top side shows that it's connected to a military or government network for unclassified information (most likely NIPRNet). At the moment of the photo, the screen showed an internet browser with on three tabs the web interface of X and "Venezuela" typed into the search bar of the front tab.

Note that Hegseth is working on a laptop that has no color label to indicate a classification level, it has only a gray label with some bar codes. This brings to mind the situation of early last year, when Hegseth had a computer in his Pentagon office that was directly connected to the public internet so he could use the Signal app for backdoor communications with the White House.




No SCIF at Mar-a-Lago?

The most remarkable thing about the meeting on January 3, is its location. According to CNN, Trump and his team met in "a discreet of the club, away from guests". The photo below shows that it was a small building with a wooden roof that looks almost like a garage or a storage room, with the area where all the highly sensitive information came in "sealed off" only by very thin black curtains:


Left to right: Ratcliffe, Trump, Rubio and Miller at Mar-a-Lago, January 3, 2026
(White House photo - click to enlarge)


Normally, these kind of meetings should at least take place in a Physically Protected Space (PPS), but preferably in a Sensitive Compartmented Information Facility (SCIF). Such a SCIF can be a room, a suite of rooms or a whole building that is protected in such a way that highly classified information can be stored, processed, viewed and/or discussed without being intercepted by outsiders.



Risks at Mar-a-Lago

Already during Trump's first term as president it was noticed that there was apparently no permanent SCIF at Mar-a-Lago. When on April 6, 2017, the US conducted airstrikes against Syria, Trump and his team sat packed around a narrow table in a small side room, looking at a secured Cisco EX90 video teleconferencing screen, with on the table some devices that were never identified.



Trump and his team of policy makers at Mar-a-Lago, April 6, 2017
(White House photo - click to enlarge)


According to Trump's press secretary at the time, the room used on April 6, 2017 was a SCIF. That wasn't very convincing because everything seemed to be hastily arranged for the occasion. At best, the room was a (temporary) Secure Working Area (SWA), which is an accredited facility "used for discussing, handling, and/or processing SCI, but where SCI will not be stored."

Mar-a-Lago isn't just Trump's private residence, but also a club resort that is open to paying members and ticketed guests, staffed by workers without the same security clearances as White House staff. Although the Secret Service screens guests before they enter, they don't determine who can access the club. All this makes the place vulnerable to infiltration and/or eavesdropping by foreign intelligence.



Precedents

By contrast, when president Barack Obama and his national security team monitored the killing of Osama bin Laden on May 1, 2011, they did so from a small room that was part of the highly secured complex of the White House Situation Room:



President Obama and his national security team watching the killing of
Osama bin Laden in the White House Situation Room, May 1, 2011.
(White House photo by Pete Souza - click to enlarge)


However, when Obama was on vacation at the Blue Heron Farm in Chilmark on the island of Martha's Vineyard, Massachusetts in August 2011, his secure and non-secure telephone equipment was installed in a living room that didn't seem very secure, with doors and windows open when calls were conducted:

> Read more: Obama on vacation


President Obama with John Brennan and some other assistents, August 26, 2011
(White House photo by Pete Souza - click to enlarge)



Much better was the situation under president George W. Bush, who had a special building on his ranch in Crawford, Texas, that was equipped as a SCIF. The space was modeled like a conference room in the White House, with comfortable chairs and all the necessary communications equipment for secure and non-secure phone calls as well as for secure video teleconferencing:



George W. Bush in the SCIF on his ranch in Texas, December 29, 2004.
(White House photo)



Links and sources
- Politico: Who was in Trump’s Mar-a-Lago war room for Maduro’s ouster
- CNN: Mar-a-Lago is a familiar place for Trump to manage high-stakes military operations
- The New York Times: C.I.A. Source Inside Venezuelan Government Helped Track Maduro
- Wikimedia Commons: Photos of Donald Trump monitoring U.S. military operations in Venezuela

October 28, 2025

AT&T's very rare Security-Plus Telephone



Since 1987, AT&T advertised a new secure telephone that operated according to the STU-III standard of the NSA. This was the Security-Plus Telephone, which is probably one of the rarest devices from the STU-III family. Already in 1992, AT&T replaced the Security-Plus Telephone by a completely different model that became more commonly used.


Advertisement from 1987 for AT&T's Security-Plus Telephone



The STU-III standard

STU-III stands for Secure Telephone Unit - Third Generation. This was a standard from the NSA for secure telephone equipment capable of encrypting voice calls (and data) up to the highest classification level.

The STU-III standard was developed from 1985 to 1986 by NSA in cooperation with the Government Electronics Group (GEG) of Motorola. In 1986, three companies were selected for the production of telephone sets based upon this standard: Motorola, RCA and AT&T.

Under the new standard, they could manufacture devices not much larger than a conventional desktop telephone set, where previous voice encryption systems, like the STU-I, required equipment as large as a small fridge.


Probably the best known and most widely used STU-III telephone set was the version manufactured by Motorola and sold under the brand name SECTEL:


Motorola's STU-III SECTEL 2500 secure telephone
(photo: Crypto Museum - click to enlarge)



AT&T's Security-Plus Telephone

The first STU-III phone made by AT&T was called the "Security-Plus Telephone". There's very little information about this particular phone, but from the advertisement from 1987 we can learn that:

- It's was "the only STU-III with a 4.8 Kb/s transmission rate";
- It accomodated up to 32 crypto-ignition keys per terminal;
- The same crypto-ignition key could be used in more than one terminal;
- It had four independent key sets to handle multiple programs and security levels;
- It could handle clear as well as secure data;
- It provided a remote interface to data processing equipment.


In an advertisement from 1988 the phone is called "Security-Plus Communications Terminal" and it's emphasized that the 4.8 Kb/s transmission rate offered a better voice quality compared to STU-III devices that only had a 2.4 Kb/s data rate. However, Motorola's Sectel 1500 was also able to provide 4.8 Kb/s transmission, and even 9.6 Kb/s, ensuring the best voice quality of all available STU-III phones.


Part of another advertisement for AT&T's Security-Plus Communications Terminal
(published in the Airforce Magazine, June 1988 - click to enlarge)


The AT&T Security-Plus phones shown in the advertisements appear to be fully black, but their actual color might have been burgundy, as suggested in an anonymous comment on this weblog from January 2013:

"There was one "version/flavor" of the US STU-III phone from AT&T that was Burgundy Red with an "R" type handset. It was the same size as the Boat Anchor / Big White Monster AT&T Security Plus STU-III with "K" handset (in Misty Cream). [...] The later AT&T/LucentTech/General Dynamic phones were white."


The AT&T Security-Plus Telephone in "Misty Cream" was/is on display in the NSA's National Cryptologic Museum (NCM), which is open for public. Some photos made by visitors provide a closer look at this very rare encryption device, which in the museum seems not to have been identified by name:


AT&T's Security-Plus Telephone on display at the National Cryptologic Museum
(photo: Flickr/Austin Mills (CC BY-SA 2.0) - click to enlarge)


AT&T's Security-Plus Telephone on display at the National Cryptologic Museum
(photo: Flickr/Austin Mills (CC BY-SA 2.0) - click to enlarge)


Another photo of the AT&T Security-Plus Telephone was posted on the Twitter-account of the National Cryptologic Museum on October 16, 2024. This photo gives a good impression of how large this phone from the STU-III family actually was:




Finally, a small drawing from an unknown source shows the basic parts and functions of the AT&T Security-Plus Telephone:




AT&T's new secure phone

In 1992, AT&T replaced its Security-Plus Telephone by a completly new STU-III phone. This telephone set had no specific name, but only a numerical designator indicating its encryption level. For example, model 1100 for Type 1 encryption, model 2100 for Type 2 encryption and model 4100 for Type 4 encryption. This made the device available for a wide range of users, ranging from US intelligence agencies to foreign customers.


AT&T's new secure telephone, here the 4100 version
(photo: Crypto Museum - click to enlarge)


This new design was less futuristic and almost similar to AT&T's series of common desktop phones for the commercial market. These became known as the MLX-series and were used in offices all over the world (see photo below). Later, these phones were sold under the newer brand names Lucent and Avaya.

While AT&T's new STU-III phone was significantly smaller than the Security-Plus Telephone, it was still larger and much heavier (ca. 3.5 kg) than the conventional office phones from the MLX series. This because the bottom part of the secure phone was made of die-cast aluminium in order to shield most of the electronic components.


A common AT&T/Lucent/Avaya MLX office phone



Some context

There's some irony in the fact that AT&T manufactured these STU-III phones for securing voice and data communications up to the highest level. Because at the same time, this company was a very close and even willing partner of the NSA when it came to intercepting (foreign) telephone and internet traffic.


The same applies of course to the NSA itself, which on one hand develops sophisticated encryption methods and standards (like STU-III) for protecting American secrets, while on the other hand takes all efforts necessary to collect foreign communications that are of interest for US foreign policy and military operations.



The STU-III made by RCA

Somewhat surprisingly, the phone in the AT&T advertisement from 1987 looks much more like the STU-III phone that was manufactured by RCA, an American electronics company that was founded in 1919 as Radio Corporation of America. RCA's STU-III unit was the largest of the three versions (measuring ca. 34 x 31 x 13 cm), but also the one that was least commonly used.


RCA's STU-III secure telephone (photo: Crypto Museum)


A close look shows that the arrangement of the buttons on RCA's STU-III phone is a bit different from those in the AT&T advertisement, but the general design and button layout is much closer than the eventual unit sold by AT&T.



Links and sources
- Crypto Museum: STU III Third generation secure telephone unit
- Web page by Jerry Proc: STU III (Secure Telephone and KSD-64)
- Granite Island Group: Secure Communications Systems
- Wikimedia Commons: Voice encryption devices in the National Cryptologic Museum

May 31, 2025

The American secure phone of Canadian prime minister Trudeau



In my series about the phones of government leaders I will now look at Canada, where former prime minister Justin Trudeau had a rarely seen telephone on his desk: the vIPer Universal Secure Phone, which is manufactured by the American defense contractor General Dynamics.


Former Canadian prime minister Justin Trudeau with a vIPer secure phone, December 2020
(photo: Ottawa Catholic School Board - click to enlarge)

April 30, 2025

How US defense secretary Hegseth circumvents the official DoD communications equipment

(Updated: June 10, 2025)

US defense secretary Pete Hegseth appears to have a private computer in his office that is linked to the public internet. He wanted this computer to use the messaging app Signal, which is the preferred method of communication among Trump's government officials.

Here I will look at the secretary of defense's official communications equipment and the SecDef Cables communications center. There's also a photo in which Hegseth's private computer can be recognized.


US defense secretary Pete Hegseth in his office in the Pentagon, January 30, 2025
(Still from a video message on X, formerly Twitter)



Hegseth's government equipment

Like his predecessors, Trump's defense secretary Pete Hegseth has access to a range of secure and non-secure telephone and computer networks. The equipment is installed at a table behind his back, when sitting at his big writing desk in the Pentagon.

In the photo above we can see that equipment in a set-up that has basically been unchanged since Chuck Hagel, who was Obama's secretary of Defense from 2013 to 2015. In the photo of Pete Hegseth we see from left to right:

- On top of a wooden stand sits a Cisco IP Phone 8841 with a 14-key expansion module. This phone is part of the Crisis Management System (CMS), which connects the most senior government officials, including the President, the National Security Council, Cabinet members, the Joint Chiefs of Staff, and others. Its bright yellow bezel indicates that it can be used for conversations up to Top Secret/Sensitive Compartmented Information (TS/SCI).

- Below the CMS phone on the wooden stand is (hardly visible) an Integrated Services Telephone-2 (IST-2), which can be used for both secure and non-secure phone calls. This phone belongs to the Defense Red Switch Network (DRSN), also known as the Multilevel Secure Voice service. It's the main system for classified military conversations and connects the White House, all military command centers, intelligence agencies and NATO allies.

- Right in front of the IST-2 is another Cisco IP Phone 8841 with a 14-key expansion module, but this time with a green bezel, which indicates that it's for unclassified phone calls. This phone is part of the internal telephone network of the Pentagon. It replaced an Avaya Lucent 6424 executive phone, which can be seen in the following photo from 2021, along with a better view on the other phones:


Former secretary of defense Lloyd Austin in his Pentagon office in 2021,
with a Cisco IP phone with yellow bezel for the CMS and
an IST-2 phone with many red buttons for the DRSN.
(DoD photo - click to enlarge)


- Besides the telephones there are two computer screens, both with a bright green wallpaper, which again indicates that they are connected to an unclassified network, most likely NIPRNet. In the photo of Lloyd Austin's office we see that there's also a KVM switch which is used to switch securely to the SIPRNet (Secret) and JWICS (Top Secret/SCI) networks, using the same keyboard, video and mouse set.

- Finally, at the right side of the table there are two Cisco Webex DX80 videoteleconferencing screens. The one at the right has a yellow label, which indicates that it's approved for Top Secret/SCI and likely also belongs to the aforementioned Crisis Management System (CMS), more particularly as successor of the Secure Video Teleconferencing System (SVTS). The other screen might then be for videoconferences at a lower classification level.



Hegseth's personal computer

Despite the wide range of options for communicating via the proper and secure government channels, secretary Hegseth insisted on using Signal. Apparently it wasn't allowed or possible to install this app on one of the government computers, nor on a smartphone that is approved for classified conversations.

Therefore, Hegseth initially went to the back area of his office where he could access Wi-Fi to use Signal, according to AP News. It's not clear whether he used a private laptop or his personal smartphone, both of which would have been strictly forbidden to use in secure areas like this.


Somewhat later, Hegseth requested an internet connection to his desk where he could use a computer of his own. This line connects directly to the public internet and bypassed the Pentagon's security protocols. Hegseth's new computer must be the one that can be seen in the photo below, as it wasn't there yet on February 21 and has no labels that indicate its classification level:


US defense secretary with a new desktop computer on his desk, March 20, 2025
(DoD photo, see also this video message on X)


Some other employees at the Pentagon also use direct lines to the public internet, for example when they don't want to be recognized by an IP address assigned to the Pentagon. That's risky because such a line is less well monitored than NIPRNet, which allows limited access to the outside internet.

At his new desktop computer, Hegseth had Signal installed, which means he effectively 'cloned' the Signal app that is on his personal smartphone. He also had interest in the installation of a program to send conventional text messages from this personal computer, according to some press sources.

The move was intended to circumvent a lack of cellphone service in much of the Pentagon and enable easier communication with the White House and other Trump officials who are using the Signal app.

Update: Ultimately on May 5, 2025, the new, unauthorized computer had apparently been removed, at least from secretary Hegseth's desk, as can be seen in this video that was published on X (formerly Twitter).



SecDef Cables

It is remarkable to what great lengths Hegseth went to use the Signal app, because as defense secretary he has his own communications center which is specialized in keeping him in contact with anyone he wants. This center is commonly called SecDef Cables and is part of Secretary of Defense Communications (SDC) unit.

SecDef Cables provides operational information management and functions as a command and control support center. It is staffed by 26 service members and 4 civilians. They provide "comprehensive voice, video, and data capabilities to the secretary and his immediate staff, regardless of their location, across multiple platforms and classifications."

Furthermore, SecDef Cables serves as a liaison to the National Military Command Center (NMCC), the White House Situation Room, the State Department Operations Center and similar communication centers. Finally, Cables manages the connections for the Defense Telephone Link (DTL), which is a lower-level hotline with military counterparts in about 25 countries, including Russia and China.



Secretary of Defense Communications recruitment video from 2023



Links and sources
- The Atlantic: Hegseth Risked Endangering Troops With Signal Messages (December 3, 2025)
- emptywheel: Whiskey Pete’s Dirty Desktop (April 25, 2025)
- AP News: Hegseth had an unsecured internet line set up in his office to connect to Signal, AP sources say (April 24, 2025)
- The Washington Post: Hegseth had Signal messaging app installed on an office computer (April 24, 2025)

See also the comments on Hacker News

March 30, 2025

The equipment that Trump's national security team should have used

(Updated: May 2, 2025)

Recently, the editor in chief of The Atlantic found himself in a group chat on Signal, in which president Trump's national security team discussed a military operation in Yemen. This immediately became SignalGate.

Here I present the secure government equipment and networks that Trump's team should have used instead of an app on their (personal) smartphones. It will also become clear why the Trump team prefers using Signal.


From left to right: Marco Rubio, Michael Waltz and Pete Hegseth in a White House conference room,
with some screenshots of messages that were exchanged in the Signal group chat.
(White House photo, January 28, 2025 - click to enlarge)



The Houthi PC small group

On March 11, 2025, president Trump's national security adviser Michael Waltz started a group chat on the open-source encrypted messaging app Signal to discuss airstrikes on Houthi rebels in Yemen, which took place on March 15.

The chatgroup was named "Houthi PC small group", with PC apparently referring to Principals Committee, a term typically used for a gathering of senior national-security officials. This group had a total of 19 participants:

- Michael Waltz, National Security Adviser
- Brian McCormack, Chief of Staff for the National Security Council
- Alex Wong, Principal Deputy National Security Adviser
- Susie Wiles, White House Chief of Staff
- Stephen Miller, White House Deputy Chief of Staff for Policy
- JD Vance, Vice-President of the United States
- Marco Rubio, Secretary of State
- Mike Needham, Special Adviser for the Department of State
- Pete Hegseth, Secretary of Defense
- Scott Bessent, Secretary of the Treasury
- Dan Katz, Chief of Staff for the Secretary of the Treasury
- Tulsi Gabbard, Director of National Intelligence
- Joe Kent, Acting Chief of Staff for the Director of National Intelligence
- John Ratcliffe, Director of the CIA
- Walker Barrett, Staff member of the House Armed Services Committee Republicans
- Steve Witkoff, Special Envoy to the Middle East
- Jacob, function unknown
- Jeffrey Goldberg, Editor in Chief of The Atlantic


This list shows that the members of the "Houthi PC small group" were from many different government departments and agencies and that some lower-ranking officials participated as well.

This is probably one of the reasons why they used Signal: given the variety of positions, they would probably not have access to the same equipment and/or networks to have a properly secured conversation.

The major US government departments and intelligence agencies have their own computer networks, usually one for unclassified and one or two for classified information:


Overview of major Homeland Security computer networks
From a briefing for Congress, July 2004



Secure computer networks

The networks of the Department of Defense (DoD) are the most widely used and therefore most suitable for interagency communications. There are separate DoD networks for different classification levels:

NIPRNet (Non-secure Internet Protocol Router Network)
- For information that is Sensitive But Unclassified (SBU)
- Circa 4,000,000 users

SIPRNet (Secret Internet Protocol Router Network)
- For information classified Secret (S)
- Circa 500,000 users

JWICS (Joint Worldwide Intelligence Communications System)
- For information classified Top Secret/SCI (TS/SCI)
- Circa 200,000 users


These classified networks are not connected to the internet and additionally secured with TACLANE network encryptors. These networks offer email (in the Signal group chat mentioned as "high side inboxes"), messaging and other collaboration tools, but they can also be used for VoIP phone calls and secure video teleconferencing.



Operations center in the US Central Command headquarters, with computers and
VoIP phones for Unclassified (green) and Secret (red) communications.
(still from 60 Minutes, January 2021 - click to enlarge)



Secure telephone networks

The DoD also operates a secure telephone network for classified conversations, called the Defense Red Switch Network (DRSN), also known as the Multilevel Secure Voice service. The DRSN connects the White House, all military command centers, intelligence agencies, government departments and NATO allies.

The DRSN has some special features and uses custom made telephone sets (currently the IST-2 made by Telecore), which can be used for both secure and non-secure phone calls. These phones also have the distinctive four red buttons for Multilevel Precedence and Preemption (MLPP).

During the attacks of September 11, 2001, the DRSN didn't function as intended and therefore a new Crisis Management System (CMS) was established. This includes a dedicated Voice over IP network that connects the President, the National Security Council, Cabinet members, the Joint Chiefs of Staff, intelligence agency watch centers, and others.

The CMS uses high-end Cisco IP phones with a bright yellow bezel. This color indicates that it can be used for conversations up to Top Secret/Sensitive Compartmented Information (TS/SCI), which is the classification category for the most sensitive, intelligence related information.


Former secretary of defense Lloyd Austin in his Pentagon office in 2021,
with a Cisco IP phone with yellow bezel for the CMS and
an IST-2 phone with many red buttons for the DRSN.
(DoD photo - click to enlarge)


Most senior members of the "Houthi PC small group" have a phone for the CMS in their office, but their deputies, advisers and staff members usually have not. So when they have to be involved in a secure phone call, that often means they have to be in the same room as their principal and listen to the conversation via the speakerphone.

It's noteworthy that not included in the Signal chat group were Michael E. Kurilla, commander of the US Central Command, and local commanders who led the military operation in Yemen. They were likely in contact with defense secretary Hegseth via the proper military channels, which would be SIPRnet or the DRSN.




Securing mobile phones

All the equipment for secure communications discussed so far are fixed/landline devices that sit on someone's desk. That's fine when working in office, but nowadays people are used to do almost everything on their smartphone.

Securing mobile communications has long been a challenge. In the first place because outside, conversations can easily be overheard. For a long time, encryption devices were large and heavy, until in 2002 the Sectéra Secure Wireless Phone was introduced, which enabled encrypted phone calls and SMS/text messages over public networks.


Around 2010, cell phones of the GSM generation were rapidly replaced by smartphones, which became so complex that it's very difficult, if not impossible to prevent the device from being compromised by malware and/or backdoors.

Under its Commercial Solutions for Classified (CSfC) program, the NSA tried to solve this problem by securing commercially available devices with multiple layers of protection and encryption. This resulted in the DoD Enterprise Mobility program, which encompasses three different classification levels:

DMUC (Unclassified)
- For Samsung and Apple smartphones and tablets
- Circa 140,000 users

DMCC-S (Secret)
- For Samsung smartphones and tablets
- Circa 8000 users

DMCC-TS (Top Secret)
- For Samsung smartphones
- Circa 500 users


Overview of the DoD Enterprise Mobility program, 2022
(click here for the full document)


The CellCrypt app

The Secret version (DMCC-S) became operational in 2015 and offers secure phone calls via the CellCrypt app, access to SIPRNet email via the Outlook Web Application (OWA) and some other pre-approved apps on a Samsung smartphone or a Samsung tablet.

The website of the manufacturer provides additional details about the encryption methods used by CellCrypt app and also says that it can also be used for secure instant messaging, including group messaging and sharing photos, videos, voice notes, and files of any kind.

The DMCC-S solution has further restrictions, because in case the phone not only handles data-in-transit (DIT), but also stores classified information (data-at-rest, or DAR) it may only be used in physically protected environments.

On social media some people claimed that a conversation like in the Signal group chat should only take place in a Sensitive Compartmented Information Facility (SCIF). However, a SCIF is only mandatory for information classified Top Secret/SCI, while military information is usually classified Secret.


At the White House

The White House provides its employees with Apple iPhones, but without access to the iOS App Store and with all text messaging capabilities disabled - under president Biden, only a few staffers in the press office had the ability to text on a limited basis.

Especially Signal's option for "disappearing messages" (which was turned on in the "Houthi PC small group") isn't compliant with the Presidential Records Act (PRA), which requires that all communications by and among White House staff members have to be archived.

The phones issued to White House officials are managed by the Presidential Information Technology Community (PITC), which is an umbrella organization established in 2015 to provide IT systems to the President, Vice President, the National Security Council, the Secret Service, the White House Communications Agency, and others.



Trump's shift to Signal

As we have seen, there are various highly secure communication channels that Trump's national security team could have used. Those who were working in their office had access to secure computer networks and a secure phone, those who were traveling (like Gabbard and Witkoff) had the option of using a DMCC-S smartphone.

However, it already was the transition team that prepared Trump's take-over of the presidency in January 2025, which deliberately refused to use government facilities and IT systems. This was in part to avoid the mandatory record-keeping that comes with using official resources (it's not clear why they prefer Signal, because Whatsapp has disappearing messages as well).

Instead, Trump's staffers and incoming government officials communicated via their personal devices, often using the Signal app, and this continued after Donald J. Trump had been inaugurated as the 47th president of the United States.

Last February, political appointees at the DoD ordered that Signal had to be installed on government phones for newly installed senior military officials: "they all use Signal and need it to communicate with the White House" - even though in the same month, the NSA had warned against vulnerabilities in using Signal.


NSA bulletin about Signal vulnerabilities, February 2025
(click here for the full document)


During a House Intelligence Committee hearing a few days ago, Trump's CIA director John Ratcliffe said that Signal is also widely used by officials and staff at his agency's headquarters: "One of the first things that happened when I was confirmed as CIA director was Signal was loaded onto my computer at the CIA as it is for most CIA officers."

National Security Council spokesperson Brian Hughes said that Signal is allowed on government devices and that some agencies automatically install it on employees’ phones. "It's one of a host of approved methods for unclassified material with the understanding that a user must preserve the record" according to Hughes.


Updates:

On April 1, 2025, The Washington Post reported that Michael Waltz and other members of the National Security Council (NSC) also used Gmail for work-related communications. One of Waltz's senior aides, for example, used Gmail for "highly technical conversations with colleagues at other government agencies involving sensitive military positions and weapons systems."

On April 2, 2025, Politico revealed that the team of national security adviser Mike Waltz had set up at least 20 group chats on Signal to coordinate official work on issues including Ukraine, China, Gaza, Middle East policy, Africa and Europe.

On April 6, 2025, The Guardian reported that an internal investigation by the White House made clear how Jeffrey Goldberg was accidentally added to the Signal group chat: in October 2024, Goldberg had emailed the Trump campaign and his email was forwarded to Trump's former spokesman Brian Hughes. The latter copied and pasted the content of the email, including the signature block with Goldberg's phone number, into a text message that he sent to Michael Waltz. Waltz' iPhone then semi-automatically stored Goldberg's number under the contact card for Hughes, who had now become the spokesman for the National Security Council. So when Waltz set up the "Houthi PC small group" on Signal, he actually wanted to add Hughes, but this resulted in the number of Goldberg being added.

On April 20, 2025, the New York Times reported that Hegseth also shared similar details about the Yemen operation in another Signal group that included his wife Jennifer, his brother Phil, and his personal lawyer Tim Parlatore. Jennifer Hegseth has no relevant role in the Defense Department, while Phil Hegseth serves in the Pentagon as a Department of Homeland Security appointee. Parlatore, a military defense attorney, recently rejoined the Navy with an assignment to improve military justice issues.

On May 1, 2025, it was reported that president Trump removed national security advisor Michael Waltz and his principal deputy Alex Wong from their functions. Waltz would be nominated as US ambassador to the United Nations.



Links and sources
- The Atlantic: Hegseth Risked Endangering Troops With Signal Messages (December 3, 2025)
- The Guardian: Exclusive: how the Atlantic’s Jeffrey Goldberg got added to the White House Signal group chat (April 6, 2025)
- Politico: Waltz’s team set up at least 20 Signal group chats for crises across the world (April 2, 2025)
- Bruce Schneier: The Signal Chat Leak and the NSA (March 31, 2025)
- The Independent: Previous administrations were wary of the messaging app Signal. Trumpworld has embraced it (March 27, 2025)
- The Atlantic: Here Are the Attack Plans That Trump’s Advisers Shared on Signal (March 26, 2025)
- The Atlantic: The Trump Administration Accidentally Texted Me Its War Plans (March 24, 2025)
- TWZ: C-17’s ‘Silver Bullet’ Airstream Trailer Pod Used By Secretary Of Defense Hegseth On First Overseas Trip (February 12, 2025)
- DoD Inspector General: Audit of Cybersecurity of DoD Classified Mobile Devices (December 13, 2024)

See also the comments on Hacker News

November 29, 2024

The phones of the new NATO Secretary General Mark Rutte

(Updated: January 13, 2025)

Since October 1, former Dutch Prime Minister Mark Rutte is the new Secretary General of the North Atlantic Treaty Organization (NATO), succeeding Jens Stoltenberg from Norway, who had held this office since 2014.

In his new function, Mr. Rutte has telephone sets for secure and non-secure calls and even a hotline with the White House. He also has a somewhat odd switch to access classified as well as unclassified computer networks.


New NATO Secretary General Mark Rutte at his desk, October 1, 2024
(photo: ANP/Remko de Waal - click to enlarge)



Telephone equipment

In the photo above we see that Secretary General Rutte has one phone in front of him, but the picture below shows that there were two additional telephone sets at the right side of the computer screen:


Former Secretary General Jens Stoltenberg (left) and his successor, October 1, 2024
(photo: ANP/Remko de Waal - click to enlarge)


Not much later, Mr. Rutte rearranged the phones and the other items on his desk, as can be seen in this crop of a photo on the NATO Flickr-account from November 19, 2024:


The desk of Secretary General Mark Rutte, November 19, 2024
(photo: Flickr/NATO - click to enlarge)


The Polycom VVX 411 VoIP phone

The first telephone set of Mr. Rutte can be identified as a Polycom VVX 411, which is a mid-range business phone for Voice over IP. It was manufactured by Polycom, an American company founded in 1990, which develops equipment for voice and video communications.

The device looks rather bulky for a modern-day IP phone, but that's not because it has additional security functions, as the commercial model is just as big. However, there's also a version of the Polycom VVX 411 that was modified by CIS Secure to prevent unintentional audio transmissions (TSG-6 approved). The available photos give no indication that the Secretary General has this modified version on his desk.


The Polycom VVX 411 VoIP phone at the desk of
former Secretary General Jens Stoltenberg
(photo: NATO Flickr-account)


The Polycom phone has a rather peculiar accessory, which is attached left of the handset. It's an HL10 Handset Lifter which is connected to the wireless headset that is also on Rutte's desk. When using this headset, one can answer an incoming call by pressing a button on the headset, after which the HL10 Handset Lifter automatically lifts up the handset of the phone, and lowers it again after pressing the headset button to disconnect the call.

The HL10 Handset Lifter was made by headset manufacturer Plantronics, an American company from Santa Cruz in California, which in 2019 acquired Polycom and then changed its name to Poly. In 2022 the company was sold to HP for $1.7 billion in cash.

As the Polycom phone has no labels or markings, it's the one that is used for all non-secure phone calls, whether internal or external.


The Cisco 8865 IP phone

The second telephone set on the desk of Secretary General Rutte is a Cisco IP Phone 8865, which is one of the most widely used high-end executive phones and includes a camera for video calls. A similar model, for example, sits in the Oval Office on the desk of the President of the United States.


The Cisco 8865 Unified IP phone on the desk
of NATO Secretary General Mark Rutte


The red labels on this phone indicate that it is used for secure (video) calls. As this phone has no encryption capability itself, it is connected to a dedicated Voice over IP network with bulk network encryptors that encrypt the outgoing and decrypt the incoming traffic.

The current Cisco 8865 replaced a slightly older model, the Cisco 9951 IP Phone, that was on the desk of Rutte's predecessor Stoltenberg. For that model the end-of-sale was in 2016, with Cisco support ending in 2021.


The Cisco 9951 Unified IP Phone on the desk of
former Secretary General Jens Stoltenberg


The Cisco 7975 Unified IP Phone

The third telephone set on Mr. Rutte's desk is an even older model: the Cisco 7975 Unified IP Phone, which was originally introduced around the year 2000. The end-of-sale for this phone was in 2018 and software maintenance ended in 2023. This phone wasn't there on Stoltenberg's first day at the new NATO Headquarters in May 2018, but it does appear in a photo from May 2020.

When such an old device is still in use, it often means that it has been rigorously tested to fit a special purpose. In this case it immediately brings to mind a similar Cisco 7975 IP Phone on the desk of Ukrainian president Zelensky. Moreover, it is not only the same device, but a very close look also shows that the touchscreen of both phones has the same wallpaper.


The 7975G Unified IP Phone on the desk of
NATO Secretary General Mark Rutte


Close-up of the Cisco 7975 Unified IP Phone on
the desk of Ukrainian president Zelensky.


The wallpaper is an image of the White House and given the fact that Zelensky used this phone for calls with US President Biden, the identical telephone set on the desk of the NATO Secretary General must also serve as a hotline with the American president.

Update: An interesting question is whether US intelligence agencies would be able to use the microphone in this hotline phone for secretly listening in to the conversations in the office of the Secretary General. To prevent such unintentional audio transmissions, telephone sets can be modified so that the microphone is disconnected when the handset is on hook and the speakerphone is disabled as well.



Computer equipment

Besides the three telephones, Secretary General Rutte of course also has a computer screen with a keyboard and mouse on his desk. Additionally, there's an unusual device, which at first sight looks a bit like an old radio with a rotary knob:




A reader of this weblog identified this device as a "5 Position ABCDE Switch" made by Black Box, an Indian-American company that provides a range of computer network products. Black Box was founded in 1976 and has its headquarters in Plano in Texas and an Indian headquarters in Mumbai.

An ABCDE Switch is used for "switching one device to any one of four other compatible devices". In this case it's most likely used for accessing computer networks with different security classifications from a single Keyboard, Video and Mouse set, which is why it's usually called a KVM-switch.

The particular device with the rotary knob on the desk of the Secretary General isn't listed on the Black Box website, nor is it visible on the list of NATO approved products for information assurance. However, a lot of them are for sale on eBay, so it might be an older model that has been replaced by newer ones with push buttons.


Interior of a 5 Position ABCDE Switch as advertised on eBay


Updates:

Besides an unclassified local area network with access to the internet, NATO has several classified computer networks, including:

- BICES (Battlefield Information Collection and Exploitation Systems; Secret)
- MINERVA, the NATO Headquarters Local Area Network (Secret)
- NATO Secret Wide Area Network (NS-WAN, also known as CRONOS)
- Mission Networks, for mission-specific information

BICES is used for sharing intelligence and information among the participating NATO members and some non-NATO nations (Australia, Austria, Ireland, New Zealand, and Switzerland). Each of them pays for the BICES Backbone Network (BBN) which connects them not only to BICES itself, but also to MINERVA, to the NS-WAN and to military intelligence agencies of other NATO members. BICES was initially managed by the NATO BICES Organisation (NBO, established in 1999) and now by the BICES Group Executive (BGX).

Earlier, NATO forces also used LOCE (Linked Operational-Intelligence Centers Europe), which was a system from the US European Command (USEUCOM) that provided near-real-time, all-source, correlated situation and order of battle information at the classification level SECRET//REL NATO.


The NATO intelligence architecture in 2001
(source - click to enlarge)


In December 2024 it was announced that NATO is in the process of creating a classified cloud system in which eventually all 32 members can share secret information. Currently the US, the UK and several other countries are drafting an implementation directive for transitioning classified data from different repositories to a single cloud environment. Inspiration for this move comes from Ukraine, which moved its sensitive data out of data centers and into the cloud following suspicious Russian cyber activity right before the the country was invaded by Russian troops.




> For the telephone equipment used by Mark Rutte as prime minister of the Netherlands, see my blog post from 2014: The phones of the Dutch Prime Minister



Links and sources
- Het Parool: Hij stelt prikkelende vragen, maakt grappen en haalt zijn eigen koffie: als Navo-chef is Mark Rutte in alles anders dan zijn voorganger (December 28, 2024)
- Trouw: In de nieuwe werkkamer van Mark Rutte kijkt Nijntje niet langer gezellig toe (October 17, 2024)
- Wade Alarie: Information Sharing Solutions for Nato Headquarters (2008)
- J.R. Karssing: De Navo en inlichtingen, in: Militaire Spectator, jrg. 170, nr. 11, 2001
- NCI Agency: NATO Information Assurance Product Catalog (NIAPC)

See also the comments on Hacker News
Some older articles on this weblog that are of current interest:
In Dutch: Volg de actuele ontwikkelingen rond de Wet op de inlichtingen- en veiligheidsdiensten via het Dossier herziening Wiv 2017