Notes on Internet Privacy

Posts and research from the URnetwork team and community.

RSS

Sweden's Military Uses Signal. Sweden's Government Wants to Ban It.

In February 2026, Brigadier General Mattias Hanson directed Swedish military personnel to use Signal for secure communications. In the same month, Sweden's government advanced legislation that would force Signal to build a backdoor or leave the country. Sweden's own Armed Forces warned that the law "cannot be fulfilled without introducing vulnerabilities." The encryption exodus has begun -- and it is not just Sweden. The United Kingdom forced Apple to withdraw encryption from British users. The EU killed Chat Control by eighty-three votes, then watched the companies keep scanning anyway. Across three continents, governments are demanding the mathematically impossible: a backdoor that only they can use. The result is a world where the most secure communication tools are being driven out of the countries that need them most.

The directive

In February 2026, Brigadier General Mattias Hanson, the Chief Information Officer of the Swedish Armed Forces, issued a directive. Calls and text messages that do not concern classified information should, as far as possible, be made using the Signal messaging app. The directive was not a suggestion. It was a decision by Sweden's military CIO, motivated by a specific and well-documented threat: the vulnerability of conventional telephone networks to eavesdropping and number spoofing.

General Hanson's reasoning was operational. "Strengthening Sweden's militarily and acting as part of a collective defense requires us to increase our defensive capabilities," he stated. "We need to utilize the latest technology and all the innovative power of the Swedish private sector." Signal, with its open-source end-to-end encryption protocol, represents that latest technology. Sweden's military adopted it because conventional communications channels are not secure enough.

In the same month, Sweden's government was advancing legislation that would make Signal's core technology -- its end-to-end encryption -- functionally illegal.

The bill, formally designated Ju2024/02286, "Datalagring och åtkomst till elektronisk information" -- Data Storage and Access to Electronic Information -- would compel messaging services including Signal, WhatsApp, and other providers to store all user communications and make them accessible to Swedish law enforcement agencies. The Swedish government proposed that the legislation take effect on March 1, 2026, with a Riksdag vote expected in the spring.

Signal's response was immediate and unequivocal. Meredith Whittaker, president of the Signal Foundation, told Swedish news outlet SVT Nyheter that Signal would leave Sweden rather than comply. "We would rather exit the market than create vulnerabilities that could be exploited by third parties," Whittaker said. "We will not walk back."

In a single month, Sweden's military told its personnel to use Signal because it is secure. Sweden's government told Signal to become insecure or leave. And the Swedish Armed Forces -- in their formal response to the proposed legislation -- warned that the bill "cannot be fulfilled without introducing vulnerabilities and backdoors that third parties could exploit."

The same government is simultaneously strengthening its military's communications security and proposing to undermine it. The contradiction is not subtle. And it is not unique to Sweden.


The mathematics of impossibility

The proposed legislation grants Swedish law enforcement expanded access to electronic communications. Its mechanism is straightforward: all providers of electronic communication services operating in Sweden would be required to store user communications data and make it available to law enforcement upon request.

For services that do not use end-to-end encryption, compliance is technically trivial. The provider already has access to message content, stored on its servers. A legal requirement to preserve and produce that content on demand changes the provider's legal obligations but not its technical architecture.

For end-to-end encrypted services, the requirement is technically impossible to fulfill without breaking the encryption. This is not a matter of engineering difficulty. It is a mathematical certainty.

End-to-end encryption means that messages are encrypted on the sender's device and decrypted only on the recipient's device. The service provider -- Signal, in this case -- never possesses the encryption keys and therefore cannot read the messages, even if it wanted to. There is no key to hand over. There is no backdoor to open. The system is designed so that the provider is technically incapable of accessing message content.

To comply with the Swedish law, Signal would need to redesign its system so that either the provider holds a copy of the encryption keys, or a third party holds a copy, or the encryption is weakened in some way that allows access. Each of these approaches introduces what cryptographers call a "single point of failure" -- a mechanism that, if compromised by anyone, compromises the security of all users.

The consensus among cryptographers is not divided on this point. There is no known method of providing government access to encrypted communications that does not simultaneously provide access to anyone else who discovers or compromises the access mechanism. A backdoor for Sweden is a backdoor for Russia, China, criminal organizations, and any other actor with the motivation and capability to exploit it.

The Swedish Armed Forces said exactly this. In their formal assessment of the proposed legislation, the military stated that "access requirements in end-to-end encrypted communications cannot be fulfilled without introducing vulnerabilities and backdoors that could be exploited by third parties." This is not a privacy advocacy organization. This is not a technology company protecting its business model. This is NATO's newest member state's military, which has operational experience with the consequences of compromised communications, telling its own government that this law will make Sweden less safe.


The coalition

The Swedish Armed Forces were not alone in their assessment. A coalition of 237 civil society organizations, cybersecurity experts, and major technology companies signed a joint letter urging Sweden's Riksdag to reject the legislation. The letter was coordinated by members of the Global Encryption Coalition, a network of over 400 organizations across 108 countries advocating for strong encryption worldwide.

The signatories included Mozilla, Proton, Wire, Tuta Mail, and Signal itself. The Center for Democracy and Technology endorsed the opposition. The Internet Society published its own analysis warning of the security implications.

The coalition's argument was technically grounded. The creation of an encryption backdoor creates vulnerabilities that would leave Sweden less safe against cyber threats and foreign adversaries. Those most reliant on encryption -- journalists protecting sources, activists organizing under threat, survivors of domestic violence communicating with support services, military personnel conducting operations -- would be disproportionately harmed.

The letter addressed the law enforcement rationale directly. Yes, encryption makes it harder for police to access the communications of criminal suspects. But weakening encryption does not selectively affect criminals. It affects everyone. And the criminals who are the ostensible targets of the legislation will simply move to other tools -- self-hosted servers, custom encryption software, or platforms operated from jurisdictions outside Sweden's reach. The people who cannot easily move to alternative tools are ordinary citizens, who will be left with weakened security while the criminal targets adapt and disappear.

The Swedish government has not publicly responded to the Armed Forces' assessment or the coalition letter with a technical rebuttal. It has not explained how the law could be implemented without introducing the vulnerabilities that its own military has identified. The legislation appears to proceed on the assumption that because the government wants access, a safe method of providing it must exist -- an assumption that every qualified cryptographer who has examined the question has rejected.


Signal draws a line

Meredith Whittaker's statement that Signal would leave Sweden was not a negotiating tactic. It was a statement of technical and organizational principle, consistent with Signal's response to identical pressure from the United Kingdom.

"We will not walk back," Whittaker said, speaking about both the Swedish and British situations. "Signal's position is very clear -- we will not walk back, adulterate, or otherwise perturb the robust privacy and security guarantees that people depend on."

This is not an abstract philosophical commitment. Signal is a nonprofit foundation. It does not sell advertising. It does not monetize user data. Its only product is secure communication. If it cannot provide secure communication, it has no product and no reason to exist. The decision to leave a market rather than compromise encryption is, for Signal, an existential imperative rather than a strategic choice.

The precedent is Signal's own history. In 2016, a federal grand jury in the Eastern District of Virginia subpoenaed Signal for user data. Signal complied with the subpoena -- and produced exactly two data points: the date the account was created and the date it last connected to Signal's servers. That was all Signal had. No message content, no contacts, no group memberships, no profile information. The system is designed so that Signal cannot produce what it does not possess.

If Sweden's law passes and Signal leaves, approximately 2.2 million Swedish Signal users -- including the military personnel who were just directed to use it -- will lose access to the app. The tool their own military selected as the best available option for secure communication will no longer be available in their country because their government required it to become insecure.


Apple already buckled

To understand what happens when a government successfully pressures a technology company on encryption, look at the United Kingdom.

On February 24, 2025, Apple announced that it would withdraw its Advanced Data Protection feature from UK users. Advanced Data Protection provided end-to-end encryption for iCloud backups, meaning that even Apple could not access the data stored in a user's iCloud account. The UK government, using a Technical Capability Notice under the Investigatory Powers Act 2016, had secretly ordered Apple to maintain the capability to provide access to iCloud data.

Apple's response was not to build the backdoor. It was to remove the encryption feature from UK users entirely. As of February 21, 2025, UK users could no longer enable Advanced Data Protection. Users who had already enabled it were required to disable it. The ten iCloud data categories covered by ADP -- including photos, notes, and device backups -- reverted to standard encryption, meaning Apple holds the keys and can provide data to law enforcement on demand.

Apple chose to reduce security for millions of UK users rather than build a backdoor that could compromise security for everyone. This is often described as Apple "standing up" to the UK government. It was not. Apple complied with the practical effect of the demand. UK users lost encryption. The government got what it wanted: access to UK users' data.

The UK did not stop there. In September 2025, the Home Office issued a second Technical Capability Notice, this time demanding backdoor access specifically to encrypted iCloud backups for UK users. Privacy International filed a challenge at the Investigatory Powers Tribunal, alongside Liberty and two individual claimants, with a seven-day hearing scheduled for 2026.

The Apple precedent demonstrates the pattern. A government issues a secret order demanding access to encrypted data. The company faces an impossible choice: comply and compromise security for all users, or withdraw the security feature from users in that jurisdiction. Either way, users lose. The encryption is either broken or removed.

Signal has stated it will not follow Apple's path. It will not withdraw encryption from Swedish users while maintaining it elsewhere. It will not build a Swedish-specific backdoor. It will leave entirely. This is a different response -- arguably a more principled one -- but the outcome for Swedish users is similar. They lose access to secure communication.


The week Europe chose

The Swedish and British situations are not isolated incidents. They are part of a pattern that becomes visible only when you see the simultaneous events.

On March 26, 2026 -- eighteen days before this article's publication -- the European Parliament voted 311-228 to reject extending the ePrivacy Directive derogation known as Chat Control. That derogation, in force since August 2021, had given Google, Meta, Microsoft, and TikTok a legal basis to voluntarily scan billions of private messages for child sexual abuse material. The Parliament killed it by a margin of eighty-three votes, after the conservative EPP Group attempted to force a re-vote and a parallel scheme emerged to obtain Council approval through a meeting of fisheries ministers.

The vote was, in the words of Pirate Party MEP Patrick Breyer who led the opposition for four years, "a historic day that brings tears of joy." The Electronic Frontier Foundation called it "the first time any major jurisdiction has actively rolled back government-sanctioned mass surveillance of private communications."

As of April 3, 2026, the legal basis for scanning European citizens' private messages expired. Google, Meta, Microsoft, and Snap immediately announced they would continue scanning anyway.

And the permanent replacement legislation -- Chat Control 2.0, the Child Sexual Abuse Regulation -- resumes trilogue negotiations on May 4, with a political deal targeted for July. The Council's position still includes mandatory age verification that privacy advocates warn would effectively kill anonymous online communication in Europe.

In Belgium, a proposed encryption backdoor law was scrapped after 107 organizations mobilized in opposition, with the final text declaring that "the use of encryption is free." In France, Article 8 of the Narco Trafficking Bill, which would have required backdoor access to encrypted communications, was rejected in March 2025.

Each of these battles was won. Each victory was narrow. Each must be defended again.


The three fronts

Step back further and the pattern becomes geopolitical.

While Europe debates whether to scan messages, China is moving to cut the physical connections that carry them. A leaked notice from Shaanxi Telecom, dated April 8, 2026, orders internet service providers to halt all outbound connections beyond mainland China -- including to Hong Kong, Macau, and Taiwan. The Ministry of Industry and Information Technology held a meeting on "strengthening management of unauthorized internet connections via dedicated cross-border data lines." The enforcement mechanism is not blocking or filtering. It is disconnection. Carriers face permanent shutdowns.

While Sweden debates whether to require backdoors, Russia is deploying artificial intelligence to make circumvention impossible. Roskomnadzor, the Russian communications regulator, is spending 2.27 billion rubles -- over $29 million -- on an AI-powered censorship system that integrates machine learning into its deep packet inspection infrastructure. The system does not just block by IP address. It detects traffic patterns that resemble VPN connections and blocks them automatically. Roskomnadzor has already restricted access to 469 VPN services, a 70 percent increase in three months. VPN-related content blocking increased 1,235 percent year-over-year.

Three models. China cuts the wires. Russia deploys AI to detect circumvention. Democratic governments demand that the tools themselves be weakened from the inside. The approaches differ in method. They converge in outcome: a world in which private communication is architecturally impossible.


The defense that does not require trust

The lesson of the Swedish contradiction is not that governments are malicious. Sweden's law enforcement has legitimate operational needs. Criminals do use encrypted communications. Investigations are harder when messages cannot be read.

The lesson is that the proposed solution -- weakening encryption for everyone to catch specific criminals -- does not work. Sweden's own military explained why. The Global Encryption Coalition's 400 organizations explained why. Every qualified cryptographer who has studied the question explained why.

The tools that protect Swedish soldiers from Russian intelligence are the same tools that protect journalists from government surveillance, activists from authoritarian repression, domestic violence survivors from their abusers, and ordinary citizens from data breaches. There is no version of encryption that is strong for the military and weak for the government. The mathematics does not negotiate.

End-to-end encryption works because nobody in the middle -- not the provider, not the carrier, not the government -- can access the communication. The moment you create an exception, the architecture fails. This is why Signal chose the design it did. This is why the Swedish military chose Signal. And this is why the Swedish government's demand is not just a policy disagreement. It is a request to weaken the national defense.

Decentralized networks extend this principle further. Traditional VPN providers route traffic through centralized servers -- servers that can be targeted by court orders, technical capability notices, or infrastructure-level disconnection. Decentralized architectures distribute traffic across independent nodes with no single point of interception. There is no central server to compromise, no single provider to serve a court order on, no cable to cut. The architecture is the defense.

The pattern of the last decade is clear. Centralized services can be pressured, compromised, or shut down. Apple buckled in the UK. Signal will leave Sweden rather than compromise. The next company may not have Signal's principles. The only durable defense is architecture that does not depend on any company's willingness to resist government pressure -- architecture that makes compliance with a backdoor order technically impossible, not just organizationally inconvenient.


The question for Sweden

Sweden's Riksdag has not yet held the final vote. The timeline has slipped from the government's initial target of March 2026, and the intensity of opposition -- from the military, the technology industry, civil society, and Sweden's international allies -- has created political uncertainty.

But the dynamics pushing toward encryption backdoors have not changed. Law enforcement wants access. Politicians want to deliver it. And the fundamental question -- what happens to the security of 10 million Swedes when a NATO member state deliberately weakens the communication infrastructure that its own military identified as essential -- has not been answered.

If the law passes, Signal leaves Sweden. Swedish military personnel lose the secure communication tool their CIO selected. Swedish journalists lose the ability to protect sources. Swedish citizens lose the encryption their government's own Armed Forces said was necessary. And the criminals the law was supposed to catch continue communicating through tools that do not comply with Swedish jurisdiction, from servers that do not sit on Swedish soil, using protocols that do not answer to Swedish law.

Sweden's military figured this out. Signal figured it out. The 237 organizations that signed the coalition letter figured it out. Every cryptographer who has examined the question figured it out.

The question is whether Sweden's parliament will figure it out before the vote.


Sources (11)

Sources: Cyber Insider, "Swedish Armed Forces Adopt Signal for Secure Communications" (February 2026); Cyber Insider, "Signal Threatens to Leave Sweden Over Encryption Backdoor Law"; Infosecurity Magazine, "Signal May Exit Sweden If Government Imposes Encryption Backdoor"; TechRadar, "Signal would rather leave the UK and Sweden than remove encryption protections"; Cyber Insider, "Global Coalition Warns Sweden Against Encryption Backdoor Legislation"; Global Encryption Coalition joint letter (April 2025, 237 signatories); Tuta Blog, "Swedish Armed Forces: Use Signal to defend against interception"; Privacy International, "PI Apple TCN Challenge" and "Update: Our case against UK Government's secret surveillance orders to be heard in 2026"; Computer Weekly, "Home Office issues new backdoor order over Apple encryption" (September 2025); Apple Support, "Apple can no longer offer Advanced Data Protection in the United Kingdom to new users" (February 2025); Element.io, "Why the Swedish Armed Forces' switch to Signal misses the mark"; State of Surveillance, "Signal Would Rather Leave the UK and Sweden Than Break Encryption"; Patrick Breyer, "End of Chat Control: EU Parliament Stops Mass Surveillance in Voting Thriller" (March 26, 2026); Electronic Frontier Foundation, "EU Parliament Blocks Mass-Scanning of Our Chats -- What's Next" (April 2026); Center for Democracy and Technology, "CDT Europe's Response to the European Parliament Rejection of Chat Control 1.0's Extension"; Vision Times, "China's Telecom Crackdown May Block All Overseas Internet Access, Leaked Notice Suggests" (April 11, 2026); United24 Media, "Russia to Launch AI-Powered Internet Censorship System in 2026"; Forbes/Pravda, "Roskomnadzor will create an AI system to block VPNs for 2.3 billion rubles" (January 2026).

Further Discussion

Signal Is Good Enough for Soldiers. Just Not for You.

The Swedish Armed Forces evaluated the available options for secure unclassified communications and chose Signal. Brigadier General Mattias Hanson, the military's Chief Information Officer, directed personnel to use Signal because conventional phone networks are vulnerable to eavesdropping and spoofing. The military's formal assessment of the encryption backdoor bill warned that it "cannot be fulfilled without introducing vulnerabilities and backdoors that third parties could exploit." Sweden joined NATO in March 2024 specifically because of the Russian threat. Its military adopted Signal specifically because Russia targets Swedish communications. Every government official who carries a secured device is making the same judgment: encryption works, it is necessary, and breaking it creates unacceptable risk. The UK government uses encrypted communications for intelligence sharing. The US military encrypts battlefield communications. NATO's entire command structure depends on the principle that encrypted channels cannot be intercepted by adversaries. They just do not want you to have the same protection. Sweden's proposed law would force Signal to build a backdoor or leave the country -- taking the secure communication tool away from the same military personnel who were directed to use it. The encryption backdoor debate is not about security. It is about who gets to be secure. When the Swedish Armed Forces say encryption is essential for national defense and the Swedish Riksdag says encryption must be weakened for law enforcement, one of them is wrong. The military has the operational experience to know which.

The Encryption Exodus Is the Plan

When Signal leaves Sweden, Signal does not lose Sweden. Sweden loses Signal. The same citizens the government claims to be protecting -- journalists, activists, domestic violence survivors, military personnel -- are left with less secure alternatives. Meanwhile, the criminals the law targets simply switch to tools outside Swedish jurisdiction: self-hosted servers, custom encryption, platforms operated from countries that do not answer to the Riksdag. The backdoor does not catch criminals. It catches everyone who followed the rules. This is not speculation. It is the documented pattern. Apple withdrew Advanced Data Protection from UK users rather than build a backdoor -- and now every British iPhone user has weaker security than users everywhere else. The UK government got access to iCloud data. UK citizens got a less secure product. Russian and Chinese intelligence services got a new attack surface. The UK Crime and Policing Bill, being debated in Commons tomorrow, will give police access to 50 million driving licence photographs for facial recognition. A Cambridge study found "no statistically significant evidence" that facial recognition reduces crime, and some tests produced false positive rates of 91 percent. The surveillance expands regardless of whether it works. The encryption exodus creates exactly the world that authoritarian governments already inhabit. China is cutting physical connections to the international internet. Russia is deploying AI to detect and block VPN traffic. Democratic governments are achieving the same outcome through legislation: driving secure tools out, leaving only the compromised ones behind. If Sweden's military figured out that encrypted communication is essential for security, why is Sweden's parliament still pretending that breaking it makes anyone safer?

Comics

#1Signal Is Good Enough for Soldiers. Just Not for You.
#2The Encryption Exodus Is the Plan