Eleven minutes. That's the whole scandal.
Eleven minutes and a timestamp.
Daniel sent us something that starts as a political story and turns into a technical one halfway through. On October eighth, Avi Gil, who was Netanyahu's military secretary on October seventh, broke three years of silence and alleged that the chief of staff, Tzachi Braverman, ordered a stenographer to change the timestamp of the first secure-line call between Gil and Netanyahu, from six forty in the morning to six twenty-nine. She refused. He allegedly did it himself.
And Daniel's real question is buried in there. He says the image of a secure line brings up the hotline, the red phone, the physical tether between Washington and Moscow. Then he asks: is a secure line purely software, or is it a full stack of vetted hardware all the way down the chain?
And he flags that we don't have the internals for Israel's version. So we're speculating from what we know.
Before we can judge what was allegedly altered, we need to know what the thing being altered actually is.
Right. So what happened?
Gil's account is precise. He was woken at six twelve by a call from the head of Shin Bet chief Ronen Bar's office, telling him to switch to a secure line. At six twenty-two he called the IDF chief of staff's office. Then he called Netanyahu and told him Hamas had launched extensive rocket fire. At six forty they held a second conversation over the secure line, where Gil said, "We are at war."
And six twenty-nine is when the first barrage hit.
Which is the entire point. If the call is logged at six twenty-nine, it sits right at the moment of impact. If it's logged at six forty, it's twenty minutes after the country was already under fire.
So the edit moves Netanyahu from reacting to being already engaged.
Gil's own theory of motive, yes. Either to make it look like Netanyahu was issuing orders from the outset, or to suggest that intelligence from that second call was already known during the first one.
And the stenographer's line is the one that stays with you. "The computer shows six forty to six forty-four."
The original record documented the call as running six forty to six forty-four. Four minutes. She refused to touch it. Braverman was questioned under caution in November twenty twenty-four and admitted changing the timestamp, saying he believed it was a clerical error. His attorney says he acted within his authority to correct one.
A clerical error of eleven minutes that happens to move the call to the exact minute the rockets landed.
Gil's phrasing was "This is forgery." And his recommendation, which I think is the line that actually matters for this episode, was: "Don't settle for transcripts. Demand the original recordings."
Hold on. That's the part I want to sit with for a second, because he's not saying the call didn't happen. He's not saying the content was fabricated.
He's saying the record of when it happened is the disputed object.
Which means the conversation itself, the encrypted part, was never the vulnerable thing.
So let's start with the mechanism. What is a secure line, technically, and why is it not just an encrypted app on a phone?
Define the baseline first.
A secure telephone provides end-to-end voice encryption. In some cases, mutual authentication of the parties, which protects against a man in the middle. That's the definitional floor, and it's already more than an ordinary call does.
And an ordinary call does basically nothing.
The Department of Homeland Security's Science and Technology Directorate has been blunt about this. Standard mobile calls and texts are subject to eavesdropping through what's sold as Access-as-a-Service. The SS7 and Diameter signaling networks, and the 5G core, have tens of thousands of entry points worldwide, and a lot of them are controlled by hostile states. That's not a hypothetical vulnerability. That's the architecture.
Tens of thousands of doors, and you don't own most of them.
So the secure phone is the answer to that. And the best-documented family is the American one, starting with STU-III.
Which is where your face lights up.
It's a good machine, Corn. Introduced in nineteen eighty-seven by the NSA. It looks like an ordinary office phone. It plugs into a standard wall jack. You'd walk past it.
And then?
When two units go secure, the call is encrypted, after about a fifteen-second delay while the two ends negotiate. You hear the line change. It's a distinct sound.
Fifteen seconds of handshake before you can talk.
And here's the part that answers Daniel's question directly. STU-III is not a software construct. It's hardware-anchored. It used Type 1 encryption with a removable key called the KSD-64A, the Crypto Ignition Key. It's a sixty-four kilobit EEPROM in a package shaped like a house key.
A house key.
You insert it to make the phone work. Pull it out, and neither the phone nor the key is considered classified. The phone becomes a paperweight. The key goes in your pocket.
So the security isn't in the device. It's in the object you carry.
Exactly where Daniel's intuition is pointing. And the logistics are the proof. A new STU-III unit arrives without a working key. It needs a seed key installed first, and that seed key is shipped by NSA registered mail or by the Defense Courier Service. Then it's converted to an operational key over the phone, through a toll-free NSA number.
The cryptographic secret arrives by post.
By registered post, with a signature.
I want to be clear about how funny that is. The most classified object in the building travels like a passport.
It's not funny, it's correct. That's how key management works. The math is the easy part. The chain of custody is the hard part.
What replaced it?
Secure Terminal Equipment, STE. Its heart is the Fortezza Plus card, the KOV-14. It's a PCMCIA card, and it carries both the algorithms and the keys. The algorithms are BATON, a block cipher, and FIREFLY for key distribution. Both classified, both proprietary. Remove the card and the unit is declassified.
Same principle, smaller object.
Same principle. And that proprietary part is a real limitation. It's why you can only use these with the US government and a short list of allies. It's not a product you buy. It's a product you're cleared for.
Which is a different kind of security altogether. The encryption isn't the moat. The clearance is.
Now, the network layer, because this is where the modern version lives. Modern secure VoIP calls are secured by connecting the phones to a classified IP network. SIPRNET is the example everyone knows. The security is a property of the path the packets travel, not just the two endpoints.
So it's not two magic phones talking to each other over the ordinary internet.
It's two ordinary-ish phones on a network that doesn't touch the ordinary internet. The encryption is still there, but the isolation is doing enormous work.
Which is more robust, the endpoint key or the network?
The network, if you can afford it. Because the endpoint can be stolen, lost, or sitting in a drawer next to a spare house key. The network you can't walk out with.
So Daniel's full-stack hypothesis holds up.
The evidence strongly supports it. Modern secure lines are hardware-anchored, crypto keys, PCMCIA cards, classified algorithms, and network-anchored, classified IP backbones. Not merely software. And the hardest part of the whole stack, historically and now, is key management and physical custody. Not the encryption math. The math has been settled for decades.
So if I'm following you, the thing that makes a secure line secure is mostly a supply chain.
A supply chain and a personnel process. Who holds the key, who signed for it, who can remove it, who logs the removal.
And none of that is the conversation.
None of it. Which is where this gets interesting for the Netanyahu story.
Say it.
The call content in that story was never in dispute. Nobody alleges the recording was altered. What's alleged is that the log, the timestamp, the computer record of when the call happened, was changed by a human with access to the system.
One person, one edit, and the record of history moves eleven minutes.
The encryption protected the conversation from outsiders. It did nothing to protect the metadata from insiders.
That's the modern shape of the problem. You spend a fortune keeping the content away from the Russians and the Chinese, and then the thing that gets altered is the clock.
Let me put a number on that, because it's not intuition. STU-III went secure at about nine kilobits per second. STE does a hundred and twenty-eight. The transfer rate got fourteen times faster.
Herman.
What?
You just told me the bandwidth of a phone from nineteen eighty-seven.
It's context.
It's a tell. You're about to bring me a folder.
I am not bringing you a folder.
He's bringing a folder.
The point is that the technology improved enormously and the metadata problem didn't move at all. The clock is still the clock.
All right. That's the modern stack. But the image in everyone's head, the red phone, the hotline, comes from somewhere, and the history is stranger than the myth.
The Moscow–Washington hotline was established in nineteen sixty-three, after the Cuban Missile Crisis. The reason was timing. During the crisis, official messages took about six hours to deliver. And it took the United States nearly twelve hours to receive and decode Khrushchev's settlement message, which ran three thousand words.
Twelve hours to read a message while the world is deciding whether to end.
That's the entire rationale. Speed of deconfliction.
And it was never a phone.
Never a telephone line and never a red phone. The first implementation, operational on August thirtieth, nineteen sixty-three, used Teletype equipment. It shifted to fax in nineteen eighty-six. Since two thousand eight, it's been a secure computer link exchanging email.
So the most famous secure line in history spent forty-five years not being a line.
The red phone is pop culture. Dr. Strangelove, Fail-Safe. It never existed.
Why text?
Deliberately text-only, and the reasoning is the good part. Speech might be misinterpreted. Written messages gave both sides time for reflection before they answered.
Which is a design decision about human beings, not about cryptography.
Entirely. And the encryption is worth a line. They used a Norwegian-built machine, the ETCRRM II, with a shared one-time pad. Chosen specifically so neither side had to reveal its own secret cryptographic methods to the other.
Neither superpower would show the other its math.
So they used a third party's, with a pad. And the key tapes were delivered by courier, through each country's own embassy. Physical custody again.
The same problem in nineteen sixty-three as in nineteen eighty-seven. The key gets walked to the door.
And the physical reality was a routed network, not a tether. The primary cable ran Washington, London, Copenhagen, Stockholm, Helsinki, Moscow. It got cut several times by accident. Once by a Danish bulldozer. Once by a Finnish farmer's plough.
A farmer.
A farmer with a plough took the hotline down. There was a backup radio circuit via Tangier.
So even the archetype of the physical secure line was cable, radio and satellite, routed through six countries, and dependent on a Finnish farmer's equipment maintenance schedule.
That's the honest picture of a "line."
And that gets us to Israel, and here I'm going to flag the ground rules before you start.
Everything from here is speculation by analogy.
Publicly, there is no technical detail on how Israel's secure line is provisioned. No vendor, no protocol, no architecture documentation. Reporting gives you two things. The IDF's "red line," which is described as an encrypted telephone system, and a physical "secure red phone" as a device.
The red line reference is real. On the night of October seventh, around two thirty in the morning, IDF Chief of Staff Herzi Halevi held an encrypted call on the IDF's red line with Oded Basyuk, the head of the Operations Directorate, and Yaron Finkelman, the head of Southern Command.
Three of the most senior people in the country, on the secure system, three and a half hours before the attack.
And then Gil's own account treats the red phone as a physical object. He told Netanyahu he was communicating with Yair Lapid, then the opposition leader, via an app. Netanyahu's response was, "What do you mean? Either on the secure red phone or face to face."
Which is a sentence about threat models. An app is not acceptable, regardless of who's on the other end.
And Gil then physically delivered a red phone to Lapid's house.
He drove a phone to a politician's house.
That's what provisioning looks like at the top. The device moves by hand.
So what do we think is inside it?
By analogy, you'd expect the same three layers. A hardware anchor, some kind of removable or embedded key material, the STU-III and Fortezza model. A network anchor, a classified backbone that the calls ride on rather than the public switched network. And physical control, a device that is issued, tracked, and probably destroyed rather than returned.
And you'd assume a heavier emphasis on it than the American version, because of the threat environment.
A heavier emphasis and a shorter supply chain. Israel doesn't have the same depth of allied vendors, so you'd expect more indigenous hardware and more of the stack kept inside the country.
Which cuts both ways. A shorter supply chain is fewer places for a key to be intercepted.
And fewer independent parties checking the logs.
Say more about that.
In the American system, you have an NSA that produces the key, a courier service that ships it, a unit that holds it, and a separate communications staff that runs the network. Four parties. In a more consolidated system, those roles can collapse into fewer hands.
And the fewer hands, the more each one can do alone.
Which is a general property of small trusted systems. It's the tradeoff you make to keep the secret inside the country.
Here's the second-order thing I keep circling. The hotline was text-only because speech might be misinterpreted. Israel's leadership uses voice precisely for speed.
Deliberate tradeoff. A written message gives you a record and reflection. A voice call gives you seconds.
And a voice call still produces a record. A transcript, a timestamp, a log entry.
Which leads us back to the exact thing that's alleged. The call was fast, it was encrypted, and the only durable artifact of it was a computer entry saying when it happened.
And that entry is the one thing in the whole stack that a person with access could edit with a keystroke.
While the recording itself sits on a different system, presumably, with different controls.
Gil's recommendation is exactly that. Don't settle for transcripts. Demand the original recordings.
Because the transcript is downstream of the timestamp. Change the time, and the transcript is filed under a different moment in the story.
The content stays true and the meaning changes.
That's the cleanest way to put it.
So to answer Daniel properly. Is a secure line purely software?
Not remotely. Hardware anchor, network anchor, key custody, personnel. Full stack, and the human layer is load-bearing.
Could Israel's version be different from that model in kind rather than degree?
In kind, no. It has to solve the same three problems: get the key to the device, keep the network off the public internet, and control who touches the log. There's no fourth way to do it.
So what's unknown is how they solve them, not whether they do.
Right. And we should say plainly that we don't know. Anyone claiming to describe Israel's secure line architecture in detail is either cleared or guessing.
And you're guessing.
I'm guessing, by analogy, with a straight face.
That's the show.
The phone was never the problem. The log was the problem.
I had access to one of those systems, years ago. The key was the whole ritual. A house key, like you said, Herman, physical, you put it in the slot on the front and the phone goes secure. Fifteen seconds. You hear it change. And when you take the key out, the phone is furniture. Nobody cares about the phone.
What did they care about?
The transcript machine. There was a separate system that logged the calls, and the person who ran that system had more power than the person who ran the phone. The phone protects the call from the outside. The log tells everyone afterward what the call was for.
The log runs on a normal computer.
The log runs on a normal computer. You keep a record of that, don't you.
Of what?
The log. I have a page for it. Every time the system went down, the date, the duration, who was on shift. Nobody asked me to keep it. I have it.
Is it here?
It's at home. The point is the key was shipped registered mail. Registered mail, signature at the door. The whole model, the whole stack you've been describing, comes down to a courier and a signature. That's the security.
A man with a van is the perimeter.
They trusted me with one of the keys for a weekend. Just the key, not the phone. So I put it in the kitchen drawer, next to the spare house key.
Hilbert.
It seemed like the safest place in the flat. Nobody looks in the kitchen drawer.
Did anything happen to it?
The cat knocked it onto the floor. I didn't find it for three days. Under the refrigerator.
Three days.
I'd already reported it lost. That triggers a review. A lot of paperwork for a Tuesday.
The most secure phone in the building was protected for two days by a drawer with a cat in the flat.
The drawer wasn't the problem. The problem was that when I reported it lost, nobody could tell me what had actually happened to it. The system knew the key was gone. It had no idea where it was. That's the same thing as your timestamp, Herman. The record is only as good as the person who wrote it down.
Which means the recovery depends on the person, not the system.
The recovery is always the person. The system just tells you something's wrong.
The key turned up under the fridge.
It turned up under the fridge. I put it back in the drawer.
Of course you did.
It's a good drawer.
The case itself. Where does it stand?
It's been with prosecutors for roughly fifteen months, transferred around July of last year. Police reportedly believe there's enough evidence to charge Braverman. Prosecutors lean toward closing it. No decision is expected for at least another month, because of the election period.
The legal question may outlast the technical question.
The technical question isn't going anywhere. As secure communications get more hardware-anchored and more network-anchored, the content gets harder and harder to touch. Which pushes everything toward the metadata.
Timestamps, logs, transcripts.
The record of the conversation rather than the conversation.
The record is only as secure as the human holding the keystroke, which is the thing Hilbert just described with a cat and a refrigerator.
Gil's line was that you shouldn't settle for transcripts. You should demand the original recordings.
Which is exactly the gap between the encrypted call and its unencrypted record.
The conversation was protected. The record of when it happened was not.
That's where we leave it. Thanks to Hilbert Flumingtop for producing. If you want more of this, try episode fourteen oh eight, Israel Wartime Readiness Field Guide; episode eighteen sixty-one, Emergency Prep You Can Sing To; and episode six thirty-four, Can the President Make an Impromptu Call. This has been My Weird Prompts, the human-AI collaboration podcast. If you want to send us a prompt, send us your own prompt on Telegram at t dot me slash MWP listener bot. We'll be back soon.