r/privacy • u/Fox3High369 • 2d ago
discussion German Police Are Using Linked Devices to Read Messages from Messaging Apps like Signal Without Cracking the Encryption
https://www.privacyguides.org/news/2026/09/30/german-police-are-using-linked-devices-to-read-signal-messages-without-cracking-the-encryption/Signal only allows linked devices through a QR code. However, it's still possible to scan a QR code sent by an attacker without them having physical access to your device.
The document states that the German customs agency has been testing messenger surveillance since the end of 2023, and it has led to success in criminal investigations. They're light on details as to exactly what strategies German customs officials use, but there are plenty of ways to maliciously link a device to an account.
This type of surveillance became an official, permanent strategy available to all agents since August 2025.
The messengers affected include WhatsApp, Telegram, Threema, and Signal.
243
u/Worried_Dinner_4082 2d ago
Okay, so what’s the solution to prevent this?
192
127
104
u/Polyxeno 2d ago
If Signal cares, they could provide a setting to not allow linked devices.
56
33
u/whatnowwproductions 2d ago
They do care, they already require authentication to link.
24
u/Dr_Jecky1l 2d ago
I think what they mean is, maybe the default setting should be not to allow linking of separate devices. That way, only those who know what they are doing can go out of their way and change settings to allow linked devices, if they require it
5
u/whatnowwproductions 2d ago
How would that stop this anymore than what the current system does? If they're getting past authentication because they're requesting the password, nothing is stopping them from going into settings and re-enabling.
7
u/Dr_Jecky1l 2d ago
It doesn’t, but it would stop people from doing it automatically, thinking it was okay…
Idk, perhaps some kind of disclaimer could be used when turning on a setting for linking devices explaining safety concerns
4
u/whatnowwproductions 1d ago
There is already ample warning in the application and it warns you several times already.
1
u/Dr_Jecky1l 1d ago
Meh, idk then… it seems common sense to me not to link any devices together that are for sensitive communication. In fact, I don’t link any devices together - each device has its own use case, persona as per compartmentalization.
Some people, despite being privacy “conscious”, may not understand the intricacies of all the nuances and settings, let alone follow all the new exploits and what not.3
u/Polyxeno 2d ago
A user setting that can only be changed from the device should prevent any attempt at linking, unless they already have access to the device.
3
u/whatnowwproductions 1d ago
The method explained in the article uses physical access when it relates to Signal.
3
u/ayleidanthropologist 2d ago
Like a toggle, then you just toggle it off and don't ever need to worry how they might get you with a QR
19
u/halls_of_valhalla 2d ago
The issue is that people are stupid. And stupid people scan QR codes if someone tells them to scan them. They might think its for a group invitation but its for device linking. The solution is the user not to be stupid. And maybe the app adding warning signs.
13
u/Tactical-Donkey 2d ago
In UK QR codes for parking are replaced by scammers. And people just scan them without thinking.
2
u/halls_of_valhalla 1d ago
Same happened during pandemic for Corona tests, which sensibilized many I guess - but others will fall for it again.
3
10
u/timmyc123 2d ago
Using passkeys (which requires physical proximity for cross device flows) would be one way to harden the linking process.
18
u/Fancy_Morning9486 2d ago
Password protected chats ontop of encryption
8
u/Busy-Measurement8893 2d ago
What? Why? Just check if you have any linked devices that you don't recognize.
34
2
1
u/tanksalotfrank 2d ago
Keep track of your shit and treat linked devices as temporary logins. Same as normal: log out of stuff regularly
1
1
u/Impossible_Sugar3266 2d ago
Why is that even news. Linked devices are always listed and visible in settings.
1
108
u/OptimusPrimeLord 2d ago
Maybe its too early in the morning and I'm not understanding this, but isn't this just phishing someones 2FA in order to log in on the attacker's device?
48
2d ago
[removed] — view removed comment
18
u/slipperyMonkey07 2d ago
I view it two fold, it is good to make people aware of tactics that can be used by scammers and government agencies alike. More informed people are of them the better.
But it also works as propaganda to get people to give up on privacy attempts. It can be overwhelming for even more tech informed people to keep up with everything, but they still try usually. But regular people want simple and straight forward they get a hurdle and will stop trying. See that x,y,z isn't as safe as they thought and just go back to sticking to the popular thing.
1
4
2d ago
[deleted]
1
u/bro_can_u_even_carve 2d ago
That can't be right, I definitely send and receive Signal messages on desktop even when my phone is powered off
72
u/j-doe411 2d ago
In the US, we don’t need tech or workarounds like that. We just put actual morons in office and wait for them to inevitably mess up
22
2d ago edited 20h ago
[removed] — view removed comment
5
u/j-doe411 2d ago
Idk did your president use Grok to decide whether to invade a foreign country and kidnap their leader?
16
u/Extra-Ad5735 2d ago
The biggest weakness of Signal (and other messengers) is the dependency on a phone number - an inherently unsafe identifier. Until they will start allowing creating accounts from email the targeted attacks will continue.
35
2d ago
[removed] — view removed comment
17
u/LurkerByNatureGT 2d ago
The examples given are phishing and physical access to the unlocked phone.
1
2d ago
[removed] — view removed comment
3
2d ago
[removed] — view removed comment
7
u/Some_Helicopter 2d ago
the guy is needlessly throwing around a buzzword and you have nothing to worry about, see my comment above if you need more details
2
2d ago edited 20h ago
[removed] — view removed comment
5
u/Quirky-Degree-6290 2d ago
Or any government like entity. See: Mexican cartels who’ve purchased Pegasus
8
u/Some_Helicopter 2d ago
looks like you heard of Pegasus once in an article and now you throw it out like a buzzword.
As LurkerByNatureGT said, the examples given were phishing and physical access.
Moreover, Pegasus as far as known publicly mostly relies on zeroclick and zeroday exploits, both not mentioned in the post as lurkerbynaturegt saidPegasus is a software "suite" not a virus or attack vector
Pegasus is owned by a company not based anywhere near germany
Also, do you genuinely believe that an airport in Germany is attacking every single device of every person entering the country, when the cost of deploying Pegasus for ONE campaign (usually against 1 person) is $650,000 to $41 million USD!!
Please stop fearmongering
- Cybersecurity Professional
1
u/unperson_1984 2d ago edited 2d ago
Police and intelligence agencies are allowed to use state Trojans to eavesdrop on messengers like WhatsApp. Maybe not "Pegasus" specifically, but if they have 0 click or 1 click exploits or if they have physical access to the device they can install Spyware or add linked accounts. The article also says both Police and Customs intercept unencrypted SMS messages to bypass 2FA, as well as secretly requesting email data from webhosts.
The original article has an emphasis on the need for transparency from these organizations. They do not reply to public inquiries about message monitoring because of "national security".
19
u/Aggressive-Hawk9186 2d ago
" WhatsApp's implementation is a bit better. It requires you to initiate the device linking from within the app, an attacker can't just send you a code unprompted. Still, it's highly possible to phish by coaching someone to go into the settings and type in the device linking code."
This is weird to me. They compel ppl to accept new devices requests?
39
u/erik_7581 2d ago
No, they get acess to the device by lying.
Here a german article that is more detailed: https://netzpolitik.org/2026/messenger-ueberwachung-immer-mehr-polizei-ueberwacht-messenger-wie-whatsapp/
A married couple goes to the police. They are asked to testify as witnesses regarding their daughter. The officers want to read the WhatsApp messages exchanged with their daughter. They ask the parents for their cell phones. The parents agree, voluntarily.
But the police officers do much more than they say. They gain permanent access to the WhatsApp accounts. They set up WhatsApp Web on a police computer. They scan the verification QR code in the parents’ WhatsApp apps. From that point on, they can
19
u/MortgageMindless7175 2d ago
Moral of the story- don't give police or government access to your private property. Always ask for a lawyer. Or better yet come already weaponized with a lawyer 😉
0
u/Lieentz188 2d ago
Don't listen to this fraud, the last time I was at the police station I whipped out my pistol called "Lawyer" and they arrested me. 🤔
/s
5
u/lorkanooo 2d ago
This is usual phishing in this case and applications can't do much against that. Its the same as if they asked for password and you said "sure here you go"
8
u/AllergicToBullshit24 2d ago
With the number of sidechannel attacks against multi-device setups don't know why anyone would link second devices and why in the world does anyone use SIMs tied to identity?
6
u/SprucedUpSpices 2d ago
why in the world does anyone use SIMs tied to identity?
In many places the government forces you to.
3
u/volutopia 2d ago
But signal doesn't allow people to even have an account without a number. I didn't get it.
8
2d ago edited 20h ago
[removed] — view removed comment
3
u/volutopia 2d ago
Good news :)
3
u/Present-Rhubarb6337 2d ago
Select to pay the $2.99 fee using Apple Pay or Google Pay.
not so good news
5
u/Dr_Jecky1l 2d ago
The solution is - don’t use QR codes to link devices.
In fact, don’t link devices period, especially if what you’re saying you’d consider sensitive, which is probably the case if you’re using signal in the first place.
4
u/VelvetViolet99 2d ago
I don't understand this. I frequently chat on signal about things I could be persecuted for in my country. Can u explain to me like I am 5?
2
1
u/cookiesnooper 2d ago
Really? All it takes in Signal to link a device is to scan a QR code? No confirmation? No information about device being linked?
2
u/Busy-Measurement8893 1d ago
I'm like eighty percent certain that it asks you to confirm it. And name the new device.
The "issue' here is that the police link their computer with your phone when they have your phone in hand, without telling you.
1
u/Dr_Jecky1l 2d ago
Perhaps the default setting for all these apps including signal, should be to not allow devices to be linked.
That way, only a user who knows what they are doing, can go into settings and change it if they know what they’re doing, and require it for whatever reasons.
If you have sensitive communication, you’d ideally not want copies of the conversation on multiple devices, so having to change default settings would make sense.
1
1
u/Buckcity42 2d ago
Get SimpleX Messenger - no phone numbers or unique identifiers. Still a work in progress but more secure & anonymous than anything else on the market with broad cross platform comparability.
1
u/Busy-Measurement8893 1d ago
How is this any better than Signal in the way mentioned in the article?
1
u/Buckcity42 1d ago
For the attack in the article, the difference is device linking. Signal lets a linked device receive messages independently, so someone tricked into linking an attacker’s device can give them ongoing access.
SimpleX’s desktop app instead accesses your phone’s profile through a direct connection, normally requiring both devices on the same local network. That makes the remote linking trick harder as you’re not authorizing a separate device to keep receiving messages from anywhere.
1
u/Imperator_Buggy 1d ago
“The messengers affected include WhatsApp, Telegram, Threema, and Signal.”
Session seems more and more appealing.
4
u/Busy-Measurement8893 1d ago
Session also has multi device support so they are also "affected"
1
•
u/AutoModerator 2d ago
Hello u/Fox3High369, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)
Check out the r/privacy FAQ
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.