r/privacy • • 2d ago

discussion German Police Are Using Linked Devices to Read Messages from Messaging Apps like Signal Without Cracking the Encryption

https://www.privacyguides.org/news/2026/09/30/german-police-are-using-linked-devices-to-read-signal-messages-without-cracking-the-encryption/

Signal only allows linked devices through a QR code. However, it's still possible to scan a QR code sent by an attacker without them having physical access to your device.

The document states that the German customs agency has been testing messenger surveillance since the end of 2023, and it has led to success in criminal investigations. They're light on details as to exactly what strategies German customs officials use, but there are plenty of ways to maliciously link a device to an account.

This type of surveillance became an official, permanent strategy available to all agents since August 2025.

The messengers affected include WhatsApp, Telegram, Threema, and Signal.

1.2k Upvotes

80 comments sorted by

•

u/AutoModerator 2d ago

Hello u/Fox3High369, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)


Check out the r/privacy FAQ

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

243

u/Worried_Dinner_4082 2d ago

Okay, so what’s the solution to prevent this?

192

u/KebabCat7 2d ago

Check linked devices regularly.

127

u/Hungry-Broccoli-7193 2d ago

Don’t add devices you don’t know as linked devices.

104

u/Polyxeno 2d ago

If Signal cares, they could provide a setting to not allow linked devices.

56

u/datahoarderprime 2d ago

This is the obvious solution. Surprised that's not already a thing.

33

u/whatnowwproductions 2d ago

They do care, they already require authentication to link.

24

u/Dr_Jecky1l 2d ago

I think what they mean is, maybe the default setting should be not to allow linking of separate devices. That way, only those who know what they are doing can go out of their way and change settings to allow linked devices, if they require it

5

u/whatnowwproductions 2d ago

How would that stop this anymore than what the current system does? If they're getting past authentication because they're requesting the password, nothing is stopping them from going into settings and re-enabling.

7

u/Dr_Jecky1l 2d ago

It doesn’t, but it would stop people from doing it automatically, thinking it was okay…

Idk, perhaps some kind of disclaimer could be used when turning on a setting for linking devices explaining safety concerns

4

u/whatnowwproductions 1d ago

There is already ample warning in the application and it warns you several times already.

1

u/Dr_Jecky1l 1d ago

Meh, idk then… it seems common sense to me not to link any devices together that are for sensitive communication. In fact, I don’t link any devices together - each device has its own use case, persona as per compartmentalization.
Some people, despite being privacy “conscious”, may not understand the intricacies of all the nuances and settings, let alone follow all the new exploits and what not.

3

u/Polyxeno 2d ago

A user setting that can only be changed from the device should prevent any attempt at linking, unless they already have access to the device.

3

u/whatnowwproductions 1d ago

The method explained in the article uses physical access when it relates to Signal.

3

u/ayleidanthropologist 2d ago

Like a toggle, then you just toggle it off and don't ever need to worry how they might get you with a QR

72

u/Rekt3y 2d ago

I guess only link to Linux PCs that have LUKS with manual password entry on boot

19

u/halls_of_valhalla 2d ago

The issue is that people are stupid. And stupid people scan QR codes if someone tells them to scan them. They might think its for a group invitation but its for device linking. The solution is the user not to be stupid. And maybe the app adding warning signs.

13

u/Tactical-Donkey 2d ago

In UK QR codes for parking are replaced by scammers. And people just scan them without thinking. 

2

u/halls_of_valhalla 1d ago

Same happened during pandemic for Corona tests, which sensibilized many I guess - but others will fall for it again.

3

u/tanksalotfrank 2d ago

Critical thinking?? That's asking a lot /s

10

u/timmyc123 2d ago

Using passkeys (which requires physical proximity for cross device flows) would be one way to harden the linking process.

18

u/Fancy_Morning9486 2d ago

Password protected chats ontop of encryption

8

u/Busy-Measurement8893 2d ago

What? Why? Just check if you have any linked devices that you don't recognize.

34

u/AllergicToBullshit24 2d ago

Never rely on one layer always use defense in depth.

2

u/Cynix85 1d ago

Why would you want to prevent this? Use real encryption for serious things and compromised messengers to deceive authorities.

3

u/digno2 2d ago

dont hand over your phone to popo

1

u/tanksalotfrank 2d ago

Keep track of your shit and treat linked devices as temporary logins. Same as normal: log out of stuff regularly 

1

u/Evonos 2d ago

If you want to link any device ask for your password / recovery code ? Something like this maybe

1

u/Impossible_Sugar3266 2d ago

Why is that even news. Linked devices are always listed and visible in settings.

1

u/tanksalotfrank 2d ago

Hell, everyone can see the number of linked devices everyone has too

108

u/OptimusPrimeLord 2d ago

Maybe its too early in the morning and I'm not understanding this, but isn't this just phishing someones 2FA in order to log in on the attacker's device?

48

u/[deleted] 2d ago

[removed] — view removed comment

18

u/slipperyMonkey07 2d ago

I view it two fold, it is good to make people aware of tactics that can be used by scammers and government agencies alike. More informed people are of them the better.

But it also works as propaganda to get people to give up on privacy attempts. It can be overwhelming for even more tech informed people to keep up with everything, but they still try usually. But regular people want simple and straight forward they get a hurdle and will stop trying. See that x,y,z isn't as safe as they thought and just go back to sticking to the popular thing.

1

u/Necr0mancerr 2d ago

So wouldn't a hardware key prevent it?

4

u/[deleted] 2d ago

[deleted]

1

u/bro_can_u_even_carve 2d ago

That can't be right, I definitely send and receive Signal messages on desktop even when my phone is powered off

1

u/yawkat 2d ago

You're right. I knew WhatsApp had moved to a "proper" multi-device system but didn't know Signal also did so.

72

u/j-doe411 2d ago

In the US, we don’t need tech or workarounds like that. We just put actual morons in office and wait for them to inevitably mess up

22

u/[deleted] 2d ago edited 20h ago

[removed] — view removed comment

5

u/j-doe411 2d ago

Idk did your president use Grok to decide whether to invade a foreign country and kidnap their leader?

https://www.the-independent.com/news/world/americas/us-politics/trump-musk-grok-venezuela-maduro-b3060366.html

15

u/KishCom 2d ago

End to end encryption is only a safeguard when each end isn't compromised.

16

u/Extra-Ad5735 2d ago

The biggest weakness of Signal (and other messengers) is the dependency on a phone number - an inherently unsafe identifier. Until they will start allowing creating accounts from email the targeted attacks will continue.

35

u/[deleted] 2d ago

[removed] — view removed comment

17

u/LurkerByNatureGT 2d ago

The examples given are phishing and physical access to the unlocked phone. 

1

u/[deleted] 2d ago

[removed] — view removed comment

3

u/[deleted] 2d ago

[removed] — view removed comment

7

u/Some_Helicopter 2d ago

the guy is needlessly throwing around a buzzword and you have nothing to worry about, see my comment above if you need more details

2

u/[deleted] 2d ago edited 20h ago

[removed] — view removed comment

5

u/Quirky-Degree-6290 2d ago

Or any government like entity. See: Mexican cartels who’ve purchased Pegasus

8

u/Some_Helicopter 2d ago

looks like you heard of Pegasus once in an article and now you throw it out like a buzzword.
As LurkerByNatureGT said, the examples given were phishing and physical access.
Moreover, Pegasus as far as known publicly mostly relies on zeroclick and zeroday exploits, both not mentioned in the post as lurkerbynaturegt said

Pegasus is a software "suite" not a virus or attack vector

Pegasus is owned by a company not based anywhere near germany

Also, do you genuinely believe that an airport in Germany is attacking every single device of every person entering the country, when the cost of deploying Pegasus for ONE campaign (usually against 1 person) is $650,000 to $41 million USD!!

Please stop fearmongering

  • Cybersecurity Professional

1

u/unperson_1984 2d ago edited 2d ago

Police and intelligence agencies are allowed to use state Trojans to eavesdrop on messengers like WhatsApp. Maybe not "Pegasus" specifically, but if they have 0 click or 1 click exploits or if they have physical access to the device they can install Spyware or add linked accounts. The article also says both Police and Customs intercept unencrypted SMS messages to bypass 2FA, as well as secretly requesting email data from webhosts.

The original article has an emphasis on the need for transparency from these organizations. They do not reply to public inquiries about message monitoring because of "national security".

16

u/D3-Doom 2d ago

I’d be more surprised if it unfolded they’ve only recently discovered this

19

u/Aggressive-Hawk9186 2d ago

" WhatsApp's implementation is a bit better. It requires you to initiate the device linking from within the app, an attacker can't just send you a code unprompted. Still, it's highly possible to phish by coaching someone to go into the settings and type in the device linking code."

This is weird to me. They compel ppl to accept new devices requests? 

39

u/erik_7581 2d ago

No, they get acess to the device by lying.

Here a german article that is more detailed: https://netzpolitik.org/2026/messenger-ueberwachung-immer-mehr-polizei-ueberwacht-messenger-wie-whatsapp/

A married couple goes to the police. They are asked to testify as witnesses regarding their daughter. The officers want to read the WhatsApp messages exchanged with their daughter. They ask the parents for their cell phones. The parents agree, voluntarily.

But the police officers do much more than they say. They gain permanent access to the WhatsApp accounts. They set up WhatsApp Web on a police computer. They scan the verification QR code in the parents’ WhatsApp apps. From that point on, they can

19

u/MortgageMindless7175 2d ago

Moral of the story- don't give police or government access to your private property. Always ask for a lawyer. Or better yet come already weaponized with a lawyer 😉

0

u/Lieentz188 2d ago

Don't listen to this fraud, the last time I was at the police station I whipped out my pistol called "Lawyer" and they arrested me. 🤔

/s

5

u/lorkanooo 2d ago

This is usual phishing in this case and applications can't do much against that. Its the same as if they asked for password and you said "sure here you go" 

8

u/AllergicToBullshit24 2d ago

With the number of sidechannel attacks against multi-device setups don't know why anyone would link second devices and why in the world does anyone use SIMs tied to identity?

6

u/SprucedUpSpices 2d ago

why in the world does anyone use SIMs tied to identity?

In many places the government forces you to.

3

u/volutopia 2d ago

But signal doesn't allow people to even have an account without a number. I didn't get it.

8

u/[deleted] 2d ago edited 20h ago

[removed] — view removed comment

3

u/volutopia 2d ago

Good news :)

3

u/Present-Rhubarb6337 2d ago

Select to pay the $2.99 fee using Apple Pay or Google Pay.

not so good news

5

u/Dr_Jecky1l 2d ago

The solution is - don’t use QR codes to link devices.

In fact, don’t link devices period, especially if what you’re saying you’d consider sensitive, which is probably the case if you’re using signal in the first place.

4

u/VelvetViolet99 2d ago

I don't understand this. I frequently chat on signal about things I could be persecuted for in my country. Can u explain to me like I am 5?

2

u/ApprehensiveLion67 1d ago

I called this previously and I was downvoted lol

1

u/cookiesnooper 2d ago

Really? All it takes in Signal to link a device is to scan a QR code? No confirmation? No information about device being linked?

2

u/Busy-Measurement8893 1d ago

I'm like eighty percent certain that it asks you to confirm it. And name the new device.

The "issue' here is that the police link their computer with your phone when they have your phone in hand, without telling you.

1

u/Dr_Jecky1l 2d ago

Perhaps the default setting for all these apps including signal, should be to not allow devices to be linked.

That way, only a user who knows what they are doing, can go into settings and change it if they know what they’re doing, and require it for whatever reasons.

If you have sensitive communication, you’d ideally not want copies of the conversation on multiple devices, so having to change default settings would make sense.

1

u/Chobielin4ever 1d ago

Gestapo methods.

1

u/Buckcity42 2d ago

Get SimpleX Messenger - no phone numbers or unique identifiers. Still a work in progress but more secure & anonymous than anything else on the market with broad cross platform comparability.

1

u/Busy-Measurement8893 1d ago

How is this any better than Signal in the way mentioned in the article?

1

u/Buckcity42 1d ago

For the attack in the article, the difference is device linking. Signal lets a linked device receive messages independently, so someone tricked into linking an attacker’s device can give them ongoing access.

SimpleX’s desktop app instead accesses your phone’s profile through a direct connection, normally requiring both devices on the same local network. That makes the remote linking trick harder as you’re not authorizing a separate device to keep receiving messages from anywhere.

1

u/Imperator_Buggy 1d ago

“The messengers affected include WhatsApp, Telegram, Threema, and Signal.”

Session seems more and more appealing.

4

u/Busy-Measurement8893 1d ago

Session also has multi device support so they are also "affected"

1

u/Imperator_Buggy 1d ago

Well. Then I need to get myself a pigeon.

1

u/WhytSquid 13h ago

The birds are in on that shit, I swear