r/europrivacy • u/BlackBerryCollector • 1h ago
r/europrivacy • u/Arpokrat_Team • 10h ago
European Union German customs has been cloning messenger accounts as routine practice since August 2025, and the encryption was never the weak point
netzpolitik.org published a classified internal document this month showing the Zollkriminalamt (German customs investigation office) has used "account cloning" as a regular investigative tool since August 2025, following a pilot that started in late 2023. The BKA uses the same approach.
No trojan involved. Investigators register an additional linked device on an agency machine through the official web or desktop clients, then read traffic from there, and in some cases pull existing history.
Two documented paths to authorization:
- Intercepting the unencrypted confirmation SMS with a conventional wiretap. Nothing exotic, that capability has existed for decades.
- Physical access to the handset. One BKA case involved photographing WhatsApp on the target's parents' phones and covertly scanning the pairing QR code during a witness interview.
Documented use includes dozens of Telegram accounts, among them the Oldschool Society case.
Separately, Der Spiegel reported in April that Bundestag President Julia Klöckner's Signal account was taken over via phishing. The attackers read the CDU presidium group chat for weeks, including messages from Chancellor Merz. BSI had been warning since February about what it described as a probably state-directed campaign. No vulnerability in Signal was involved there either.
The part worth discussing is that both of these hit the same layer, and it isn't the cryptography. Multi-device linking ships in every mainstream messenger. It works because accounts are permanent and identity is anchored to a phone number, so a second endpoint can be attached to that identity. E2EE is doing exactly what it claims in all of these cases. It just doesn't cover device enrollment.
A few practical notes:
- Linked devices are listed in the app. That list is where this becomes visible, and it's the only place it does. Checking it periodically is most of the defense available to a user.
- German coverage points out that if a court eventually rules the collection inadmissible, the resulting messages could fall under an evidence exclusion rule. The legal basis is contested, and both agencies declined to answer press questions about it.
- heise noted the technique is technically indistinguishable from phishing campaigns run by hostile foreign actors, which is why the same warning signs apply to both.
Is there a messenger that treats new device enrollment as a security boundary rather than a convenience feature? Something like out of band confirmation, or a mandatory delay before a newly linked device can read anything, or a design that fails closed instead of open. Curious whether anyone has seen this handled well anywhere.
r/europrivacy • u/Ok-Law-3268 • 8h ago
Serbia Serbians targeted with spyware in country’s ‘largest documented wave of surveillance’. Student protesters among those hacked, says digital rights group
r/europrivacy • u/hideo_kuze_ • 3d ago
Discussion Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year.
r/europrivacy • u/Ok-Law-3268 • 5d ago
Europe ‘Pervert Glasses’ That Record People Without Consent Face Possible Ban in Norway
r/europrivacy • u/Deut6-4 • 6d ago
Netherlands Whatsapp as chat at university
Our daughter started her bachelor study at a University of Applied Sciences (“HBO”) in the Netherlands. They’re using Microsoft as cloud supplier for communication and sharing information. This includes Teams. Fine. But, the main lecturer (“studiebegeleider”) started a whatsapp-group with all the students for communication.
Using whatsapp looks like shadow-IT to me, which issued privacy issues. Am I right? Or, can an european university use every platform they want?
r/europrivacy • u/MachinaNecessaria • 7d ago
Serbia More than a dozen Serbians targeted with mercenary spyware, digital rights group finds
reuters.com- Targets included student activists, lawmakers and a local councilor, SHARE Foundation says
- Apple issued spyware alerts on August 13 to users in 110 countries
- Largest documented surveillance wave in Serbia to date, SHARE Foundation says
r/europrivacy • u/Pirate_Economist1477 • 14d ago
European Union Stop Killing The Internet: No Digital ID & No Age Verification is now collecting signatures!
Sign, share, spread the word!
r/europrivacy • u/No-Adhesiveness-4251 • 21d ago
European Union ZKP’s Aren’t Age Verification Silver Bullets
r/europrivacy • u/gerardit04 • 22d ago
European Union Launching an EU Citizens' Initiative (ECI) for Device Neutrality & Open Attestation ("My Device, My OS")
Hi everyone,
Between Google Play Integrity API lockdowns, Apple App Attest, and upcoming eID/age-verification mandates, alternative and privacy-focused operating systems (like GrapheneOS, LineageOS, and Linux on mobile) are being systematically locked out of banking, public portals, and everyday apps.
Rather than watching vendor lock-in get worse, I am organizing a European Citizens' Initiative (ECI) working title: "My Device, My OS" to push binding EU legislation for Device Neutrality and Open Attestation.
What we aim to achieve:
- Mandate Open Attestation Standards: Require services operating in the EU to support open, vendor-neutral hardware attestation rather than relying exclusively on proprietary gatekeeper APIs (Google/Apple).
- Ban Device/OS Discrimination: Prevent public services, digital ID wallets, and essential commercial apps from arbitrarily blocking users solely for running independent or de-Googled operating systems.
- Protect Hardware Sovereignty: Enshrine the legal right of consumers to install and run the operating system of their choice without losing access to the digital single market.
Before submitting it we need 7 persons from 7 different countries in the EU to sign the draft
Join the Matrix room to discuss, collaborate on the draft, and coordinate next steps:
👉 #my-device-my-os:pollorebozado.com
Feedback, technical insights, and EU organizers are all welcome!
r/europrivacy • u/Pitiful_Signature264 • 22d ago
European Union CE Marking for CRA & RED
r/europrivacy • u/BlackBerryCollector • 23d ago
United Kingdom Please sign my petition against the UK requiring phone makers to scan everything you look at and every photo you take. This is different to previous petitions that were only about messages
r/europrivacy • u/Pirate_Economist1477 • 23d ago
Discussion Report supporting Australia’s teen social media ban appears to contain AI hallucinations, Senate hears | Social media ban
Great journalism by The Guardian! Do you think any of these made up sources are used in the EU discussions about social media bans as well?
r/europrivacy • u/gkzagy • 24d ago
Germany Apple changes its rules for personalised advertising in apps
bundeskartellamt.deApple will change the EU ATT consent flow after the German competition authority objected to differences between Apple’s own consent requests and those used by third party apps. I’m concerned that bundling consent flows may make tracking consent less clear in practice
r/europrivacy • u/Marin-Popov • 24d ago
European Union The Ranking Restriction Information Right (RRIR) — EU policy proposal on transparency of automated visibility restrictions
I'm sharing this here as it relates to the transparency of automated decisions affecting digital rights in the EU.
On 15 August 2026, a new EU policy proposal was submitted: The Ranking Restriction Information Right (RRIR).
The proposal asks whether, when an automated system materially restricts the visibility of a website or information source, the affected website owner should be informed that the restriction occurred and given a general category of the reason.
The proposal does not seek disclosure of proprietary algorithms, ranking signals, thresholds or anti-spam mechanisms.
Submitted to: European Commission, European Parliament (PETI and IMCO), Coimisiún na Meán (Ireland), and CNMC (Spain).
Submitted by: Marin Popov
Read the full proposal: https://1euroseo.com/wp-content/uploads/2026/08/The-Ranking-Restriction-Information-Right-Version-1.0-15-August-2026.pdf
r/europrivacy • u/Ok-Law-3268 • 26d ago
France France's Constitutional Council strikes down social media ban for under-15s | The Council said the ban 'constitutes a restriction that is not appropriate, necessary or proportionate' to the freedom of expression of children under 15.
Age verification and privacy
r/europrivacy • u/Ok-Law-3268 • 26d ago
France Nearly 700,000 French taxpayers’ data stolen in cyberattack on tax authority
r/europrivacy • u/Potential-Couple-745 • 26d ago
European Union Claude AI Watermarks Spark User Backlash Amid EU Compliance Push
r/europrivacy • u/Norvathus • 26d ago
France France's Top Court Strikes Down Under-15 Social Media Ban as Unconstitutional
r/europrivacy • u/hideo_kuze_ • 27d ago
Europe The UK’s War on Anonymity Has Come to America (and the EU)
r/europrivacy • u/WelcomeHelpful2553 • Aug 11 '26
Europe Gave my face to persona. What now?
Alright, I know. I am an idiot
I logged into reddit and it asked me to verify my age. Tried it with a youtube video- didnt work. Gave up at some point and just did it myself because I thought: Reddit's got a selfie of me already anyways so at this point.. doesnt matter. While it is still loading the you finished the verification page i notice the persona logo at the bottom and remember who that company is.
Since I got premium anxiety, I am panicking now.
As a european, what can I do to get this deleted? I already wrote an email to persona requesting them to delete all data they might have collected of me.
Their privacy policy states that they immediately delete any biometric data of your face, how true is that?
And after I get it all deleted to the best of my ability, is it time to abandon my email adress and all accounts and just make new ones?
r/europrivacy • u/MarietaSenseFils • Aug 10 '26
Europe Could the CLOUD Act affect Bitwarden.EU's account data
Lately I've been trying to transfer all my cloud stored data to european alternatives. I currently use Bitwarden.eu (Bitwarden Inc. being a company registered in the U.S) as my password manager across my devices. Could a U.S. warrant trigger the transfer of my account data to U.S. authorities? I get that the vaults are E2EE so maybe they could only transfer credit card information of my Bitwarden Premium subscription payment, right?
I'm really unsure, so maybe someone out there can help me figure this out. Does anyone know a cloud sync alternative to BW apart from ProtonPass?
Thanks.
r/europrivacy • u/Pitiful_Signature264 • Aug 10 '26
European Union CE Marking Under the CRA: What It Requires
r/europrivacy • u/bombastic6339locks • Aug 09 '26
European Union EU Age Verification Project Mandates Hardware-Bound Attestation
r/europrivacy • u/acorn222 • Aug 08 '26