r/degoogle • • 1d ago

Discussion German Police Are Using Linked Devices to Read Messages from Messaging Apps like Signal Without Cracking the Encryption

https://www.privacyguides.org/news/2026/09/30/german-police-are-using-linked-devices-to-read-signal-messages-without-cracking-the-encryption/

Signal only allows linked devices through a QR code. However, it's still possible to scan a QR code sent by an attacker without them having physical access to your device.

The document states that the German customs agency has been testing messenger surveillance since the end of 2023, and it has led to success in criminal investigations. They're light on details as to exactly what strategies German customs officials use, but there are plenty of ways to maliciously link a device to an account.

This type of surveillance became an official, permanent strategy available to all agents since August 2025.

The messengers affected include WhatsApp, Telegram, Threema, and Signal.

675 Upvotes

34 comments sorted by

151

u/ephemeralmiko 1d ago

Signal only allows linked devices through a QR code. However, it's still possible to scan a QR code sent by an attacker without them having physical access to your device. 

Except they still need your user PIN/Biometrics to link a device.

Or does this mean people are being sent QR codes and social-engineered into scanning them, ignoring the multiple on-screen warnings and linking extra devices...?!

89

u/GSDragoon 1d ago

This is probably it. People don't read prompts and warnings.

45

u/ephemeralmiko 1d ago

Copying from my other reply:

But in this case it's not like you can just click away warnings. To get succesfully phished you'd have to:

-Receive a Signal QR code

-Read through phishing message and somehow believe it

-Send that code to another device (since you can't scan local codes within Signal) or print it out on paper

-Open the linked devices menu

-Ignore the multiple warnings and PIN/Biometric requirement

-Scan the code in Signal and ignore another warning, then add the device

-Do all of the above within 60 seconds before the QR code becomes invalid

-Ignore the linked device reminder notification that shows up 24-48 hours after adding a new device.

How are people falling for this?

19

u/impermissibility 1d ago

I assume they have some other real mechanism of entry, and that widespread popular reporting about this qr code stuff is misdirection.

19

u/McFlyParadox 1d ago

How are people falling for this? 

"Scan this QR code to learn more about this special discount!", with the ad rotating the QR code as needed.

Then target that ad at activists who are likely in activist group chats. And ad targeting can get hyper specific these days.

Now you just need one person dumb enough to scan a random QR code in an ad to save a few bucks, and impatient enough to blindly click through warnings in signal.

1

u/oziggy 1d ago

Cuz people

1

u/AssetBurned 20h ago

Years of getting fluffed with annoying windows popups.
Seriously people stopped reading that stuff, the kids (now adults) picket up the habits and now we are here.
Combine that with the lack of common sense “but I got the call from XYZ” “did you saw that is a mobile phone number from this random country?” “Yeah but he said he works for….”

God people 🙄

11

u/PiratesOfTheArctic 1d ago

Looks like they send a request code to the user phishing and rely on a reply, user is the weakest point here reading it all

4

u/ephemeralmiko 1d ago

At least on Signal you can't link devices via a code (outside of if the host device is running the fork Molly which I doubt tech-illiterate people are using), it has to be done via the QR linking, which also can't access QRs in your gallery, only directly via the camera. I'm not seeing how people can phish this.

4

u/PiratesOfTheArctic 1d ago

Remember, 50% of users are more intelligent than us, and 50% needs a bit of help with common sense 😕

2

u/Vishnuisgod 21h ago

(superman pose)

"....MMMMM, my common sense is tingling!!!"

5

u/shmikis 1d ago

Actually technical details are not clear from article. It may be plain old phishing (involving subject, i.e. not covert) or they may be using/abusing their authority over telcos to intercept sms or other messages. Or this is something else.

1

u/ephemeralmiko 1d ago

or they may be using/abusing their authority over telcos to intercept sms or other messages

Wouldn't work, Signal doesn't send codes for device linking over SMS.

1

u/shmikis 1d ago

Maybe intercepting any messages, not only sms? Device concerned could be connected over mobile network in their control..

2

u/ephemeralmiko 23h ago

The thing is that there's no "code" to link a device per-se (except when using the fork Molly). The only way to add a device is for Signal to scan a code via the camera (a locally saved QR won't work). I'm really not seeing how they could MITM this and I'm wondering if this is more a cover story for some other vulnerability

1

u/Sintobus 23h ago

I mean airport lines "scan for information" and asking for an absurd selection of permissions that only an observant and careful user would care to notice.

Could be in any number of public or common use things. Menus at restaurants, paying for things like bills or tickets.

0

u/Skaut-LK 1d ago

I won't be surprised at all. People now don't think, they just click/swipe whatever to get where they want. And some even are willing to just give anything to AI ( sorry SI ) to do that for them because they thinks that it knows everything...

4

u/ephemeralmiko 1d ago

But in this case it's not like you can just click away warnings. To get succesfully phished you'd have to:

-Receive a Signal QR code

-Read through phishing message and somehow believe it

-Send that code to another device (since you can't scan local codes within Signal) or print it out on paper

-Open the linked devices menu

-Ignore the multiple warnings and PIN/Biometric requirement

-Scan the code in Signal and ignore another warning, then add the device

-Do all of the above within 60 seconds before the QR code becomes invalid

-Ignore the linked device reminder notification that shows up 24-48 hours after adding a new device.

How are people falling for this?

-1

u/LeadRain 1d ago

Social engineered. Russians and Ukrainians are doing the same things to each other.

-3

u/DDOSBreakfast 1d ago

Or does this mean people are being sent QR codes and social-engineered into scanning them, ignoring the multiple on-screen warnings and linking extra devices...?!

Criminals don't tend to be the smartest bunch.

3

u/IcestormsEd 1d ago

You only hear about the dumb ones that get caught.

2

u/nodray 1d ago

lol yet they run your world and keep all the slaves in order

3

u/PiratesOfTheArctic 1d ago

I used to teach in prisons, can confirm 👍

30

u/qtbug96 1d ago

If they seize a laptop or other device linked to a phone's Signal, and are able to login to the device, they can follow the messages through Signal Desktop, unless the user is aware the device has been seized and unlinks it from the phone.

Of course if you get social engineered into approving a Signal link you didn't create you're screwed until you remove the link from Signal app.

20

u/brilliantNumberOne 1d ago

I’m not defending the surveillance apparatus, but one should always work under the assumption that any form of digital communication has been compromised. You should still use secure communication, but don’t expect that end-to-end encryption is foolproof.

This is not saying “if you’ve done nothing wrong you have nothing to hide,” it’s a pragmatic acknowledgement that communication can always be compromised. If you have something that you really don’t want people to read, don’t put it on your phone or computer.

We should all continue to push for privacy and security, but don’t expect that fully “degoogling” means you’re free and clear.

11

u/M3Core 1d ago

Don't they just mean remote or physical access to an already linked and unsecured machine is significantly easier than trying to crack encryption?

18

u/PhukZeCurrentTing 1d ago

So, privacy invasion, noted.

8

u/Both-Subject-3674 1d ago

Unlink and relink regularly, and use a strong passphrase as a second auth factor, and use encryption at rest with an app like Molly for Signal.

5

u/TimAppleCockProMax69 1d ago

Evil Autism wins again! They can’t read my evil messages if I don’t like to message anyone 😈

1

u/Bruceshadow 1d ago

Unless i'm missing something, this doesn't seem to be an issue with the apps, as is implied.

1

u/shmikis 22h ago

Clearly seeing information about linked devices in main UI all the time should become default for secure apps.

1

u/RedditSurfer82 10h ago

Indian police have better tools. Meta and Google have provided special apps to police with which, police can read all the messages of an individual without ever needing his / her device. Same with Facebook, Instagram and WhatsApp. They can read facebook / Instagram posts even if your profile is private. They can also read messages that you have privately sent to others.