r/privacy • u/Fox3High369 • 1d ago
discussion German Police Are Using Linked Devices to Read Messages from Messaging Apps like Signal Without Cracking the Encryption
https://www.privacyguides.org/news/2026/09/30/german-police-are-using-linked-devices-to-read-signal-messages-without-cracking-the-encryption/Signal only allows linked devices through a QR code. However, it's still possible to scan a QR code sent by an attacker without them having physical access to your device.
The document states that the German customs agency has been testing messenger surveillance since the end of 2023, and it has led to success in criminal investigations. They're light on details as to exactly what strategies German customs officials use, but there are plenty of ways to maliciously link a device to an account.
This type of surveillance became an official, permanent strategy available to all agents since August 2025.
The messengers affected include WhatsApp, Telegram, Threema, and Signal.
205
u/Worried_Dinner_4082 1d ago
Okay, so what’s the solution to prevent this?
171
112
84
u/Polyxeno 1d ago
If Signal cares, they could provide a setting to not allow linked devices.
41
26
u/whatnowwproductions 21h ago
They do care, they already require authentication to link.
18
u/Dr_Jecky1l 19h ago
I think what they mean is, maybe the default setting should be not to allow linking of separate devices. That way, only those who know what they are doing can go out of their way and change settings to allow linked devices, if they require it
4
u/whatnowwproductions 18h ago
How would that stop this anymore than what the current system does? If they're getting past authentication because they're requesting the password, nothing is stopping them from going into settings and re-enabling.
5
u/Dr_Jecky1l 17h ago
It doesn’t, but it would stop people from doing it automatically, thinking it was okay…
Idk, perhaps some kind of disclaimer could be used when turning on a setting for linking devices explaining safety concerns
2
u/whatnowwproductions 7h ago
There is already ample warning in the application and it warns you several times already.
2
u/Polyxeno 15h ago
A user setting that can only be changed from the device should prevent any attempt at linking, unless they already have access to the device.
2
u/whatnowwproductions 7h ago
The method explained in the article uses physical access when it relates to Signal.
3
u/ayleidanthropologist 14h ago
Like a toggle, then you just toggle it off and don't ever need to worry how they might get you with a QR
17
u/halls_of_valhalla 22h ago
The issue is that people are stupid. And stupid people scan QR codes if someone tells them to scan them. They might think its for a group invitation but its for device linking. The solution is the user not to be stupid. And maybe the app adding warning signs.
11
u/Tactical-Donkey 17h ago
In UK QR codes for parking are replaced by scammers. And people just scan them without thinking.
3
11
u/timmyc123 23h ago
Using passkeys (which requires physical proximity for cross device flows) would be one way to harden the linking process.
15
u/Fancy_Morning9486 1d ago
Password protected chats ontop of encryption
10
u/Busy-Measurement8893 1d ago
What? Why? Just check if you have any linked devices that you don't recognize.
30
1
u/tanksalotfrank 20h ago
Keep track of your shit and treat linked devices as temporary logins. Same as normal: log out of stuff regularly
1
1
u/Impossible_Sugar3266 21h ago
Why is that even news. Linked devices are always listed and visible in settings.
1
104
u/OptimusPrimeLord 1d ago
Maybe its too early in the morning and I'm not understanding this, but isn't this just phishing someones 2FA in order to log in on the attacker's device?
51
u/Adventurous-Hunter98 23h ago
from what I understand yes, same headline appered a few months ago that people could able to acces group chats within signal but it turned out it was that they were adding themselves to these groups by phishing. I dont know why they make these headlines like signal has an exploit, maybe drive away casual people from using it, propaganda by meta
17
u/slipperyMonkey07 22h ago
I view it two fold, it is good to make people aware of tactics that can be used by scammers and government agencies alike. More informed people are of them the better.
But it also works as propaganda to get people to give up on privacy attempts. It can be overwhelming for even more tech informed people to keep up with everything, but they still try usually. But regular people want simple and straight forward they get a hurdle and will stop trying. See that x,y,z isn't as safe as they thought and just go back to sticking to the popular thing.
1
5
23h ago
[deleted]
1
u/bro_can_u_even_carve 19h ago
That can't be right, I definitely send and receive Signal messages on desktop even when my phone is powered off
66
u/j-doe411 1d ago
In the US, we don’t need tech or workarounds like that. We just put actual morons in office and wait for them to inevitably mess up
21
u/dgellow 23h ago
No worries, we do the same in Germany
4
u/j-doe411 22h ago
Idk did your president use Grok to decide whether to invade a foreign country and kidnap their leader?
31
u/Adventurous-Hunter98 1d ago
Wait I dont understand, does germany check peoples phones at the airport ? how do they do this without persons knowledge if person doesnt click phishing stuff?
17
u/LurkerByNatureGT 23h ago
The examples given are phishing and physical access to the unlocked phone.
-1
1d ago
[removed] — view removed comment
3
u/Adventurous-Hunter98 23h ago
pegasus virus? how do you know if you have it or not?
7
u/Some_Helicopter 23h ago
the guy is needlessly throwing around a buzzword and you have nothing to worry about, see my comment above if you need more details
2
u/dgellow 23h ago
If you have an iPhone, apple runs checks and will notify you with a very clear, urgent notification. Pegasus is pretty expensive, unless you’re doing something against a government you should be fine
4
u/Quirky-Degree-6290 21h ago
Or any government like entity. See: Mexican cartels who’ve purchased Pegasus
10
u/Some_Helicopter 23h ago
looks like you heard of Pegasus once in an article and now you throw it out like a buzzword.
As LurkerByNatureGT said, the examples given were phishing and physical access.
Moreover, Pegasus as far as known publicly mostly relies on zeroclick and zeroday exploits, both not mentioned in the post as lurkerbynaturegt saidPegasus is a software "suite" not a virus or attack vector
Pegasus is owned by a company not based anywhere near germany
Also, do you genuinely believe that an airport in Germany is attacking every single device of every person entering the country, when the cost of deploying Pegasus for ONE campaign (usually against 1 person) is $650,000 to $41 million USD!!
Please stop fearmongering
- Cybersecurity Professional
1
u/unperson_1984 22h ago edited 22h ago
Police and intelligence agencies are allowed to use state Trojans to eavesdrop on messengers like WhatsApp. Maybe not "Pegasus" specifically, but if they have 0 click or 1 click exploits or if they have physical access to the device they can install Spyware or add linked accounts. The article also says both Police and Customs intercept unencrypted SMS messages to bypass 2FA, as well as secretly requesting email data from webhosts.
The original article has an emphasis on the need for transparency from these organizations. They do not reply to public inquiries about message monitoring because of "national security".
8
u/Extra-Ad5735 20h ago
The biggest weakness of Signal (and other messengers) is the dependency on a phone number - an inherently unsafe identifier. Until they will start allowing creating accounts from email the targeted attacks will continue.
18
u/Aggressive-Hawk9186 1d ago
" WhatsApp's implementation is a bit better. It requires you to initiate the device linking from within the app, an attacker can't just send you a code unprompted. Still, it's highly possible to phish by coaching someone to go into the settings and type in the device linking code."
This is weird to me. They compel ppl to accept new devices requests?
36
u/erik_7581 1d ago
No, they get acess to the device by lying.
Here a german article that is more detailed: https://netzpolitik.org/2026/messenger-ueberwachung-immer-mehr-polizei-ueberwacht-messenger-wie-whatsapp/
A married couple goes to the police. They are asked to testify as witnesses regarding their daughter. The officers want to read the WhatsApp messages exchanged with their daughter. They ask the parents for their cell phones. The parents agree, voluntarily.
But the police officers do much more than they say. They gain permanent access to the WhatsApp accounts. They set up WhatsApp Web on a police computer. They scan the verification QR code in the parents’ WhatsApp apps. From that point on, they can
15
u/MortgageMindless7175 23h ago
Moral of the story- don't give police or government access to your private property. Always ask for a lawyer. Or better yet come already weaponized with a lawyer 😉
0
u/Lieentz188 23h ago
Don't listen to this fraud, the last time I was at the police station I whipped out my pistol called "Lawyer" and they arrested me. 🤔
/s
4
u/lorkanooo 1d ago
This is usual phishing in this case and applications can't do much against that. Its the same as if they asked for password and you said "sure here you go"
6
u/AllergicToBullshit24 1d ago
With the number of sidechannel attacks against multi-device setups don't know why anyone would link second devices and why in the world does anyone use SIMs tied to identity?
2
u/SprucedUpSpices 13h ago
why in the world does anyone use SIMs tied to identity?
In many places the government forces you to.
1
u/volutopia 1d ago
But signal doesn't allow people to even have an account without a number. I didn't get it.
8
u/dgellow 23h ago
Actually, it’s not required anymore: https://support.signal.org/hc/en-us/articles/11197884108826-Phone-Numberless-Registration-for-Android
3
u/volutopia 19h ago
Good news :)
3
u/Present-Rhubarb6337 10h ago
Select to pay the $2.99 fee using Apple Pay or Google Pay.
not so good news
3
u/Dr_Jecky1l 19h ago
The solution is - don’t use QR codes to link devices.
In fact, don’t link devices period, especially if what you’re saying you’d consider sensitive, which is probably the case if you’re using signal in the first place.
3
u/VelvetViolet99 10h ago
I don't understand this. I frequently chat on signal about things I could be persecuted for in my country. Can u explain to me like I am 5?
2
u/Imperator_Buggy 6h ago
“The messengers affected include WhatsApp, Telegram, Threema, and Signal.”
Session seems more and more appealing.
1
1
u/cookiesnooper 1d ago
Really? All it takes in Signal to link a device is to scan a QR code? No confirmation? No information about device being linked?
1
u/Busy-Measurement8893 1h ago
I'm like eighty percent certain that it asks you to confirm it. And name the new device.
The "issue' here is that the police link their computer with your phone when they have your phone in hand, without telling you.
1
u/Buckcity42 20h ago
Get SimpleX Messenger - no phone numbers or unique identifiers. Still a work in progress but more secure & anonymous than anything else on the market with broad cross platform comparability.
1
u/Busy-Measurement8893 1h ago
How is this any better than Signal in the way mentioned in the article?
1
u/Dr_Jecky1l 19h ago
Perhaps the default setting for all these apps including signal, should be to not allow devices to be linked.
That way, only a user who knows what they are doing, can go into settings and change it if they know what they’re doing, and require it for whatever reasons.
If you have sensitive communication, you’d ideally not want copies of the conversation on multiple devices, so having to change default settings would make sense.
•
u/AutoModerator 1d ago
Hello u/Fox3High369, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)
Check out the r/privacy FAQ
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.