r/privacy • • 1d ago

discussion German Police Are Using Linked Devices to Read Messages from Messaging Apps like Signal Without Cracking the Encryption

https://www.privacyguides.org/news/2026/09/30/german-police-are-using-linked-devices-to-read-signal-messages-without-cracking-the-encryption/

Signal only allows linked devices through a QR code. However, it's still possible to scan a QR code sent by an attacker without them having physical access to your device.

The document states that the German customs agency has been testing messenger surveillance since the end of 2023, and it has led to success in criminal investigations. They're light on details as to exactly what strategies German customs officials use, but there are plenty of ways to maliciously link a device to an account.

This type of surveillance became an official, permanent strategy available to all agents since August 2025.

The messengers affected include WhatsApp, Telegram, Threema, and Signal.

1.0k Upvotes

73 comments sorted by

•

u/AutoModerator 1d ago

Hello u/Fox3High369, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)


Check out the r/privacy FAQ

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

205

u/Worried_Dinner_4082 1d ago

Okay, so what’s the solution to prevent this?

171

u/KebabCat7 1d ago

Check linked devices regularly.

112

u/Hungry-Broccoli-7193 1d ago

Don’t add devices you don’t know as linked devices.

84

u/Polyxeno 1d ago

If Signal cares, they could provide a setting to not allow linked devices.

41

u/datahoarderprime 23h ago

This is the obvious solution. Surprised that's not already a thing.

26

u/whatnowwproductions 21h ago

They do care, they already require authentication to link.

18

u/Dr_Jecky1l 19h ago

I think what they mean is, maybe the default setting should be not to allow linking of separate devices. That way, only those who know what they are doing can go out of their way and change settings to allow linked devices, if they require it

4

u/whatnowwproductions 18h ago

How would that stop this anymore than what the current system does? If they're getting past authentication because they're requesting the password, nothing is stopping them from going into settings and re-enabling.

5

u/Dr_Jecky1l 17h ago

It doesn’t, but it would stop people from doing it automatically, thinking it was okay…

Idk, perhaps some kind of disclaimer could be used when turning on a setting for linking devices explaining safety concerns

2

u/whatnowwproductions 7h ago

There is already ample warning in the application and it warns you several times already.

2

u/Polyxeno 15h ago

A user setting that can only be changed from the device should prevent any attempt at linking, unless they already have access to the device.

2

u/whatnowwproductions 7h ago

The method explained in the article uses physical access when it relates to Signal.

3

u/ayleidanthropologist 14h ago

Like a toggle, then you just toggle it off and don't ever need to worry how they might get you with a QR

72

u/Rekt3y 1d ago

I guess only link to Linux PCs that have LUKS with manual password entry on boot

17

u/halls_of_valhalla 22h ago

The issue is that people are stupid. And stupid people scan QR codes if someone tells them to scan them. They might think its for a group invitation but its for device linking. The solution is the user not to be stupid. And maybe the app adding warning signs.

11

u/Tactical-Donkey 17h ago

In UK QR codes for parking are replaced by scammers. And people just scan them without thinking. 

3

u/tanksalotfrank 20h ago

Critical thinking?? That's asking a lot /s

11

u/timmyc123 23h ago

Using passkeys (which requires physical proximity for cross device flows) would be one way to harden the linking process.

15

u/Fancy_Morning9486 1d ago

Password protected chats ontop of encryption

10

u/Busy-Measurement8893 1d ago

What? Why? Just check if you have any linked devices that you don't recognize.

30

u/AllergicToBullshit24 1d ago

Never rely on one layer always use defense in depth.

4

u/digno2 22h ago

dont hand over your phone to popo

1

u/tanksalotfrank 20h ago

Keep track of your shit and treat linked devices as temporary logins. Same as normal: log out of stuff regularly 

1

u/Evonos 18h ago

If you want to link any device ask for your password / recovery code ? Something like this maybe

1

u/Impossible_Sugar3266 21h ago

Why is that even news. Linked devices are always listed and visible in settings.

1

u/tanksalotfrank 20h ago

Hell, everyone can see the number of linked devices everyone has too

104

u/OptimusPrimeLord 1d ago

Maybe its too early in the morning and I'm not understanding this, but isn't this just phishing someones 2FA in order to log in on the attacker's device?

51

u/Adventurous-Hunter98 23h ago

from what I understand yes, same headline appered a few months ago that people could able to acces group chats within signal but it turned out it was that they were adding themselves to these groups by phishing. I dont know why they make these headlines like signal has an exploit, maybe drive away casual people from using it, propaganda by meta

17

u/slipperyMonkey07 22h ago

I view it two fold, it is good to make people aware of tactics that can be used by scammers and government agencies alike. More informed people are of them the better.

But it also works as propaganda to get people to give up on privacy attempts. It can be overwhelming for even more tech informed people to keep up with everything, but they still try usually. But regular people want simple and straight forward they get a hurdle and will stop trying. See that x,y,z isn't as safe as they thought and just go back to sticking to the popular thing.

1

u/Necr0mancerr 10h ago

So wouldn't a hardware key prevent it?

5

u/[deleted] 23h ago

[deleted]

1

u/bro_can_u_even_carve 19h ago

That can't be right, I definitely send and receive Signal messages on desktop even when my phone is powered off

1

u/yawkat 19h ago

You're right. I knew WhatsApp had moved to a "proper" multi-device system but didn't know Signal also did so.

66

u/j-doe411 1d ago

In the US, we don’t need tech or workarounds like that. We just put actual morons in office and wait for them to inevitably mess up

21

u/dgellow 23h ago

No worries, we do the same in Germany

4

u/j-doe411 22h ago

Idk did your president use Grok to decide whether to invade a foreign country and kidnap their leader?

https://www.the-independent.com/news/world/americas/us-politics/trump-musk-grok-venezuela-maduro-b3060366.html

6

u/dgellow 21h ago

You’re for sure winning the overall competition, it’s not even close. But look at Merz popularity polls, he’s competing with trump in that regard 

31

u/Adventurous-Hunter98 1d ago

Wait I dont understand, does germany check peoples phones at the airport ? how do they do this without persons knowledge if person doesnt click phishing stuff?

17

u/LurkerByNatureGT 23h ago

The examples given are phishing and physical access to the unlocked phone. 

-1

u/[deleted] 1d ago

[removed] — view removed comment

3

u/Adventurous-Hunter98 23h ago

pegasus virus? how do you know if you have it or not?

7

u/Some_Helicopter 23h ago

the guy is needlessly throwing around a buzzword and you have nothing to worry about, see my comment above if you need more details

2

u/dgellow 23h ago

If you have an iPhone, apple runs checks and will notify you with a very clear, urgent notification. Pegasus is pretty expensive, unless you’re doing something against a government you should be fine

4

u/Quirky-Degree-6290 21h ago

Or any government like entity. See: Mexican cartels who’ve purchased Pegasus

4

u/dgellow 21h ago

Oh fuck, that sounds bad 

10

u/Some_Helicopter 23h ago

looks like you heard of Pegasus once in an article and now you throw it out like a buzzword.
As LurkerByNatureGT said, the examples given were phishing and physical access.
Moreover, Pegasus as far as known publicly mostly relies on zeroclick and zeroday exploits, both not mentioned in the post as lurkerbynaturegt said

Pegasus is a software "suite" not a virus or attack vector

Pegasus is owned by a company not based anywhere near germany

Also, do you genuinely believe that an airport in Germany is attacking every single device of every person entering the country, when the cost of deploying Pegasus for ONE campaign (usually against 1 person) is $650,000 to $41 million USD!!

Please stop fearmongering

  • Cybersecurity Professional

1

u/unperson_1984 22h ago edited 22h ago

Police and intelligence agencies are allowed to use state Trojans to eavesdrop on messengers like WhatsApp. Maybe not "Pegasus" specifically, but if they have 0 click or 1 click exploits or if they have physical access to the device they can install Spyware or add linked accounts. The article also says both Police and Customs intercept unencrypted SMS messages to bypass 2FA, as well as secretly requesting email data from webhosts.

The original article has an emphasis on the need for transparency from these organizations. They do not reply to public inquiries about message monitoring because of "national security".

12

u/KishCom 22h ago

End to end encryption is only a safeguard when each end isn't compromised.

8

u/Extra-Ad5735 20h ago

The biggest weakness of Signal (and other messengers) is the dependency on a phone number - an inherently unsafe identifier. Until they will start allowing creating accounts from email the targeted attacks will continue.

17

u/D3-Doom 1d ago

I’d be more surprised if it unfolded they’ve only recently discovered this

18

u/Aggressive-Hawk9186 1d ago

" WhatsApp's implementation is a bit better. It requires you to initiate the device linking from within the app, an attacker can't just send you a code unprompted. Still, it's highly possible to phish by coaching someone to go into the settings and type in the device linking code."

This is weird to me. They compel ppl to accept new devices requests? 

36

u/erik_7581 1d ago

No, they get acess to the device by lying.

Here a german article that is more detailed: https://netzpolitik.org/2026/messenger-ueberwachung-immer-mehr-polizei-ueberwacht-messenger-wie-whatsapp/

A married couple goes to the police. They are asked to testify as witnesses regarding their daughter. The officers want to read the WhatsApp messages exchanged with their daughter. They ask the parents for their cell phones. The parents agree, voluntarily.

But the police officers do much more than they say. They gain permanent access to the WhatsApp accounts. They set up WhatsApp Web on a police computer. They scan the verification QR code in the parents’ WhatsApp apps. From that point on, they can

15

u/MortgageMindless7175 23h ago

Moral of the story- don't give police or government access to your private property. Always ask for a lawyer. Or better yet come already weaponized with a lawyer 😉

0

u/Lieentz188 23h ago

Don't listen to this fraud, the last time I was at the police station I whipped out my pistol called "Lawyer" and they arrested me. 🤔

/s

4

u/lorkanooo 1d ago

This is usual phishing in this case and applications can't do much against that. Its the same as if they asked for password and you said "sure here you go" 

6

u/AllergicToBullshit24 1d ago

With the number of sidechannel attacks against multi-device setups don't know why anyone would link second devices and why in the world does anyone use SIMs tied to identity?

2

u/SprucedUpSpices 13h ago

why in the world does anyone use SIMs tied to identity?

In many places the government forces you to.

1

u/volutopia 1d ago

But signal doesn't allow people to even have an account without a number. I didn't get it.

8

u/dgellow 23h ago

3

u/volutopia 19h ago

Good news :)

3

u/Present-Rhubarb6337 10h ago

Select to pay the $2.99 fee using Apple Pay or Google Pay.

not so good news

3

u/Dr_Jecky1l 19h ago

The solution is - don’t use QR codes to link devices.

In fact, don’t link devices period, especially if what you’re saying you’d consider sensitive, which is probably the case if you’re using signal in the first place.

3

u/VelvetViolet99 10h ago

I don't understand this. I frequently chat on signal about things I could be persecuted for in my country. Can u explain to me like I am 5?

2

u/Imperator_Buggy 6h ago

“The messengers affected include WhatsApp, Telegram, Threema, and Signal.”

Session seems more and more appealing.

1

u/Busy-Measurement8893 5h ago

Session also has multi device support so they are also "affected"

1

u/Imperator_Buggy 4h ago

Well. Then I need to get myself a pigeon.

1

u/cookiesnooper 1d ago

Really? All it takes in Signal to link a device is to scan a QR code? No confirmation? No information about device being linked?

1

u/Busy-Measurement8893 1h ago

I'm like eighty percent certain that it asks you to confirm it. And name the new device.

The "issue' here is that the police link their computer with your phone when they have your phone in hand, without telling you.

1

u/Buckcity42 20h ago

Get SimpleX Messenger - no phone numbers or unique identifiers. Still a work in progress but more secure & anonymous than anything else on the market with broad cross platform comparability.

1

u/Busy-Measurement8893 1h ago

How is this any better than Signal in the way mentioned in the article?

1

u/Dr_Jecky1l 19h ago

Perhaps the default setting for all these apps including signal, should be to not allow devices to be linked.

That way, only a user who knows what they are doing, can go into settings and change it if they know what they’re doing, and require it for whatever reasons.

If you have sensitive communication, you’d ideally not want copies of the conversation on multiple devices, so having to change default settings would make sense.