# What happened Germany's Customs Office has been using the device-linking features built into WhatsApp and Signal to add a police-controlled computer as a linked device on suspects' accounts. Once a desktop or laptop is linked, messages for that account are delivered to that device just like they are to the phone, without law enforcement having to break the apps' end-to-end encryption.
# How the technique works WhatsApp Web/WhatsApp Desktop and Signal Desktop permit a primary phone account to be paired with additional devices. Pairing requires a verification step: the phone user must confirm the new device, typically by scanning a QR code or entering a one-time verification code. If an attacker can complete that verification, the new device becomes a trusted endpoint and receives messages.
There are three methods described for obtaining the verification step:
- Physical access to the target's unlocked phone, allowing the attacker to complete pairing directly.
- Intercepting the one-time verification code via a state-authorized interception or telephone surveillance that captures SMS messages.
- Phishing campaigns that trick the user into disclosing the code or otherwise completing the pairing step under false pretenses.
Each method circumvents the need to break message encryption because the linked device is an authorized endpoint for the account.
# User-consent and the weak link The critical point is that the apps are working as designed: a new device must be authorized. The vulnerability lies in how that authorization can be captured or coerced. If a user unwittingly provides the confirmation or an attacker obtains the code through interception, the app will treat the device as legitimate.
# What users can do now
- Regularly check the app's list of linked devices. WhatsApp and Signal include device lists that often show device names and last-active timestamps and provide an option to remove links.
- Revoke any linked device you don't recognize immediately. Doing so severs that endpoint's access to future messages.
- Avoid handing unlocked phones to others. Physical access remains one of the simplest ways to authorize a device.
- Consider messaging apps that do not require a phone number for registration if you want to avoid SMS-based verification risks. (A comment in the discussion pointed to Session as an example of a service that uses no phone number.)
# Practical limits and trade-offs Device linking supports legitimate use cases: desktop clients, convenience, and multi-device workflows. Those same features create an access vector when verification safeguards fail. Removing phone-number dependence reduces some risks but can change usability and contact discoverability.
# Bottom line Linked-device functionality makes it possible to receive an account's real messages on additional machines. That capability is being used by investigators who can obtain the linking confirmation by physical access, SMS interception, or phishing. The most immediate defenses are vigilant monitoring of linked-device lists, removing unknown links, and reducing reliance on SMS/phone-number verification where feasible.