Schneier iconSchneierSep 29, 2026 ~8 min source read

How device linking can let authorities (or attackers) read WhatsApp and Signal without breaking encryption

Germany’s Customs Office has been using desktop linking features to add an investigative computer as a trusted device on suspects’ WhatsApp and Signal accounts. The technique delivers messages to that device without cracking end-to-end encryption; it relies on getting the linking confirmation.

Share this story

Send the public story page.

Useful takeaways from this story.

Access to link a new device requires the account’s verification step, which can be fulfilled by physical access to an unlocked phone, intercepted SMS codes, or phishing that captures the confirmation code.

Using messaging systems that don’t tie accounts to phone numbers reduces the attack surface tied to carrier-controlled SMS or number-based verification.

# What happened Germany's Customs Office has been using the device-linking features built into WhatsApp and Signal to add a police-controlled computer as a linked device on suspects' accounts. Once a desktop or laptop is linked, messages for that account are delivered to that device just like they are to the phone, without law enforcement having to break the apps' end-to-end encryption.

# How the technique works WhatsApp Web/WhatsApp Desktop and Signal Desktop permit a primary phone account to be paired with additional devices. Pairing requires a verification step: the phone user must confirm the new device, typically by scanning a QR code or entering a one-time verification code. If an attacker can complete that verification, the new device becomes a trusted endpoint and receives messages.

There are three methods described for obtaining the verification step:

  • Physical access to the target's unlocked phone, allowing the attacker to complete pairing directly.
  • Intercepting the one-time verification code via a state-authorized interception or telephone surveillance that captures SMS messages.
  • Phishing campaigns that trick the user into disclosing the code or otherwise completing the pairing step under false pretenses.

Each method circumvents the need to break message encryption because the linked device is an authorized endpoint for the account.

# User-consent and the weak link The critical point is that the apps are working as designed: a new device must be authorized. The vulnerability lies in how that authorization can be captured or coerced. If a user unwittingly provides the confirmation or an attacker obtains the code through interception, the app will treat the device as legitimate.

# What users can do now

  • Regularly check the app's list of linked devices. WhatsApp and Signal include device lists that often show device names and last-active timestamps and provide an option to remove links.
  • Revoke any linked device you don't recognize immediately. Doing so severs that endpoint's access to future messages.
  • Avoid handing unlocked phones to others. Physical access remains one of the simplest ways to authorize a device.
  • Consider messaging apps that do not require a phone number for registration if you want to avoid SMS-based verification risks. (A comment in the discussion pointed to Session as an example of a service that uses no phone number.)

# Practical limits and trade-offs Device linking supports legitimate use cases: desktop clients, convenience, and multi-device workflows. Those same features create an access vector when verification safeguards fail. Removing phone-number dependence reduces some risks but can change usability and contact discoverability.

# Bottom line Linked-device functionality makes it possible to receive an account's real messages on additional machines. That capability is being used by investigators who can obtain the linking confirmation by physical access, SMS interception, or phishing. The most immediate defenses are vigilant monitoring of linked-device lists, removing unknown links, and reducing reliance on SMS/phone-number verification where feasible.

More context around this story.

Runet iconRunetSep 17, 2026

Полиция в ЕС «клонирует аккаунты» для чтения Telegram, WhatsApp* и Signal без взлома шифрования

Правоохранительные органы Германии используют метод «клонирования аккаунтов» для слежки за перепиской в WhatsApp, Signal и Telegram. Этот метод позволяет подключать служебный компьютер к учетной записи подозреваемого как обычное доверенное устройство, при этом шифрование остается нетронутым. Об этом сообщает «СNews». «

Misc
Blogspot iconBlogspotSep 10, 2026

Misc

Misc Miscellaneous category. No Placement. A lot a great resin crafts. <img border="0" data-original-height="961" data-ori...

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app