Using Device Linking to Eavesdrop on WhatsApp and Signal

Refract AI Intelligence Digest

BLUF

End-to-end encryption is being circumvented via legitimate multi-device linking features exploited by law enforcement.

NEWS

Germany’s Customs Office has been utilizing device linking capabilities in WhatsApp Web and Signal Desktop to connect police computers to suspect accounts. Once linked, messages are delivered to the police device without requiring decryption keys or technical cracking.

Why I Care

This undermines trust in end-to-end encryption for journalists, activists, and ordinary users who rely on these platforms for privacy. It sets a precedent for other agencies to exploit similar vulnerabilities globally without judicial oversight on technical breaches.

Next Steps

Users should regularly audit linked devices in their messaging app settings and remove any unrecognized sessions immediately. Organizations handling sensitive data should consider alternative communication channels less susceptible to device linking exploits until policy updates occur.

Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers. Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account. Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them. Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance...
Back to Blog Listing

Source: Schneier on Security ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.