Using Device Linking to Eavesdrop on WhatsApp and Signal

Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability:

Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers.

Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account.

Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them.

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance.

That last paragraph is important. Making this work requires user consent.

What we want is a feature that displays connected devices, so users could notice if a new device gets connected to their account.

Posted on September 29, 2026 at 7:02 AM • 22 Comments

Comments

Henrik • September 29, 2026 8:00 AM

Had to double check Signal and WhatsApp, and both have “a feature that displays connected devices”. At least on Android in Sweden.

It’s a complete list of linked devices with “last active” timestamp and the possibility to remove the link.

Matthias Urlichs • September 29, 2026 8:20 AM

Telegram has that feature too (yes I know, ugh Telegram, but still). So what’s the problem? Other than, you know, don’t hand an unlocked phone to anybody …

Clive Robinson • September 29, 2026 8:23 AM

@ Bruce, ALL,

If you step back a little you will realise this is an attack almost as old as telephones themselves (think intercepting telegraphy by clipping across the line to “tee off” the signal).

“Signaling System 7″(SS7) was shown to have a similar “tee off” weakness long before it was discussed on this blog back a decade ago in 2016.

The problem is one that has no easily resolvable solution, which is,

“How do more than two people communicate securely?”

At some point you have to “mix together” the messages as plaintext then send them on encrypted to the end users.

This “mix together” requires a high traffic node so is rarely done on a client device but some centralized server etc.

The only secure solution currently is,

“No group communications in real time.”

Which is not what most humans with money to spend want enforced on them…

It’s also something the “guard labour” at all levels do not want fixed either, because adding somebody to a “group” is often childishly simple and gets the person –or AI machine etc– onto the inside track.

It’s in part the reason why “Communications Assistance for Law Enforcement Act”(CALEA) and similar legislation is written the way it is.

And if French recent behaviour is to be believed something they will jail people for providing even minimal protection against Guard Labour and other evesdropping entities performing even in foreign countries (like silencing political discourse in other countries).

See the case of the arrest of Pavel Durov, the co-founder and CEO of Telegram, who was detained near Paris in August 2024 amid a clown crap show of cockerel posturing by French Authorities in Paris that the French courts have in part struck down,

https://en.wikipedia.org/wiki/Arrest_and_indictment_of_Pavel_Durov

(With the question arising that since France has jumped more right wing after the recent election will it all just get quietly dropped,

‘https://www.politico.eu/article/far-right-scores-historic-victory-in-french-senate-election/ )

Rontea • September 29, 2026 9:27 AM

WhatsApp for iOS also has a feature called linked devices which you can monitor. Not sure if you’ll receive an alert if things change in that list.

Q • September 29, 2026 10:07 AM

I avoided Signal and WhatsApp because they require a telephone number. The phone number is a weak point because I don’t control it, the telco controls it. And a telephone number is also useless when I travel to another country and get a “tourist sim” thing. And if I change my telephone number it gets reallocated to someone else later.

I use Session. https://getsession.org/

It’s free. It requires no user account, no email, no telephone number, no registration, no name. It can be used on any and all devices I choose. It can’t be intercepted by someone else by backdooring a telco.

KC • September 29, 2026 11:04 AM

re: the Order for messenger surveillance for Customs Investigation, ZKA

The direct link to this rather measured confidential order is in the OP.

A few informative excerpts:

“Using messenger surveillance (MU), it may be possible to record data exchanged via instant messengers without having to infiltrate the information technology system with surveillance software … The ZKA uses the technical assistance of other federal authorities for this purpose.”

“Since these operations are extremely complex, I would like to point out now that the ZKA will have to prioritize which operations can be carried out. A corresponding questionnaire will be sent to the requesting agencies after a support request has been received.”

In another translation, the last sentence reads as:

“The needy providers will receive a corresponding questionnaire …” lol

This article lists how to check for linked devices on Signal, WhatsApp, and Telegram:

https://www.internationalcyberdigest.com/german-police-read-encrypted-chats-by-adding-themselves-as-a-second-device/

freedom • September 29, 2026 12:46 PM

Why would people use things like signal and watsup anyway, things that are clearly malware provided by the enemy.

Bob • September 29, 2026 1:46 PM

WhatsApp: Settings → Linked devices
Signal: Settings → Linked devices
Telegram: Settings → Devices

Clive Robinson • September 29, 2026 6:26 PM

@ Billy Jack, ALL,

With Regards,

“I know some people who are going to hate learning that Signal is not the ultimate in security.”

It never was and I said as much, much to many peoples surprise.

The point that every one was forgetting is that Signal and all the other “security apps” were just one small part of the system. Just one link all be it a strong one in a chain that had very weak links.

As our host @Bruce had noted some years before Signal was even named,

“A chain is only as strong as it’s weakest link”

Or more technically the design of smart phones as such is that,

“You can from the communications end point, reach around to the user interface beyond the security end point.”

Thus no matter how strong and clever the cryptography and other security features built into the Application are, an attacker can simply bypass it all from the “Over The Air Interface” directly to what the user sees and types etc of the User Interface.

It is as true now as when I said it on this blog some years ago…

Can it be changed?

Yes, but it won’t be convenient for the user… And as “convenience” is what the majority of smart device / mobile phone users want it won’t get fixed…

Because what you have to do is move the security end point beyond the reach of the communications end point. And that cannot be done securely or reliably on a commercial or consumer grade device as the fundamental design will not support it “on device”.

Which means you have to have another device that takes the security end point and following user interface off of the smart device / mobile phone…

Fun thing is you can do it using a pencil and paper with a “hand cipher” implementation of Claude Shannon’s “perfect secrecy”.

You will find I’ve given details of how to do this, in quite some detail on this blog a couple of times in the past. Including how to do it in a deniable form.

Do I think anyone actually does that?

No of course not…

Why?

Because it’s just too inconvenient to do…

Which is just what the Guard Labour and other authoritarian entities want you to do, due to the usefulness of attacks like the one this thread describes.

However the new game in town is not defeating “End to End Encryption”(E2EE) because even the US SigInt agencies and FBI have admitted that it is to important.

No… the new game was actually started by Apple to try and stop the “think of the children” type attacks that were very clearly going to be Guard Labour and Authoritarian agency next type of attack via CSAM accusations.

So Apple came up with the first “Client Side Scanning” that ran on your smart device / mobile phone and if it recognised certain types of flesh coloured images it would report them back…

The thing is once you have the “Client Side Scanning” on your device effectively embedded in the OS it can look for anything not just CSAM.

So text messages and the like or anything else visible in the device User Interface gets scanned.

Microsoft has gone way further with it’s AI nonsense and “ET Phone Home” every few seconds with everything on screen, “just so you don’t forget it” and Microsoft steal all your IP to put in their ML systems…

The only way to defeat “Client Side Scanning” is with “off device security end points”… Unfortunately, sending ciphertext is a “red flag” and any half assed Client Side Scanning will spot it and report it.

It’s one of the reasons I came up with “deniable encryption” that just sends what looks like “ordinary plaintext” not the gobbledygook looking “ciphertext”.

It also has other advantages as it helps protect a communicating “first party” from betrayal by the “second party” to a “third party” such as Guard Labour and the like.

The funny thing is that quite a while after I first posted how to do “deniable encryption” somebody showed how to do it with quirks in AI.

This in turn tells you why “prompt injection” attacks will always be able to bypass Guard-rails on both the Inputs and outputs of LLMs.

But… It also shows by the same logic, that AI agents will always be able to escape/bypass sandboxes.

So yes I can see all sorts of problems ahead and no way to stop them unless AIs are run fully segregated on private systems. Which is not what the “investors” of “AI for rent” companies such as Anthropic, OpenAI, etc want you hearing as the ROI flies out the door.

Likewise the other companies such as Google, Microsoft, Meta, etc that are reliant on “spying on users” and “selling them on as product” want you to hear either again because their Shareholders will not want to see share price and dividends to drop either.

If you look at what has happened to Oracle in recent times you can see what might happen to other large Silicon Valley Corps. And worse what that will do to the US economy….

freedom • September 29, 2026 7:39 PM

Notice that malware like signal and watsoup is meant to force people to use so called “smart phones”.

And “smart phones” are the ultimate example of cyber weapon used by the corporate-government mafia to control their subjects.

So this is all an insane farce. It would be funny if it wasn’t a disaster.

Anonymous • September 30, 2026 3:33 AM

So what, even the introduction of laws to disable e2e encryption is just a temporary measure. When the ecosystem of messaging will become tamperable, I’m assuming that a series of apps will emerge which provides encryption/decrpyption of custom text. Messaging apps like Telegram, Signal, Whatsapp will just become a pipe of encrypted base64 text what will be decrypted by the third app on receiving.

As long as the smartphone is in my hands, and I’m the administrator, I can always set up a safe channel. If I can do it, then I can share the method and this will spread to everyone, even to non-capable users. I have the knowledge to write such application, and with AI everyone can do it too now.

“Life… uh… find a way” [cit.]

lurker • September 30, 2026 4:31 AM

@Anonymous
“As long as the smartphone is in my hands, and I’m the administrator, I can always set up a safe channel.”

Uh, good luck with that. You do know I hope, that the encryption needs to be done on a physically separate device from the “safe channel.”

Q • September 30, 2026 6:38 AM

To Q – no, Signal no longer requires a phone number.

Okay, thanks, this a new development, but it still requires a “smart”phone. I don’t trust those insecure spy devices. I don’t even have one. Besides I long ago trained all my contacts to not expect me to blindly join every random service.

iAPX • September 30, 2026 6:43 AM

Apple is adding virtual devices for more than a decade, identified internally as iPhones, usually silently to intercept their iMessages …

The device is not displayed, but sometimes the notification (new device added) is displayed.
Last time it happened to me (3 months ago), I not only had the notification displayed, but also this virtual iPhone device considered a new iPhone and thus the promotions for few month of AppleTV+ and games and so on offered to me on my own iPhone !

It was comically obvious to say the least …

The explanation ?
There’s a lot of engineers working on iOS/macOS/etc. code, the code could not visibly contain backdoors enabling that. This would be public very quickly.
The only mechanism I know for sure is the ability to have a device that is not displayed on device list.
Kinda “retired” device but still active for Messages (2 different tests) !

Clive Robinson • September 30, 2026 6:59 AM

@ Anonymous, ALL,

With regards,

“I’m assuming that a series of apps will emerge which provides encryption/decrpyption of custom text. Messaging apps like Telegram, Signal, Whatsapp will just become a pipe of encrypted base64 text what will be decrypted by the third app on receiving.”

There is already a way to do this that is cryptographically secure, uses just paper and pencil, and importantly looks like inane “plaintext” language not suspicious base64 or other coding.

Search this site for my name and deniable encryption to read how to do it.

But remember your modile phone or smart device is a pile of monkey crap when it comes to security.

Any security app on it can be easily bypassed through the OS so an attacker can over the air bypass a security app and go directly to what the target sees and types.

So you have to get things “off device” and the advantage of paper over electronics is it only needs a match and a few seconds[1] to destroy it beyond usable evidence.

[1] Look up “flash paper” it’s used by magicians as “part of the act”. There are two types, one that is nitrocellulose based and the other cellulose washed in nitrate. The first uses sulfuric acid and should be avoided as it is a low grade explosive and is without care poisonous. In essence the second sort is very fine paper that has been washed with food grade nitrates as an oxidizing agent to make the paper burn very very quickly and completely to ash finner than dust. The reason for “food grade” chemicals is that at a push you can swallow the paper instead (ie same nitrates as used in curing meat).

Though I would not swallow some nitrates as they are also heart medications and can give you a “Nitrate Headache” that anyone who has used a little to much “NG Spray” under the tongue can tell you all about as “migraine city” or “suicide headache”.

freedom • September 30, 2026 11:51 AM

So how are the alleged “good guys” solving the “smart phone” problem?

“smart phones” are backdoored at every level of the hardware/software stack.

Where are the “good guys” telling the public about such a disaster and proposing solutions.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.