Screenshot of WhatsApp Web settings showing a list of linked devices with timestamps

Using Device Linking to Eavesdrop on WhatsApp and Signal

When messaging services let you run a desktop client, they open a shortcut around the encryption that protects your chats. Law‑enforcement agencies in Germany have already turned that shortcut into a surveillance tool, linking a police‑controlled computer to a suspect’s WhatsApp or Signal account without ever breaking the cryptographic protocol. If you assume that end‑to‑end encryption guarantees privacy, you are overlooking the very real risk that a seemingly convenient feature can become a backdoor.

How Device Linking Bypasses End‑to‑End Encryption

Both WhatsApp Web and Signal Desktop require the user’s phone to generate a QR code that the secondary device scans, establishing a session key that mirrors the phone’s encryption state. Once the session is active, every incoming and outgoing message is mirrored to the linked computer, meaning the desktop sees the plaintext before it is displayed on the phone. WhatsApp Web and Signal Desktop therefore act as legitimate extensions rather than independent cryptographic endpoints.

The security model assumes that the user controls the linked device and that the linking process cannot be hijacked without the user’s consent. In practice, the QR code can be captured by malware on the phone, or the verification code sent via SMS can be intercepted, allowing an attacker to complete the pairing without the user noticing. This undermines the “only the phone can read the messages” guarantee that the services advertise.

Law Enforcement Exploitation of Linking Mechanisms

Germany’s Customs Office has demonstrated a practical application of this weakness: officers obtain physical access to a suspect’s phone or intercept the SMS verification code through a state‑sanctioned phishing attack, then pair a police‑controlled computer to the suspect’s account. Germany’s Customs Office can thus read messages in real time without ever needing to decrypt the traffic on the network. The operation sidesteps the need for a court‑ordered decryption order or a technical exploit against the encryption algorithm itself.

The method relies on two surveillance capabilities that many governments already possess: telephone surveillance that can capture SMS messages, and the ability to launch phishing campaigns that appear to come from trusted sources. By combining these with the device‑linking feature, authorities gain a low‑cost, high‑yield vector for mass surveillance of targeted individuals, especially those who rely on encrypted messaging for sensitive communications.

User Consent and Visibility Gaps

Both WhatsApp and Signal require the user to approve the new device during the QR‑code scan, but the approval step can be bypassed if the attacker already controls the phone long enough to confirm the pairing. Moreover, the apps provide limited visibility into active sessions; a user must manually open a settings screen to see a list of linked devices, and the list may not highlight recent additions. The source calls for a feature that “displays connected devices, so users could notice if a new device gets connected to their account,” underscoring the current UI shortfall.

From a design perspective, the trade‑off is between usability—allowing seamless cross‑device access—and security—ensuring that each new link is unmistakably authorized. The current balance leans heavily toward convenience, leaving a window where an attacker can silently harvest messages. Users who are unaware of the linking process are effectively blind to a surveillance channel that operates entirely within the legitimate app ecosystem.

What This Actually Means For You

  1. Linking a desktop client creates a parallel plaintext stream; any compromise of the phone or verification channel instantly exposes all chats.
  2. State actors can exploit existing phone‑surveillance tools to hijack verification codes, turning a benign feature into a surveillance conduit.
  3. Because the apps hide linked‑device information behind a few taps, many users never notice an unauthorized session.
  4. Disabling desktop linking removes the attack surface entirely, at the cost of losing the convenience of typing on a full keyboard.
  5. Vigilance over SMS messages and phishing attempts is essential, as those are the primary vectors for forced pairing.

Immediate Action Steps

Review the linked‑device list in your messaging app’s security settings today and revoke any sessions you do not recognize. If you do not regularly need a desktop client, turn off the linking feature in the app’s settings to eliminate the attack vector.

Strengthen the security of the SMS verification channel: use a carrier that offers encrypted messaging for two‑factor codes, or switch to an authenticator app that does not rely on SMS. Be skeptical of unsolicited messages that request you to scan a QR code, even if they appear to come from a trusted contact.

Frequently Asked Questions

Can police read my WhatsApp messages without breaking encryption?

Yes. By linking a police‑controlled computer to your account through a compromised phone or intercepted verification code, authorities can view messages in plaintext without decrypting the network traffic.

How does Signal Desktop expose my chats to eavesdroppers?

Signal Desktop mirrors the phone’s session keys; if an attacker pairs a device using a stolen QR code or intercepted verification code, the desktop client receives every message before it reaches the phone.

What should I do if I suspect an unauthorized device is linked?

Open the app’s security settings, check the list of active sessions, and revoke any unfamiliar devices. Disabling the linking feature altogether prevents future unauthorized pairings.

What Do You Think?

Given that a simple UI tweak could alert users to rogue sessions, should messaging platforms prioritize visibility over the convenience of silent device linking?

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.