Law Enforcement Exploits Device Linking to Eavesdrop on WhatsApp and Signal
What Happened — WhatsApp Web and Signal Desktop let users link a phone account to a computer. German customs officials have demonstrated that, by obtaining physical access to a phone or intercepting the verification code (often via state‑sanctioned phishing or SMS interception), they can link a police‑controlled computer to a suspect’s account and read messages in real time without breaking end‑to‑end encryption.
Why It Matters for Trust & Control Assurance
- Demonstrates a gap in device‑access controls: the platform trusts a newly linked device once the verification code is presented, without independent verification that the user initiated the link.
- Highlights the need for continuous monitoring and logging of linked devices so that any unexpected addition can be detected and investigated promptly.
- Underscores the importance of user awareness and verification policies (e.g., multi‑factor confirmation, notification of new device links) as a control that mitigates credential‑based attacks.
Who Is Affected – Messaging service providers (WhatsApp, Signal, and similar SaaS platforms), their enterprise customers, and any end‑users who rely on device‑linking for convenience.
Recommended Actions
- Implement a policy that requires out‑of‑band confirmation (e.g., push notification, secondary factor) for every new device link.
- Deploy real‑time alerts and audit logs for device‑link events; integrate these logs into a continuous control‑assurance dashboard.
- Educate users on the risks of phishing and SMS interception, and enforce secure verification code delivery (e.g., in‑app push rather than SMS).
Technical Notes – The technique leverages phishing or SMS interception to capture the one‑time verification code required for device linking. No cryptographic break is needed; the attacker simply becomes an authorized device. Source: Schneier on Security