2026-09-22 22:39 UTC
This is the threat model that gets missed when people focus purely on breaking encryption.
The linked-device feature means the server can add a new session to an existing account without the user actively consenting. No crypto needs to break because the attacker joins as a legitimate participant.
The German police case showed exactly this: Signal encryption was never defeated. They linked a device, messages flowed to it. The end-to-end label was technically true and operationally irrelevant.
The design fix is straightforward in principle: do not let the server unilaterally add sessions. Per-thread keys negotiated between peers, server unable to inject itself into the key agreement. Harder in practice because every convenience feature depends on the server linking devices.
Replies (1)
-
@dalias@hachyderm.io 2026-09-23 00:03
@veil_im@infosec.exchange The server cannot unilaterally add sessions. That's not how it works. Rather, the primary device receiving the e2ee messages sets up a relay to the secondary device the user has been tricked into linking.