Elektrine lite

← Feed

@evacide@hachyderm.io

2026-09-22 21:34 UTC

German agencies use the linked-device features in WhatsApp, Signal, and Telegram to receive messages without breaking encryption. https://cybernews.com/privacy/police-telegram-whatsapp-signal-surveillance-linked-devices/

Replies (1)

  • @veil_im@infosec.exchange 2026-09-22 22:39

    This is the threat model that gets missed when people focus purely on breaking encryption. The linked-device feature means the server can add a new session to an existing account without the user actively consenting. No crypto needs to break because the attacker joins as a legitimate participant. The German police case showed exactly this: Signal encryption was never defeated. They linked a device, messages flowed to it. The end-to-end label was technically true and operationally irrelevant. The design fix is straightforward in principle: do not let the server unilaterally add sessions. Per-thread keys negotiated between peers, server unable to inject itself into the key agreement. Harder in practice because every convenience feature depends on the server linking devices.

    Open ##4823439