“Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account.”
How WhatsApp Web and Signal Desktop enable multi-device access
Modern messaging apps such as WhatsApp Web and Signal Desktop allow an account tied to a phone to be used on other devices, including laptops and desktop computers. The linked device becomes a recipient for messages sent to the account; once a connection is established, messages can be delivered to that computer without the police having to crack the encryption protecting them.
Germany’s Customs Office: a concrete example of device linking in investigations
The article reports that Germany’s Customs Office has used device-linking features to attach a police-controlled computer to a suspect’s account. That maneuver provides access to the suspect’s incoming messages on the connected machine, effectively bypassing the need to break end-to-end encryption.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleMethods used to obtain a link: physical access, verification codes, and interception
Netzpolitik, cited in the article, outlines three routes by which police can achieve a linked-device connection. First, an investigator with physical access to a target’s phone can establish the pairing directly. Second, police may obtain the verification codes required to authorize a new device by intercepting those codes through a state-sanctioned phishing operation. Third, the verification SMS itself can be intercepted through telephone surveillance. The article underscores the procedural hinge point: making this work requires user consent.
Device-visibility as a defensive design: the article’s recommendation
The article recommends a simple, user-facing mitigation: "What we want is a feature that displays connected devices, so users could notice if a new device gets connected to their account." A clear, persistent listing of active sessions or linked devices would give account holders a direct signal that a new machine has been added and could prompt timely action.
What this means for technologists, policymakers, and end users
- Technologists and security teams: Implementing visible, tamper-resistant device lists and session-management controls is the specific product-level change the article advocates — a targeted engineering fix that does not require changing the underlying encryption model.
- Policymakers and oversight bodies: The reported use of verification-code interception through state-sanctioned phishing or telephone surveillance links a technical feature to lawful-access practices; policymakers will need to account for how device-linking workflows interact with legal authorities’ access methods.
- End users and the general public: Users should be aware that linking a phone account to a desktop is the mechanism by which messages can be mirrored to other machines, and that such linking typically depends on a verification step that can be abused if an adversary obtains the verification material.
The reported combination of an available linking feature and the ability to obtain verification codes means that end-to-end encryption can be circumvented in practice without cryptographic compromise. The article puts a narrow, actionable proposition on the table: surface device connections to users so they can spot unexpected links. Whether vendors will adopt conspicuous device listings, or whether investigative authorities will adapt their techniques accordingly, is left as the next chapter of this debate.




