this post was submitted on 12 Sep 2026
408 points (96.2% liked)

Technology

88328 readers
3173 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

you are viewing a single comment's thread
view the rest of the comments
[–] Zak@lemmy.world 72 points 2 weeks ago (1 children)

What's described in the article is the same method Russia was using to compromise Ukrainian Signal accounts. It's just phishing.

[–] SergeantSushi@lemmy.world 11 points 2 weeks ago (1 children)

I think you're the only person here so far who read the linked article.

I also found the netzpolitik article that was referenced but not linked to in the original article.

This describes police adding a linked device to a person's WhatsApp account while gathering evidence (translated with Google Translate).

On January 12, 2020, Mr. and Mrs. P. were questioned. During the questioning, they voluntarily handed over the mobile phones they were carrying to the interviewing officers for a brief period so that messages from their daughter contained on the devices could be viewed and, among other things, photographed.

While the photographs were being taken, the computer-based application WhatsApp Web was covertly activated via a website made available online by the Federal Criminal Police Office (BKA), allowing the messages to be read on a BKA computer (sic!). This did not involve any intrusion via a Trojan horse or similar software.

The only link to Signal here is the nation state campaign which used social engineering via a phishing message from 'Signal Support'.

This nation state campaign was originally reported by a researcher at Citizen Lab.

[–] Zak@lemmy.world 7 points 2 weeks ago

I did notice some comments that may be from people who did not read and understand the article. These attacks are not sophisticated or hard to defend against, which is probably why the German police want to limit public awareness.

I find their view shortsighted/narrow; the attacks they're using (including SIM swapping) are also widely used by criminals for fraud and identity theft. Police agencies should not discourage the public from being more cybersecurity-aware.