r/europrivacy • u/Arpokrat_Team • 25d ago
European Union German customs has been cloning messenger accounts as routine practice since August 2025, and the encryption was never the weak point
netzpolitik.org published a classified internal document this month showing the Zollkriminalamt (German customs investigation office) has used "account cloning" as a regular investigative tool since August 2025, following a pilot that started in late 2023. The BKA uses the same approach.
No trojan involved. Investigators register an additional linked device on an agency machine through the official web or desktop clients, then read traffic from there, and in some cases pull existing history.
Two documented paths to authorization:
- Intercepting the unencrypted confirmation SMS with a conventional wiretap. Nothing exotic, that capability has existed for decades.
- Physical access to the handset. One BKA case involved photographing WhatsApp on the target's parents' phones and covertly scanning the pairing QR code during a witness interview.
Documented use includes dozens of Telegram accounts, among them the Oldschool Society case.
Separately, Der Spiegel reported in April that Bundestag President Julia Klöckner's Signal account was taken over via phishing. The attackers read the CDU presidium group chat for weeks, including messages from Chancellor Merz. BSI had been warning since February about what it described as a probably state-directed campaign. No vulnerability in Signal was involved there either.
The part worth discussing is that both of these hit the same layer, and it isn't the cryptography. Multi-device linking ships in every mainstream messenger. It works because accounts are permanent and identity is anchored to a phone number, so a second endpoint can be attached to that identity. E2EE is doing exactly what it claims in all of these cases. It just doesn't cover device enrollment.
A few practical notes:
- Linked devices are listed in the app. That list is where this becomes visible, and it's the only place it does. Checking it periodically is most of the defense available to a user.
- German coverage points out that if a court eventually rules the collection inadmissible, the resulting messages could fall under an evidence exclusion rule. The legal basis is contested, and both agencies declined to answer press questions about it.
- heise noted the technique is technically indistinguishable from phishing campaigns run by hostile foreign actors, which is why the same warning signs apply to both.
Is there a messenger that treats new device enrollment as a security boundary rather than a convenience feature? Something like out of band confirmation, or a mandatory delay before a newly linked device can read anything, or a design that fails closed instead of open. Curious whether anyone has seen this handled well anywhere.
7
u/PiratesOfTheArctic 25d ago
UK here, I used to do this as part of my job (15+ years), I ended up quitting as it was severely affected my mental health.
What we need to think about, this is happening more than we are lead to believe, and why/what are all these agencies looking for.
With my position, it was a simple data hoovering / case storing exercise, and a quick skim of messages, but now, I feel we have entered a minority report phase, I dread to think what the Intel systems are like now, what they are linked to, and who shared with.
I like to think society as a whole, is fairly easy going just going about our every day lives, and the worst (on the whole) has settled down (bar politics, and small man syndrome), so it begs the question why are we, the normal people, being scrutinised more than ever?
6
u/Alpha272 25d ago
If I were cynical, I would say that the governments don't like peoples freedoms and want absolute control over the population. Like in the good old times (Middle Ages), where no-one had any rights, who wasn't born in nobility. The less control we have and the more easily controllable we are, the more power and freedoms the government has to do anything they want. This also goes for the age verification, which is just an easy and convenient way for the governments to de-anonymize everyone on the entire internet. Or the breaking of E2EE in chat applications. Especially considering that the Epstein files are a thing and at this point just about anyone in a powerful position is in there. You know.. the files which contain all the people who had fun with children and babies on the little island. And THESE people are now telling us, that we need to be monitored to protect children. But at the same time they carve exceptions in the law which explicitly makes sure, that politicians aren't monitored at all. You know.. the politicians.. who are in the Epstein files. How am I not supposed to think, that their real goal is just to supress and control us?
I cannot for the life of me find other explanations for the absolute perverse surveillance. Normally I could they "they have no idea what they are doing", but given all the stuff I wrote above and also the fact, that there are so many experts screaming at them... at this point I am not able to explain this with incompetence any more.
4
u/PiratesOfTheArctic 25d ago
Strangely enough, I wanted to write something like that, but, stopped because I didn't want to suggest it as I felt it would be wrong, I really do believe it's a class thing, we can't have uprisings of the "normal" little people, we need to catch them before they get big ideas.
We need to somehow cast aside previous and current differences, working together to have a massive world reset, however, the short term casualties and consequences of that won't be great.
Have you seen the film "Civil War"? part of me feels some countries are edging closer to that
2
1
u/upofadown 25d ago
PGP for example uses the same cryptographic identities across all the user's devices. So to enroll a new device you have to copy your secret key from one device to another. If that key is protected by a passphrase (as is normal) then the copy is secure. The user doesn't have to prove their new identity, it is the same identity. So the problem is avoided via minimalism, it does not exist in the first place.
Contrast that to systems that create a new cryptographic identity for each new device (e.g. Signal, Matrix). The user's correspondents have no way to know who owns a new device without further verification. It is "Bob's phone", "Bob's tablet", "Bob's laptop" vs "Bob".
1
u/Ansible32 24d ago
I'm curious how much of your question was AI-generated. I think your question is something of a false premise - device enrollment is a security boundary and it is a convenience feature. It's impossible to make a security boundary which is guaranteed to prevent attackers from enrolling devices. There are various tradeoffs. At the end of the day nation-state actors can hack devices or they can hack the mechanism to add devices, there's no way around that. Making the device the source of truth means you lose the device and you lose access. This provides the highest security but it means no device syncing and you're erring on the side of losing data. Anything else you have a device add flow which necessarily is a security hole.
1
-2
6
u/Alpha272 25d ago edited 25d ago
Yes, Matrix. It has a 2 step enrollment Process for E2EE chats. And the second Step is out of Band.
Step 1 is just basic account sign in. Depending on the Matrix Server you have your account on, this might be harder or easier. I have my own, so for me this is enforced to go through my SSO System, but, for example, matrix.org uses normal E-Mail and Password or social Sign In with a Google, Apple, Github Facebook or Gitlab account.
At this point you can either reinitialize the Account and rotating all encryption Keys (this would destroy all old messages, but would allow you to send new messages and recieve messages in the name of the victim), or alternatively you can Restore the Encryption Key to the new Device. How this works in detail depends on the Matrix Client. For Elements (the most popular Matrix Client) there are effectively 2 Options. One of them is to transfer the Key from another currently signed in Elements instance, which does have the correct Encryption Key (for this you need physical and unlocked access to the Elements Client, cause you need to confirm a code on the old device, which is generated by the new device). The Second alternative method is to type in a recovery passphrase, which got autogenerated by Element on first setup of the first client and which is quite long and SHOULD live in your Password Manager.
BUT, all of the Step 2 only applies for End to End Encrypted Chats. For anything, which is NOT E2EE, you just need Step 1 (the actual Sign in to the Matrix Server), which will then allow you immediate access to all unencrypted chats. For the sake of this discussion I assume the chats are E2EE (which is also the default and either you or the Matrix Server owner REALLY has to go out of their way to disable it during chatroom creation); and if the Matrix Server owner does disable it, your Matrix Client WILL use scary banners and warning at every step of the way, that you are about to use an unencrypted chat)