cross-posted from : https://lemmy.zip/post/71321898
Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance


To me, this proves that the police can still get the information they need without us handing over our encryption keys and requiring ‘service providers’ to MITM for them.
Except they had to get the keys, at least for Signal, as described in the article. Only you can allow a new device. If you get a notification for a new device and you go “sure, let me flash that code for you”, you’re giving the key. And a moron.
Can’t say about the other services.
for signal, that is still required. if you look, they used linked devices to get the messages
That’s not MITM done by the signal foundation.
I meant us handing over our encryption keys. ofc MITM does not work here