Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance.

all 3 comments

sorted by: hot top controversial new old
[–] 19 points 1 day ago* (last edited 20 hours ago)

The police take physical access from your phone and link it to a computer so that way they can read all of your messages and whatever via the computer app and it looks like you authorized it.

Essentially you hand them an unlock device and they sync your account to their computer.

They're also using tower intercepts to try and intercept SMS messages for two-factor authentication, so don't be using SMS for two-factor authentication.

Easiest way to prevent this type of attack is to not give your phone to the police and if you do give it to them, make sure it is locked. If you have to give them an unlocked device, make sure you have one that can be easily wiped or one that you don't mind if they monitor.

  • source
  • [–] 17 points 1 day ago* (last edited 1 day ago)

    Literally every western (and some non western) country has bought and used Pegasus against activists and journalists, the virtually undetectable Israeli Spyware that essentially gives the state root access to your phone.This is small beans compared to it.

  • source
  • Yubico and other physical key 2FA folks, look it up!

  • source