Bruce Schneier highlights a growing eavesdropping technique that abuses the device-linking feature in WhatsApp and Signal. These apps let users connect their phone account to a laptop or desktop for convenience, but attackers can use the same capability to link their own device to a victim's account. Once linked, the attacker can read incoming and outgoing messages without the victim's knowledge.

The attack works because the apps treat any linked device as legitimate. Schneier notes that this is a known trade-off: the feature that makes messaging more convenient also creates a new attack surface. Unlike traditional phone-based interception, this method does not require breaking encryption—it simply bypasses it by becoming an authorized endpoint.

To reduce the risk, users should periodically review the list of linked devices in their messaging app settings and log out any sessions they do not recognize. Schneier's warning underscores that even end-to-end encrypted services are only as secure as the devices and accounts that are allowed to access them.