Yesterday I moved my Signal account over to my new phone. They sent a sms to verify a code. The sms was intercepted (like in WhatsApp) by the Signal app. Any ideas how they do it? As I know even notifications are not interceptable anymore.
Starting from Android 6 there is an Api from Google which can Listen for a Incoming SMS for you. But you do not need any Permission for this. The SMS ends up in the Devices standard SMS App but your app can do an Phoneauthentification using an SMS from your Server. Usually the way would be: 1...