Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CONTENT-CHANGE] WhatsApp now offers encrypted cloud backup #132

Closed
Smankusors opened this issue Apr 10, 2022 · 3 comments
Closed

[CONTENT-CHANGE] WhatsApp now offers encrypted cloud backup #132

Smankusors opened this issue Apr 10, 2022 · 3 comments
Assignees
Labels
enhancement New feature or request

Comments

@Smankusors
Copy link

Explain why it should be added

On Security List > Secure Messaging > Disable Cloud Services, it's mentioned that "WhatsApp backups are not encrypted". But now WhatsApp offers end to end encrypted backup. So even though other parties can obtain the backup, it will need user's password to read it. So I think this section should be updated to reflect this? Wdyt?

Additional Context

FAQ link: https://faq.whatsapp.com/general/chats/how-to-turn-on-and-turn-off-end-to-end-encrypted-backup

@Smankusors Smankusors added the enhancement New feature or request label Apr 10, 2022
@Lissy93
Copy link
Owner

Lissy93 commented Apr 10, 2022

Yup, that should be updated. Are you able to submit a PR? No worries if now, I can also do it.

@Lissy93
Copy link
Owner

Lissy93 commented Apr 10, 2022

Also worth noting that a) not on by default, b) WA can still read your messages prior to them being backed up, c) WA stores your key, so this could be exploited or subpoenaed to read your messages anyway.

That last point was inferred from this section in the WhatsApp docs:

You can change the password for your encrypted backup even if you can’t remember your old password.

This implies that that a copy of the decryption key is stored somewhere...

@Smankusors
Copy link
Author

Also worth noting that a) not on by default, b) WA can still read your messages prior to them being backed up, c) WA stores your key, so this could be exploited or subpoenaed to read your messages anyway.

That last point was inferred from this section in the WhatsApp docs:

You can change the password for your encrypted backup even if you can’t remember your old password.

This implies that that a copy of the decryption key is stored somewhere...

I do agree for all of your points. But for the last point, I think they meant it's to create the entirely new backup, not reading the last backup. Because the password isn't tied with user's password/pin.

I mean it's possible because most likely the messages on the internal storage isn't encrypted. CMIIW

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants