Lissy93 / personal-security-checklist

🔒 A compiled checklist of 300+ tips for protecting digital security and privacy in 2024
https://digital-defense.io
Other
16.71k stars 1.16k forks source link

[CONTENT-CHANGE] WhatsApp now offers encrypted cloud backup #132

Closed Smankusors closed 2 years ago

Smankusors commented 2 years ago

Explain why it should be added

On Security List > Secure Messaging > Disable Cloud Services, it's mentioned that "WhatsApp backups are not encrypted". But now WhatsApp offers end to end encrypted backup. So even though other parties can obtain the backup, it will need user's password to read it. So I think this section should be updated to reflect this? Wdyt?

Additional Context

FAQ link: https://faq.whatsapp.com/general/chats/how-to-turn-on-and-turn-off-end-to-end-encrypted-backup

Lissy93 commented 2 years ago

Yup, that should be updated. Are you able to submit a PR? No worries if now, I can also do it.

Lissy93 commented 2 years ago

Also worth noting that a) not on by default, b) WA can still read your messages prior to them being backed up, c) WA stores your key, so this could be exploited or subpoenaed to read your messages anyway.

That last point was inferred from this section in the WhatsApp docs:

You can change the password for your encrypted backup even if you can’t remember your old password.

This implies that that a copy of the decryption key is stored somewhere...

Smankusors commented 2 years ago

Also worth noting that a) not on by default, b) WA can still read your messages prior to them being backed up, c) WA stores your key, so this could be exploited or subpoenaed to read your messages anyway.

That last point was inferred from this section in the WhatsApp docs:

You can change the password for your encrypted backup even if you can’t remember your old password.

This implies that that a copy of the decryption key is stored somewhere...

I do agree for all of your points. But for the last point, I think they meant it's to create the entirely new backup, not reading the last backup. Because the password isn't tied with user's password/pin.

I mean it's possible because most likely the messages on the internal storage isn't encrypted. CMIIW