The article doesn't specify whether or not the encryption was "broken", or whether Cohen is simply cooperating. My hunch tells me it's the latter.
* the main WhatsApp msgstore database in /data is not encrypted
* the msgstore backup databases (.crypt* in /sdcard) can be decrypted easily using the key file (mentioned in the article) which is also stored in /data
One could probably reverse engineer the WhatsApp APK to figure out how the key file is generated.I would hazard a guess that Signal messages are also not stored encrypted at the source and destination (beyond the protection offered by the operating system).
Bet he sung.
We've all seen it. Hundreds of times.