I don't get this. How could you possibly decrypt encrypted messages without WhatsApp or Signal's assistance?
Isn't the whole point of encryption that no-one can decrypt it unless they have the necessary keys?
I don't get this. How could you possibly decrypt encrypted messages without WhatsApp or Signal's assistance?
Isn't the whole point of encryption that no-one can decrypt it unless they have the necessary keys?
For instance, WhatsApp on Android will happily back up to Google Drive, if you allow it, and it does so in cleartext.
Backup key security is compromised by usability concerns (the need to restore the backup to a new phone without the old one).
https://blog.elcomsoft.com/2018/01/extract-and-decrypt-whats...
In any case you are right that if you can restore an "encrypted" backup onto a fresh phone without any info from the old one, then all the bits necessary to do are held by parties who can be legally compelled to give them up.
No special skills needed except running locating the file, running a command and connecting using SQLite or something.
Hence, it is reasonable to apply any distinction to the content as a user of Google Drive sees it, and not as it may be stored on the backend. Hence, if the data WhatsApp pushes to the Google Drive API is unencrypted (and we're talking about the data, not about the HTTPS-encapsulated form that passes over the network), it is reasonable to call it "in clear text", and it wouldn't be reasonable to call it encrypted.
They would not be able to recover your data upon requesting a password reset, if they used proper end-to-end-encryption.
There is no indication that they decrypted anything by breaking into the end-to-end transport/network encryption used by these apps.
P.S.: Your honest question (which wasn't snarky) was downvoted by some people for reasons I don't understand. Upvoted in an attempt to compensate. Such questions and responses can help more people learn about encryption and the protections necessary at different stages/layers.
But if the person who knows the relevant keys willingly hands over appropriate passwords/etc. for a more lenient sentence then encryption is moot.
I believe Whatsapp has made a few compromises in this regard, but obviously Michael Cohen didn't bother to use disappearing messages in Signal or encrypt his Signal DB, despite how easy it is to do.
That screen was never meant to serve an encryption role and Moxie recommends using Android's full disk encryption feature to ensure data confidentiality at rest.