https://faq.whatsapp.com/android/chats/about-google-drive-ba...
https://faq.whatsapp.com/android/chats/about-google-drive-ba...
The funny thing is that I cannot find a way to access that backup myself, is anyone aware of a method to download that backup as a data dump and inspect it?
98% of users enable that option. The fact that whatsapp is e2ee is a complete lie.
Use Signal for true e2ee, or if you don't like it, Telegram. Telegram stores everything in the cloud tho. (they haven't disclosed any private messages, and are much more trustworthy than Whatsapp). They just wanted to back up messages without giving it to Google/Apple
It has a good UX which is rare for open source apps. It seems to be based around a decent community. But I don't know why I don't use it.
Even the e2ee thing is not audited properly.
They are just more trustworthy, have open source apps, better usability [ and unlimited storage :) ] .
Signal > Telegram > Whatsapp
IIRC it is stored in your Google Drive under an API key that is dedicated to whatsapp (in some kind of per-app storage). I don't really know much about Google Drive API.
However, I am fairly sure that the key is in the binary on your phone, so it shouldn't be much of a challenge to get access.
I think there was something like this on Github once, that no longer works (due to trivial changes, likely).
Update: https://github.com/YuriCosta/WhatsApp-GD-Extractor-Multithre...
Looks recent, didn't try myself.
I got an iPhone SE and turns out I can't really import the Android backup on an iPhone, and there's no way to access it either.
Some backup.
Damnit why is everything related to mobile so needlessly fecking difficult. I just want to read some damn plain text files that are right there but it doesn't allow me to access for no reason in particular. I hate everything about mobile so much.
The main problem here is that like everything FB related, you are the product, not the customer At least, I haven't found any reasonable explanation about why Google and Apple get an unencrypted copy of your chat history but you can't. (And not for lack of trying - there are always ridiculous answers on Reddit and HN about "but if you could read your messages, so can the bad guys")
This is a pretty bold claim. Do you have a citation for this?
How about instead of guessing and concluding it must be compromised (argument from ignorance), you do a cursory search and get an actual response?
https://security.stackexchange.com/questions/148321/how-does...
> Be kind. Don't be snarky. Have curious conversation; don't cross-examine. Please don't fulminate. Please don't sneer, including at the rest of the community.
As for your link, I'm aware how they claim it works, and even if that is all true (we can't audit the source code), then it is still a compromise of E2EE. E2EE is between two devices, a receiver and a sender. The third device also able to receive, without the sender knowing or agreeing about it, is dangerous. Why? Because you can't know for sure the receiver has access to both machines. If you consider laptop and PCs are much less safe than mobile devices, then the danger is obvious.
I don't get it. Does that mean if I have PGP installed on my desktop, and I also have a VNC server installed on it, it's no longer E2E? That seems like an arbitrary distinction to me. If you extend this further, you could also argue that being able to print out the message, or even have a second person look at the screen breaks E2E. I think the main point of E2E is that unauthorized third parties (including service providers) can't read the message, not that only two devices can read the message.
Alice uses a smartphone and a laptop with WhatsApp. Bob only uses a smartphone with WhatsApp. Alice and Bob discuss something secret. Alice assumes only Bob's (secure) smartphone can read the data. Bob assumes only Alice's (secure) smartphone can read the data. They both got physical access to the smartphone, which lowers the attack surface at that moment. Alice's laptop is in her house. As is Mallory.
My problem with above isn't that this works; it is how it works. My problem is that Alice never temporary authorizes WhatsApp Web. My problem is that Bob doesn't know about Alice's 2nd device. These 2 issues are issues which can be addressed and raise the privacy of the data considerably. The gut reaction "oh, its E2EE, so its secure." is dangerous, and untrue.
Yes, I'm aware you can make screenshots and print chats. You can also send temporary messages with Signal though. That's on top of E2EE, because E2EE isn't a panacea.