Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

WhatsApp uses dark patterns to encourage unencrypted cloud backups.


... and it doesn't matter if you know how to avoid those unless your friends also do so.

BTW, is there an authoritative source whether these cloud backups to Google Drive are unencrypted/encrypted with Google keys, or encrypted with keys held by Facebook?

I see no reason not to encrypt them the same as local backups (with a key that is held by Facebook, and provided to your phone once they verify your phone number).

The difference between these against the US government filing warrants is just one piece of paper, but against an attacker that compromises your Google account, it does make a significant difference.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: