WhatsApp to Let Users Encrypt Chat Backups Uploaded to iCloud

WhatsApp has announced it will give its two billion users the option to upload their chat backups to Apple's iCloud using password-protected encryption.

Whatsapp E2EE Backups
Currently, WhatsApp on iPhone lets users back up their chat history to ‌‌iCloud‌‌, but messages and media that users back up aren't protected by WhatsApp's end-to-end encryption while in ‌‌Apple's cloud servers‌.

Given that Apple holds the encryption keys for ‌iCloud‌, a subpoena of Apple or an unauthorized ‌iCloud‌ hack could potentially allow access to WhatsApp messages backed up there. Apple was reportedly pressured to not add encryption to ‌iCloud‌ Backups after the FBI complained.

The upcoming WhatsApp feature will resolve that security vulnerability by allowing users to encrypt and password-protect their chat history before uploading it to Apple's cloud-based platform. WhatsApp began early work on the security feature back in March 2020.

The rollout will make backups secure in remote ‌iCloud‌ servers by making them unreadable without an encryption key. Encrypted backups will be optional, and users will be asked to save a 64-bit encryption key or create a password that is associated with the key.

According to a whitepaper published by the Facebook-owned platform, when a WhatsApp user creates a password linked to their account's encryption key, WhatsApp stores the key in a physical hardware security module (HSM) that acts like a safety deposit box and can only be unlocked using the correct password. WhatsApp only knows that a key exists in a HSM, not the key itself or the associated password to unlock it.

When the password is used to unlock the HSM, the encryption key is released which then decrypts the account's backup on Apple's servers. If the wrong password is entered repeatedly, however, the data in the HSM becomes permanently inaccessible. WhatsApp will only know that a key exists in a HSM, not the key itself or the associated password to unlock it.

"WhatsApp is the first global messaging service at this scale to offer end-to-end encrypted messaging and backups, and getting there was a really hard technical challenge that required an entirely new framework for key storage and cloud storage across operating systems," said Facebook CEO Mark Zuckerberg in a post announcing the feature.

The encrypted chat backups feature will be rolled out in the coming weeks on Android (for WhatsApp users backing up to Google Drive) and iOS, and will be available in every market where WhatsApp is operational, which could put the company at odds with some governments.

Comparatively, Apple is not making its upcoming ‌iCloud‌+ Private Relay encrypted browsing feature available to users living under certain authoritarian regimes, including China, Belarus, Colombia, Egypt, Kazakhstan, Saudi Arabia, South Africa, Turkmenistan, Uganda, and the Philippines. According to Apple, "regulatory reasons" are preventing the Private Relay feature from launching in those countries.

Top Rated Comments

Ifti Avatar
24 months ago
WhatsApp is what iMessage should have been.
Score: 25 Votes (Like | Disagree)
InGen Avatar
24 months ago
It’s your turn, iMessage/iCloud…
Score: 20 Votes (Like | Disagree)
rikscha Avatar
24 months ago
Yeah fully encrypted when FB already announced they will place ads inside whatsapp based on what you write

you are a fool for using the service
Score: 14 Votes (Like | Disagree)
ecatomb Avatar
24 months ago
Just too bad that WhatsApp owner is Facebook ?
Score: 13 Votes (Like | Disagree)
0924487 Avatar
24 months ago

Signal is the answer
Yeah, good luck finding normal people willing to go that far. I have zero active contacts in Signal.
Score: 6 Votes (Like | Disagree)
sdz Avatar
24 months ago

https://gizmodo.com/whatsapp-moderators-can-read-your-messages-1847629241
So true ?

Without joking, I can only agree... If iMessage was available on Android long time ago, iMessage could be at the same place than WhatsApp : encryption, used by nearly everyone...

Maybe Signal will replace WhatsApp ?
Big deal. Messages are forwarded after you’ve been warned. They cannot control it from the outside. It stays e2e encrypted. Actually a very good design. Much better than the rotten Apple solution (we will store your key in the Backup file just because hehehehe )
Score: 6 Votes (Like | Disagree)

Popular Stories

Rapid Security Response Feature 1

Apple Releases Rapid Security Response Updates for iOS 16.5.1 and macOS 13.4.1 to Fix Actively Exploited Vulnerability [Updated]

Monday July 10, 2023 10:31 am PDT by
Apple today released Rapid Security Response (RSR) updates that are available for iPhone and iPad users running the iOS and iPadOS 16.5.1 updates and the macOS Ventura 13.4.1 update. Rapid Security Response updates are designed to provide iOS and macOS users with security fixes without the need to install a full software update. Today's updates address an actively exploited WebKit...
iPhone 15 Pro Two Volume Buttons and Titanium Feature Blue Green

iPhone 15 Pro's Top Rumored Features: USB-C Port, Titanium, and More

Tuesday July 11, 2023 6:37 am PDT by
Apple is expected to unveil the iPhone 15 lineup in September. As usual, the Pro and Pro Max models are expected to have a wide range of new features, including a USB-C port, A17 Bionic chip, titanium frame, and more. Below, we have recapped the top five new features rumored for the iPhone 15 Pro models. USB-C port: iPhone 15 Pro models are widely rumored to feature a USB-C port, providing...
Rapid Security Response Feature 1

Apple Pulls iOS 16.5.1 and macOS 13.4.1 Rapid Security Response Updates Due to Safari Bug

Monday July 10, 2023 8:39 pm PDT by
Apple earlier today released new Rapid Security Response updates for iOS 16.5.1, iPadOS 16.5.1, and macOS Ventura 13.4.1 users, but Apple has pulled the software, likely due to an issue that caused certain websites not to work after the RSRs were installed. According to reports on the MacRumors forums, Facebook, Instagram, WhatsApp, Zoom, and other websites started giving a warning about not ...
primeday2020 feature3

Amazon Prime Day: The Best Apple Deals

Tuesday July 11, 2023 5:30 am PDT by
Amazon Prime Day is back again, and this summer it will last for two days. During this time, you'll find a large selection of deals and offers across Amazon's storefront, covering savings on tech, clothing, video games, groceries, and much, much more. Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us...
iPhone 15 Pro Blue Side and Back 2

iPhone 15 Pro Expected to Come in Blue

Friday July 7, 2023 2:12 pm PDT by
The iPhone 15 Pro models that are set to be introduced this September will be available in a unique dark blue color that has a gray tone, according to Unknownz21, a source that has provided multiple details on what we can expect from the next-generation iPhones and accurate information on other Apple devices like the Vision Pro. Available in a new titanium material, the blue shade will have...