March 8 – WhatsApp is reportedly working to increase the security of its cloud backups with a new password protection feature that’ll encrypt chat backups, making them accessible only to the user. WABetaInfo reported on the work-in-progress feature last year, and today it shared screenshots of how it could be presented in the service’s iOS and Android apps.
“To prevent unauthorized access to your iCloud Drive backup, you can set a password that will be used to encrypt future backups,” one of the screenshots reads. “This password will be required when you restore from the backup.” The app then asks the user to confirm their phone number, and select a password that’s at least eight characters long. Another screenshot warns that “WhatsApp will not be able to help recover forgotten passwords.”
Although WhatsApp chats are end-to-end encrypted, meaning they’re only visible to the sender and recipient, the service warns that this protection doesn’t extend to online backups stored on Google Drive and iCloud. Once on these servers, the security of the backups is the responsibility of the cloud service providers, who in the past have made them accessible to law enforcement authorities with valid search warrants. Encrypting the backups with a password only you know would theoretically prevent anyone from accessing your chat history without your authorization.
These latest reports about the feature come as WhatsApp’s reputation has taken a hit from a new privacy policy, which has stoked fears that it may store more information with parent company Facebook. Although WhatsApp insists the new policy doesn’t affect the security of users’ personal messages, rival messaging services like Signal and Telegram have seen a surge in interest as users explore other options.
WhatsApp declined to comment on the unannounced feature when contacted by The Verge, but WABetaInfo has a good track record of unearthing features before they become official. It’s spotted features like adding contacts via QR codes or disappearing messages long before their official announcements.
Source – The Verge