Does backing up WhatsApp on Google Drive expose messages?

You're confusing message integrity and security with secrecy. WhatsApp provides end to end encryption, meaning the message you send can only be read by the recipient and vice versa. This protects you from third parties trying to eavesdrop on your conversation, and even prevents WhatsApp themselves from reading the messages. You can't demand WhatsApp to allow you to wiretap a conversation if WhatsApp themselves have no idea what's being sent.

However once the message is in the hands of the recipient, it's a different story. In order for it to appear in their chat history, it has to be saved on the phone. If a persons device is compromised, so is your chat history with that person. The person could also screenshot your conversation, or even use another phone to take a picture of your conversation. Backup to Google Drive is simply a way of backing up your chat history so if you change devices or reset your phone all your messages aren't gone.

Once the conversation is in Google Drive however, if a valid law enforcement request is made for your files, your conversation is now compromised, as Google only provides server side encryption, which allows them to decrypt your files. This even opens you up to further compromise if the recipients Google account was ever hacked, as the hackers would have access to your message history with that person.

In short, no, the warning is accurate. It's not ambiguous, it tells you exactly what it means, if you save the messages to Google Drive, anyone with access to that account can retrieve the messages. This all boils down to the level of trust you have in your recipient. If you're not 100% sure that the person you're talking to isn't going to rat you out, best not to voice your dissent of your government to them.


No it doesn't. Whatsapp sends you a key and your client use that for encrypting backup.

(The remaining problem for me is that it is a closed-source timer bomb. And open-source alternatives do not provide cloud backup even as an option, which flee ordinary users, so activists hesitate to become only users, besides being impractical)

Source: https://blog.elcomsoft.com/2018/01/extract-and-decrypt-whatsapp-backups-from-google/