Is WhatsApp safe to use? How does its end-to-end encryption work? (2024)

Is WhatsApp safe to use? How does its end-to-end encryption work? (1)

Edgar Cervantes / Android Authority

WhatsApp is easily the single most used chat app in the world, handily surpassing rivals like Messenger, Signal, and Telegram. Given how much sensitive data we tend to share in online conversations, is the app safe to use? Moreover, should you be worried about potential hacks or data leaks, even with the encryption WhatsApp claims to offer?

So to answer those questions, let’s take a closer look at WhatsApp’s security measures, including the end-to-end encryption it claims to offer. Later, we’ll also discuss some additional features you can take advantage of to keep your chats safe from prying eyes.

QUICK ANSWER

Yes, WhatsApp is safe and better than texting as all chats are automatically encrypted. This means your messages cannot be read or eavesdropped by anyone, including WhatsApp and its parent company Meta. Keep reading to learn more about how the app's end-to-end encryption works and what you can do to secure your WhatsApp chats further.

Is WhatsApp safe? What is end-to-end encryption?

Is WhatsApp safe to use? How does its end-to-end encryption work? (2)

Rita El Khoury / Android Authority

Instant messaging has been around since the dawn of the internet, but early implementations were far from secure. For one, many of them exchanged messages over the internet in plain text. This meant that anyone with access to the company’s servers could read your messages, as could any intermediaries or malicious actors down the line. And even though many services implemented encryption-in-transit in the late 2000s, the companies operating chat apps usually held the keys to decrypt user communications. Put simply, your chats were never truly private.

More recently, however, many platforms have adopted end-to-end encryption (E2EE) to improve message confidentiality and user privacy. In an end-to-end encrypted communication channel, only the sender and receiver have the keys necessary to decrypt each other’s messages. Nobody else — including the platform, your ISP, or even a hacker with access to the encrypted data — can read your messages.

WhatsApp uses end-to-end encryption for all messages and calls by default.

Since 2014, WhatsApp’s end-to-end encryption system has relied on Open Whisper Systems’ open-source Signal protocol. You may know the company as the developers of chat app Signal, a WhatsApp competitor that prides itself on putting security and privacy first.

According to WhatsApp’s documentation, virtually all of your communication on the platform is secured with end-to-end encryption. This includes messages, media, voice notes, calls, and even status updates.

How safe is WhatsApp? Encryption explained

The Signal encryption protocol used by WhatsApp combines multiple cryptographic techniques, starting with public-key encryption. Put simply, it involves each user owning a pair of randomly generated keys — one that stays private and another that gets distributed publicly.

The idea here is that a sender uses the recipient’s public key to encrypt messages. On the other end, the recipient uses their private key to decrypt it. Since your device generates the private key, WhatsApp never has access to it. This simple cryptographic technique has been used for decades now, with modified versions securing everything from emails to cryptocurrency wallets.

The Signal protocol used by WhatsApp is universally regarded as the gold standard for encrypted messaging.

However, standard public-key encryption isn’t secure enough on its own. It suffers from a single point of failure. If your private key ever gets compromised, an attacker could decrypt your past, present, and future chats completely unchecked. To remedy this, the developers behind Signal’s protocol devised a novel technique called double ratchet encryption.

Instead of using a static set of keys for each user, the protocol uses a mix of permanent and temporary keys. The latter changes every time you send a new message. This means that if a theoretical attacker were to gain access to one particular key, they wouldn’t be able to decrypt more than a few messages. Constantly renewing keys seems like an overkill solution, but it’s also simple enough that our smartphones can handle it effortlessly.

Of course, there’s a lot more to WhatsApp’s encryption system — which you can find in the company’s technical white paper on the subject. However, the crux of the matter is that the encryption is sound and robust enough to ward off eavesdropping and similar basic attacks.

Is WhatsApp safe from hackers? What do the experts think?

Is WhatsApp safe to use? How does its end-to-end encryption work? (4)

Dhruv Bhutani / Android Authority

WhatsApp lets you verify that your individual chats and calls are end-to-end encrypted. Simply open a chat within the app, tap on the contact’s name, and, finally, the “Encryption” label. You’ll find yourself presented with a QR code and a 60-digit number. Now, follow the same steps on the recipient’s phone and compare the values.

As long as the number matches on both devices, your chat is properly end-to-end encrypted. WhatsApp calls this a “security code,” but it’s just an easier way to represent the public key we spoke about earlier. Completing this step also helps ensure that your communication is reaching the right person and not a malicious imposter pretending to be your contact. It also keeps WhatsApp accountable — if the keys don’t match, it would place the company under tremendous scrutiny.

WhatsApp's key verification feature ensure that your chat didn't get hijacked or intercepted on the way to you.

Having said that, WhatsApp isn’t perfect — it records a fair amount of information about you outside of the chat interface. The data collected includes your contact list, location, device identifiers, and transaction history, among others. However, Signal is the only alternative that claims to collect less data and emphasizes security with independent security audits. Other popular chat applications like Messenger and Telegram don’t even offer end-to-end encryption by default.

For this reason, security researchers recommend WhatsApp over most of the competition. The Electronic Frontier Foundation is a vocal critic of the app’s data-sharing practices. However, it maintains that “WhatsApp still uses strong end-to-end encryption, and there is no reason to doubt the security of the contents of your messages on WhatsApp.”

Signal co-founder and renowned cryptographer Moxie Marlinspike has also vouched for the app in the past. In a 2017 blog post, he said, “We [Signal] believe that WhatsApp remains a great choice for users concerned with the privacy of their message content.”

Do you think WhatsApp is safe?

1071 votes

How does WhatsApp collect and use my data?

Is WhatsApp safe to use? How does its end-to-end encryption work? (5)

Edgar Cervantes / Android Authority

By now, it’s clear that WhatsApp does not store your chats, media, and other private data. But what else does the app know about you and how does it store this data? We combed through WhatsApp’s Privacy Policy and here are the highlights in simplified form:

  • You provide your phone number and basic data about yourself like a name, status, and profile picture when signing up for a WhatsApp account.
  • If you agree to the location permission and use a feature like Live Location, WhatsApp can potentially see and collect geolocation data. It can also deduce your approximate location based on your internet connection and phone number’s region code.
  • If you use WhatsApp Payments, the platform can see transaction data like the recipient, shipping details, and amount.
  • The platform does not collect or store your contact list. However, it does keep a record once it detects a contact already has a WhatsApp account.
  • WhatsApp collects details about usage activity like Last Seen, online activity, device model, signal strength, and time zone.

Most of this information seems harmless on the surface. However, WhatsApp is only one of many Meta platforms. So even basic data can go a long way toward identifying you as an individual when combined with your Facebook and Instagram profiles. For example, Meta can use phone numbers to recommend new friends on Facebook based on frequent WhatsApp conversations. Sure, it cannot see the contents of your messages, but it still knows that some communication took place.

How to keep your WhatsApp safe from hackers

Is WhatsApp safe to use? How does its end-to-end encryption work? (6)

Andy Walker / Android Authority

Your WhatsApp chats stay encrypted and confidential at all times. However, there are still some potential security pitfalls that you should be aware of. While your chats won’t ever get intercepted on their way to you, they’re pretty exposed once they reach their destination. In other words, your phone and any recipient’s device are far easier targets for potential attacks.

If you lose your smartphone, for example, an attacker with physical access to it could copy your WhatsApp message database off the device. Thankfully, WhatsApp encrypts this file, and recovering the key requires root access on Android. If you don’t know what that is, you likely have nothing to worry about. That said, they could still access media files such as images and videos. All of this can be easily remedied with a simple screen lock on your smartphone.

Your phone and cloud storage account are easier targets for most attackers, so secure your backups well.

Another well-publicized potential attack vector involves cloud backups to Google Drive and iCloud. By default, WhatsApp will back up your chats to these services without any encryption whatsoever. This means that if an attacker somehow gains access to your cloud storage account, they could also theoretically get their hands on your WhatsApp data.

Luckily, WhatsApp has already rolled out the ability to encrypt chat backups with a password or encryption key. The latter is a randomly generated 64-digit key. You can store it in a password manager for maximum security. This is an opt-in feature, so make sure that you enable it under Settings > Chats > Chat backup within the WhatsApp app on Android.

On the subject of WhatsApp’s optional security features, consider turning on two-factor authentication as well. You can find it under WhatsApp Settings > Account > Two-step verification. This will require you to enter a PIN when registering your account on a new phone. It won’t prevent data leaks but could prevent fraudulent login attempts from malicious actors.

FAQs

WhatsApp uses end-to-end encryption, which means nobody except the sender and recipient can read messages. Other chat apps like Facebook Messenger and Telegram don’t use end-to-end encryption by default.

Yes, all chats on WhatsApp are encrypted by default, which isn’t the case with SMS or text messaging. WhatsApp uses an end-to-end encryption system based on the Signal protocol.

A remote hacker cannot read your WhatsApp chat history because all communication on the platform is encrypted. However, someone with physical access to your smartphone could read your messages.

Yes, WhatsApp is safe for sending private photos as it encrypts all messages between the sender and recipient.

Your chats and media on WhatsApp are safe and private. However, other metadata like your Last Seen, phone hardware details, and general location (based on your IP address) may be visible to WhatsApp and its owner, Meta/Facebook.

Features

Android SecurityWhatsApp

Is WhatsApp safe to use? How does its end-to-end encryption work? (2024)

FAQs

Is WhatsApp safe to use? How does its end-to-end encryption work? ›

WhatsApp provides end-to-end encryption for all personal messages that you send and receive. This makes sure that only you and the person you're talking to can read or listen to them. With end-to-end encrypted backup, you can add that same layer of protection to your iCloud and Google Account backups.

How secure is WhatsApp end-to-end encryption? ›

Secure Server Relay. While WhatsApp's servers facilitate call setup and relay the encrypted data between devices, they do not have access to the actual content of your calls due to end-to-end encryption. This means that even if someone gains access to WhatsApp's servers, they cannot eavesdrop on your conversations.

Can anyone break end-to-end encryption in WhatsApp? ›

Breaking encryption on its platform, the company argued, would infringe upon users' fundamental right to privacy and consequently, WhatsApp is seeking judicial intervention to challenge the rule as unconstitutional.

What is the disadvantage of end-to-end encryption on WhatsApp? ›

Cons. Despite the considerable security benefits of end-to-end encryption, it is not invincible. Sophisticated cybercriminals could potentially exploit the encryption feature by compromising a user's device and gaining access to the decryption keys.

Are there any dangers in using WhatsApp? ›

Often, hackers try to steal your personal information by sending you a malicious link to download. Once you do, they can get your personal information through infected files. If you use WhatsApp on your desktop, it's easier for hackers to send malicious desktop programs.

Can I trust end-to-end encryption? ›

Additionally, end-to-end encryption does not protect against threats posed by hacked devices or phishing attacks, which can compromise the security of communications.

Is WhatsApp really private? ›

We can't see your personal messages or hear your calls, and neither can Meta: Neither WhatsApp nor Meta can read your messages or hear your calls with your friends, family, and co-workers on WhatsApp. Whatever you share, it stays between you. That's because your personal messages are protected by end-to-end encryption.

What is the loophole in WhatsApp encryption? ›

The loophole in WhatsApp's end-to-end encryption is simple: The recipient of any WhatsApp message can flag it. Once flagged, the message is copied on the recipient's device and sent as a separate message to Facebook for review.

What are the disadvantages of end-to-end encryption? ›

End-to-end encryption cons

Though everything sounds good, there are still drawbacks of the E2EE: Message metadata cannot be hidden. It does not guarantee data protection once the message has reached the recipient's device. This type of encryption can be banned by governments and law enforcements.

Why do people avoid WhatsApp? ›

Data Privacy and Security: WhatsApp has been criticized for its data privacy record and the lack of protection for users' personal information. In contrast, Beekeeper offers banking-standard security, with data hosted in ISO 27001 certified data centers and full encryption using AES 256 and TLS 1.2 encryption.

Can someone hack my WhatsApp? ›

A hacker needs your verification code to gain access to your WhatsApp account, so handle the codes with care. Also, check the linked devices on your account from WhatsApp settings and delete all unknown devices linked to your WhatsApp account.

What are 3 disadvantages of WhatsApp? ›

Disadvantages
  • No support for VoIP numbers. As of 2022, WhatsApp no longer supports VoIP numbers. ...
  • Limited account access. ...
  • Potential over-messaging. ...
  • Ties to Facebook. ...
  • Dependency on internet access. ...
  • Limited customization.
5 days ago

Can my WhatsApp chats be traced? ›

WhatsApp can trace the origin of a message using its source and destination codes, which many forms of communication rely on. These things do not reveal any content, but they do allow messages to be tracked from one person to another.

Can WhatsApp messages be traced by police? ›

WhatsApp does have end-to-end encryption, which means that messages are only accessible to the sender and recipient. However, if the police obtain a warrant or court order, they can request access to the messages from WhatsApp.

Can WhatsApp messages be tracked? ›

Can whatsapp messages be tracked? Yes but only by WhatsApp and Facebook. Unless your whatsapp account is hacked, you will not be tracked because WhatsApp is end to end encrypted.

Is WhatsApp safe to send private pictures? ›

Is WhatsApp safe for sending private photos? WhatsApp encrypts your data while in transit, which makes the app a good option for sending private photos. While images and videos are moving between users, they are encrypted and cannot be decrypted until they reach their intended recipient.

Top Articles
Latest Posts
Article information

Author: The Hon. Margery Christiansen

Last Updated:

Views: 6124

Rating: 5 / 5 (70 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: The Hon. Margery Christiansen

Birthday: 2000-07-07

Address: 5050 Breitenberg Knoll, New Robert, MI 45409

Phone: +2556892639372

Job: Investor Mining Engineer

Hobby: Sketching, Cosplaying, Glassblowing, Genealogy, Crocheting, Archery, Skateboarding

Introduction: My name is The Hon. Margery Christiansen, I am a bright, adorable, precious, inexpensive, gorgeous, comfortable, happy person who loves writing and wants to share my knowledge and understanding with you.