Hacker News new | ask | show | jobs
by stalf 2776 days ago
Even though I also find it very suspicious that WhatsApp keeps proactively badgering me about turning backup on, I don’t see how this could be exploited by Facebook as the messages are stored in iCloud and Google Drive which it can’t access.
1 comments

Whatapps needs a Google Drive API token to write that backup, don't they? If so, surely they can read it using the same token?
My assumption was that the data gets handed off to Google/Apple functions on your phone that handle backups. Could anyone confirm?
Would there be any way for a user to see if/when the token has been reused? Doubtful but perhaps Google provides (or could provide) some kind of log similar to how Facebook lets you view Active Sign Ins and Sign In history.
Once it has been used, it is too late. This insight would therefore not be a solution to the problem.