Hacker News new | ask | show | jobs
by jononor 2777 days ago
Whatapps needs a Google Drive API token to write that backup, don't they? If so, surely they can read it using the same token?
2 comments

My assumption was that the data gets handed off to Google/Apple functions on your phone that handle backups. Could anyone confirm?
Would there be any way for a user to see if/when the token has been reused? Doubtful but perhaps Google provides (or could provide) some kind of log similar to how Facebook lets you view Active Sign Ins and Sign In history.
Once it has been used, it is too late. This insight would therefore not be a solution to the problem.