Bollywood WhatsApp chats are leaking: How and is WhatsApp safe?

Bollywood WhatsApp chats are leaking: How and is WhatsApp safe?

Bollywood actress Deepika Padukone's WhatsApp leaks have raised several questions about WhatsApp's security and privacy policies.

Many Bollywood A-listers have been in the eye of the storm ever since the Narcotics Control Bureau acquired some of the WhatsApp chats about banned drugs. While this could have helped the authorities in probing the drug angle in Sushant Singh Rajput's death case, the chat leaks have raised several questions about the security and privacy policies of WhatsApp.

Netizens raise security questions after Deepika's WhatsApp chats leak

Ever since actress Deepika Padukone's chats have been leaked online, the netizens are in two minds about WhatsApp's policies. It is no secret that all WhatsApp chats are end-to-end encrypted. This means that the chats can only be accessed or read by the sender and receiver and nobody in between. Not even WhatsApp can access the chats of its users. The end-to-end encryption is activated automatically and no one has the option of turning it off.

"WhatsApp protects your messages with end-to-end encryption so that only you and the person you're communicating with can read what is sent, and nobody in between can access it, not even WhatsApp. It's important to remember that people sign up on WhatsApp using only a phone number, and WhatsApp doesn't have access to your message content. WhatsApp follows guidance provided by operating system manufacturers for on-device storage and we encourage people to take advantage of all the security features provided by operating systems such as strong passwords or biometric IDs to prevent third parties from accessing content stored on the device," WhatsApp spokesperson said in a statement.

WhatsApp has a different set of guidelines for law enforcement authorities

WhatsApp has a different set of rules concerning the law enforcement authorities. The company states in its blog that there are various guidelines that the law enforcement officials seeking records from WhatsApp have to follow while filing a request. "We disclose account records solely in accordance with our terms of service and applicable law. Additionally, we will assess whether requests are consistent with internationally recognized standards including human rights, due process, and the rule of law. A Mutual Legal Assistance Treaty request or letter rogatory may be required to compel the disclosure of the contents of an account," the WhatsApp blog says. The Facebook-owned messaging app takes various measures to preserve account records in connection with official criminal investigations for 90 days. However, requests submitted by non-law enforcement officials are not reviewed. This means that no news channel can write to WhatsApp and access the chats of users.

So what could have gone wrong in Deepika Padukone's case?

In Deepika and her manager Karisma's case, this could not be the case. It was being speculated that Jaya Saha, through whom the drug chats between Deepika and Karisma dating back to 2017 were accessed, had backed up her chats history on the Google Drive or Apple's iCloud. In such cases, WhatsApp notes that messages that are backed up on either Google Drive, iCloud, or any such platforms are not covered by WhatsApp's end-to-end protection. So to access the unprotected chats, a law enforcement official only needs the suspect's phone and can create a clone of it on another device using the phone cloning process. Through this process, the agencies and forensic experts can retrieve messages even if they are deleted from the device.

Accessing the chats physically is a lot easier

However, the easiest and most predictable way of leaking a chat can be screenshotting the chat and sharing it with others. But you can only take a screenshot if you know the password to someone's phone and can access the chats. In any case, breaking the encryption is a lot harder than accessing the chats physically.