https://engineering.fb.com/2021/09/10/security/whatsapp-e2ee-backups/ fbpx Skip to content Facebook Engineering Search this site [ ] # * Open Source + Open Source + Facebook Open Source * Platforms + Android + iOS + Web * Infrastructure Systems + Core Data + Data Infrastructure + DevInfra + Production Engineering + Security * Physical Infrastructure + Connectivity + Data Center Engineering + Networking & Traffic * Video Engineering & AR/VR + Video Engineering + Virtual Reality + Research Publications * Artificial Intelligence + ML Applications + AI Research + Research Publications * Watch Videos [ ] POSTED ON SEPTEMBER 10, 2021 TO Security How WhatsApp is enabling end-to-end encrypted backups WhatsApp end-to-end encrypted backups By Slavik Krassovsky, Gabriel Cadden For years, in order to safeguard the privacy of people's messages, WhatsApp has provided end-to-end encryption by default so messages can be seen only by the sender and recipient, and no one in between. Now, we're planning to give people the option to protect their WhatsApp backups using end-to-end encryption as well. People can already back up their WhatsApp message history via cloud-based services like Google Drive and iCloud. WhatsApp does not have access to these backups, and they are secured by the individual cloud-based storage services. But now, if people choose to enable end-to-end encrypted (E2EE) backups once available, neither WhatsApp nor the backup service provider will be able to access their backup or their backup encryption key. How E2EE backups work Generating encryption keys and passwords To enable E2EE backups, we developed an entirely new system for encryption key storage that works with both iOS and Android. With E2EE backups enabled, backups will be encrypted with a unique, randomly generated encryption key. People can choose to secure the key manually or with a user password. When someone opts for a password, the key is stored in a Backup Key Vault that is built based on a component called a hardware security module (HSM) -- specialized, secure hardware that can be used to securely store encryption keys. When the account owner needs access to their backup, they can access it with their encryption key, or they can use their personal password to retrieve their encryption key from the HSM-based Backup Key Vault and decrypt their backup. The HSM-based Backup Key Vault will be responsible for enforcing password verification attempts and rendering the key permanently inaccessible after a limited number of unsuccessful attempts to access it. These security measures provide protection against brute-force attempts to retrieve the key. WhatsApp will know only that a key exists in the HSM. It will not know the key itself. Storing keys in the Backup Key Vault WhatsApp's front-end service, ChatD, handles client connections and client-server authentication, and will implement a protocol that sends the keys to the backups to and from WhatsApp's servers. The client and HSM-based Backup Key Vault will exchange encrypted messages, the contents of which will not be accessible to ChatD itself. The HSM-based Backup Key Vault will sit behind ChatD and provide highly available and secure storage for the encryption keys to the backups. The backups themselves will be generated as a continuous stream of data that is encrypted using symmetric encryption with the generated key. With E2EE backups enabled, upon being encrypted, a backup can then be stored off device (e.g., to iCloud or Google Drive). WhatsApp serves over 2 billion people, and one of the core challenges of this product was to make sure the HSM-based Backup Key Vault operates reliably. To help ensure that the system is always available, the HSM-based Backup Key Vault service will be geographically distributed across multiple data centers to keep it up and running in case of a data center outage. WhatsApp end-to-end encrypted backups Backups can be end-to-end encrypted using a 64-digit encryption key. WhatsApp end-to-end encrypted backups Backups can also be secured with a password, in which case the encryption key is saved to the HSM-based Backup Key Vault. The HSM-based Backup Key Vault and the encryption and decryption process When the account owner uses a personal password to protect their end-to-end encrypted backup, the HSM-based Backup Key Vault will store and safeguard it. When someone wants to retrieve their backup: 1. They enter their password, which is encrypted and then verified by the Backup Key Vault. 2. Once the password is verified, the Backup Key Vault will send the encryption key back to the WhatsApp client. 3. With the key in hand, the WhatsApp client can then decrypt the backups. Alternatively, if an account owner has chosen to use the 64-digit key alone, they will have to manually enter the key themselves to decrypt and access their backups. E2EE backups will be available on iOS and Android in the coming weeks. Check out the end-to-end encrypted backups white paper to learn more about the technical details. TAGS: E2EE end-to-end encryption WhatsApp Read More in Security View All WhatsApp multi-device hero JUL 14, 2021 How WhatsApp enables multi-device capability Enforcing Encryption at Scale JUL 12, 2021 Enforcing encryption at scale [DIT-1] APR 16, 2021 DIT -- enabling de-identified data collection on WhatsApp Minesweeper FEB 9, 2021 Minesweeper automates root cause analysis as a first-line defense against bugs DELF: Safeguarding deletion correctness in online social networks AUG 12, 2020 DELF: Safeguarding deletion correctness in online social networks Pysa: An open source static analysis tool to detect and prevent security issues in Python code AUG 7, 2020 Pysa: An open source static analysis tool to detect and prevent security issues in Python code Related Posts --------------------------------------------------------------------- [WhatsApp-Multi-Device_Hero-Image_FINAL] Jul 14, 2021 How WhatsApp enables multi-device capability [DIT-1] Apr 16, 2021 DIT -- enabling de-identified data collection on WhatsApp [encryption_hero] Jul 12, 2021 Enforcing encryption at scale Related Positions --------------------------------------------------------------------- * Privacy Program Manager, System Integrations MENLO PARK, US * Application Security Engineer MENLO PARK, US * Application Security Engineer SEATTLE, US * Senior EU Security Lead DUBLIN, IRELAND * Senior EU Security Lead LONDON, UNITED KINGDOM See All Jobs Available Positions --------------------------------------------------------------------- * Privacy Program Manager, System Integrations MENLO PARK, US * Application Security Engineer MENLO PARK, US * Application Security Engineer SEATTLE, US * Senior EU Security Lead DUBLIN, IRELAND * Senior EU Security Lead LONDON, UNITED KINGDOM See All Jobs Stay Connected * footer-fb-engineering Facebook Engineering Like * footer-fbopensource @fbOpenSource Follow * footer-research Facebook Research Like * footer-developers Facebook Developers Like * footer-rss RSS Subscribe Open Source Facebook believes in building community through open source technology. Explore our latest projects in Artificial Intelligence, Data Infrastructure, Development Tools, Front End, Languages, Platforms, Security, Virtual Reality, and more. * android ANDROID * ios iOS * web WEB * backend BACKEND * hardware HARDWARE Learn More Facebook (c) 2021 * About * Careers * Privacy * Cookies * Terms * Help To help personalize content, tailor and measure ads, and provide a safer experience, we use cookies. By clicking or navigating the site, you agree to allow our collection of information on and off Facebook through cookies. Learn more, including about available controls: Cookies Policy I Agree