WhatsApp

Official website (opens in a new tab)

The app that brought end-to-end encryption to billions of users, but whose operator, Meta, makes its living from exploiting everything the encryption leaves out — metadata, address book, backups.

At a glance
• End-to-end encryption — ✅ Good
• End-to-end authentication — ❌ Poor
• End-to-end security — ❌ Poor
• No identity substitution — ❌ Poor
• Open source client — ❌ Poor
• End-to-end multi-device — ✅ Good
• Minimal personal data — ❌ Poor
• No contact discovery and spam — ❌ Poor
• Post-quantum encryption — ❌ Poor

WhatsApp occupies a unique place in this benchmark: it is the app that put end-to-end encryption in the pockets of billions of people, by adopting the Signal protocol in 2016archived for all conversations, by default and with no way for the user to turn it off. But WhatsApp also shows, better than any other messaging app, that encrypted content is not enough to make a communication private. Its operator, Meta, makes its living from exploiting data — and everything that is not message content (metadata, address book, backups in their default configuration, interactions with AI) falls outside end-to-end encryption. The official linearchived, “WhatsApp has no ability to see the content of messages,” illustrates the problem on two counts. First, it is false, because WhatsApp does not meet the end-to-end authentication criterion. Without end-to-end authentication, the operator, which itself distributes its users’ keys through its directory, is able to insert itself into a conversation and therefore to access the content of messages; encryption alone does not prevent this (see the End-to-end authentication criterion). Second, its scope is narrow: it only talks about message content. Yet WhatsApp’s own privacy policy describes what else is collectedarchived: account information, usage and connection metadata (who communicates with whom, when, how often, from which device), and the address book when the user shares it. End-to-end encryption does not protect that data.

Notable points

By default, WhatsApp backups go to iCloud or Google Drive without end-to-end encryption: Apple or Google then have access to the full history. An end-to-end encrypted backup option has existed since 2021; it is off by defaultarchived. And the flaw is contagious: it only takes one of your contacts backing up with the default settings for your conversations with them to be exposed, regardless of your own digital hygiene.

WhatsApp now includes an AI assistant. By design, what you write to it is read by the system that processes it: these exchanges are communication with a service, not a private end-to-end conversation. In 2025, Meta announced Private Processingarchived, an architecture that confines this processing to attested secure hardware, which Meta presents as inaccessible even to itself. This is the same logic already seen with Signal’s profile backup: confidentiality that rests not on a mathematical impossibility, but on an infrastructure promise; as long as the enclave holds, all is well, and the day it gives way, these exchanges are exposed. The presence of the assistant at the heart of the application also feeds the confusion between “the app is encrypted” and “everything that happens in it is confidential.”

End-to-end encryption ✅ Good

All conversations (messages, attachments, calls, groups included) are end-to-end encrypted using the Signal protocol, and encryption cannot be turned off. One simply needs to be clear about its scope: this encryption covers the exchanges, not the services around them. Backups, in particular, fall outside it in their default configuration.

End-to-end authentication ❌ Poor

To add a contact, all you need to do is enter their number: the application fetches their public key from Meta’s centralized directory and automatically trusts it, without any interaction with the contact. This is precisely the directory scenario described in the End-to-end authentication criterion. Manual verification (comparing 60 digits, or scanning each other’s QR code) is optional and exceedingly rare. WhatsApp was one of the first mainstream players to deploy a Key Transparency mechanism (the Auditable Key Directoryarchived), which makes its directory’s operations auditable. As explained in the criterion on identity substitution, this advance reduces the risk without changing its nature: security still rests on a third party.

End-to-end security ❌ Poor

End-to-end authentication is not provided, so there is no end-to-end security.

No identity substitution ❌ Poor

The account is tied to the phone number and can be re-registered with an SMS code, with all the consequences detailed in the No identity substitution criterion. The additional protections (two-step verification) are optional, off by default, and can be bypassed by email or simply by waiting seven days. Note that on WhatsApp, the alert telling your contacts that your key has changed is off by defaultarchived: a key change, whether legitimate or malicious, is therefore completely silent.

Open source client ❌ Poor

WhatsApp is the only solution in the benchmark to fail here. The encryption protocol is documented, but the application itself, the one that handles the keys, is closed source. The client can be neither recompiled nor audited. The Code Verifyarchived extension, developed with Cloudflare, only attests that the WhatsApp Web code received by the browser is identical to the code Meta published, not what that code does; nothing comparable exists for the native apps. The most telling illustration comes from academia: the researchers who published the first formal analysis of WhatsApp’s multi-device protocolarchived had to reverse-engineer the implementation, for lack of source code and complete documentation.

End-to-end multi-device ✅ Good

Since its 2021 overhaul, WhatsApp’s multi-device supportarchived has followed the same model as Signal’s: each device has its own key, the primary phone signs the keys of the companion devices, and it maintains a signed device list that the server cannot alter; the pairing secret displayed in the QR code is never sent to the server. The architecture meets the criterion. One caveat, though, which ties in with the previous criterion: without an open client, these guarantees are hard to verify.

Minimal personal data ❌ Poor

A phone number is mandatory, and the application strongly encourages sharing the address book — which hands the operator data about third parties who never gave their consent. On top of that come the metadata (who talks to whom, when, from which device), which end-to-end encryption does not protect and which join the mass of data collected by a company whose revenue comes almost entirely from advertising (see Meta’s official 10-K filing for fiscal year 2025archived, Item 1A, “Risk Factors”: “We generate substantially all of our revenue from advertising. The loss of marketers, or reduction in spending by marketers, could seriously harm our business.” Or, in Part I, Item 1, “Business”: “Currently, we generate substantially all of our revenue from selling advertising placements on our family of apps to marketers”).

No contact discovery and spam ❌ Poor

Anyone who knows your number can find you and, above all, send you content directly (messages, attachments, calls) without you having accepted anything, since there is no contact-request confirmation. This is the most exposed configuration in the criterion’s table, and its consequences are not theoretical: it was on WhatsApp that, in 2019, the textbook zero-click attackarchived took place, in which a simple call, even one left unanswered, installed the Pegasus spyware — an attack attributed to NSO Grouparchived. The only prerequisite was knowing the target’s number. WhatsApp has since added reactive measures, such as the option to silence unknown callersarchived (2023); they reduce the nuisance without removing the attack surface, since a call from a stranger is still processed by the application — only the ringing disappears.

Post-quantum encryption ❌ Poor

WhatsApp has announced no post-quantum encryption for its conversations. Meta has indeed begun a post-quantum migration of its internal infrastructure, but it does not concern the end-to-end encryption of messages.