El cifrado whatsapp funciona. Entonces, ¿por qué se filtran los chats?
WhatsApp encryption works. So why are chats being leaked?
WhatsApp encryption works. So why are chats being leaked? 在哥伦比亚,前政府官员、国会议员、军人和法官的聊天截图和音频几乎每天都在曝光。最常被问到的问题是:“WhatsApp 不是有端到端加密吗?”它确实有,而且运行良好。问题出在别处,这正好是一个回顾端到端加密(E2E)到底保护什么以及信任边界在哪里的好案例。
Threat model in one line: E2E protects the channel, not the endpoints. 威胁模型一句话总结:端到端加密保护的是传输通道,而不是终端设备。
[Phone A] ══ encrypted message ══> [Server] ══ encrypted message ══> [Phone B] plaintext (cannot read) plaintext ▲ ▲ └── this is where almost all leaks occur ──────────────────────────────────────┘ [手机 A] ══ 加密消息 ══> [服务器] ══ 加密消息 ══> [手机 B] 明文(无法读取) 明文 ▲ ▲ └── 几乎所有的泄露都发生在这里 ──────────────────────────────────────┘
No one along the path (the company, the ISP, someone intercepting the signal) can read the content. But at each end, the message is in plaintext, and that is where encryption no longer applies. 在传输路径上的任何人(公司、ISP、拦截信号的人)都无法读取内容。但在两端,消息是以明文形式存在的,而加密机制在此时已不再适用。
Real leakage vectors
真实的泄露途径
| Vector | Breaks encryption? | Comment |
|---|---|---|
| Legitimate counterpart (screenshot, forward, export) | No | It is an authorized recipient. It is the most common vector. |
| Seized device and forensic analysis | No | The content is read already decrypted on the device. |
| Cloud backups (Google Drive / iCloud) | Depends | Not E2E encrypted by default in WhatsApp; must be enabled. |
| Linked sessions (WhatsApp Web, desktop) | No | A forgotten session exposes the entire history. |
| Pegasus-type spyware | No | Reads what the user sees, directly on the device. |
| Metadata | N/A | Who talks to whom, when, and how often is not encrypted. |
| 途径 | 是否破解加密? | 备注 |
|---|---|---|
| 合法对话方(截图、转发、导出聊天) | 否 | 这是授权接收者,也是最常见的途径。 |
| 设备被扣押及取证分析 | 否 | 在设备上直接读取已解密的内容。 |
| 云备份 (Google Drive / iCloud) | 取决于设置 | WhatsApp 默认不开启端到端加密;需手动激活。 |
| 关联会话 (WhatsApp Web, 桌面端) | 否 | 被遗忘的会话会暴露整个聊天记录。 |
| Pegasus 类间谍软件 | 否 | 直接在设备上读取用户所看到的内容。 |
| 元数据 | 不适用 | 谁与谁通话、时间及频率等信息未加密。 |
No row requires breaking cryptography. It is social engineering, physical access, or misconfiguration. 以上任何一行都不需要破解加密技术。这全是社会工程学、物理访问或配置错误导致的。
Why they come out “in cascade” 为什么泄露会呈“级联”式爆发
A single phone contains dozens of conversations. By obtaining the device of a central node (an advisor, a chief of staff, a military officer), all their interlocutors appear. It is the equivalent of compromising a node with many edges in a graph: the impact radius is enormous. Added to this is the incentive: after a change of government, former allies become counterparts, and handing over chats serves as a bargaining chip. 一部手机包含数十个对话。通过获取一个中心节点(顾问、幕僚长、军官)的设备,他们所有的联系人都会暴露。这相当于在一个图中攻破了一个拥有许多连接的节点:影响范围巨大。此外还有利益驱动:政府更迭后,昔日的盟友变成了对手,交出聊天记录成了谈判的筹码。
Does switching apps fix it? 换个应用能解决吗?
It helps, but it doesn’t eliminate the problem. 有帮助,但不能根除问题。
| App | E2E | Note |
|---|---|---|
| By default | Cloud backups are unencrypted unless enabled. | |
| Signal | By default | Fewer metadata; usually considered the gold standard. |
| Telegram | Only in “Secret Chats” 1-on-1 | Normal chats and groups are not E2E; they stay on servers. |
| Line | In text (Letter Sealing) | Less audited. |
| 应用 | 端到端加密 | 备注 |
|---|---|---|
| 默认开启 | 云备份除非手动开启,否则不加密。 | |
| Signal | 默认开启 | 元数据较少;通常被视为行业标杆。 |
| Telegram | 仅限 1 对 1“私密聊天” | 普通聊天和群组非端到端加密;数据留存在服务器。 |
| Line | 文本加密 (Letter Sealing) | 审计较少。 |
The most common mistake: believing that Telegram is “more secure” and using normal chats for sensitive matters. There, there isn’t even E2E. And the perfect example that the best app doesn’t save you from human error: in 2025, high-ranking U.S. officials coordinated military issues via Signal and added a journalist by mistake. The encryption worked well; the failure was in the process. 最常见的错误是:认为 Telegram“更安全”,并在普通聊天中讨论敏感事项。那里甚至根本没有端到端加密。最好的应用也无法避免人为错误,一个完美的例子是:2025 年,美国高级官员通过 Signal 协调军事议题时,误将一名记者拉入群组。加密运行得很好,但流程出了问题。
Authenticity is another problem 真实性是另一个问题
A screenshot can be faked in minutes. An audio can be edited or cloned with AI. What has evidentiary value is the forensic extraction of the original device with a chain of custody, not the image circulating on social media. Leaks are selective: whoever leaks decides what and when to publish, and a fragment without context can change its meaning. Material obtained by illegal interception may be inadmissible as evidence, even if it is true. 截图可以在几分钟内伪造。音频可以通过人工智能编辑或克隆。具有证据价值的是通过监管链对原始设备进行取证提取,而不是社交媒体上流传的图片。泄露是有选择性的:泄露者决定发布什么和何时发布,而断章取义的片段可能会改变其含义。通过非法拦截获取的材料,即使内容属实,也可能无法作为证据。
Practical Checklist 实用清单
-
Enable disappearing messages in sensitive chats.
-
Enable encrypted WhatsApp backups or disable backups.
-
Review “Linked Devices” and close unknown sessions.
-
Strong screen lock and updated operating system.
-
Separate personal and work devices.
-
Base rule: Do not write anything in a chat that you are not willing to see published, because the other end can always export it.
-
在敏感聊天中开启“阅后即焚”消息。
-
开启 WhatsApp 加密备份,或直接关闭备份。
-
检查“已关联设备”并关闭未知会话。
-
设置强力屏幕锁并保持操作系统更新。
-
将个人设备与工作设备分开。
-
基本原则: 不要写下任何你不希望被公开的内容,因为对方随时可以将其导出。
Conclusion 结论
As developers, we know that a system is only as secure as its weakest link. Here, the encryption is well implemented; what fails is the human factor, device management, and default configuration. Next time someone says “WhatsApp is not secure,” it’s worth asking them which part of the threat model they are looking at. What other vectors would you add? Let me know in the comments. 作为开发者,我们知道系统的安全性取决于其最薄弱的环节。在这里,加密实现得很好;失败的是人为因素、设备管理和默认配置。下次有人说“WhatsApp 不安全”时,值得问问他们关注的是威胁模型的哪一部分。你们还会补充哪些途径?欢迎在评论区留言。