Is sharing passwords via WhatsApp safe enough?
The end-to-end encryption argument
WhatsApp uses end-to-end encryption, which means messages cannot be intercepted in transit. That sounds reassuring. Many people take it as a green light to share sensitive information — passwords included. But transit security is only one piece of the puzzle, and arguably not the most important one.
What end-to-end encryption does not protect
End-to-end encryption protects the message while it is moving between devices. It does not protect:
- The message once it arrives — it sits unencrypted in the recipient's chat history
- Cloud backups — WhatsApp backups to Google Drive or iCloud are often unencrypted, or encrypted with a key stored by the cloud provider
- Screenshots — the recipient can screenshot the message at any point
- Device access — anyone who picks up an unlocked phone can scroll through the conversation
- The recipient's account — if their WhatsApp is compromised or they log in on a new device, all previous messages are potentially accessible
Persistence is the core problem
The fundamental issue with sharing a password via any messaging app — WhatsApp, Telegram, Signal, iMessage — is persistence. Once the message is sent, it stays in the conversation history indefinitely unless manually deleted. Most people never delete individual messages. The password you sent six months ago to help a colleague log into a shared account is still sitting there, waiting to be found.
Business accounts and BYOD
In a work context, things get more complicated. When employees use personal WhatsApp accounts on personal devices to share company credentials, those credentials leave the organisation's control entirely. There is no audit trail, no ability to revoke access to the message, and no way to enforce deletion. For any business taking information security seriously, this is a significant governance problem.
A better approach for quick sharing
The appeal of WhatsApp for password sharing is the speed and convenience — you can reach someone instantly. You don't have to give that up. You can paste a PassTransfer link into a WhatsApp message just as easily as typing a password. The difference is:
- The link is only valid once — after the recipient opens it, the password is gone
- Even if someone scrolls back through the chat months later, the link no longer works
- The password itself never appears in the chat history
The practical takeaway
WhatsApp is a reasonable channel for sending a one-time link. It is not a reasonable channel for sending the password itself. Keep the credentials out of the chat and use a tool built for secure, single-use delivery. The convenience stays; the risk disappears.