> if the user allows it to access the SD card. And since majority of the people allows everything on their Android device 1. So basically, if you're installing an app AND you're allowing the app to access all of your phone (and its dirty secrets) 2. I don't see why whatsapp would encrypt the chats (I might be very wrong on this one), isn't it better if we can access them offline through a computer if the phone crashe…
The idea of handling the SD card has a global shared filesystem that totally bypasses the application sandbox is a security disaster from the get go. Fortunately, SD cards are on the way out, and Google doesn't even bother to fix it at the system level since they're dropping it anyway at some point.