Meta announced a set of new WhatsApp security features on Tuesday, targeting three of the most common ways accounts get compromised: weak two-step verification codes, single-device passkey limitations, and unfamiliar callers exploiting a lack of context. With WhatsApp now serving more than three billion users worldwide, the company framed the updates as a necessary expansion of account-level protection to sit alongside its existing end-to-end encryption, which secures message content but does nothing on its own to stop someone from taking over an account in the first place.
The most significant of the three changes overhauls two-step verification, a feature WhatsApp has offered for years as an extra layer of protection against account takeovers, even when an attacker manages to obtain a user’s one-time registration code. Until now, that protection relied on a simple six-digit PIN, a format WhatsApp itself acknowledged was often left at easily guessable defaults, with the company specifically citing “123456” as an example of the kind of PIN users should move away from immediately. The PIN is now being replaced with a full alphanumeric password, allowing users to create longer credentials that combine letters, numbers and special characters, a considerably harder target for anyone attempting to brute-force their way into an account after intercepting a verification code.
The second update expands passkey support to allow more than one passkey per account, addressing a limitation that had been a genuine inconvenience for anyone using WhatsApp across both an iPhone and an Android device. Passkeys let users log back into their accounts using Face ID, Touch ID or a device’s screen lock, rather than typing a password or entering a one-time code, and WhatsApp says more than one billion people have already set one up since the feature first rolled out on Android in October 2023 and expanded to iPhone the following year. Because passkey credentials are tied to the device that generates them, users who switch between two different operating systems previously had to choose which device’s passkey to prioritise. With this update, both can now be registered to the same account simultaneously, removing what had been one of the more practical friction points in the feature’s rollout.
The third change is narrower in scope but addresses a different kind of risk entirely, social engineering rather than credential theft. Android users will now see additional context when receiving a call from a number that isn’t saved in their contacts, including whether the number originates from a different country and whether the caller shares any groups in common with the user. That detail matters because a meaningful share of WhatsApp account takeovers don’t rely on breaking encryption or cracking a password at all, but instead depend on convincing a user to hand over a verification code directly, often through a call or message designed to look legitimate. Giving users more visible information about an unfamiliar caller before they answer is aimed squarely at making that kind of manipulation harder to pull off.
Taken together, the three updates reflect a broader shift in how WhatsApp is approaching account security, moving away from protections that depend on users remembering or safeguarding a secret, whether a PIN, a password or a one-time code, and toward methods rooted in device-level biometrics and contextual information that are inherently harder to phish. Passkeys in particular represent that shift most clearly, since they eliminate the username-and-password model altogether in favour of credentials that never leave the user’s own device and that an attacker would need physical access to actually exploit.
The timing of the announcement is not incidental. WhatsApp and competing messaging platforms, including Signal and Telegram, have faced growing pressure to modernise account security as phishing techniques and social engineering attempts targeting messaging app users have become more sophisticated in recent years. For an app of WhatsApp’s scale, protecting three billion individual accounts against increasingly convincing impersonation attempts is a materially different challenge than it was even a few years ago, and Tuesday’s updates suggest the company is treating account-level security as an area requiring continued, incremental investment rather than a problem solved once with the introduction of end-to-end encryption.
All three features are rolling out now and can be managed directly within the app. Users looking to switch to the new password-based two-step verification, or to add a second passkey for a device running a different operating system, can do so from WhatsApp’s account settings menu, where the passkey and two-step verification options have been updated to reflect the new choices. WhatsApp has recommended that any user still relying on a simple or previously used PIN take the opportunity to update it now that stronger password options are available.
Compiled by the Weekly PK Tech Desk.

Leave a Reply