By Interestana AI Editorial — AI-drafted, human-overseen. How we report
WhatsApp Enhances Security With Multiple Passkeys and 2FA
WhatsApp has begun implementing a suite of enhanced account security features, significantly bolstering user protection. The rollout includes support for multiple passkeys, allowing users to register more than one digital key for account access, and a strengthened two-step verification (2SV) process. This dual approach aims to provide users with more flexible yet more secure methods for safeguarding their accounts against unauthorized access. The introduction of multiple passkey support means users are no longer limited to a single device or key for authentication, offering greater convenience and redundancy. Passkeys, which are based on FIDO standards, utilize cryptographic key pairs to authenticate users, offering a more secure alternative to traditional passwords by being resistant to phishing attacks and server-side breaches. The enhanced two-step verification process adds an extra layer of security by requiring a PIN or a six-digit code, in addition to the one-time password sent via SMS, when registering a new phone number on WhatsApp. This move addresses potential vulnerabilities in the 2SV system, particularly concerning SIM-swapping attacks where malicious actors can intercept SMS-based verification codes. By requiring an additional, pre-set PIN, WhatsApp makes it considerably harder for attackers to gain access even if they manage to compromise the user's phone number. These security upgrades are being rolled out globally to both Android and iOS users, with the company stating that the features will become available to everyone over the coming weeks. The company has not specified a precise end date for the global rollout but indicated it would be completed in stages. This initiative represents WhatsApp's ongoing commitment to user privacy and security, building upon previous measures such as end-to-end encryption for all messages and calls. The platform, owned by Meta Platforms, Inc., has faced scrutiny regarding data privacy and security in the past, making these proactive enhancements a critical step in maintaining user trust. The implementation of passkey support aligns with broader industry trends towards passwordless authentication, aiming to simplify the login experience while simultaneously improving security posture. The FIDO Alliance, a global leader in standards for secure authentication, has been a key proponent of passkey technology. WhatsApp's adoption of this standard is expected to encourage further integration across other digital platforms. The enhanced 2SV process also reflects a growing awareness of the limitations of SMS-based verification in the face of sophisticated cyber threats. By adding a PIN requirement, WhatsApp is adopting a more robust multi-factor authentication strategy that is less susceptible to common attack vectors. Users will be prompted to create a PIN when they enable the enhanced 2SV, and they will be asked to enter this PIN periodically to ensure they remember it. Failure to enter the correct PIN after multiple attempts could lead to account lockout, a measure designed to deter brute-force attacks. The company has also stated that it will provide clear in-app guidance to help users set up and manage these new security features, ensuring a smooth transition and maximizing adoption. This comprehensive update underscores WhatsApp's dedication to providing a secure communication environment for its over two billion global users.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.