WhatsApp has reportedly rolled out an update that enhances account security through the addition of multiple passkeys and stronger two-step verification (2SV) options. This development aims to provide users with more robust methods for securing their accounts against unauthorized access.
The core of this security update appears to be the integration of multiple passkeys. Passkeys are a modern authentication standard designed to replace passwords, offering a more secure and user-friendly login experience. By allowing users to register multiple passkeys, WhatsApp enables greater flexibility and redundancy in account access. For instance, a user could register passkeys on their primary smartphone, a backup device, and a computer, ensuring they can still access their account even if one device is lost or compromised. This approach leverages public-key cryptography, making passkeys resistant to phishing attacks, which are a common vector for credential theft.
In conjunction with passkeys, the update also reportedly strengthens the existing two-step verification system. While the specific enhancements to 2SV were not detailed, typical improvements in this area often include more secure methods for generating or receiving verification codes, such as through authenticator apps rather than SMS, or more stringent requirements for resetting 2SV. Stronger 2SV mechanisms are critical because they add an additional layer of security beyond the primary authentication method, making it significantly harder for attackers to gain access even if they manage to compromise a user's password or passkey.
The report also mentions a separate feature for Android users, where incoming calls from non-contacts will display additional caller information, specifically their country. While this feature is distinct from the account security enhancements, it contributes to user safety by providing context for unknown callers, potentially helping users identify and avoid spam or fraudulent calls. This information could be particularly useful in mitigating social engineering attempts that often precede account compromise.
For users, the recommended mitigation advice for these types of security features typically involves actively enabling and configuring them. Users should be encouraged to set up passkeys on all their trusted devices and ensure their 2SV is configured using the strongest available method, such as a hardware security key or an authenticator app. Regularly reviewing security settings and being vigilant against phishing attempts are also standard best practices.
This update reflects a broader industry trend towards adopting more secure and user-friendly authentication methods. As cyber threats continue to evolve, platforms like WhatsApp are under increasing pressure to provide robust security features that protect user data and privacy. The move to support multiple passkeys and enhance 2SV aligns with the push for passwordless authentication and multi-factor security, aiming to make accounts more resilient against common attack vectors.






