WhatsApp Bolsters Security with Three New Features

WhatsApp security features: WhatsApp Bolsters Security with Three New Features
TL;DR

WhatsApp has introduced three new security upgrades—passkey support, reinforced two‑step verification, and an activity‑monitoring tool—to give users tighter control over their accounts and fend off credential‑theft attacks.

WhatsApp Unveils a Triple‑Layer Security Upgrade

Meta announced today that WhatsApp is adding three free, user‑facing security tools designed to make account hijacking significantly harder. The rollout, which begins this week for Android, iOS, and desktop clients, expands passkey authentication, tightens two‑step verification, and introduces a real‑time account‑activity monitor. All three features are enabled by default for new users and can be activated retroactively by existing accounts.

1. Expanded Passkey Support – Password‑Free Login

Passkeys are a FIDO2‑based credential that replaces passwords with cryptographic key pairs stored on a device’s secure enclave. When a user registers a passkey, the private key never leaves the device, while the public key is uploaded to WhatsApp’s servers. Authentication is performed via biometric verification (Face ID, Touch ID, or Android’s Trusted Face/Print) or a device PIN, then the private key signs a challenge from the server.

WhatsApp’s new implementation broadens platform coverage:

  • iOS 17+ devices can now use iCloud Keychain‑synced passkeys across iPhone, iPad, and Mac.
  • Android 14+ devices support Google Password Manager passkeys, enabling cross‑device login without re‑registration.
  • Desktop clients (Windows 11, macOS Ventura) can authenticate via a linked mobile device, eliminating the need for QR‑code scans.

By removing the password entry step, WhatsApp cuts the attack surface for phishing, credential stuffing, and brute‑force attacks. The move also aligns the app with industry‑wide shifts toward password‑less authentication championed by Apple, Google, and Microsoft.

2. Stronger Two‑Step Verification – A Hardened PIN Layer

WhatsApp already offered two‑step verification, which required a six‑digit PIN in addition to the SMS code during device registration. The new version adds two key improvements:

  • Encrypted PIN storage: The PIN is now salted and hashed on the device before being sent to Meta’s backend, preventing plaintext exposure even if the server is compromised.
  • Recovery email optionality: Users can link a recovery email address that receives a one‑time link for PIN reset, reducing reliance on SMS which is vulnerable to SIM‑swap attacks.

Meta also introduced a “PIN strength meter” that nudges users toward a random, non‑sequential PIN, and a lockout policy that temporarily disables registration attempts after five consecutive failed PIN entries.

3. Account‑Activity Monitor – Real‑Time Breach Alerts

The third feature is a dashboard that logs recent login attempts, device changes, and security‑related settings modifications. Users can view a timeline that includes:

  • Timestamp and geographic location of each login.
  • Device model and operating system version.
  • Whether the login was authenticated via passkey, SMS code, or two‑step verification.

If an unfamiliar device or location is detected, WhatsApp pushes an in‑app notification and offers an immediate “Log out of all sessions” button. The monitor also surfaces any failed two‑step verification attempts, giving users early warning of potential brute‑force probing.

3New Security Tools
Passkey‑Based LoginPassword‑Less Auth
Enhanced Two‑Step PINEncrypted & Recoverable

How WhatsApp Stacks Up Against Competitors

Feature WhatsApp Signal Telegram
End‑to‑End Encryption (E2EE) Default for all chats Default for all chats Optional (Secret Chats)
Passkey Support iOS 17+, Android 14+ iOS 16+, Android 13+ Not yet supported
Two‑Step Verification Encrypted PIN + optional email Encrypted PIN (no email) SMS code only
Login Activity Dashboard Real‑time log with alerts Basic device list None

Why These Changes Matter for the Average User

WhatsApp powers over 2 billion active accounts worldwide, making it a prime target for credential‑theft campaigns. By adopting passkeys, the platform eliminates the most common phishing vector—password reuse across services. The hardened two‑step verification mitigates SIM‑swap attacks, a threat that surged in 2023‑2024 and led to high‑profile account takeovers.

The activity monitor gives users visibility that was previously only available to enterprise‑grade messaging platforms. Early detection of anomalous logins can stop attackers before they gain full control, reducing the risk of social‑engineering scams that often leverage compromised WhatsApp accounts to spread malware.

Sources: Meta press release, Bloom Pakistan, The Mirror

Share This Story:
Tech Tabloid Desk

Tech Tabloid Desk

Editorial & Intelligence Desk

The Tech Tabloid Editorial Desk delivers breaking scoops, architectural deep-dives, hardware benchmarks, and verified analysis across artificial intelligence, semiconductors, cybersecurity, and global venture capital.

Keep Reading
Loading next Tech Tabloid story...