This post is also available in:
End-to-end encryption can keep the contents of a conversation private, but it cannot protect users if an attacker manages to take over the account itself. With more than three billion people using WhatsApp, account recovery, authentication and social-engineering attempts remain a separate security challenge from protecting messages in transit.
The company is addressing that problem with three account-security updates: stronger two-step verification, additional information about unknown callers and expanded support for passkeys. The features are rolling out across Android and iOS, although availability may vary during the gradual release.
The biggest change affects two-step verification. The existing system uses a six-digit numerical PIN as an additional barrier against unauthorized account access. That PIN is now being upgraded to a full account password capable of containing letters, numbers and special characters.
According to WABetaInfo, the wider range of possible combinations can make a properly chosen password considerably harder to guess than a short numeric PIN, strengthening the additional authentication layer protecting the account.
It is also giving Android users more information about unfamiliar callers before they answer. When a call arrives from an unknown number, the app can indicate whether the number originates from another country and show how many groups the recipient shares with that caller.
Neither detail proves that a call is legitimate or malicious. However, the additional context can help users recognize suspicious approaches, for example, an unexpected international number with no shared groups, before deciding whether to engage.
The third update expands passkey authentication, which they say has already been enabled by more than one billion users. Passkeys replace traditional login codes with cryptographic credentials protected by a device’s fingerprint reader, facial recognition or screen lock.
Users can now associate multiple passkeys with one account, making the system more practical for people who regularly move between different devices or mobile operating systems.
Passkeys can also protect end-to-end encrypted chat backups. Instead of remembering a separate password or storing a 64-digit encryption key, users can unlock their encrypted backup using the authentication mechanism already secured on their device.
These features also have relevance for government, defense and critical-infrastructure personnel who use mainstream messaging applications in their personal or professional environments. Account takeover and social engineering can expose contacts and other sensitive information even when message encryption itself remains intact.
The updates do not change its underlying end-to-end encryption. Instead, they strengthen the security surrounding it: making accounts harder to take over, suspicious callers easier to assess and encrypted backups simpler to protect.
For users, the practical step is straightforward: keep the application updated and enable the strongest authentication options available as the new features reach their devices.


























