WhatsApp Introduces Passkey Login and Stronger Two‑Step Verification for Over 1 B Users
What Happened — WhatsApp announced that more than one billion users can now log in with FIDO‑compatible passkeys and that its two‑step verification has been upgraded from a six‑digit PIN to a longer alphanumeric password. The Android client also shows contextual information for calls from unknown numbers to help users spot scams.
Why It Matters for Compliance & Audit Readiness
- Passkey authentication eliminates shared secrets, directly addressing SOC 2 CC6.1 (Logical Access) and reducing the likelihood of credential‑theft findings during an audit.
- The stronger two‑step verification password satisfies the “password complexity” requirement of the SOC 2 security principle and provides concrete evidence for access‑control policies.
- Caller‑context information helps demonstrate a documented anti‑phishing awareness control, useful when auditors review user‑training and incident‑response evidence.
Who Is Affected – Consumer‑messaging platforms, telecom operators, and any organization that relies on WhatsApp for business communications (e.g., support centers, sales teams).
Recommended Actions – Review your own account‑access policies, require password‑less or MFA solutions that meet FIDO standards, update two‑step verification settings to meet complexity guidelines, and log authentication events for continuous‑monitoring evidence. Source: Malwarebytes Labs
Technical Notes – Passkeys are stored in the device’s credential manager and unlocked via biometrics or screen‑lock; they are resistant to phishing because no secret is typed. The new two‑step verification password can include upper‑/lower‑case letters, numbers, and symbols, raising the brute‑force cost dramatically. Caller‑context pulls contact‑group and geographic data to flag potentially fraudulent calls. Source: same as above