WhatsApp Adds Multi‑Passkey Support for Phishing‑Resistant Sign‑Ins on iOS and Android
What Happened — Meta announced that WhatsApp now supports multiple passkeys per account, allowing users on both iOS and Android to authenticate with phishing‑resistant, FIDO2‑based credentials. The change expands on the October 2023 Android rollout and is already used by more than 1 billion passkey‑enabled accounts.
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (Logical Access) requires strong, MFA‑level authentication; passkeys provide a verifiable, password‑less control that auditors can evidence.
- Continuous‑compliance programs must capture credential‑management events; multi‑passkey enrollment creates a clear audit trail for each device.
- Security awareness training can now reference a concrete, phishing‑resistant login method, reducing reliance on risky password practices.
Who Is Affected — Consumer messaging services, enterprises that use WhatsApp Business for customer support, and any organization that integrates WhatsApp APIs for communications.
Recommended Actions —
- Update your access‑control policy to require passkey or equivalent MFA for all privileged WhatsApp Business accounts.
- Capture passkey enrollment logs as part of your SOC 2 evidence collection (e.g., via continuous‑control monitoring).
- Incorporate passkey usage into security‑awareness curricula to reinforce phishing‑resistant practices.
Source: The Hacker News
Technical Notes — Passkeys are built on the FIDO2/WebAuthn standards, stored in device‑specific secure enclaves (Secure Enclave on iOS, Titan M on Android). They eliminate password transmission and are resistant to phishing, man‑in‑the‑middle, and credential‑stuffing attacks. Source: same as above