WhatsApp Rolls Out Multi‑Passkey Support and Alphanumeric Two‑Step Verification
What Happened — WhatsApp announced the rollout of multiple passkey support for both Android and iOS devices and upgraded its two‑step verification from a six‑digit PIN to a full alphanumeric password. Additional call‑screen context and a “Scam Alert” feature were added to give users more information about unknown callers and potential fraud attempts.
Why It Matters for Compliance & Audit Readiness —
- Credential‑based attacks remain the leading cause of SOC 2 “Security” (CC6.1) failures; stronger authentication directly mitigates that risk.
- Continuous evidence of multi‑factor and passkey usage can satisfy the “Logical Access” control testing required for SOC 2 audits.
- The new controls map to SOC 2 Access Control criteria (CC6.2) and provide a defensible audit trail for user‑authentication logs.
Who Is Affected — Global consumer messaging platforms; enterprises that rely on WhatsApp for business communications (e.g., customer‑support, field‑team coordination).
Recommended Actions — Review your organization’s access‑control policies against the new WhatsApp authentication options; enforce alphanumeric two‑step verification for any corporate‑managed accounts; capture authentication logs as audit evidence; update security‑awareness training to highlight passkey usage. Source: BleepingComputer
Technical Notes — The feature adds platform‑specific passkeys stored in device secure enclaves, and replaces the legacy 6‑digit PIN with a password that can include special characters. No CVEs are disclosed. Source: same article