WhatsApp Introduces Optional Account Password Feature to Strengthen Login Security
WhatsApp has introduced an update for Android users via the Google Play Beta Program , advancing the version to 2.26.7.8. This update reveals the development of an optional account password feature aimed at enhancing security by adding an additional…
WhatsApp has introduced an update for Android users via the Google Play Beta Program , advancing the version to 2.26.7.8. This update reveals the development of an optional account password feature aimed at enhancing security by adding an additional layer to the existing two-step verification (2FA) system.
Currently, WhatsApp provides two-step verification as an optional security measure, requiring a secondary PIN after successful phone number registration.
Previously, the WhatsApp beta for Android 2.23.24.10 introduced account protection via a registered email address, facilitating account recovery when the 6-digit SMS verification code cannot be received, such as during SIM card unavailability.
Building on these measures, WhatsApp is developing an account password feature as a third authentication credential, intending to strengthen account security against unauthorized access, including scenarios involving SIM swapping or compromised devices.
The account password is an alphanumeric string, between 6 and 20 characters, requiring at least one letter and one number.
WhatsApp has introduced an update for Android users via the Google Play Beta Program , advancing the version to 2.26.7.8.
Once established, WhatsApp will assess the password's strength, aiding users in enhancing security. Users retain the flexibility to update or remove their password as needed.
This feature is integrated into the login process. If an account password is set but not two-step verification, WhatsApp prompts for the password immediately after the 6-digit SMS code is entered.
If both 2FA and the account password are enabled, users must enter the two-step verification PIN followed by the account password, forming a three-factor authentication barrier against unauthorized access.
Even if an attacker acquires both the SMS verification code and the 2FA PIN, techniques like SIM swapping would not circumvent the account password.
The account password feature is optional, allowing users to decide whether to enable this additional protection. It complements existing security mechanisms by introducing a credential layer known solely to the account owner.
This feature is currently under development according to Wabetainfo and is not yet publicly available. It will be gradually rolled out post testing, reinforcing account authentication against threats like SIM swapping and phishing for WhatsApp's global user base exceeding two billion.
Based on reporting by Cyber Security News.
