WhatsApp’s August 25 security announcement says the service is replacing the six-digit PIN used for two-step verification with a longer password that can include letters, numbers and special characters. The extra credential is intended to protect an account even when someone else obtains its one-time registration code. The rollout also allows more than one passkey on an account and gives Android users additional context about calls from numbers outside their contacts. A same-day TechCrunch report describes all three changes and notes that multiple passkeys are meant to accommodate people using WhatsApp across Android and iOS. The password protects the step after the one-time code WhatsApp’s stronger two-step verification targets account takeovers in which an attacker obtains the temporary code sent during phone-number registration. When two-step verification is enabled, the additional password remains a separate barrier: possession of the one-time code alone should not complete registration on another device. The previous credential was restricted to six digits. Allowing a longer combination of letters, numbers and special characters expands the possible credential space and makes an unpredictable password harder to guess. The new format does not automatically make every password strong, however; a short, obvious or reused choice can still weaken the
Read More











