Apps

WhatsApp Says One Billion People Now Sign In With A Passkey

Online messaging platform, WhatsApp, says more than a billion people have set up a passkey on the service and that it’s now letting a single account hold more than one.

A passkey signs a user back into WhatsApp with a fingerprint, a face scan or the phone’s screen lock code, with no code or PIN to type.

A second passkey matters for anyone who moves between platforms: until now an account could hold only one, and the company says the change is aimed at people who use Android and iOS devices together. The setting sits under Settings, then Account, then Passkeys.

Underneath the passkey sits an older layer, and it is being rewritten too. Two-step verification on WhatsApp has been a six-digit PIN, an extra check that stops someone taking over an account even if they obtain the one-time passcode used to register the account. That PIN becomes a full password, longer and alphanumeric, and able to carry special characters. “If you’ve been using 123456, this is your sign to upgrade,” the company wrote.

A separate addition targets scam calls rather than account takeover, and is on Android only for now. A call from a number that is not in the user’s contacts will show more about the caller, including whether the number is registered in another country and whether the two share any group chats.

The billion figure is WhatsApp’s own and covers people who have set a passkey up, not a measure of how often the credential is used. It arrives while the same technology is drawing scrutiny elsewhere. Palo Alto Networks researchers described three ways malware can abuse synced Google passkeys this month, and a WebKit flaw was found to expose iPhone IP addresses during passkey checks.

Large platforms have been moving users off SMS codes, with Microsoft setting Entra customers a deadline to replace SMS with passkeys.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button