WhatsApp has unveiled a new security feature in its latest Android update through the Google Play Beta Program, advancing the version to 2.26.7.8. This update introduces an optional account password, aimed at enhancing user security by complementing the existing two-step verification (2FA) system.
Enhancing Security Measures
Previously, WhatsApp implemented two-step verification as a security option, requiring users to input a second PIN after their phone number registration. Furthermore, a prior beta update, version 2.23.24.10, offered users the option to safeguard their accounts using a registered email address, facilitating quick access recovery when the SMS verification code cannot be received.
Building on these developments, WhatsApp is now focusing on an account password as a third layer in the verification process. This initiative is designed to bolster account security, significantly reducing the risk of unauthorized access, particularly in scenarios involving SIM card swapping or compromised devices.
Functionality of the Account Password
The proposed account password is an alphanumeric string, ranging from 6 to 20 characters, which must contain at least one letter and one number. Once users set their password, WhatsApp will assess its strength, offering suggestions for stronger security choices. Users retain control over their security settings, with the ability to modify or remove their password as needed.
This new feature integrates into the login process at the final stage. Users who establish an account password but skip two-step verification will be prompted to enter the password immediately after the SMS verification code. When both 2FA and the account password are activated, users must provide the two-step verification PIN followed by the account password, creating a robust three-factor authentication system.
Optional Yet Robust Security
The decision to set an account password remains entirely optional, aligning with WhatsApp’s strategy for two-step verification. This addition does not replace any existing security measures; instead, it strengthens them by adding another credential layer known solely to the account holder.
Currently under development as reported by Wabetainfo, the account password feature is not yet available to the public. WhatsApp is refining the password configuration to enhance account protection against unauthorized access. Once the testing phase concludes, the feature will be gradually introduced to users worldwide.
As threats like SIM swapping and phishing persist, this new security measure marks a significant step in WhatsApp’s ongoing efforts to secure accounts and minimize unauthorized access risks for its over two billion users globally.
