Security4 distinct publishers2 min readPublished
The two-step secret becomes a full alphanumeric password, and an account can now hold one passkey per platform. Both remain opt-in settings inside the app.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A six-digit PIN has exactly one million possible values [17]. WhatsApp's pitch for replacing it is guessing resistance: longer, alphanumeric, special characters permitted, with a nudge that anyone still using "123456" should move [4][5]. Take a six-character password over case-sensitive letters and digits and the space becomes about 56.8 billion values, roughly 56,800 times the PIN, before a single special character is counted [18]. None of the four accounts of the announcement mentions a minimum length or a complexity rule [21], so the ceiling has moved further than the floor.
The reason this is more than a settings tweak is the shape of a WhatsApp takeover. Accounts are closely tied to phone numbers, which makes the one-time verification code the thing worth stealing, whether lifted directly or talked out of the victim, according to CyberInsider [7]. The two-step secret is the hop after that, and until now it was six digits [4]. WhatsApp says two-step verification exists precisely to hold when someone already has the one-time passcode [6]. Passkeys avoid that path: authentication runs against the device fingerprint, Face ID or screen lock, with no separate code or PIN to type [8].
The multi-passkey change looks minor and is not. CyberInsider describes the account as previously supporting a single passkey [20], so anyone carrying an Android handset and an iPhone had one enrolled platform and a typed-code fallback on the other. Two enrollments remove the reason to keep the fallback warm. What no version of the announcement says is that the one-time code route has been retired [22], which means the phishing-resistant method is additive rather than exclusive, and the weakest enabled path still sets the account's real strength.
Most of what shipped this year aims at the user rather than the credential: Strict Account Settings in January for high-risk people such as journalists and public figures [13], warnings in March on device-linking requests that may be fraudulent [14], and an optional Scam Alert beta this month running a local machine learning model [15], alongside the new caller context on Android [10]. Those are all interventions at the moment of attack. Passkeys change what an attacker has to hold. The vendor report promoted under BleepingComputer's own coverage makes the matching point from the defender's side: across 338 million simulations in production environments, prevention falls off sharply once an intruder is using valid credentials [16]. Making valid credentials harder to obtain is the part of that curve a messaging app can touch.
Ranked by verification strength, evidence, and original report placement.
Meta announced on Tuesday a set of WhatsApp account security features, including support for adding multiple passkeys to a single account, aimed at users with both iOS and Android devices signing in with the phishing-resistant method.
WhatsApp said: "Until now it was a six-digit PIN, we've now upgraded it to a full password: longer, alphanumeric, and even with special ch@racters to make it harder to guess."
WhatsApp said: "If you've been using '123456,' this is your sign to upgrade."
On Android, WhatsApp will now show more information about a non-contact caller, such as whether the number is from a different country and whether the parties share any groups.
Users can manage or add passkeys by navigating to Settings > Account > Passkeys.
The Hacker News reports the extra call context will include where the call originates, whether the person calling is already on the contact list, and whether both parties are in any common groups.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Well-attested announcement, single origin, no independent testing
The feature set is documented consistently across four outlets with verbatim vendor quotes and a reproducible settings path, which makes the existence and shape of the changes reliable. All of it traces back to one Meta blog post — The Hacker News says the post was shared with it — and no source tests the rollout, states availability windows, or verifies the vendor's adoption figure, so evidence sits above midpoint rather than high.
Large self-reported passkey base; new opt-in settings unmeasured
Adoption of the surrounding capability is real and large by vendor account — more than 1 billion passkey logins on a base of more than 3 billion users, with passkeys shipping since October 2023 on Android and early 2024 on iOS. But that is under a third of accounts, the figures are self-reported, and there is zero data on uptake of the three changes announced here, one of which is Android-only and all of which are opt-in.
Slightly overstated: strength language outruns disclosed specifics
Coverage is largely descriptive and the underlying changes are genuine, so the gap is small. It is positive rather than zero because 'full password', 'harder to guess' and 'phishing-resistant' are asserted without any published password policy, without rollout scope, and without noting that code-based login and the phone-number anchor remain in place — while the loudest adoption number, 1 billion passkeys, covers under a third of accounts.
Vendor-authored announcement plus sponsored security-vendor placement
Every factual element originates in a Meta communications release distributed to security outlets, including the unaudited adoption figure, giving the promoter clear reputational incentive on a trust-and-safety narrative. Two of the five source items additionally carry a Blue Report 2026 promotional panel with its own commercial framing about prevention failing once attackers hold valid credentials, sitting directly beneath authentication-hardening coverage.
High agreement on facts, low visibility into scope and enforcement
Four publishers, including two near-identical BleepingComputer items, converge on the same three changes with matching quotes and no contradictions, so the descriptive core is dependable. Confidence is held below high because everything derives from one vendor statement, the rollout scope and password enforcement rules are unknown, and secondary details vary slightly (multiple passkeys versus one per platform; Scam Alert described as 'AI' versus a local model).
invest
Meta's Hatch agent tops out at $199.99 a month, with DoorDash and Etsy behind the meter2 distinct publishers
product
France's under-15 ban failed on the age check, not the age limit1 distinct publisher
invest
The AI moat is now a balance sheet, so price the financing and not the model1 distinct publisher
invest
Nvidia is now VOO's biggest holding, and no index owner voted for it1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 25, 2026
1 article · August 25, 2026
1 article · August 25, 2026
1 article · August 25, 2026