WhatsApp is making its two-step verification harder to crack.
According to TechCrunch, the messaging app's two-step verification previously relied on a six-digit PIN. Users can now choose a longer, alphanumeric password that includes special characters instead. Engadget frames the change the same way: you can now ditch the six-digit code for a stronger password.
The distinction matters more than it might sound. A six-digit PIN has exactly one million possible combinations — a number that is trivial for software to work through, and small enough that people tend to reuse birthdays, anniversaries, or repeating digits. A password that mixes letters, numbers, and symbols, and that can run longer than six characters, expands that pool enormously.
Two-step verification is the backstop that sits behind your phone number on WhatsApp. It is what stands between an attacker and your account if they manage to get hold of the SMS code sent during registration — the exact scenario behind SIM-swap attacks and the account-takeover scams that circulate through hijacked chats. Strengthening that second factor strengthens the weakest link in the chain.
TechCrunch reports the stronger two-step verification arrives alongside other security changes to the app, though the alphanumeric password is the headline feature in both accounts.
For most people, the practical takeaway is simple: the option is there, but it is an option. Changing it means opening WhatsApp's settings and choosing the new format rather than waiting for it to happen automatically.
Why it matters: WhatsApp is one of the most widely used messaging apps on the planet, and giving billions of users a meaningfully stronger lock on their accounts raises the floor of security for the conversations, contacts, and payment details that live inside them.