{"id":24647,"date":"2024-06-07T08:30:03","date_gmt":"2024-06-07T16:30:03","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/06\/07\/news-18377\/"},"modified":"2024-06-07T08:30:03","modified_gmt":"2024-06-07T16:30:03","slug":"news-18377","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2024\/06\/07\/news-18377\/","title":{"rendered":"Security and privacy settings in WhatsApp | Kaspersky official blog"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/07112941\/WhatsApp-Privacy-Security-featured.png\"\/><\/p>\n<p><strong>Credit to Author: Alanna Titterington| Date: Fri, 07 Jun 2024 15:34:29 +0000<\/strong><\/p>\n<p>Despite being owned by Meta \u2014 a company frequently criticized for privacy issues \u2014 WhatsApp remains the most popular instant messenger in the world. Surprisingly, it&#8217;s also one of the most secure. In this post, we discuss why this is the case, and explain how you can further fortify your WhatsApp conversations with the right privacy and security settings, as well as protect your smartphone with <a href=\"https:\/\/www.kaspersky.com\/home-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_blo_lnk_sm-team______\" target=\"_blank\">our security solutions<\/a>.<\/p>\n<h2>WhatsApp end-to-end encryption: always on<\/h2>\n<p>The most important thing to know about WhatsApp&#8217;s security is that all communications are securely protected with end-to-end encryption. It&#8217;s powered by the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Signal_Protocol\" target=\"_blank\" rel=\"nofollow noopener\">Signal Protocol<\/a>, developed by the creators of the independent privacy-focused <a href=\"https:\/\/www.kaspersky.com\/blog\/signal-privacy-security\/40377\/\" target=\"_blank\" rel=\"noopener\">Signal<\/a> messenger. This is an open protocol, so anyone (with the necessary know-how, of course) can scrutinize its <a href=\"https:\/\/github.com\/signalapp\/libsignal\" target=\"_blank\" rel=\"noopener\">source code<\/a> for bugs and backdoors.<\/p>\n<p>What this means for you is that all text and voice messages (be they in one-on-one or group chats), along with images, videos, documents, and calls, are encrypted on the sender&#8217;s device and only decrypted on the recipient&#8217;s device.<\/p>\n<p>This ensures that even WhatsApp itself has no technical ability to snoop on your conversations. This also creates an impenetrable barrier for cybercriminals attempting to intercept messages, whether in transit or by compromising WhatsApp&#8217;s servers.<\/p>\n<p>The use of end-to-end encryption for all messages sets WhatsApp apart from <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-privacy-security\/38444\/\" target=\"_blank\" rel=\"noopener\">Telegram<\/a>. While Telegram touts its security features, end-to-end encryption isn&#8217;t on the default. It&#8217;s relegated to so-called &#8220;secret chats&#8221;, which must be specially created \u2014 and which, unfortunately, <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-why-nobody-uses-secret-chats\/46889\/\" target=\"_blank\" rel=\"noopener\">almost no one ever uses<\/a> for various reasons.<\/p>\n<h2>How to make communication on WhatsApp even safer<\/h2>\n<p>So, we&#8217;ve covered what makes WhatsApp secure at the base level. Now, let&#8217;s explore how you can bolster your defenses against surveillance, unauthorized access to your messages, and other threats to your privacy and security. This involves a bit of fine-tuning within WhatsApp&#8217;s settings. Let&#8217;s get started\u2026<\/p>\n<h3>How to protect WhatsApp from being hijacked<\/h3>\n<p>The first thing you should do is to fortify your WhatsApp account against hijacking. WhatsApp accounts are tethered to phone numbers. Therefore, if someone takes control of your number, they can also access your WhatsApp account. This could happen intentionally through a <a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-sim-swapping\/50797\/\" target=\"_blank\" rel=\"noopener\">SIM swapping attack<\/a>, or through an unfortunate consequence of number recycling: if you don&#8217;t pay your phone bill on time, the operator could disconnect your number and reassign it to another subscriber.<\/p>\n<p>To protect against this threat, enable <a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-two-factor-authentication\/48289\/\" target=\"_blank\" rel=\"noopener\">two-factor authentication<\/a> for WhatsApp. Navigate to <em>Settings \u2192 Account \u2192 Two-step verification<\/em> and set a PIN code to confirm account logins.<\/p>\n<p>In addition, you can link an email address to your account. This provides a lifeline if you lose access to your phone number. You can enable this in <em>Settings \u2192 Account \u2192 Email address<\/em>.<\/p>\n<p>Beyond PIN codes, WhatsApp offers an alternative option for confirming account login: so-called &#8220;passkeys&#8221;. We&#8217;ve dedicated a <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-set-up-passkeys-in-google-account\/49515\/\" target=\"_blank\" rel=\"noopener\">separate post<\/a> to discussing what these are and how they work. To enable this option, go to <em>Settings \u2192 Account \u2192 Passkeys<\/em>.<\/p>\n<p>I also recommend making it a habit to audit the list of devices logged into your WhatsApp account. You can find this list in <em>Settings \u2192 Linked devices<\/em>. If you spot any suspicious entries, play it safe and log out of that session by selecting the device and tapping <em>Log out<\/em>.<\/p>\n<h3>How to protect your WhatsApp chats from prying eyes<\/h3>\n<p>The next step is to ensure that your conversations remain private \u2014 even if your phone falls into the wrong hands. To do this, first and foremost, enable the screen lock in your phone&#8217;s settings. Don&#8217;t forget to disable message previews in WhatsApp push notifications on the lock screen, so no one can read your secrets without unlocking your smartphone \u2014 this is done in the <em>Notifications<\/em> section of your smartphone settings.<\/p>\n<p>It&#8217;s also a good idea to enable WhatsApp&#8217;s own app lock, in case you forget to lock your device. To do this, head to <em>Settings \u2192 Privacy<\/em>, scroll down almost to the bottom, and locate <em>App lock<\/em>. I recommend choosing <em>After 1 minute<\/em> \u2014 this strikes a good balance between security and convenience. This way, if you switch from WhatsApp to another app, you&#8217;ll have one minute to return to your messages, after which you&#8217;ll need to unlock WhatsApp using your chosen method. However, keep in mind that if you leave your smartphone unattended with an open chat and the screen on, WhatsApp won&#8217;t automatically lock until the screen times out.<\/p>\n<p>Another way to keep your confidential information away from prying eyes is to lock chats. Such chats disappear from your main chat list and reside in a separate folder. To hide a chat, tap the contact&#8217;s profile picture, scroll down, and tap <em>Lock chat<\/em>.<\/p>\n<p>Situations may arise where you need to quickly get rid of locked chats and their contents. WhatsApp makes this easy to do with a single button: go to <em>Settings \u2192 Privacy \u2192 Chat lock<\/em> and tap <em>Unlock and clear locked chats<\/em>.<\/p>\n<p>To further protect your WhatsApp chats, you can use disappearing messages. There are two ways to use this function. First, you can set a timer for a specific chat. To do this, tap the contact&#8217;s profile picture, scroll down to <em>Disappearing messages<\/em>, and select the desired duration.<\/p>\n<p>The second way is to set a default timer for all new chats. To do this, go to <em>Settings \u2192 Privacy \u2192 Default message timer<\/em> and set the interval after which messages will disappear.<\/p>\n<p>Additionally, WhatsApp lets you send photos, videos, and voice messages for one-time viewing (no more). This is easy to do: select the item you want to send, and before hitting send, tap the icon with the number one in the caption field.<\/p>\n<h3>How to disable &#8220;blue ticks&#8221; in WhatsApp<\/h3>\n<p>If you prefer to keep your message-reading habits under wraps, you can disable read receipts. To do this, go to <em>Settings \u2192 Privacy<\/em>, scroll down, and toggle off the switch next to <em>Read receipts<\/em>.<\/p>\n<p>Bear in mind that this is a two-way street: if you disable read receipts, you too will stop seeing blue ticks in chats. It&#8217;s also important to know that this feature doesn&#8217;t apply to group chats, where people will still see read receipts.<\/p>\n<h3>\u00a0Other privacy settings in WhatsApp<\/h3>\n<p>The<em> Settings \u2192 Privacy<\/em> section in WhatsApp holds a few more settings worth paying attention to. These determine who can access specific information about you. While there are no hard and fast rules \u2014 it all boils down to your personal circumstances and preferences \u2014 here&#8217;s what I consider a balanced approach:<\/p>\n<ul>\n<li><em>Last seen &amp; online \u2192 Nobody<\/em>.<\/li>\n<li><em>Profile photo \u2192 Everyone<\/em>.<\/li>\n<li><em>About \u2192 Everyone<\/em>.<\/li>\n<li><em>Groups \u2192 My contacts<\/em>.<\/li>\n<li><em>Status \u2192 My contacts<\/em>.<\/li>\n<li><em>Calls \u2192 Silence unknown callers<\/em>.<\/li>\n<\/ul>\n<p>If you use WhatsApp&#8217;s live location sharing feature, it&#8217;s a good idea to regularly review the list of chats where your location is visible. To do this, go to <em>Settings \u2192 Privacy \u2192 Live location<\/em>.<\/p>\n<p>Also, keep in mind that, by default, WhatsApp calls establish a direct connection between participants without involving WhatsApp servers. This helps achieve maximum sound quality, but also means that, in theory, your IP address can be traced. If this concerns you, navigate to <em>Settings \u2192 Privacy \u2192 Advanced<\/em> and toggle on <em>Protect IP address in calls<\/em>.<\/p>\n<h3>How to verify the authenticity of someone on WhatsApp<\/h3>\n<p>WhatsApp provides a way to confirm that you really are talking to the right person and that no one is eavesdropping on your conversation. Each chat has a unique security code, and you can check it with your chat partner verbally during a call or through a different communication channel. If the codes match, you&#8217;re all good. To locate this code, tap your contact&#8217;s profile picture in the chat, scroll down, and tap <em>Encryption<\/em>.<\/p>\n<p>Additionally, you can set up security notifications, which alert you whenever a security code in one of your chats changes. These notifications are disabled by default but can be activated in <em>Settings \u2192 Account \u2192 Security notifications<\/em>.<\/p>\n<h3>How to create a secure backup of your WhatsApp chats or migrate chats to a new device<\/h3>\n<p>WhatsApp allows you to back up your chats, and the backup is stored not on WhatsApp&#8217;s own servers, but in the Apple or Google cloud. To protect this backup against leaks, you can also use end-to-end encryption.<\/p>\n<p>To create a backup, go to <em>Settings \u2192 Chats \u2192 Chat backup<\/em>. Note here that encryption is off by default. To enable it, select <em>End-to-end encrypted backup<\/em>.<\/p>\n<p>The <em>Settings \u2192 Chats<\/em> section also allows you to transfer your WhatsApp chats to another device without relying on Apple or Google cloud services. From an iPhone, you can transfer your chats to another iOS device or an Android device by selecting <em>Transfer chats to iPhone<\/em> or <em>Move chats to Android<\/em>, respectively. On Android, you can only transfer to another Android device \u2014 select <em>Transfer chats<\/em>.<\/p>\n<h2>Don&#8217;t forget to protect your devices using WhatsApp<\/h2>\n<p>Remember that all your efforts to protect your WhatsApp chats could be completely wasted if someone gains access to one of your devices where the messenger is installed. This could be either physical access or remote access through spyware. Therefore, ensuring the security of these devices is a top priority:<\/p>\n<ul>\n<li>Enable screen lock and set a secure unlock method.<\/li>\n<li>Disable lock screen notifications.<\/li>\n<li>Use <a href=\"https:\/\/www.kaspersky.com\/premium?icid=gl_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\">a reliable security solution<\/a> on all your devices.<\/li>\n<\/ul>\n<p>And to set up privacy and security not only in WhatsApp, but also on social networks, and in online services and applications, use our free <a href=\"https:\/\/privacy.kaspersky.com\/\" target=\"_blank\" rel=\"noopener\">Privacy Checker<\/a> service. Select the platform, application, and security level you&#8217;re interested in, and get step-by-step, detailed recommendations.<\/p>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"premium-geek\" \/> <br \/><a href=\"https:\/\/www.kaspersky.com\/blog\/whatsapp-privacy-security\/51428\/\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/07112941\/WhatsApp-Privacy-Security-featured.png\"\/><\/p>\n<p><strong>Credit to Author: Alanna Titterington| Date: Fri, 07 Jun 2024 15:34:29 +0000<\/strong><\/p>\n<p>How to set up WhatsApp&#039;s security and privacy for maximum protection against surveillance, and unauthorized access to your correspondence.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[21309,10439,11307,10450,5897,714,11226,3205,10428,10440],"class_list":["post-24647","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security","tag-e2e","tag-encryption","tag-end-to-end-encryption","tag-messengers","tag-privacy","tag-security","tag-settings","tag-signal","tag-tips","tag-whatsapp"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24647","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24647"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24647\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24647"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24647"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24647"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}