{"id":33684,"date":"2024-06-08T02:42:03","date_gmt":"2024-06-07T15:42:03","guid":{"rendered":"https:\/\/www.kaspersky.com.au\/blog\/?p=33684"},"modified":"2024-06-08T02:42:03","modified_gmt":"2024-06-07T15:42:03","slug":"whatsapp-privacy-security","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.au\/blog\/whatsapp-privacy-security\/33684\/","title":{"rendered":"Setting up both security and privacy in WhatsApp"},"content":{"rendered":"<p>Despite being owned by Meta \u2014 a company frequently criticized for privacy issues \u2014 WhatsApp remains the most popular instant messenger in the world. Surprisingly, it\u2019s also one of the most secure. In this post, we discuss why this is the case, and explain how you can further fortify your WhatsApp conversations with the right privacy and security settings, as well as protect your smartphone with <a href=\"https:\/\/www.kaspersky.com.au\/home-security?icid=au_kdailyplacehold_acq_ona_smm__onl_b2c_blo_lnk_sm-team______\" target=\"_blank\" rel=\"noopener\">our security solutions<\/a>.<\/p>\n<h2>WhatsApp end-to-end encryption: always on<\/h2>\n<p>The most important thing to know about WhatsApp\u2019s security is that all communications are securely protected with end-to-end encryption. It\u2019s powered by the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Signal_Protocol\" target=\"_blank\" rel=\"nofollow noopener\">Signal Protocol<\/a>, developed by the creators of the independent privacy-focused <a href=\"https:\/\/www.kaspersky.com\/blog\/signal-privacy-security\/40377\/\" target=\"_blank\" rel=\"noopener nofollow\">Signal<\/a> messenger. This is an open protocol, so anyone (with the necessary know-how, of course) can scrutinize its <a href=\"https:\/\/github.com\/signalapp\/libsignal\" target=\"_blank\" rel=\"noopener nofollow\">source code<\/a> for bugs and backdoors.<\/p>\n<p>What this means for you is that all text and voice messages (be they in one-on-one or group chats), along with images, videos, documents, and calls, are encrypted on the sender\u2019s device and only decrypted on the recipient\u2019s device.<\/p>\n<p>This ensures that even WhatsApp itself has no technical ability to snoop on your conversations. This also creates an impenetrable barrier for cybercriminals attempting to intercept messages, whether in transit or by compromising WhatsApp\u2019s servers.<\/p>\n<p>The use of end-to-end encryption for all messages sets WhatsApp apart from <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-privacy-security\/38444\/\" target=\"_blank\" rel=\"noopener nofollow\">Telegram<\/a>. While Telegram touts its security features, end-to-end encryption isn\u2019t on the default. It\u2019s relegated to so-called \u201csecret chats\u201d, which must be specially created \u2014 and which, unfortunately, <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-why-nobody-uses-secret-chats\/46889\/\" target=\"_blank\" rel=\"noopener nofollow\">almost no one ever uses<\/a> for various reasons.<\/p>\n<h2>How to make communication on WhatsApp even safer<\/h2>\n<p>So, we\u2019ve covered what makes WhatsApp secure at the base level. Now, let\u2019s explore how you can bolster your defenses against surveillance, unauthorized access to your messages, and other threats to your privacy and security. This involves a bit of fine-tuning within WhatsApp\u2019s settings. Let\u2019s get started\u2026<\/p>\n<h3>How to protect WhatsApp from being hijacked<\/h3>\n<p>The first thing you should do is to fortify your WhatsApp account against hijacking. WhatsApp accounts are tethered to phone numbers. Therefore, if someone takes control of your number, they can also access your WhatsApp account. This could happen intentionally through a <a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-sim-swapping\/50797\/\" target=\"_blank\" rel=\"noopener nofollow\">SIM swapping attack<\/a>, or through an unfortunate consequence of number recycling: if you don\u2019t pay your phone bill on time, the operator could disconnect your number and reassign it to another subscriber.<\/p>\n<p>To protect against this threat, enable <a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-two-factor-authentication\/48289\/\" target=\"_blank\" rel=\"noopener nofollow\">two-factor authentication<\/a> for WhatsApp. Navigate to <em>Settings \u2192 Account \u2192 Two-step verification<\/em> and set a PIN code to confirm account logins.<\/p>\n<p>In addition, you can link an email address to your account. This provides a lifeline if you lose access to your phone number. You can enable this in <em>Settings \u2192 Account \u2192 Email address<\/em>.<\/p>\n<p>Beyond PIN codes, WhatsApp offers an alternative option for confirming account login: so-called \u201cpasskeys\u201d. We\u2019ve dedicated a <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-set-up-passkeys-in-google-account\/49515\/\" target=\"_blank\" rel=\"noopener nofollow\">separate post<\/a> to discussing what these are and how they work. To enable this option, go to <em>Settings \u2192 Account \u2192 Passkeys<\/em>.<\/p>\n<p>I also recommend making it a habit to audit the list of devices logged into your WhatsApp account. You can find this list in <em>Settings \u2192 Linked devices<\/em>. If you spot any suspicious entries, play it safe and log out of that session by selecting the device and tapping <em>Log out<\/em>.<\/p>\n<h3>How to protect your WhatsApp chats from prying eyes<\/h3>\n<p>The next step is to ensure that your conversations remain private \u2014 even if your phone falls into the wrong hands. To do this, first and foremost, enable the screen lock in your phone\u2019s settings. Don\u2019t forget to disable message previews in WhatsApp push notifications on the lock screen, so no one can read your secrets without unlocking your smartphone \u2014 this is done in the <em>Notifications<\/em> section of your smartphone settings.<\/p>\n<p>It\u2019s also a good idea to enable WhatsApp\u2019s own app lock, in case you forget to lock your device. To do this, head to <em>Settings \u2192 Privacy<\/em>, scroll down almost to the bottom, and locate <em>App lock<\/em>. I recommend choosing <em>After 1 minute<\/em> \u2014 this strikes a good balance between security and convenience. This way, if you switch from WhatsApp to another app, you\u2019ll have one minute to return to your messages, after which you\u2019ll need to unlock WhatsApp using your chosen method. However, keep in mind that if you leave your smartphone unattended with an open chat and the screen on, WhatsApp won\u2019t automatically lock until the screen times out.<\/p>\n<p>Another way to keep your confidential information away from prying eyes is to lock chats. Such chats disappear from your main chat list and reside in a separate folder. To hide a chat, tap the contact\u2019s profile picture, scroll down, and tap <em>Lock chat<\/em>.<\/p>\n<p>Situations may arise where you need to quickly get rid of locked chats and their contents. WhatsApp makes this easy to do with a single button: go to <em>Settings \u2192 Privacy \u2192 Chat lock<\/em> and tap <em>Unlock and clear locked chats<\/em>.<\/p>\n<p>To further protect your WhatsApp chats, you can use disappearing messages. There are two ways to use this function. First, you can set a timer for a specific chat. To do this, tap the contact\u2019s profile picture, scroll down to <em>Disappearing messages<\/em>, and select the desired duration.<\/p>\n<p>The second way is to set a default timer for all new chats. To do this, go to <em>Settings \u2192 Privacy \u2192 Default message timer<\/em> and set the interval after which messages will disappear.<\/p>\n<p>Additionally, WhatsApp lets you send photos, videos, and voice messages for one-time viewing (no more). This is easy to do: select the item you want to send, and before hitting send, tap the icon with the number one in the caption field.<\/p>\n<h3>How to disable \u201cblue ticks\u201d in WhatsApp<\/h3>\n<p>If you prefer to keep your message-reading habits under wraps, you can disable read receipts. To do this, go to <em>Settings \u2192 Privacy<\/em>, scroll down, and toggle off the switch next to <em>Read receipts<\/em>.<\/p>\n<p>Bear in mind that this is a two-way street: if you disable read receipts, you too will stop seeing blue ticks in chats. It\u2019s also important to know that this feature doesn\u2019t apply to group chats, where people will still see read receipts.<\/p>\n<h3>\u00a0Other privacy settings in WhatsApp<\/h3>\n<p>The<em> Settings \u2192 Privacy<\/em> section in WhatsApp holds a few more settings worth paying attention to. These determine who can access specific information about you. While there are no hard and fast rules \u2014 it all boils down to your personal circumstances and preferences \u2014 here\u2019s what I consider a balanced approach:<\/p>\n<ul>\n<li><em>Last seen &amp; online \u2192 Nobody<\/em>.<\/li>\n<li><em>Profile photo \u2192 Everyone<\/em>.<\/li>\n<li><em>About \u2192 Everyone<\/em>.<\/li>\n<li><em>Groups \u2192 My contacts<\/em>.<\/li>\n<li><em>Status \u2192 My contacts<\/em>.<\/li>\n<li><em>Calls \u2192 Silence unknown callers<\/em>.<\/li>\n<\/ul>\n<p>If you use WhatsApp\u2019s live location sharing feature, it\u2019s a good idea to regularly review the list of chats where your location is visible. To do this, go to <em>Settings \u2192 Privacy \u2192 Live location<\/em>.<\/p>\n<p>Also, keep in mind that, by default, WhatsApp calls establish a direct connection between participants without involving WhatsApp servers. This helps achieve maximum sound quality, but also means that, in theory, your IP address can be traced. If this concerns you, navigate to <em>Settings \u2192 Privacy \u2192 Advanced<\/em> and toggle on <em>Protect IP address in calls<\/em>.<\/p>\n<h3>How to verify the authenticity of someone on WhatsApp<\/h3>\n<p>WhatsApp provides a way to confirm that you really are talking to the right person and that no one is eavesdropping on your conversation. Each chat has a unique security code, and you can check it with your chat partner verbally during a call or through a different communication channel. If the codes match, you\u2019re all good. To locate this code, tap your contact\u2019s profile picture in the chat, scroll down, and tap <em>Encryption<\/em>.<\/p>\n<p>Additionally, you can set up security notifications, which alert you whenever a security code in one of your chats changes. These notifications are disabled by default but can be activated in <em>Settings \u2192 Account \u2192 Security notifications<\/em>.<\/p>\n<h3>How to create a secure backup of your WhatsApp chats or migrate chats to a new device<\/h3>\n<p>WhatsApp allows you to back up your chats, and the backup is stored not on WhatsApp\u2019s own servers, but in the Apple or Google cloud. To protect this backup against leaks, you can also use end-to-end encryption.<\/p>\n<p>To create a backup, go to <em>Settings \u2192 Chats \u2192 Chat backup<\/em>. Note here that encryption is off by default. To enable it, select <em>End-to-end encrypted backup<\/em>.<\/p>\n<p>The <em>Settings \u2192 Chats<\/em> section also allows you to transfer your WhatsApp chats to another device without relying on Apple or Google cloud services. From an iPhone, you can transfer your chats to another iOS device or an Android device by selecting <em>Transfer chats to iPhone<\/em> or <em>Move chats to Android<\/em>, respectively. On Android, you can only transfer to another Android device \u2014 select <em>Transfer chats<\/em>.<\/p>\n<h2>Don\u2019t forget to protect your devices using WhatsApp<\/h2>\n<p>Remember that all your efforts to protect your WhatsApp chats could be completely wasted if someone gains access to one of your devices where the messenger is installed. This could be either physical access or remote access through spyware. Therefore, ensuring the security of these devices is a top priority:<\/p>\n<ul>\n<li>Enable screen lock and set a secure unlock method.<\/li>\n<li>Disable lock screen notifications.<\/li>\n<li>Use <a href=\"https:\/\/www.kaspersky.com.au\/premium?icid=au_bb2022-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener\">a reliable security solution<\/a> on all your devices.<\/li>\n<\/ul>\n<p>And to set up privacy and security not only in WhatsApp, but also on social networks, and in online services and applications, use our free <a href=\"https:\/\/privacy.kaspersky.com\/\" target=\"_blank\" rel=\"noopener\">Privacy Checker<\/a> service. Select the platform, application, and security level you\u2019re interested in, and get step-by-step, detailed recommendations.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-geek\">\n","protected":false},"excerpt":{"rendered":"<p>We discuss key aspects of WhatsApp&#8217;s security and privacy, and how to configure this messenger to enhance protection.<\/p>\n","protected":false},"author":2726,"featured_media":33685,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1788,9],"tags":[3351,261,3315,607,43,97,835,1532,131,546],"class_list":{"0":"post-33684","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-privacy","8":"category-tips","9":"tag-e2e","10":"tag-encryption","11":"tag-end-to-end-encryption","12":"tag-messengers","13":"tag-privacy","14":"tag-security-2","15":"tag-settings","16":"tag-signal","17":"tag-tips-2","18":"tag-whatsapp"},"hreflang":[{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/whatsapp-privacy-security\/33684\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/whatsapp-privacy-security\/27540\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/whatsapp-privacy-security\/22858\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/whatsapp-privacy-security\/30211\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/whatsapp-privacy-security\/27690\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/whatsapp-privacy-security\/27442\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/whatsapp-privacy-security\/30108\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/whatsapp-privacy-security\/28995\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/whatsapp-privacy-security\/37612\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/whatsapp-privacy-security\/12468\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/whatsapp-privacy-security\/51428\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/whatsapp-privacy-security\/21949\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/whatsapp-privacy-security\/22693\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/whatsapp-privacy-security\/31349\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/whatsapp-privacy-security\/36626\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/whatsapp-privacy-security\/27858\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/whatsapp-privacy-security\/33348\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.au\/blog\/tag\/messengers\/","name":"messengers"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/33684","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/comments?post=33684"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/33684\/revisions"}],"predecessor-version":[{"id":33686,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/33684\/revisions\/33686"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media\/33685"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media?parent=33684"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/categories?post=33684"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/tags?post=33684"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}