Site navigation

Why is Everyone Talking About WhatsApp’s Deactivation Policy?

Michael Edgar

,

WhatsApp deactivation
“So let me get this right, WhatsApp, I can type in any number and you will deactivate that account?”

This was a tweet by Jack Moore, Global Security Advisor at cybersecurity company ESET, along with a screenshot of WhatsApp’s Help Centre which shows WhatsApp allows anyone to request an account deactivation with no more than the phone number used for the account. 

Screenshot from WhatsApp’s help centre.

Deactivation, in this context, does not mean the account is deleted but rather, logged out. Moore even tested the feature out himself, logging himself out of his WhatsApp account from an email.

Since the deactivation method gained online interest from Jack Moore’s tweet – which garnered over 1.1 million views –WhatsApp updated the deactivation process. The app no longer allows immediate automated deactivation, but now asks for further verification the account belongs to you, such as a copy of your phone bill or of the contract.

“Losing your phone is an awful experience and we want to help people if we can,” said a WhatsApp spokesperson in an email to DIGIT. They went on to say locking your sim or deactivating your phone is the best option, but in some instances that is unavailable, which is why WhatsApp offers the ability to log you out on your behalf until you find your phone again.

While the former automated deactivation policy did not compromise security laws or violate any protection regulations, “the company is walking a tightrope between making it convenient to make changes to an account, while also needing to provide security for the accounts,” said Chris Hauk, Consumer Privacy Advocate at Pixel Privacy.


Recommended


Lisa Ventura, Advisory Council Member of International Cyber Expo and Founder of Cyber Security Unity suggested the loophole could extend beyond dangers from domestic abusers. Even with two-factor authentication, the perpetrator can have access to the email address and verification details associated with the account, allowing them to go through with full deactivation.

Speaking on how individuals can increase their digital security in this context, Darren Guccione, CEO and co-founder of Keeper Security said: “Users should ensure they have strong and unique passwords for all of their accounts, always enable MFA, fabricate answers that an outsider couldn’t guess, and store their passwords, along with their recovery information, in an encrypted password manager.

“This reduces, if not eliminates the need to recover accounts altogether and allows the user to keep all of their recovery information saved in a single, safe and secure location.”

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data