News : WhatsApp Introduces Passkey-Encrypted Backups

WhatsApp is rolling out passkey-encrypted backups, thereby letting users protect and recover their chat history using their face, fingerprint, or device screen lock instead of remembering a long password or storing a 64-digit recovery key.

A Major Step in WhatsApp’s Encryption Journey

WhatsApp has announced a new feature that allows users to encrypt their chat backups with passkeys rather than relying on passwords or lengthy encryption codes. Passkeys are a form of passwordless authentication that combine something a user has (their phone) with something they are or know (such as biometrics or a screen lock code). According to WhatsApp, this will make end-to-end encrypted backups simpler and safer to use across iOS and Android devices.

Previously

For years, the app’s end-to-end encryption actually only covered live chats and calls. Messages were secure in transit but often less so once stored in cloud backups. Until 2021, backups to iCloud and Google Drive were not encrypted, which meant anyone who gained access to those cloud accounts could potentially read the stored chat history. That year, Meta introduced end-to-end encrypted backups, giving users the option to protect those files using a password or a randomly generated 64-character key. It was a major privacy milestone, but a cumbersome one: if a user lost the password or key, their backup became permanently inaccessible.

No Need to Memorise a Key

WhatsApp’s new passkey approach doesn’t change how backups are encrypted, but it does change how users unlock them. Instead of memorising a key, people can now rely on the same biometric or lock screen verification they already use to access their phone.

Why Passkeys, and Why Now?

In a blog post titled Encrypting Your WhatsApp Chat Backup Just Got Easier, the company explained the rationale behind the move. “Passkeys will allow you to use your fingerprint, face, or screen lock code to encrypt your chat backups instead of having to memorise a password or a cumbersome 64-digit encryption key,” WhatsApp said. “Now, with just a tap or a glance, the same security that protects your personal chats and calls on WhatsApp is applied to your chat backups so they are always safe, accessible and private.”

The move actually reflects a broader trend in cybersecurity and user experience. For example, while passwords remain the default for most online services, they are increasingly seen as both inconvenient and insecure. Passkeys, built on the FIDO and WebAuthn standards, have been adopted by Apple, Google, and Microsoft as part of the industry-wide transition towards passwordless authentication. WhatsApp’s latest feature extends this approach to backup protection, bringing it in line with these major ecosystems.

Usability is also a central motivation. For example, many users either forgot their encrypted backup password or never enabled the feature at all because of fears they might lose the key. With passkeys, the backup process is far more seamless. The device itself becomes the trusted gatekeeper, using local authentication that the user already understands.

This could also help WhatsApp’s reputation among privacy advocates. The service now has over three billion monthly active users worldwide, and any improvement in accessibility could drive wider adoption of its encryption features.

When?

The company said the rollout will take place “over the coming weeks and months”, meaning not all users will see the new option immediately.

How It Works in Practice

Once available, users can enable passkey-encrypted backups through the app’s settings: Settings → Chats → Chat backup → End-to-end encrypted backup. From there, they can choose to secure their backup using a passkey rather than a password or encryption key.

The difference becomes most apparent when restoring chats to a new device. For example, under the old system, the user needed to type their password or locate their encryption key before WhatsApp could decrypt and restore messages. With passkeys, they simply authenticate using biometrics or a screen lock from their old device, which confirms their identity and decrypts the backup automatically.

This means that a small business owner switching to a new phone can now restore years of client messages and attachments simply by scanning their fingerprint, instead of searching for a forgotten password. It is a small change in process but a significant improvement in ease of use and data recovery.

Why This Matters to UK Businesses

In the UK, WhatsApp is used by millions of professionals as an informal business communication tool. From contractors and consultants to property managers and customer service teams, many rely on WhatsApp to share documents, voice notes, and updates. This has often created a compliance and data protection challenge. Backups stored on cloud platforms without encryption could expose client data if an employee’s personal account were hacked.

By making encrypted backups easier to use, therefore, WhatsApp is now closing one of the remaining security gaps. Businesses that use WhatsApp informally can now encourage staff to enable backup encryption without worrying that forgotten passwords will lock them out of their data. For industries handling sensitive information, e.g., healthcare, construction, and legal services, this makes it simpler to protect communications while maintaining accessibility.

WhatsApp’s focus on usability could also help retain users in the face of competition. For example, rivals such as Signal have long made privacy their main selling point, while enterprise platforms like Microsoft Teams and Slack promote compliance features and centralised data management. Making encrypted backups effortless helps WhatsApp defend its position as both a consumer and small-business communication tool.

Context

The introduction of passkeys for backups also appears to align with Meta’s wider strategy to make encryption a default standard across its messaging platforms. In late 2023, Meta completed the rollout of end-to-end encryption for Messenger and Facebook chats, drawing both praise and criticism from privacy campaigners and regulators. WhatsApp’s latest enhancement, therefore, reinforces that commitment to strong encryption, while also signalling that Meta is aware of usability barriers that have historically held users back.

At the same time, this move may raise new questions for regulators, e.g., governments in the UK, EU, and elsewhere continue to debate how encrypted services fit with lawful access and online safety legislation. If backups are locked behind device-specific passkeys that even Meta cannot access, traditional data requests will yield little beyond metadata such as contact timestamps. That strengthens user privacy but complicates investigations where access to message history has previously depended on unencrypted backups in the cloud.

Potential Challenges and Criticisms

While the update marks another step forward in security and privacy, it is not without its caveats. For example, the security of passkey-encrypted backups depends on the strength of the device lock itself. A weak PIN or an easily accessible biometric can undermine the system. If someone can unlock a user’s phone, they may also be able to restore the encrypted backup. Users are therefore advised to maintain strong device security to benefit fully from the new system.

Recovery is another concern. Unlike a password, a biometric cannot be written down or stored safely elsewhere. That means if a user loses their device and has no other registered one to authorise the restore, they may permanently lose access to their encrypted backup. WhatsApp has confirmed that it will not store recovery copies of encryption keys, maintaining its position that “only you” can access your backup. This reinforces privacy but leaves no route for account recovery if the passkey cannot be used.

The staggered rollout also means adoption will be uneven. Not all users will have access immediately, and device compatibility could differ by region. For organisations using WhatsApp across multiple teams or countries, this might temporarily complicate backup policies or support processes.

There are also some technical limits to consider. For example, the new passkey feature does not address certain underlying encryption vulnerabilities identified by researchers earlier this year, such as weaknesses in WhatsApp’s “prekey” handshake mechanism that could theoretically expose some message metadata under specific conditions. Those findings relate to message exchange rather than backups, but they underline that security in complex systems is never static.

Finally, while this change enhances privacy for individuals, it introduces new complications for organisations that must retain communication records for legal or contractual reasons. Encrypted backups that only employees can decrypt may hinder internal auditing or eDiscovery processes unless alternative data management policies are in place.

WhatsApp’s decision to make passkey-encrypted backups available, therefore, reflects both a technological evolution and a strategic balancing act, i.e., strengthening privacy while trying to keep security practical for billions of users and acceptable to regulators. It reinforces Meta’s message that personal data should remain under user control, but it also leaves open questions about recovery, compliance, and how far convenience can coexist with absolute privacy.

What Does This Mean for Your Business?

WhatsApp’s passkey-encrypted backups close a long-standing gap in its privacy model by uniting strong security with genuine ease of use. The change ensures that users can now protect years of chat history without worrying about lost passwords or unmanageable encryption keys. It also signals Meta’s intent to keep WhatsApp at the forefront of privacy technology while aligning with the global shift toward passwordless authentication across major platforms.

For UK businesses, the update is both an advantage and a challenge. For example, it strengthens protection for sensitive conversations, reducing the risk of data exposure from insecure cloud backups. However, it also places more control in the hands of individual employees, limiting an organisation’s ability to monitor or recover business communications when needed. Firms that use WhatsApp informally for client contact or internal coordination will need to update their data management policies to account for encrypted, user-controlled backups.

Regulators and policymakers are likely to see this as another reminder that end-to-end encryption is now the default expectation rather than a specialist option. While it may complicate lawful access to stored message data, it reflects the direction most major tech companies are taking to meet user privacy demands. For everyday users, the result should be a simpler, more trustworthy backup system that makes security part of the normal experience rather than an optional extra.

The broader lesson here is that encryption can only achieve mass adoption when it becomes invisible to the user. WhatsApp’s move may bring that goal closer, reshaping how individuals, businesses, and governments think about control over digital information in a world where privacy and usability must now coexist.

News : UK Backs Down In Apple Privacy Row

The UK government has backed down from its demand that Apple create a “back door” into its encrypted systems, ending a high-profile dispute that drew in Washington and sparked widespread criticism from privacy campaigners and industry experts.

How the Row Began

The confrontation began late last year when the UK Home Office issued Apple with a “technical capability notice” under the Investigatory Powers Act. This law (also known as the “snooper’s charter”) allows the government to compel technology companies to assist law enforcement in accessing data to investigate serious crimes such as terrorism and child sexual abuse.

The notice required Apple to make encrypted customer data available to authorities on demand. What made it unusual was its global scope, i.e. the order applied not just to British customers but potentially to Apple users anywhere in the world, including in the United States.

The demand clashed directly with Apple’s Advanced Data Protection (ADP) tool, launched in 2022, which provides end-to-end encryption for iCloud backups. Once activated, not even Apple itself can access the contents of a user’s iCloud files, photos, notes or reminders. For law enforcement, this meant some data would be completely beyond reach. For Apple, complying with the UK’s order would have meant deliberately undermining its own encryption.

Apple responded by withdrawing ADP for new customers in the UK, saying it was “deeply disappointed” and would “never build a backdoor or master key” to its products. At the same time, it launched a legal challenge to the government’s order at the Investigatory Powers Tribunal, with a hearing scheduled for early 2026.

Escalation Into a Transatlantic Dispute

What might have remained a UK legal battle soon escalated into an international row. Because the UK’s notice applied worldwide, it raised the possibility of British authorities accessing the data of American citizens.

US leaders reacted strongly. President Donald Trump accused Britain of “behaving like China” and publicly told Prime Minister Keir Starmer: “You can’t do this.” Vice President JD Vance called the demand “crazy”, warning that it risked creating a vulnerability in US technology that could be exploited by hostile states. Tulsi Gabbard, the US Director of National Intelligence, was equally blunt, saying the order “would have encroached on our civil liberties”.

Behind the scenes, senior American officials pressed London to change course. According to the Financial Times, Vice President Vance personally intervened during a recent visit to the UK, negotiating what US officials later described as a “mutually beneficial understanding” that the order would be withdrawn.

The UK Retreats

On 19 August, Gabbard confirmed in a post on X that the UK had “agreed to drop its mandate for Apple to provide a ‘back door’ that would have enabled access to the protected encrypted data of American citizens”. She added that she had been working with President Trump and Vice President Vance “to ensure Americans’ private data remains private and our constitutional rights and civil liberties are protected”.

The Home Office has refused to confirm or deny her claim, citing a long-standing policy not to comment on operational matters. However, multiple British officials told reporters that the issue was “settled” and that London had “caved” to US pressure.

Whether the technical capability notice will be formally withdrawn, amended to target only UK citizens, or left in place but unenforced remains unclear. Legal experts have pointed out that limiting access to UK citizens’ data alone may be technologically unrealistic, since Apple’s cloud systems do not distinguish by nationality.

Why the Government Backed Down

Several factors contributed to the reversal. The most immediate was diplomatic pressure from Washington. With Trump’s administration already imposing tariffs on European goods and pressing allies on defence spending, the UK government may have had little appetite for a damaging rift over encryption policy. Also, some would say that, given Apple’s Tim Cook’s recent public strategic outreach (financially and symbolically) with President Trump, and UK Prime Minister Starmer’s wish not to have tariffs increased following recent negotiations, this may have been one fight the UK government thought it best not to have at this time.

Another factor was the risk to Britain’s global reputation. Legal experts and business groups had warned that forcing Apple to break encryption could deter companies from operating in the UK, damaging the country’s status as a safe destination for data. Charlotte Wilson, head of enterprise at Check Point Software, described the original order as “hugely damaging”, saying that once a master key to encrypted data exists “criminal groups and hostile states will try to exploit it too”.

Civil liberties organisations also appear to have played a role. Liberty and Privacy International had both launched legal action against the government, arguing that creating a back door would be unlawful and reckless. Sam Grant, Liberty’s director of external relations, called the reported U-turn “hugely welcome”, warning that such powers would put campaigners, minority groups and politicians at heightened risk of targeting.

What It Means for Apple and Its Users

For Apple, the retreat could be seen as a vindication of its long-standing stance on encryption. The company has repeatedly argued that any deliberate weakness, even one intended for law enforcement, could eventually be exploited by criminals or foreign governments.

It is now likely that Apple will reinstate Advanced Data Protection for new UK customers, although the company has not yet confirmed its plans. If it does, British businesses and individuals will again be able to benefit from the highest level of iCloud encryption, aligning with customers elsewhere in the world.

For UK businesses in particular, the move has real significance. For example, end-to-end encryption is increasingly seen as a baseline requirement for protecting sensitive intellectual property, financial data and client communications. Any perception that the UK was a weak link could have harmed firms’ ability to meet international compliance standards or reassure overseas partners.

Lingering Concerns

Despite the climbdown, some critics argue that the underlying problem remains. The Investigatory Powers Act still contains provisions allowing the government to issue similar notices in future. Jim Killock, executive director of the Open Rights Group, said: “The UK’s powers to attack encryption are still on the law books, and pose a serious risk to user security and protection against criminal abuse of our data.”

There are also unanswered questions about whether other technology companies have been served with similar demands. WhatsApp, for example, has said it has not received such a notice, but secrecy provisions mean firms cannot always disclose whether they have been targeted.

Another unresolved issue is whether Britain will seek to revise its order in a way that applies only to UK citizens. Privacy experts caution that such an approach could still create risks, since once a back door exists, it cannot easily be limited to one group of users.

The Wider Picture

The dispute highlights the tension between governments’ desire for access to digital evidence and technology companies’ commitment to protecting user privacy. Governments argue that encryption can provide cover for criminals and terrorists, while companies and privacy advocates insist that undermining encryption would weaken security for everyone.

For the UK government, the episode has also shown the limits of its extraterritorial powers. While the Investigatory Powers Act gives British authorities the ability to issue global data access demands, enforcing them against multinational firms without international support is fraught with difficulty.

For the United States, the outcome demonstrates the strength of its leverage over allies when civil liberties and the interests of its technology sector are at stake. Gabbard framed the UK’s reversal as a victory for American citizens’ rights, while Senator Ron Wyden described it as “a win for everyone who values secure communications”.

What Does This Mean For Your Business?

The UK government’s retreat may settle the immediate dispute but it leaves many questions unanswered about how far states can and should go in seeking access to private data. The fact that London backed down only after sustained US pressure shows the difficulty of enforcing extraterritorial demands when they clash with the interests of powerful allies and companies. It also underlines that encryption has become more than a technical feature, it is now a geopolitical fault line between privacy, commerce and national security.

For Apple, the outcome strengthens its position as a global defender of encryption and restores confidence among its UK customers, many of whom had been left without the strongest level of iCloud protection. Businesses in particular stand to gain if Advanced Data Protection is reinstated, since they rely heavily on secure storage and communications to safeguard sensitive information. The reassurance that the UK will not compel Apple to weaken its systems may also help British firms demonstrate compliance with international standards and maintain trust with overseas partners.

For the UK government, however, the episode risks being seen as a climbdown that exposes the limits of its investigatory powers. Ministers continue to argue that strong surveillance powers are essential to combat threats such as terrorism and child abuse, yet critics have been quick to say that Britain has undermined its own credibility by pushing for a back door it could not deliver. Privacy campaigners and technology experts will also point out that the Investigatory Powers Act still contains the same provisions, leaving open the possibility that a future government may attempt a similar move.

The wider implications go beyond Apple. Other technology companies will be weighing what this episode means for their own obligations under UK law and whether they too could face demands that clash with global privacy protections. Civil liberties groups will continue to press for reforms to prevent governments from seeking back doors in the first place, while law enforcement agencies are likely to warn that criminals will continue to exploit encryption to hide their activities. What is clear is that this confrontation has highlighted the difficulty of balancing privacy, security and international diplomacy, and it will not be the last time these issues collide.

Tech Tip – Turn On End-to-End Encrypted Backups in WhatsApp

Backing up your chats? Make sure your backups are also encrypted. Otherwise, they could be accessed if your cloud account is compromised.

How to:

– Open WhatsApp and tap ‘Settings’.
– Go to ‘Chats > Chat Backup > End-to-End Encrypted Backup’.
– Tap ‘Turn On’ and create a password or use a 64-digit encryption key.
– Save your password safely. If you lose it, you won’t be able to restore your backup.

Pro-Tip: Encrypting backups ensures your messages stay private even if someone breaches your cloud storage.