
In February 2019, I reached out to the Facebook team regarding a bug I found in WhatsApp's two-step verification reminder feature—a feature designed to help users remember their PIN.
WhatsApp Two-Step Verification?
Two-step verification is an optional feature that adds an extra layer of security to your account. When you have two-step verification enabled, any attempt to verify your phone number on WhatsApp must be accompanied by the six-digit PIN you created with this feature.
For more details, check the WhatsApp FAQ: https://faq.whatsapp.com/en/android/26000021

How does it work?
To help you remember your PIN, WhatsApp will periodically ask you to enter it. There is no option to disable this without disabling the two-step verification feature altogether.
Did you catch that? "There is no option to disable this without disabling the two-step verification feature."

How did I find the bug?
While using WhatsApp, it prompted me for my PIN, and I started doing random things on my iPhone to see how the app would react—until I discovered that if I rotated the iPhone to landscape and opened WhatsApp while in that position, it would let me open the app and access it without disabling the two-step verification feature.
I won't take all the credit for this discovery. I have to confess that my little girl teaches me how to do all sorts of weird things on my iPhone—she's always doing quirky stuff on every smartphone she gets her hands on. So this bug carries her name, my princess 🙂
The bug affects iOS and the latest version of WhatsApp. I tested it on the iPhone 8 Plus and iPhone 6 (although the latter doesn't rotate the home screen). It could affect Android or other iPhone models—that's up to you to test and report.
Bug Reported to Facebook
If you find a bug in one of Facebook's applications, you can report it through this link: https://www.facebook.com/whitehat/
Since this bug is in the reminder feature and doesn't affect the registration process or your privacy in any way, it was not considered a security issue. Here's their response to my report:

I agree with the Facebook team, since this two-step verification is not a two-factor authentication mechanism but rather a reminder to help the user remember their PIN.
Although I agree with the Facebook team, I'd like to ask you: what do you think of their response? Do you think it's a security flaw, or do you also agree with them?
Conclusion
As Security Specialists, we sometimes overcomplicate things when looking for security vulnerabilities or bugs in applications. Numerous times I found myself trying to pull off ninja-level moves in a Pentest, Web Application, or CTF challenge, and the solution was much simpler than I initially thought.
I just want to recommend that all security professionals start by fixing the low-hanging-fruit security issues in their networks, applications, systems, etc., that could cause a big impact on operations—and then move on to building defenses against advanced threats or whatever 0-days pop up on Twitter.
Thanks for reading. 🙂
God bless you! Serving Christ is not a task, but a relationship. Friends of God. Jn 15:15
