The feature is called "Login Verification", I think, and it's only SMS based, no Google Authenticator / Authy style one-time password... Also, it was saying I needed to verify my email address before that feature can be used, but there was no option to verify the email address that is used since I've registered almost a decade ago... Had to change my email (used the username+somestring@gmail.com trick to reuse my address, as one email can be used with only one twitter account...) then change it back.
If I go 40 miles south I'm in ( the Republic of ) Ireland and can't receive SMS.
It feels like data collection veiled in security. Giving out more personal information is the exact opposite of everything I've learned about privacy and security.
Twitter uses a one-time code sent via sms so I don't think this would be an issue unless the hack is persistent.
Oh, damn. Thanks for pointing this out. I'd never looked into the details of HOTP or TOTP -- I assumed they were using public-key crypto rather than just a hash of shared values. That sucks. :(
The article says data may have come from user input, so yeah, 2FA would actually help there and wouldn't "leak".
The post also gives a justification for using symmetric encryption, it lets the tokens users enter be shorter.
If you're worried about your privacy, which is understandable, buy a prepaid sim card, a cheap phone and use it only for your 2FA accounts. Not sure about the US, but in my country prepaid GSM sim cards are cheap and you don't have to give away your ID to buy one (though this may change soon).
So no, "by that logic" doesn't apply. You can choose to use something else than a phone to auth, but if it's SMS based well... I just came back from a week in France where I had zero cell connectivity. Had I been using any kind of SMS based 2fa, I would have lost access to those accounts with no forewarning.
My bank requires SMS confirmation every time I send money online, and when I was in the US for 10 days, even with my SIM, I couldn't get SMS's, and thus couldn't do banking. This is extremely annoying.
All I'm really saying is that limited options does not mean "broken". It just means limited options.
It's vulnerable to social engineering of your cell provider's customer support line, for one. It's happened before [1].
[1] http://gizmodo.com/how-hackers-reportedly-side-stepped-gmail...
All I can suggest is to keep trying every few months. I have been trying for years. My carrier still isn't listed but it finally started working about two weeks ago for me (I'm not in Germany though). Now I have to hope it keeps working with my still unlisted carrier or I risk getting locked out of my account. At least the bad guys are locked out too...