Twitter faces FTC probe, likely fine over use of phone numbers for ads
arstechnica.com
arstechnica.com
In general, SMS is better than no 2FA, but it's weaker than OTP/OTH or a token like YubiKey or Titan.
And IIRC at the time Twitter didn't offer any other 2FA mechanisms.
It's certainly a violation of trust that could make people less likely to volunteer extra information for 2FA that could be used against them, even if it might also make them safer. For that alone, wilful violations ought to be treated as a serious breach under data protection laws.
The number of important financial services I use that now insist on phone numbers for 2FA is getting irritating, too. Apparently in some cases it's been prompted by the changes in EU rules under PSD2, but as with almost everything else I've come across so far under PSD2, I'm not sure how much safer it will really make anyone. At least those financial services -- and my government, which is the other organisation I see doing this routinely now -- probably aren't going to use the contact information for anything other than the 2FA they claim, though.
Trust me, if our agencies had teeth, and executed a corporation for shit like this, we'd have a better technology ecosystem.
This sort of nonsensical reasoning has also used by individuals portraying themselves as "whitehats" who try to profit from large leaks of personal data. Users are asked to provide personal data to the whitehat in order to confirm whether their personal data has been leaked.
They obviously have enough engineers and awareness to do software based OTP, and clearly only want SMS for their phone number social graph and data brokering operation.
So, LOL FTC.
That's close to 10% of Twitter's annual revenue. How do the likes of Google and Facebook get away with fines <1% of annual revenue? This seems disproportionate. I am not taking a position on whether it should be higher or lower, just that it appears unbalanced.
It is really hard to grasp how pathetic the modern web is, where this is commonplace.
The weakness here is both the legal system that allowed it and the regulatory system that failed to police it for years.
Google and Facebook spend more on lobbying.
Did they send spam SMS? Or were they using the numbers as another data point for analytics?
Maybe some pseudonymous proof using cryptographic functions of modern passports could be used somehow without revealing real identity to the passport issuer too? It should not be possible to know who issued the pseudonymous identity proof but should also only be proof-able by me...
>Maybe some pseudonymous proof using cryptographic functions of modern passports could be used somehow without revealing real identity to the passport issuer too?
You can still lose your passport. It's less likely than losing your phone, but still. Also, to access the cryptographic functions of a passport, you probably need a NFC reader, which isn't exactly accessible.
i thought maybe the pseudonymous identity proof could still work after your passport has been reissued either because of loss or because of invalidation. But its probably not really doable with named constraints. Modern phones are apparently often equipped with an NFC reader. I think this could be usable enough for the recovery case.
I know there is Google Voice, but it I don't want my disposal number to be linked with my real phone number.
When opening a support ticket about it, they claim it was a "mistake and" offer to unlock the account but I always suspected it was a disgusting tactic for harvesting phone numbers and I guess I was right.
TikTok for Tulsa Twitter for warning labels
Or did the investigation begin before those events?
> In addition to these violations of its 2012 order, the FTC alleges that Facebook violated the FTC Act’s prohibition against deceptive practices when it told users it would collect their phone numbers to enable a security feature, but did not disclose that it also used those numbers for advertising purposes.
https://www.ftc.gov/news-events/press-releases/2019/07/ftc-i...