> that's just shifting the blame onto the user.
Even so, it's the first time I've seen a company actually imply to the public in plain English that they can't protect private info, rather than maintain a facade of security that doesn't actually exist.
As you point out though, if Twitter requires a phone number to sign up and 99.9% of users use their personal number, then Twitter are basically saying "our security sucks and if you want an account you have no alternative...".
Some interesting corollaries:
- Are there any services that will sign up to twitter on behalf of users? (and would they work or would it be merely shifting trust from Twitter to a potentially less trustworthy party?)
- I wonder if Twitter could consider not requiring personal info at sign up so as to avoid this dark UX
- Is there a 10 minute mail for phone numbers?