An update on two-factor authentication using SMS on Twitter
blog.twitter.com
blog.twitter.com
> While historically a popular form of 2FA, unfortunately we have seen phone-number based 2FA be used - and abused - by bad actors. So starting today, we will no longer allow accounts to enroll in the text message/SMS method of 2FA unless they are Twitter Blue subscribers.
This is a cost cutting measure. The irony is that "Blue" users are probably are the ones to be attacked, and they are by no means more conscious about security.
On a lighter note, I have won more lotteries on email when compared to SMS
Like what does "you have to pay us to use this feature" have ANYTHING to do with the flaws that SMS 2FA has? Does paying get you someone to look at every login attempt or something? Otherwise... the blue checkbox kinda paints a target on your back?
This one in particular is just a very odd choice. Pushing people away from SMS 2FA is one thing, but not like this.
What people are missing is that the Twitter Blue people who paid for Twitter are the people that Twitter doesn't want to stop paying. They would if this hit them, because _even though_ security professionals know that SMS-based two-factor authentication is a security problem, and even though getting rid of it has been widely propounded by Microsoft and others for almost half a decade now (Microsoft having doco going back to 2018), the userbase still sees it as "getting rid of security" and the loss of a perquisite.
Just witness the headlines and news coverage in the past 24 hours: "Twitter will now charge to secure your account", "security features that could put a large number of the site’s members at risk if disabled", and so forth.
Amusingly, the best headline today is probably Charisma Madarang in Rolling Stone magazine: "Twitter to Allow Only Blue Subscribers to Use Worst Form of Authentication" (https://www.rollingstone.com/culture/culture-news/twitter-bl...) M. Madarang even reminds us that Jack Dorsey fell victim to this very vulnerability in 2019.
Remove this authentication choice from Twitter Blue people, and they stop paying for Twitter Blue, because they too, like the headline writers, don't see this as finally taking away something that has made them as vulnerable as Jack Dorsey was for years. So, ironically, in order to keep them paying, the Twitter Blue people get disadvantaged by Twitter. Security improvements are sacrificed in order to retain a revenue stream.
As a result of this, I guarantee that tons of users will just go without any 2FA solution at all (it's still optional) which will end up being much less secure for the vast majority of users.
It’s a way to gather PII which of course they eventually get hacked and leak.
Good riddance.
A lot of the folks using SMS-based 2FA will just turn it off.
If you're someone who is likely to be targeted specifically (you're a known crypto 'investor', you're a celebrity of some kind or another) then it's a disaster.
You're much better off just having a high-quality, unique password than you are with a high-quality, unique password on a site that with a password reset flow via SMS 2FA.
Yay! Finally some horse sense is starting to penetrate the online community.
> unless they are Twitter Blue subscribers
Wait what
At least they're dogfooding!
Small companies have been hit with absolutely massive bills due to this, I’d guess Twitter has probably had its share of exorbitant SMS bills too.
Makes total sense to sunset the insecure login method, support the free & more secure version for everyone, while allowing paying users to continue to use SMS if they insist.
That's absolutely not going to happen. Tons of users who currently use SMS will just resort to having no 2FA at all - it's still optional.
So frustrating for companies to tell me it’s for my safety and not some stupid way to gather PII on me and eventually get hacked and lose it (like Twitter did in 2021).
...Wait, did they start requiring this at some point? I thought it was optional unless they decided to randomly lock your account later. (In other words you could play the lottery to try to avoid it if you're lucky.)
It’s a sad development for “Twitter Digits.”
In 2014, having harnessed text messaging around the world, Twitter leveraged its global SMS support to create sign-in capabilities that anyone could use. (Twilio, Stripe, Shop now excel at this). https://blog.twitter.com/developer/en_us/a/2014/a-better-way...
https://www.coinbase.com/blog/authentication-matters-coinbas...
https://images.ctfassets.net/c5bd0wqjc7v0/3Ku5foxu1kUTXa3l5x... (ato = account takeover)
But you cannot argue them dropping it is a good thing while ignoring that they're charging money for people to continue to use it.
For Twitters owner it's probably a matter of saving a few bucks on SMS fees (but that can't be much).
Twitter Blue still makes very little sense for most people unless Twitter becomes fully paywalled.
https://csrc.nist.gov/csrc/media/Presentations/2022/multi-fa...
https://www.cisa.gov/sites/default/files/publications/fact-s...
They‘re only (almost) free in the US and a few other places.
And they still allow it. They just make you pay for it. So it isn't a decision based on security, even though they chalk it up as such.
What are the odds you’re using Twitter without a smartphone or a desktop/laptop? Twitter deprecated tweet via sms long ago.
Anyway! I stand by the assertion. Less users using SMS for 2FA is a good thing, even if a much, much smaller paid cohort still can (~300k Blue subscribers vs ~237M daily active users).
I include CISA and NIST factsheet links on the topic in another comment in the thread, so I won’t duplicate them here.
https://www.theverge.com/2019/9/4/20849865/twitter-disables-...
https://www.theverge.com/2020/4/27/21238131/twitter-sms-noti...
Not accurate. There are applications for totp for Windows, Mac and Linux.
1. Governments and phone companies have "stepped up their game" a bit to greatly reduce SIM swapping attacks.
2. For the vast majority of people, SMS 2FA is better than nothing, and if you don't allow SMS people won't do anything - they don't use authenticator apps and keys can (currently) be cumbersome to use, especially across different device types.
Until we have good solutions to get off passwords altogether, SMS is a good solution for a lot of users.
This is a "wet streets cause rain" level of understanding.
They lost $270 million dollars in the latest quarter before Musk acquired them.
This is 'make up bs to blame someone I don't like in spite of my total ignorance' levels of knowledge and understanding.
But 4 million a day is $1.4 billion per year which is still larger than $1.31 billion (adjusted for inflation)
> They lost $270 million dollars in the latest quarter before Musk acquired them.
But $270 million a quarter is only $1.08 billion per year.
So that means they were actually improving before they were acquired... but now they are getting worse again... what changed the slope?
I imagine the main motivation isn't actually the raw cost, but rather attracting more people to Twitter Blue ($8/month) to keep the minority investors happy. Just looking for any feature they can move under that umbrella.
We're talking about a company where you have to bring your own toilet paper to work now. The turnip will be squeezed until it bleeds.
Account takeover attacks are no laughing matter. They can defame people and cause a lot of damage. Yubikeys/U2F should be the de facto standard for 2FA, and that feature should be for free at all times. 'Everyone deserves good security'.
> We encourage non-Twitter Blue subscribers to consider using an authentication app or security key method instead.
I've already had one person say "Why in the world would anyone target me? I am nobody out of hundreds of millions of people."
What’s frustrating was that Twitter leaked numbers and caused a major unmasking for anon accounts.
https://www.bleepingcomputer.com/news/security/twitter-confi...
1. legacy verified & regular verified accounts
2. blue accounts
3. neither
Accounts in #3 are not allowed to make replies to their posts be visible in comments. They always get collapsed or hidden. Or when replying to others.
Good. 2FA SMS was a liability anyway, and TOTP is a much better secure alternative to that.
SMS 2FA should be removed entirely.