https://www.coinbase.com/blog/authentication-matters-coinbas...
https://images.ctfassets.net/c5bd0wqjc7v0/3Ku5foxu1kUTXa3l5x... (ato = account takeover)
https://www.coinbase.com/blog/authentication-matters-coinbas...
https://images.ctfassets.net/c5bd0wqjc7v0/3Ku5foxu1kUTXa3l5x... (ato = account takeover)
But you cannot argue them dropping it is a good thing while ignoring that they're charging money for people to continue to use it.
For Twitters owner it's probably a matter of saving a few bucks on SMS fees (but that can't be much).
Twitter Blue still makes very little sense for most people unless Twitter becomes fully paywalled.
https://csrc.nist.gov/csrc/media/Presentations/2022/multi-fa...
https://www.cisa.gov/sites/default/files/publications/fact-s...
They‘re only (almost) free in the US and a few other places.
And they still allow it. They just make you pay for it. So it isn't a decision based on security, even though they chalk it up as such.
What are the odds you’re using Twitter without a smartphone or a desktop/laptop? Twitter deprecated tweet via sms long ago.
Anyway! I stand by the assertion. Less users using SMS for 2FA is a good thing, even if a much, much smaller paid cohort still can (~300k Blue subscribers vs ~237M daily active users).
I include CISA and NIST factsheet links on the topic in another comment in the thread, so I won’t duplicate them here.
https://www.theverge.com/2019/9/4/20849865/twitter-disables-...
https://www.theverge.com/2020/4/27/21238131/twitter-sms-noti...
Not accurate. There are applications for totp for Windows, Mac and Linux.
1. Governments and phone companies have "stepped up their game" a bit to greatly reduce SIM swapping attacks.
2. For the vast majority of people, SMS 2FA is better than nothing, and if you don't allow SMS people won't do anything - they don't use authenticator apps and keys can (currently) be cumbersome to use, especially across different device types.
Until we have good solutions to get off passwords altogether, SMS is a good solution for a lot of users.