Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
An update on two-factor authentication using SMS on Twitter (blog.twitter.com)
66 points by lopkeny12ko on Feb 18, 2023 | hide | past | favorite | 64 comments


Two points in a single sentence (ok 1 or 2 lines, not a single sentence)

> While historically a popular form of 2FA, unfortunately we have seen phone-number based 2FA be used - and abused - by bad actors. So starting today, we will no longer allow accounts to enroll in the text message/SMS method of 2FA unless they are Twitter Blue subscribers.

This is a cost cutting measure. The irony is that "Blue" users are probably are the ones to be attacked, and they are by no means more conscious about security.

On a lighter note, I have won more lotteries on email when compared to SMS


I am super confused about how they could write that with a straight face.

Like what does "you have to pay us to use this feature" have ANYTHING to do with the flaws that SMS 2FA has? Does paying get you someone to look at every login attempt or something? Otherwise... the blue checkbox kinda paints a target on your back?


I'm guessing it's something like "pay us for the hassle of having to clean up your mess when you end up getting hit". But the reality of it is "please pay for twitter blue. we can't just make the whole site blue only so we'll piecemeal each bit of functionality until we can just make the site paid-for only."


Yeah that's exactly what it is, them desperately trying to find reasons to force people to pay.

This one in particular is just a very odd choice. Pushing people away from SMS 2FA is one thing, but not like this.


I think you missed the point of their comment -- you both agree with each other.


I am referring to the comment the OP is talking about. Updated to make that clear.


A lot of people think that this is cost cutting. It isn't.

What people are missing is that the Twitter Blue people who paid for Twitter are the people that Twitter doesn't want to stop paying. They would if this hit them, because _even though_ security professionals know that SMS-based two-factor authentication is a security problem, and even though getting rid of it has been widely propounded by Microsoft and others for almost half a decade now (Microsoft having doco going back to 2018), the userbase still sees it as "getting rid of security" and the loss of a perquisite.

Just witness the headlines and news coverage in the past 24 hours: "Twitter will now charge to secure your account", "security features that could put a large number of the site’s members at risk if disabled", and so forth.

Amusingly, the best headline today is probably Charisma Madarang in Rolling Stone magazine: "Twitter to Allow Only Blue Subscribers to Use Worst Form of Authentication" (https://www.rollingstone.com/culture/culture-news/twitter-bl...) M. Madarang even reminds us that Jack Dorsey fell victim to this very vulnerability in 2019.

Remove this authentication choice from Twitter Blue people, and they stop paying for Twitter Blue, because they too, like the headline writers, don't see this as finally taking away something that has made them as vulnerable as Jack Dorsey was for years. So, ironically, in order to keep them paying, the Twitter Blue people get disadvantaged by Twitter. Security improvements are sacrificed in order to retain a revenue stream.


The FTC recently fined Twitter for using 2FA numbers in ad targeting. I wonder if the Blue sub includes a clause about being able to use numbers in such a way. Or the fine has reduced the value of having those numbers.


Yeah, I'm honestly offended about them saying it has anything to do with security. This is 100% solely a cost cutting measure.

As a result of this, I guarantee that tons of users will just go without any 2FA solution at all (it's still optional) which will end up being much less secure for the vast majority of users.


I’d like to see required phone numbers when signing up (presumably for my “safety”) eliminated absolutely everywhere.

It’s a way to gather PII which of course they eventually get hacked and leak.


I’m generally positive about the changes at Twitter but they really needed to keep at least one PR guy on the payroll. Adding a single sentence, “We encourage Twitter Blue subscribers to migrate away from insecure SMS-based 2FA, but we will maintain that service for their convenience” would do wonders for the overall message here.


The new Twitter; where insecurity is a for-pay feature.


Ask any security professional their thoughts are on SMS 2FA. It was not only unsafe, but also led to PII leaks and anon account unmasking.

Good riddance.


Then ask them if it's better than nothing, especially for casual users.

A lot of the folks using SMS-based 2FA will just turn it off.


It depends on your threat model. If you're an average Twitter user whose worst threat is a password spraying attack then sure, it's better than nothing.

If you're someone who is likely to be targeted specifically (you're a known crypto 'investor', you're a celebrity of some kind or another) then it's a disaster.

You're much better off just having a high-quality, unique password than you are with a high-quality, unique password on a site that with a password reset flow via SMS 2FA.


> So starting today, we will no longer allow accounts to enroll in the text message/SMS method of 2FA

Yay! Finally some horse sense is starting to penetrate the online community.

> unless they are Twitter Blue subscribers

Wait what


It's very straightforward. If you have money, you're allowed to be stupid. This is clearly the policy of Twitter 2.0.


If you have money, you're allowed to be stupid.

At least they're dogfooding!


The problem with SMS 2FA isn’t just that it’s awful/fake security, but it’s also turned into a fraud with scammers generating SMS traffic to “premium” phone numbers that charge extra for the SMS and then the scammer gets a cut.

Small companies have been hit with absolutely massive bills due to this, I’d guess Twitter has probably had its share of exorbitant SMS bills too.

Makes total sense to sunset the insecure login method, support the free & more secure version for everyone, while allowing paying users to continue to use SMS if they insist.


> Makes total sense to sunset the insecure login method, support the free & more secure version for everyone, while allowing paying users to continue to use SMS if they insist.

That's absolutely not going to happen. Tons of users who currently use SMS will just resort to having no 2FA at all - it's still optional.


While I don’t like leaving these legacy users in the dust, I do like that Twitter will no longer require a phone number when signing up (or soon after).

So frustrating for companies to tell me it’s for my safety and not some stupid way to gather PII on me and eventually get hacked and lose it (like Twitter did in 2021).


> Twitter will no longer require a phone number when signing up

...Wait, did they start requiring this at some point? I thought it was optional unless they decided to randomly lock your account later. (In other words you could play the lottery to try to avoid it if you're lucky.)


You could always sign up with email but every account was locked after it started any kind of activity (likes, tweets, etc), and was only unlocked by providing a phone number.


Tons of users might also be incentivized to spend the 3 minutes to check out and start using an Auth app to have the more secure 2FA for free.


I wish I had one of these numbers I could associate with my public profile. I would be a little more willing to talk to spammers and scammers if they had to pay for the privilege.


Yes, it’s a cost cutting measure — but a particularly sad one as Twitter once hoped to lead in this space and seemingly conceded it all to Twilio.

It’s a sad development for “Twitter Digits.”

In 2014, having harnessed text messaging around the world, Twitter leveraged its global SMS support to create sign-in capabilities that anyone could use. (Twilio, Stripe, Shop now excel at this). https://blog.twitter.com/developer/en_us/a/2014/a-better-way...


It’s hard to feel sad about the loss of a service that apparently propagates the idea of phone numbers as logins or user identifiers.


Insane that this is how far cost cutting has come.


Even if it’s because they’re broke, it’s a good move to drop SMS as an auth factor.

https://www.coinbase.com/blog/authentication-matters-coinbas...

https://images.ctfassets.net/c5bd0wqjc7v0/3Ku5foxu1kUTXa3l5x... (ato = account takeover)


Cannot have it both ways, either it is unsecure and Twitter dropping it is a security improvement, or it is secure, and they're charging for a security feature.

But you cannot argue them dropping it is a good thing while ignoring that they're charging money for people to continue to use it.


For users it's probably a security improvement.

For Twitters owner it's probably a matter of saving a few bucks on SMS fees (but that can't be much).

Twitter Blue still makes very little sense for most people unless Twitter becomes fully paywalled.


For any twitter user that goes from only-SMS-2FA to no 2FA, it isn't a "security improvement"


You can’t fix lazy users and Twitter is not so valuable (being social media) to mandate 2FA. Twitter still offers 2FA options, just not the low effort low security one (per NIST and CISA) for non paying subscribers. If you’re an unpaid user, you shouldn’t be surprised when the burden is being shifted to you (as SMS has a cost; TOTP and passkeys do not). With that said, they should implement passkeys and eliminate SMS auth entirely. 2FA is then a moot point, and everyone can move on to complaining about passkey edge cases.

https://csrc.nist.gov/csrc/media/Presentations/2022/multi-fa...

https://www.cisa.gov/sites/default/files/publications/fact-s...


You‘d be surprised how much SMS to some countries cost!

They‘re only (almost) free in the US and a few other places.


Is it? Non-SMS authentication requires a smartphone and not just a cell phone.

And they still allow it. They just make you pay for it. So it isn't a decision based on security, even though they chalk it up as such.


Is anyone using Twitter from a non smart mobile device? And if you’re using a desktop/laptop, you can use TOTP (via password managers or similar apps) or secure authenticators (hardware or passkey), no?

What are the odds you’re using Twitter without a smartphone or a desktop/laptop? Twitter deprecated tweet via sms long ago.

Anyway! I stand by the assertion. Less users using SMS for 2FA is a good thing, even if a much, much smaller paid cohort still can (~300k Blue subscribers vs ~237M daily active users).

I include CISA and NIST factsheet links on the topic in another comment in the thread, so I won’t duplicate them here.

https://www.theverge.com/2019/9/4/20849865/twitter-disables-...

https://www.theverge.com/2020/4/27/21238131/twitter-sms-noti...


Are there any cell phones left that can connect to modern cell networks but cannot run a TOTP authentication app? There are even authenticator apps for Java ME!


I was thinking of users who might have phones that have a Twitter app or capability (didn't realize at the time of my comment that SMS tweeting is no longer allowed) but no authentication method other than SMS, presumably also without a computer or reliable access to one. Maybe this is inaccurate. However, it still stands that Twitter is pushing people towards the paid subscription by using poor security arguments.


>Non-SMS authentication requires a smartphone and not just a cell phone.

Not accurate. There are applications for totp for Windows, Mac and Linux.


People love to say this, and I used to agree with them, but I don't believe this any more:

1. Governments and phone companies have "stepped up their game" a bit to greatly reduce SIM swapping attacks.

2. For the vast majority of people, SMS 2FA is better than nothing, and if you don't allow SMS people won't do anything - they don't use authenticator apps and keys can (currently) be cumbersome to use, especially across different device types.

Until we have good solutions to get off passwords altogether, SMS is a good solution for a lot of users.


It is, but having SMS MFA enabled on an account is better than no MFA.


That chart might be misleading. In the blog post they say that 95% of their users use SMS auth. 95% of people getting hacked also use SMS auth.


Isn't losing 4 million dollars a day insane for a 17 year old company?


Yes, geez, who would ever load up a company with a debt load like that?

This is a "wet streets cause rain" level of understanding.


They lost $1.14 Billion in 2020, long before Musk bought the company.

They lost $270 million dollars in the latest quarter before Musk acquired them.

This is 'make up bs to blame someone I don't like in spite of my total ignorance' levels of knowledge and understanding.


> They lost $1.14 Billion in 2020, long before Musk bought the company.

But 4 million a day is $1.4 billion per year which is still larger than $1.31 billion (adjusted for inflation)

> They lost $270 million dollars in the latest quarter before Musk acquired them.

But $270 million a quarter is only $1.08 billion per year.

So that means they were actually improving before they were acquired... but now they are getting worse again... what changed the slope?


gotta cut down on that Twilio bill


I guestimate, if they were using Twilio with the volume discount, it might be $10.5K/day ish. Which both is a lot but also isn't a lot when you consider their currently daily losses.

I imagine the main motivation isn't actually the raw cost, but rather attracting more people to Twitter Blue ($8/month) to keep the minority investors happy. Just looking for any feature they can move under that umbrella.


Which both is a lot but also isn't a lot

We're talking about a company where you have to bring your own toilet paper to work now. The turnip will be squeezed until it bleeds.


I protect my Twitter with Universal Second Factor (using a Yubikey). Does this mean Twitter will stop that feature and devolve to insecure SMS for paying members? If that's the case, it should be called out at every instance.

Account takeover attacks are no laughing matter. They can defame people and cause a lot of damage. Yubikeys/U2F should be the de facto standard for 2FA, and that feature should be for free at all times. 'Everyone deserves good security'.


what? no- it directly says so in the linked article:

> We encourage non-Twitter Blue subscribers to consider using an authentication app or security key method instead.


I do hope this in one way starts a wave of removing SMS 2FA. While convenient it is the worst solution to added security that's come around.


Does someone know of a good article on the issues with SMS 2FA suitable for non tech folk? I would like to send it to friends and family members. It just has to be easy to digest for a general audience.



That's not bad, thanks. I'll test it out with a few people and see what feedback I get.

I've already had one person say "Why in the world would anyone target me? I am nobody out of hundreds of millions of people."


This is great news. For a long time Twitter required you to add a number. Even if you signed up without it, within a few days you’d be required to add it to unlock your account.

What’s frustrating was that Twitter leaked numbers and caused a major unmasking for anon accounts.

https://www.bleepingcomputer.com/news/security/twitter-confi...


This is absolutely the correct decision. SMS 2FA is a legacy feature. Those who want a legacy feature can pay for it.


It just makes sense to align your marginal costs with your marginal price.


three tiered twitter now:

1. legacy verified & regular verified accounts

2. blue accounts

3. neither

Accounts in #3 are not allowed to make replies to their posts be visible in comments. They always get collapsed or hidden. Or when replying to others.


> So starting today, we will no longer allow accounts to enroll in the text message/SMS method of 2FA unless they are Twitter Blue subscribers.

Good. 2FA SMS was a liability anyway, and TOTP is a much better secure alternative to that.

SMS 2FA should be removed entirely.


Posted today...dated 2 days ago.


Nothing like putting a paywall on consumer security options.


2FA over SMS is the least secure option. It is free to use more secure options.


Not having 2FA at all is the least secure option. SMS-based MFA is better than no MFA, and, to be honest, I'm not sure I trust most people to keep track of MFA tokens and apps. Heck, I don't even fully trust myself to keep track of my yubikeys.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: