Two points in a single sentence (ok 1 or 2 lines, not a single sentence)
> While historically a popular form of 2FA, unfortunately we have seen phone-number based 2FA be used - and abused - by bad actors. So starting today, we will no longer allow accounts to enroll in the text message/SMS method of 2FA unless they are Twitter Blue subscribers.
This is a cost cutting measure. The irony is that "Blue" users are probably are the ones to be attacked, and they are by no means more conscious about security.
On a lighter note, I have won more lotteries on email when compared to SMS
I am super confused about how they could write that with a straight face.
Like what does "you have to pay us to use this feature" have ANYTHING to do with the flaws that SMS 2FA has? Does paying get you someone to look at every login attempt or something? Otherwise... the blue checkbox kinda paints a target on your back?
I'm guessing it's something like "pay us for the hassle of having to clean up your mess when you end up getting hit". But the reality of it is "please pay for twitter blue. we can't just make the whole site blue only so we'll piecemeal each bit of functionality until we can just make the site paid-for only."
A lot of people think that this is cost cutting. It isn't.
What people are missing is that the Twitter Blue people who paid for Twitter are the people that Twitter doesn't want to stop paying. They would if this hit them, because _even though_ security professionals know that SMS-based two-factor authentication is a security problem, and even though getting rid of it has been widely propounded by Microsoft and others for almost half a decade now (Microsoft having doco going back to 2018), the userbase still sees it as "getting rid of security" and the loss of a perquisite.
Just witness the headlines and news coverage in the past 24 hours: "Twitter will now charge to secure your account", "security features that could put a large number of the site’s members at risk if disabled", and so forth.
Amusingly, the best headline today is probably Charisma Madarang in Rolling Stone magazine: "Twitter to Allow Only Blue Subscribers to Use Worst Form of Authentication" (https://www.rollingstone.com/culture/culture-news/twitter-bl...) M. Madarang even reminds us that Jack Dorsey fell victim to this very vulnerability in 2019.
Remove this authentication choice from Twitter Blue people, and they stop paying for Twitter Blue, because they too, like the headline writers, don't see this as finally taking away something that has made them as vulnerable as Jack Dorsey was for years. So, ironically, in order to keep them paying, the Twitter Blue people get disadvantaged by Twitter. Security improvements are sacrificed in order to retain a revenue stream.
The FTC recently fined Twitter for using 2FA numbers in ad targeting. I wonder if the Blue sub includes a clause about being able to use numbers in such a way. Or the fine has reduced the value of having those numbers.
Yeah, I'm honestly offended about them saying it has anything to do with security. This is 100% solely a cost cutting measure.
As a result of this, I guarantee that tons of users will just go without any 2FA solution at all (it's still optional) which will end up being much less secure for the vast majority of users.
I’m generally positive about the changes at Twitter but they really needed to keep at least one PR guy on the payroll. Adding a single sentence, “We encourage Twitter Blue subscribers to migrate away from insecure SMS-based 2FA, but we will maintain that service for their convenience” would do wonders for the overall message here.
It depends on your threat model. If you're an average Twitter user whose worst threat is a password spraying attack then sure, it's better than nothing.
If you're someone who is likely to be targeted specifically (you're a known crypto 'investor', you're a celebrity of some kind or another) then it's a disaster.
You're much better off just having a high-quality, unique password than you are with a high-quality, unique password on a site that with a password reset flow via SMS 2FA.
The problem with SMS 2FA isn’t just that it’s awful/fake security, but it’s also turned into a fraud with scammers generating SMS traffic to “premium” phone numbers that charge extra for the SMS and then the scammer gets a cut.
Small companies have been hit with absolutely massive bills due to this, I’d guess Twitter has probably had its share of exorbitant SMS bills too.
Makes total sense to sunset the insecure login method, support the free & more secure version for everyone, while allowing paying users to continue to use SMS if they insist.
> Makes total sense to sunset the insecure login method, support the free & more secure version for everyone, while allowing paying users to continue to use SMS if they insist.
That's absolutely not going to happen. Tons of users who currently use SMS will just resort to having no 2FA at all - it's still optional.
While I don’t like leaving these legacy users in the dust, I do like that Twitter will no longer require a phone number when signing up (or soon after).
So frustrating for companies to tell me it’s for my safety and not some stupid way to gather PII on me and eventually get hacked and lose it (like Twitter did in 2021).
> Twitter will no longer require a phone number when signing up
...Wait, did they start requiring this at some point? I thought it was optional unless they decided to randomly lock your account later. (In other words you could play the lottery to try to avoid it if you're lucky.)
You could always sign up with email but every account was locked after it started any kind of activity (likes, tweets, etc), and was only unlocked by providing a phone number.
I wish I had one of these numbers I could associate with my public profile. I would be a little more willing to talk to spammers and scammers if they had to pay for the privilege.
Yes, it’s a cost cutting measure — but a particularly sad one as Twitter once hoped to lead in this space and seemingly conceded it all to Twilio.
It’s a sad development for “Twitter Digits.”
In 2014, having harnessed text messaging around the world, Twitter leveraged its global SMS support to create sign-in capabilities that anyone could use. (Twilio, Stripe, Shop now excel at this). https://blog.twitter.com/developer/en_us/a/2014/a-better-way...
Cannot have it both ways, either it is unsecure and Twitter dropping it is a security improvement, or it is secure, and they're charging for a security feature.
But you cannot argue them dropping it is a good thing while ignoring that they're charging money for people to continue to use it.
You can’t fix lazy users and Twitter is not so valuable (being social media) to mandate 2FA. Twitter still offers 2FA options, just not the low effort low security one (per NIST and CISA) for non paying subscribers. If you’re an unpaid user, you shouldn’t be surprised when the burden is being shifted to you (as SMS has a cost; TOTP and passkeys do not). With that said, they should implement passkeys and eliminate SMS auth entirely. 2FA is then a moot point, and everyone can move on to complaining about passkey edge cases.
Is anyone using Twitter from a non smart mobile device? And if you’re using a desktop/laptop, you can use TOTP (via password managers or similar apps) or secure authenticators (hardware or passkey), no?
What are the odds you’re using Twitter without a smartphone or a desktop/laptop? Twitter deprecated tweet via sms long ago.
Anyway! I stand by the assertion. Less users using SMS for 2FA is a good thing, even if a much, much smaller paid cohort still can (~300k Blue subscribers vs ~237M daily active users).
I include CISA and NIST factsheet links on the topic in another comment in the thread, so I won’t duplicate them here.
Are there any cell phones left that can connect to modern cell networks but cannot run a TOTP authentication app? There are even authenticator apps for Java ME!
I was thinking of users who might have phones that have a Twitter app or capability (didn't realize at the time of my comment that SMS tweeting is no longer allowed) but no authentication method other than SMS, presumably also without a computer or reliable access to one. Maybe this is inaccurate. However, it still stands that Twitter is pushing people towards the paid subscription by using poor security arguments.
People love to say this, and I used to agree with them, but I don't believe this any more:
1. Governments and phone companies have "stepped up their game" a bit to greatly reduce SIM swapping attacks.
2. For the vast majority of people, SMS 2FA is better than nothing, and if you don't allow SMS people won't do anything - they don't use authenticator apps and keys can (currently) be cumbersome to use, especially across different device types.
Until we have good solutions to get off passwords altogether, SMS is a good solution for a lot of users.
I guestimate, if they were using Twilio with the volume discount, it might be $10.5K/day ish. Which both is a lot but also isn't a lot when you consider their currently daily losses.
I imagine the main motivation isn't actually the raw cost, but rather attracting more people to Twitter Blue ($8/month) to keep the minority investors happy. Just looking for any feature they can move under that umbrella.
I protect my Twitter with Universal Second Factor (using a Yubikey). Does this mean Twitter will stop that feature and devolve to insecure SMS for paying members? If that's the case, it should be called out at every instance.
Account takeover attacks are no laughing matter. They can defame people and cause a lot of damage. Yubikeys/U2F should be the de facto standard for 2FA, and that feature should be for free at all times. 'Everyone deserves good security'.
Does someone know of a good article on the issues with SMS 2FA suitable for non tech folk? I would like to send it to friends and family members. It just has to be easy to digest for a general audience.
This is great news. For a long time Twitter required you to add a number. Even if you signed up without it, within a few days you’d be required to add it to unlock your account.
What’s frustrating was that Twitter leaked numbers and caused a major unmasking for anon accounts.
Not having 2FA at all is the least secure option. SMS-based MFA is better than no MFA, and, to be honest, I'm not sure I trust most people to keep track of MFA tokens and apps. Heck, I don't even fully trust myself to keep track of my yubikeys.
> While historically a popular form of 2FA, unfortunately we have seen phone-number based 2FA be used - and abused - by bad actors. So starting today, we will no longer allow accounts to enroll in the text message/SMS method of 2FA unless they are Twitter Blue subscribers.
This is a cost cutting measure. The irony is that "Blue" users are probably are the ones to be attacked, and they are by no means more conscious about security.
On a lighter note, I have won more lotteries on email when compared to SMS