Twitter has announced that starting with March 20, users who don’t pay the Twitter Blue subscription will no longer be able to use the SMS-based two-factor authentication (2FA) option. “While historically a popular form of 2FA, unfortunately we have seen phone-number based 2FA be used – and abused – by bad actors,” the company said. Twitter CEO Elon Musk further explained the rationale behind the move by claiming that “Twitter is getting scammed by phone companies for $60M/year of fake 2FA SMS messages.” For good or for bad Some security professionals have been commenting the move, some arguing that it’s good because it will push users away from a relatively easily bypassed 2FA option towards more secure ones: authenticator apps that provide one-time access codes and hardware security keys. Others pointed out that even SMS-based 2FA is better than just securing accounts with a password. According to the last known 2FA usage numbers (from 2H 2021), the SMS-based 2FA option is the most widely used by far, because less tech-savvy users find it to be the easiest to understand and set up. It now remains to be seen if this latest move by Twitter will push those users towards a
Read More











