Twitter is set to prohibit its non-paying users from using the SMS-based two-factor authentication (2FA) to secure their accounts, forcing millions to look for an alternative protection method.
The 2FA is a security method that requires users to confirm their identity twice before being granted an access to their accounts. One of the most popular 2FA method is the SMS-based one, which allows users to receive a one-time password through a text message to authenticate themselves before logging into their accounts.
“While historically a popular form of 2FA, unfortunately we have seen phone-number based 2FA be used – and abused – by bad actors,” Twitter said in a statement, encouraging its non-paying users to use an authentication app or security key method instead.
Twitter: “Effective March 20, 2023, only Twitter Blue subscribers will be able to use text messages as their two-factor authentication method.”
Twitter Blue is a paid subscription service that adds a blue checkmark to a user’s account for £8 or £11 a month. It’s estimated that there were about 290,000 Twitter Blue subscribers as of mid-January, just a fraction of the social media giant’s 368 million monthly active users.
Despite an outcry from various users against the new Twitter policy, SMS-based 2FA is actually notorious for its weak security. As SMS is relatively easy to compromise, hackers can intercept an OTP texted to a phone and gain access to a user’s account. Hence, this may be a good time to switch to an authentication app or security key method.