HomeUpdatesTwitter: End of 2FA via SMS for non-Blue users

Twitter: End of 2FA via SMS for non-Blue users

Twitter has decided to no longer provide two-factor authentication (2FA) via SMS to users who don't pay for a Twitter Blue subscription. Fortunately, there are other alternatives to protect accounts.

Twitter: End of 2FA via SMS for non-Blue users

Twitter announced that non-Twitter Blue users who use SMS two-factor authentication must switch to an alternative method by March 20, 2023, or 2FA will be disabled.

“This additional step helps ensure that you and only you can access your account,” said about the process.

See also: Elon Musk will appoint a new Twitter CEO by the end of 2023

“Non-Twitter Blue subscribers who are already signed up will have 30 days to disable this method and sign up for another,” Twitter warned. “After March 20, 2023, we will no longer allow non-Twitter Blue subscribers to use text messages as a 2FA method.”

According to a recent Twitter account security report covering the period July 2021-December 2021, only 2.6% of users actively use 2FA for added protection. Of these users, 74.4% rely on SMS 2FA , 28.9 choose an authenticator app , and 0.5% prefer a hardware security key as their preferred verification method

Elon Musk revealed that they are making this change because they are losing $60 million due to fake 2FA SMS messages.

Musk argued that authentication apps “are much more secure than SMS,” possibly referring to the risk of SIM-swapping on mobile devices.

See also: Service provider sues Twitter for not being paid

In SIM-swapping attacks, attackers take control of a target's mobile phone number by tricking or bribing mobile phone company employees to reassign the numbers to SIM controlled by the attackers. This enables threat actors to use the phone number on their own devices and receive the victim's SMS messages, including SMS multi-factor authentication (MFA) codes.

Twitter Blue

So you'll need to switch to app authenticator or security keyif you don't have a Twitter Blue subscription (otherwise you won't have 2FA protection).

While some may not agree with the introduction of this policy, it could ultimately lead to increased security for those who decide to opt out of Twitter Blue. There are more secure 2FA methods than SMS.

For maximum security, a hardware security key, such as the Google Titan or Yubikey, is the best option. They are considered more secure as they are physical devices that must be connected to a computer and in your possession to log in to account . This means that if someone gains access to your credentials, they cannot bypass 2FA, even if they steal your 2FA tokens somehow.

An alternative is to use a two-factor authentication app, such as Google Authenticator, Microsoft Authenticator, and Authy.

Twitter 2FA
Twitter: End of 2FA via SMS for non-Blue users

If an attacker obtains your login information, they won't be able to log in, thanks to the unique code generated by your mobile app. This additional security measure prevents malicious users from accessing confidential data and increases the security of user accounts.

See also: Twitter Blue introduces 4,000-character tweets

One of the biggest drawbacks of authenticator apps is that if you lose your phone, you essentially lose access to your 2FA codes, making it difficult and time-consuming to regain access to websites.

Microsoft Authenticator and Authy, however, provide the user with the ability to back up their 2FA settings to the cloud for future access in the event of a device loss. If you use Authy, make sure to disable the “Allow Multi-device” setting when not transferring codes to another device, as if your phone number is stolen, it could potentially be used to access your Authy account.

Regardless of the authentication method you use, Twitter statistics show that a large number of users do not protect their accounts with 2FA.

It is highly recommended that you enable 2FA on all online accounts you use, including Twitter, to enhance your security! With cybercrime increasing every year, setting up two-factor authentication (2FA) for all your online accounts should be one of your top priorities.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS