Twitter Users, You’ll Soon Lose Access to Two-Factor Authentication Unless You Pay

Here's why it matters.

twitter app
PHOTO BY Shuttershock

(SPOT.ph) Elon Musk’s Twitter Blue subscription has changed the way everyone’s favorite bird app works, for better or for worse.

This time around, many online users—security experts included—believe it has officially taken a turn for the worst following Twitter’s announcement that it will only allow Twitter Blue subscribers to use the SMS two-factor authentication starting March 20.

Two-factor authentication (2FA) is an additional layer of protection that asks users to have a two-step verification process to log in, the first piece being the traditional username/email and password combination, and the second being a 2FA method of your choice. 

Non-Twitter Blue subscribers will be given 30 days until March 19 to disable the SMS method and enroll in another. Doing so won’t remove the phone number from the user’s account information.

However, it is unclear what happens to users in countries such as the Philippines where Twitter Blue isn’t even available yet. This leaves them with no choice but to switch to other less common methods of 2FA or risk staying unprotected.

Also read: How to Turn On Two-Factor Authentication, Avoid Getting Hacked

What does this mean for non-Twitter Blue users?

2FA was never a required step for logging in on Twitter, but it helps maintain account protection.

Article continues after this ad.
ADVERTISEMENT - CONTINUE READING BELOW

There are three common methods of 2FA: text message, authentication app, and security key. Of the Twitter users who have 2FA enabled, 74.4% of them use SMS authentication. 

“While historically a popular form of 2FA, unfortunately, we have seen phone-number based 2FA be used—and abused—by bad actors,” Twitter wrote in a blog. “So starting today, we will no longer allow accounts to enroll in the text message/SMS method of 2FA unless they are Twitter Blue subscribers.”

Musk also confirmed in a tweet that Twitter decided to change its security policy after it was losing U.S. $60 million a year from bot accounts pushing out scam SMS for 2FA.

Instead, Twitter is encouraging its free users to consider using an authentication app or a security key for 2FA. However, these methods aren’t as easy and convenient to set up compared to SMS-based 2FA, so it has several implications for less tech-savvy Twitter users: should we have to pay for basic security?

For digital rights activist Evan Greer, turning SMS-based 2FA into a “luxury feature” will only expose more users to potential data hacks and breaches.

"We know that most users simply stick with defaults or just don't take action if they're confused or unsure," Greer told NPR in an email. "In practice, this could mean that millions of vulnerable Twitter users are suddenly booted off of 2-factor authentication and don't set it back up again."

Twitter was half right in its claim—the SMS method of 2FA isn’t as secure as most make it out to be with its own set of vulnerabilities, but at the end of the day, it’s still better than nothing.

Once released, Twitter Blue is reported to cost P145 a month in the Philippines.

Also read:
Twitter to Suspend Parody Accounts Who Fail to Label Themselves as Parody Accounts
Twitter Users, Promoting Your Facebook or Instagram Account Could Get You in Trouble

Article continues after this video.
ADVERTISEMENT
watch now
Article continues after this ad.
ADVERTISEMENT - CONTINUE READING BELOW
Share this story with your friends!

Help us make Spot.ph better!
Take the short survey

Read more stories about

Latest Stories

Load More Stories