Greenfrog Computing

Call Us: 01246 520000

sales@greenfrogcomputing.co.uk

  • REMOTE SUPPORT
  • Team
  • Support
  • Security
  • Solutions
  • Infrastructure
  • Industry
  • More
    • About Us
    • Referral Program
    • 3CX
    • Web Design and Development
    • OpenText GroupWise
    • OpenText Filr
    • OpenText Open Enterprise Server
    • Cyber Essentials
    • Testimonials
    • Blog
  • Menu Menu
photo 4 3

Tech News : 2FA Storm At Twitter

February 21, 2023/in Technology News/by Greenfrog Computing

Twitter-owner Elon Musk’s latest decision to turn off SMS 2FA after 20 March unless you pay for Blue Tick has caused another storm of criticism.

What And Why? 

On 15 February, Twitter announced that: “starting today, we will no longer allow accounts to enroll in the text message/SMS method of 2-Factor Authentication unless they are Twitter Blue subscribers.” Twitter Blue is Twitter’s own paid-for authentication service which was ramped-up recently as a way of giving Twitter another revenue stream to get away from its near total reliance upon ad revenue.

Twitter justified the change by saying that: “unfortunately we have seen phone-number based 2FA be used – and abused – by bad actors”. 

SMS 2FA Known To Be Insecure 

It’s true to say that SMS as a form of 2FA has been known (for several years) to be much less secure for authentication than some other methods. For example, cyber criminals operate SIM jacking and SIM swap hacks and obtain leaked credentials like a username, cracked password, and phone number, enabling them to get past 2FA, e.g. using a password reset and fooling the device.

That said, at least having SMS 2FA is much better and more secure than having no second authentication factor enabled.

Non-Twitter Blue Users Have 30 Days  

Twitter also announced that for non-Twitter Blue subscribers (i.e. the vast majority of Twitter users) who are currently using SMS as their 2FA method on the platform, it’s a case of being given 30 days to disable SMS and find another third-party 2FA solution, after which time, SMS 2FA will be switched off. Twitter says that “After 20 March 2023, we will no longer permit non-Twitter Blue subscribers to use text messages as a 2FA method. At that time, accounts with text message 2FA still enabled will have it disabled”. 

What Are The Options? 

Twitter recommends using an authentication app or security key method instead. Examples of popular authentication apps include Google Authenticator, Microsoft Authenticator, Authy, and LastPass Authenticator. A security key can use a USB based method, or some people connect wirelessly or through Apple’s lightning port. Examples of popular security keys include Yubico Yubikey, Kensington VeriMark USB-C, and Nitrokey FIDO2.

What If You Haven’t Found An Alternative In That Time? 

One of the main criticisms within the online storm following the announcement is that if non-Blue Tick users don’t get an alternative in place before 20 March they’ll simply be left with no protection and, presumably, open to security threats.

Others have questioned the fact that if Twitter’s move was motivated by security, wouldn’t they want their paid accounts to have a more secure method of 2FA than SMS too?

What Does This Mean For Your Business? 

Although it’s accepted that SMS for 2FA is one of the less secure methods, it seems likely that this change is more about money. For example, the Blue Tick service is a way to create a revenue stream beyond advertising and although it appears a little heavy handed, this announcement may get more Twitter users to sign up. Also, sending SMS messages costs money and Twitter presumably needs to save more money right now wherever possible. It’s not surprising that many users may feel a little concerned about being given a time limit and being essentially told to go and sort their own security arrangement out but given the troubles at Twitter lately, they may not be too surprised. That said, one positive aspect may be that it may increase awareness about the different types and brands of authenticators and security key options available and their pros and cons, and it may actually mean that non-Blue Tick accounts will be more secure and less at risk as a result.

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
https://www.greenfrogcomputing.co.uk/wp-content/uploads/2023/02/photo-4-3.jpg 375 500 Greenfrog Computing https://www.greenfrogcomputing.co.uk/wp-content/uploads/2022/08/greenfrog-computing-logo-22-1.png Greenfrog Computing2023-02-21 20:45:102023-02-21 20:45:10Tech News : 2FA Storm At Twitter

Recent Comments

    © Copyright - Greenfrog | Registered in England 04653352 | VAT No. GB 813 689800 | Legal - T&Cs | Cookies & Privacy Policy
    • Link to LinkedIn
    • Link to Facebook
    Link to: Tech Insight : What Are SPF, DKIM, And DMARC Records? Link to: Tech Insight : What Are SPF, DKIM, And DMARC Records? Tech Insight : What Are SPF, DKIM, And DMARC Records?photo 3 3 Link to: Featured Article : Usage Based Pricing And Now Hybrid Pricing Link to: Featured Article : Usage Based Pricing And Now Hybrid Pricing photo 5 3Featured Article : Usage Based Pricing And Now Hybrid Pricing
    Scroll to top Scroll to top Scroll to top

    We are using cookies to give you the best experience on our website.

    You can change your consent by clicking Settings.

    Greenfrog Computing
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

    Strictly Necessary Cookies

    Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

    3rd Party Cookies

    This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

    Keeping this cookie enabled helps us to improve our website.