Twitter 2FA changes bring more risks than benefits

Twitter’s approach to nudging users away from insecure SMS-based 2FA is being questioned over its logic

Alex Scroxton

By

Published: 20 Feb 2023 14:15

Security experts are unanimous that using SMS-based two-factor authentication (2FA) is insecure and puts users at risk of compromise – SMS-based communications are too easily intercepted or redirected by malicious actors in so-called SIM swapping attacks, and the time to move away from this outdated and unsafe technology has long since passed.

So if one accepts Twitter’s announcement that it plans to remove SMS-based 2FA as an option for non-paying users on 20 March 2023 at face value, it is easy to read it as an entirely sensible and reasonable attempt to nudge users towards more secure MFA options, such as the use of a mobile application or a physical security key. It seems like a logical decision.

But it is no longer clear if Twitter is taking decisions on a logical basis; the social media platform has been plagued by a myriad of problems, many of them cyber security and compliance issues, since its takeover by erratic billionaire Elon Musk in 2022.

Many of these issues are widely thought to have been caused by Musk’s tendency to make spur-of-the-moment decisions on a whim, and there is some suggestion that this latest policy change may be one such decision, made to address one specific problem – possibly the expense of offering SMS 2FA – but without thought to the wider ramifications.

For one thing, the decision to allow paying users to retain the ability to use an insecure authentication method as a premium feature makes no sense, and nor has Twitter done anything to incentivise users to start paying for its premium “Blue” tier.

As such, said Andy Kays, CEO of Socura, a supplier of managed detection and response (MDR) services, it will shortly be “Christmas come early” for fraudsters.

Everyone knows SMS-based 2FA has its flaws, explained Kays, but because it is easier – and usually cheaper – to use, it has become a security feature of great value to the lay population.

“In the short term, the removal of 2FA could be harmful, especially among less tech-savvy social media users,” said Kays. “Most people will switch from using SMS 2FA to using no form of 2FA whatsoever. They will be far less secure as a result, and a prime target for fraudsters, cyber criminals and identity thieves.”

“In the long term, we can only hope that this move is the catalyst for universal authentic app adoption. It is true that authenticator apps are a much better form of 2FA, but users should have been encouraged to switch at their own free will over a period of time, not forced to do so,” he said.

Alexander Heid, chief research and development officer at security rating specialist SecurityScorecard, said: “When SMS-based 2FA is disabled on 20 March, there may be a small percentage of non-paying users experience account takeovers if they have been reusing passwords that are circulating on public data breaches and relying solely on SMS-based 2FA to keep their account secure.

“If a person is in the habit of reusing old passwords, it is advised to change your password regardless of the 20 March switchover.

However, he added: “It has been reported that only 2.6% of Twitter users make use of 2FA – so only a small portion of overall Twitter users will be impacted by these changes.”

Alternative options

If you are currently using SMS-based 2FA to log in to Twitter and would prefer not to be made to pay to retain the use of an insecure service, Twitter will continue to make two other options available, both of which are worth considering.

The most secure 2FA option for Twitter is a physical security key – such as Yubikey by Yubico or Google Titan – a small device that connects to your computer, either via the USB port or wireless connectivity, to generate a one-time passcode (OTP) that you can then use to log in to the service.

Physical keys are considered highly secure because they must be in your possession, and cannot be easily bypassed should a cyber criminal have compromised your Twitter credentials.

An authenticator application – such as Authy by Twilio, Google Authenticator or LastPass – works on a similar principle but generates codes on your mobile device that you can use when you log in to Twitter.

Such apps still provides a decent level of protection should your credentials have been compromised somehow, but are vulnerable if your mobile is stolen and impractical if your mobile is lost.

Read more on Identity and access management products

Read More
Elida Klemp

Latest

Embracer Follows Ubisoft In Splitting Off New Publisher To Handle Huge IP, Tomb Raider & LOTR Included

Say hello to Fellowship Entertainment by Ben Kerry 11 hours ago Embracer Group has today announced plans to create a secondary publishing label called Fellowship Entertainment, in order to "capture the full potential of the high-quality assets" that the group currently owns. The Swedish game publisher says that it hopes to spin off Fellowship Entertainment

Gwyneth Paltrow’s Daughter Apple Martin in Nancy Meyers Movie

Gwyneth Paltrow's Daughter Apple Martin Makes Directorial Debut With Student Show Apple Martin doesn’t fall far from the tree. Gwyneth Paltrow and Chris Martin ’s daughter will be following in her mom’s acting footsteps and making her movie debut in Nancy Meyers’ upcoming film, Deadline and Entertainment Weekly reported on May 18. The 22-year-old—who graduated

Lil Wayne speaks out after feeling overlooked by Coachella and the Grammys

Music Lil Wayne reacts to Coachell and Grammys snub Award-winning...

Newsletter

Don't miss

Embracer Follows Ubisoft In Splitting Off New Publisher To Handle Huge IP, Tomb Raider & LOTR Included

Say hello to Fellowship Entertainment by Ben Kerry 11 hours ago Embracer Group has today announced plans to create a secondary publishing label called Fellowship Entertainment, in order to "capture the full potential of the high-quality assets" that the group currently owns. The Swedish game publisher says that it hopes to spin off Fellowship Entertainment

Gwyneth Paltrow’s Daughter Apple Martin in Nancy Meyers Movie

Gwyneth Paltrow's Daughter Apple Martin Makes Directorial Debut With Student Show Apple Martin doesn’t fall far from the tree. Gwyneth Paltrow and Chris Martin ’s daughter will be following in her mom’s acting footsteps and making her movie debut in Nancy Meyers’ upcoming film, Deadline and Entertainment Weekly reported on May 18. The 22-year-old—who graduated

Lil Wayne speaks out after feeling overlooked by Coachella and the Grammys

Music Lil Wayne reacts to Coachell and Grammys snub Award-winning...

Kehlani at 30: How ‘Folded’ Changed Everything | Billboard Women In Music 2026

MusicBillboard Women in Music 2026 Impact Award recipient...

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand