Twitter Will Finally Let Users Disable SMS as Default 2FA Method (zdnet.com) 9
Twitter says users will finally be able to disable SMS-based two-factor authentication (2FA) for their accounts, and use an alternative method only, such as a mobile one-time code (OTP) authenticator app or a hardware security key. Until this week, this was impossible. From a report: If users wanted to use 2FA for their Twitter account, they had to register a phone number and enable the SMS-based 2FA method, even if they wished it or not. Users who wanted to use an OTP mobile authenticator app or a hardware security key, had to enable the SMS-based 2FA first, and they couldn't disable it. Even if the user chose to use a security key, the SMS-based 2FA method was still active, and exposed the account to attacks known as SIM swaps. Hackers who knew a user's password would perform a SIM swap to temporarily hijack a user's phone number, bypass SMS-based 2FA, and then take over that user's account.
It only took Jack Dorsey being hacked (Score:1)
to add such a basic feature!
Don't use it, your now authenticated. (Score:2)
Phone number deleted! (Score:2)
This is great. Now someone get Google to stop pestering me for my phone number. I want as few entities as possible to have it, and security app 2FA has always been better anyway.
Re: (Score:2)
2FA sucks. It's nothing but an annoyance which doesn't serve it's intended purpose. The only ones who benefit are the people pushing 2FA because now they have your information and can sell it, or push ads to you.
Re: (Score:2)
Comment removed (Score:4, Insightful)
Re: (Score:2)
Re: (Score:2)
They consider anonymous speech dangerous.
It's supposed to be.
Great. Now can we get EBay to follow suit? (Score:2)