21 ms·
FTC fines Twitter $150M for using 2FA phone numbers for ad targeting
- oblio 4y agoWe need to turn data into a liability. There's a reason many places work on a "need to know" basis.
- xbar 4y agoClownish. If I were the CEO, some folks would have already been fired.
- annoyingnoob 4y agoWould you fire yourself?
- mrkramer 4y agoThat's called resignation. Yea you would do it if you respect your company and your users. Call in someone more mature.
- deleted 4y ago[deleted]
- zaroth 4y agoClearly anyone with the ethical chops to consider resigning over this would be a net-loss to Twitter if in fact they resigned. Is this some sort of named paradox?
- bogwog 4y ago> would be a net-loss to Twitter Would it? It seems to me like unethical behavior is always more profitable.
- rsstack 4y agoSeveral people _were_ fired recently. We don't know why, so maybe. But probably not.
- neighbour 4y agoPersonally I think the CEO would have known about this happening and turned a blind eye until it became an issue. I have nothing to back this up though. Just a pessimistic take on corporate culture.
- techsupporter 4y agoThis is an interesting part to me: "[T]he new order[0] adds more provisions to protect consumers in the future: ... Twitter must provide multi-factor authentication options that don’t require people to provide a phone number." I would like to see this be a more broad-based rule. No, I am not moved by "SMS is easy" or "getting a number that can receive SMS is harder for scammers to do in bulk." If you must, give users the choice but not the obligation to hand over a mobile number. 0 - https://www.ftc.gov/legal-library/browse/cases-proceedings/2023062-twitter-inc-us-v https://www.ftc.gov/legal-library/browse/cases-proceedings/2...
- latchkey 4y agoThey already provide these options today.
- falcolas 4y agoIt's a precedent. This isn't just about Twitter; there are many who do not offer such options.
- zaroth 4y agoI don’t think it has any applicability to anyone beyond Twitter. Maybe it’s a precedent that the FTC will tell you to add non-SMS 2-factor if you are misusing the SMS factor for advertising, but that’s a pretty limited precedent!
- tomnipotent 4y agoIt emboldens prosecutors and DA's and makes conversations around going after other bad actors more tenable.
- gabereiser 4y agoTo further expand on this. 2FA should not rely on SMS at all. It should be an option but not the default one. An Authenticator app should be the default. I know we assume everyone has a cell phone but that’s not the case.
- karatinversion 4y agoFor context, Twitter‘S revenue in 2021 was $5 billion, on which they made a loss of $220 million.
- tpmx 4y agoWhich is bizarre, in itself.
- JohnJamesRambo 4y agoWhat a great buy... I saw a tweet the other day that said they can't think of a worse purchase since Bank of America bought Countrywide for $40 billion. TWTR has traded flat since its inception in one of the greatest bull markets of all time.
- missedthecue 4y agoHP bought Autonomy which turned out to be a total fraud.
- rasz 4y agoCuban sold Broadcast.com to Yahoo for almost $6B. $10K per user, instantly worthless.
- sitkack 4y agoWhen I think twitter, I think of a service that costs 5.2B to run.
- tpmx 4y agoI can't even fathom how it's possible to use $5B/yr to run Twitter. So, I co-architected the Opera Mini infrastructure. It peaked at a similar number of users (250-300M monthly active users). Sure, Twitter is much more DB-intensive, but transcoding web pages is pretty CPU intensive too, and typically we transcoded every single web page for them. Opera Mini was their only browser. Twitter is spending $5B/300M =~ $17/user per year I believe that from public sources, it's now possible to deduce that we spent less than a 1/100th of that per user/year, almost a decade ago. Since we didn't have crazy money, we optimized things at every step. Or, well, mostly avoided doing stupid stuff.
- AdvertisingMan 4y ago
- pessimizer 4y agoThis is surprisingly reasonable. I would like to see a decisionmaker do some time for fraud, though. They locked people out of their accounts and demanded phone numbers for "safeguarding," then used them for targeting in direct contravention of a previously negotiated agreement with the FTC. If that doesn't rise to criminality, the fraud statutes need to be updated. edit: they should also be required to dump the phone numbers (even to be recollected later, without the deception), but I didn't see that in the article. Are they being allowed to keep the proceeds of a crime?
- rmbyrro 4y agoIt says they cannot use the data commercially, only for the stated purposes (security, recovery). In practice, it'll be hard to enforce, though.
- piva00 4y agoWhy not increase the punishment by having random audits like the government do for drug checks? And make the company pay, would be an even bigger deterrent if it's not just a fine...
- colechristensen 4y agoFirst you have to establish who goes to jail, corporations are able to avoid this by having vague structures of shifting blame so a jury can't decide if any particular individual is actually at fault. There probably should be laws establishing ultimately responsible people with the unenviable duty of being responsible for illegal things corporations do (sort of like an engineer signing off on the design of a bridge), but doubtful such a thing will happen. We're left then with personal responsibility being limited to people stupid enough to leave pretty explicit records of nefarious intent to commit crimes.
- xanaxagoras 4y agoPick a C-suite exec or VP at random then. "Nobody, it's too hard to unravel the organizational structure" isn't really cutting it.
- wanderr 4y agoA fine is a cost. It's quite possible that Twitter made more than $150m in doing this.
- missedthecue 4y agoI don't think Twitter makes money at all.
- bpodgursky 4y agoI truly doubt this was a calculated tradeoff. It was almost certainly a fuckup where the phone # was mistakenly stored in a shared schema, and someone on the ads side saw it and decided to use it for targeting, knowing nothing about 2FA or how it got there. This probably only affects a tiny fraction of their users.
- ziddoap 4y ago>I truly doubt this was a calculated tradeoff. Potentially, sure. >It was almost certainly a fuckup where the phone # was mistakenly stored in a shared schema, and someone on the ads side saw it and decided to use it How is this an "almost certainly"? Do you have additional information you'd care to share on why you think so? If this were the case, it would point to insanely sloppy policies, procedures, and implementations. >This probably only affects a tiny fraction of their users. Why?
- ntoskrnl 4y agoSigh. Yep. Don't ever give a company your phone number for 2FA. It's insecure anyways due to SIM swapping. Stick to FIDO (e.g. yubikey) or TOTP (e.g. google authenticator)
- RamRodification 4y agoAny clear reason to go for Google for TOTP? As opposed to Authy or something else.
- ntoskrnl 4y agoThose were examples I thought people were likely to recognize, not vendor recommendations. I edited for clarity.
- jeromegv 4y agoNo, it's all the same.
- encryptluks2 4y agoYou do realize that TOTP is a standard that doesn't require you to use either, that you can use the same secrets for any TOTP app, right?
- RamRodification 4y agoYou did read my comment where I suggested "Authy or something else", as in any TOTP app, right?
- regecks 4y agoThere is a clear reason not to use Authy, which is that making your data portable is extremely annoying. No export function. I ended up writing a 3rd party Authy client just to get my TOTP keys out. For iOS users, I cannot say enough good things about https://apps.apple.com/us/app/otp-auth/id659877384 https://apps.apple.com/us/app/otp-auth/id659877384. Author is responsive, encrypted backups, portable data format.
- mrkramer 4y agoI remember I got scared this might happen when Epic introduced 2FA for claiming free games[0]. FTC check Epic Games too. [0] https://www.pcgamer.com/uk/for-a-while-epic-games-store-will-require-two-factor-authentication-to-claim-free-games/ https://www.pcgamer.com/uk/for-a-while-epic-games-store-will...
- jazzythom 4y ago
- brailsafe 4y agoI appreciate the security of 2FA, but I don't like the liability and and I don't like being required to have my phone at all times. Jus one of my gripes with the world
- sedatk 4y agoI propose multiple YubiKeys for this. Unlike TOTP, it's not susceptible to phishing, and you can keep Nano keys inserted in your USB ports that you regularly use. You don't need your phone or anything most of the time.
- brailsafe 4y agoYa, seems like a decent alternative
- kevin_thibedeau 4y agoNot looking forward to Github making it mandatory. I don't want something I can lose to control my access. The insidious part is, as it becomes normalized, more employers will think that they can force their workers to participate in broken security theater with their own private property rather than a proper solution with corporate assets.
- lucb1e 4y ago> [Twitter] agreed to an order that became final in 2011 that would impose substantial financial penalties if it further misrepresented “the extent to which [Twitter] maintains and protects the security, privacy, confidentiality, or integrity of any nonpublic consumer information.” They violated that order and that's what the fine is for. I was wondering what kind of authority the FTC has to impose fines based on what as a European I'd consider a GDPR violation (in the USA, this california privacy act thing sounds like it would be the nearest thing, but that's not federal so that couldn't be it). But what was this order about? Clicking the reference in the article: > The FTC’s complaint against Twitter charges that serious lapses in the company’s data security allowed hackers to obtain unauthorized administrative control of Twitter, including access to non-public user information, tweets that consumers had designated private, and the ability to send out phony tweets from any account including those belonging to then-President-elect Barack Obama and Fox News, among others. > Under the terms of the settlement, Twitter will be barred for 20 years from misleading consumers about the extent to which it protects the security, privacy, and confidentiality of nonpublic consumer information So this wasn't about privacy initially, the FTC's attention came from allowing some public figures' accounts to be hacked, after which it imposed some broad set of requirements, which are broad enough to now include this privacy issue. Not a bad outcome, but interesting turn of events to get the FTC to act as data protection authority.
- em-bee 4y agobarred for 20 years from misleading consumers what is that time limit for? seems badly expressed to me. i suspect it means there will be a harsher punishment if this happens again within 20 years.
- staunch 4y agoAt first I thought the fine sounded excessive but after thinking about it, it seems far too low. I'd like to know the the people that were specifically responsible for this scam. Did Jack Dorsey implement and endorse this scam?
- autoexec 4y agoThere are a lot of details I don't see about this, even in the order itself. How did the FTC know twitter was abusing this data? Was there a whistleblower who notified them, or did they break down the doors and start scanning twitter's internal documents? Were they authorized to dig into twitters internal processes as part of the initial security investigation?
- gareth_untether 4y agoI really can't believe companies are still doing this with people's data. Insane that this is still a thing companies abuse.
- pinewurst 4y agoDidn't Facebook do something similar without any apparent comebacks?
- octagons 4y agoI don't have the most optimistic outlook for this having any impact, but I really hope this sets a precedent for limiting the use of dark patterns with which companies try to tie your identity to a phone number. I think the total sum for this fine is rather myopic: it ignores the long tail of possible future data leaks and the impact it might have on the people behind the affected accounts. I created my current Twitter account a few years ago and it remained dormant for a while. It was flagged as "in violation of our policies" despite having not made any tweets or using a handle or nickname that would cause offense to anyone. In order to resolve this, I had to enter my phone number to "secure" my account. I don't know what process triggered this review, but I'll be damned if it didn't smell like an easy way to associate an existing marketing profile with my Twitter account. Of course, it's vitally important to profile a service I used to keep up with industry news and post about Goban puzzles. I've also run into similar patterns on Discord and similar platforms; "Oops! Something suspicious is happening with the account [you literally just created]. Please add a phone number to your profile to proceed." Although I follow a reasonable set of practices around identity/password management, I usually architect my risk profile with a "I don't care if I lose this account" approach. If that statement isn't true, then I will happily apply all of the security measures available. However, it seems like the idea of creating "I don't care" accounts is becoming increasingly difficult as we continue to invest in user marketing analytics and lower the barrier of entry to these types of technologies that do not have the consumer's best interests in mind.
- pixl97 4y ago>I created my current Twitter account a few years ago and it remained dormant for a while. It was flagged as "in violation of our policies Same here, linked it to PSN to get images off my PS4 and it was flagged before I could do anything. Never did add my number and shortly after that they had a leak where any hacker could figure your number out.
- travisporter 4y agoSame here although after a year of “come back come back!” Emails almost daily (that went straight to spam for some reason) I tried again and got my account working. Seriously twitter- go suck an egg. With so much money, how can you betray trust of your users? I get daily calls from car warranty scams because of stuff like this
- dbg31415 4y agoI hate all the different ways companies target people. I recently booked flight on American Airlines for my 80+ year-old father. I requested the golf cart to take him between gates. Immediately I got a call from "American Airlines Health Alert." They made it sound like there was an issue with the booking... "An important health alert related to your flight." And there was a "Press 1, if you're over 50" option. Anyway long story short it was some shady marketing company selling me a panic button in case of falls. The lady was like"these are very expensive devices"... "we'll give you the device... but you pay a small fee for monitoring every month." Clearly she'd given the pitch 1,000 times. Didn't give me any time to talk. Finally, I was like, "Hey is there a problem with my Dad's flight, or are you just trying to sell me something?" And she hung up on me. Fuck American Airlines. Fuck all the airlines really, but it should be illegal to target the elderly just because they asked for help with connection flights.
- linuxhansl 4y agoSome weeks ago I wanted to deactivate my Twitter account. I hadn't used it for a while, and it claimed that my account was locked. Nothing was sent from it in many months, so it wasn't clear why/how it would be locked now. For some reason you cannot deactivate your account when it is locked. So I contacted Twitter demanding that as EU citizen (which is true) I hereby demand all data about me that Twitter or its subsidiaries might have, including account data, to be deleted under the GDPR... Or alternatively unlock my account so that I would be able to deactivate it. They were actually pretty responsible. My account was unlocked 30 minutes later and I was able to deactivate it.
- MiddleEndian 4y agoGood, but it should be 10x that amount.
- lelandfe 4y agoThe FTC really ought to take a leaf out of GDPR's book, and start fining truly punitive amounts: https://www.tessian.com/blog/biggest-gdpr-fines-2020/#:~:text=1.%20Amazon%20%E2%80%94%20%E2%82%AC746%20million%20(%24877%20million) https://www.tessian.com/blog/biggest-gdpr-fines-2020/#:~:tex... $150M for a repeat offense affecting millions of users is paltry.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- heavyset_go 4y agoGuarantee they're doing the same thing with phone numbers used to verify accounts, as well. I'm not talking about the blue check mark verification, but the verification they impose upon new accounts to prove that you're "real" and not a bot.
- 1270018080 4y agoI figured that was the whole reason every social media site bombards you with requests to "verify" your phone number.
- tinyhouse 4y agoThat's a settlement they reached recently on things that happened at least 2 years ago. Just to be clear.
- radicaldreamer 4y agoTwitter itself is still doing it, even if you opt-out of all personalized ads in their app, it'll still advertise stuff to you derived from tracking your browser history.
- jrochkind1 4y agoI've assumed facebook and google do this too. No? Or it's okay if they haven't promised not to (have they?)
- kleinsch 4y agoThe $5B the FTC fined FB for privacy issues was in part bc of using two factor phone numbers for ads.
- gnicholas 4y agoTwitter doesn't let me DM people who don't follow me because I haven't provided a cell phone number. I refuse to give it, mostly on principle. I send messages very rarely and am clearly not a bot. When did demanding a phone number become OK to access basic elements of a service? This happens even when I try to DM people whose DMs are open.
- Vladimof 4y agoGoogle forced me to give a phone number to verify my 10+ year old account, not because I forgot my password, but because they want all your information (I think that they buy ID info from the phone companies)... and I don't even use any kind of 2FA...
- outoftheabyss 4y agoDid the same to me. Refused to give it, luckily I only used it for YouTube, lost the 100 odd channels I subscribed to and my playlists and that was about it. Use an RSS reader now to track my favourite channels
- derbOac 4y agoThe one time I tried to make a Twitter account it locked me out "due to suspicious activity" and then later required me to provide a phone number. I never even made a post or really finished entering account information. So it seems it's now basically required for an account period. I was outraged and agree with you. It also takes on a new cast in light of this FTC action.
- nickjj 4y agoWho benefits from these fines? Will these fines end up being paid out to everyone who now needs to deal with a lifetime barrage of spam calls and texts?
- milesward 4y agoRepeat after me: we need FIDO2 in exactly the same physical form factor as your house key. Give ‘em away all over the place, make it the default conference swag. SMS is not good.
- sergiomattei 4y agoAgreed, but they need to be sold cheaper first. A YubiKey costs me around $40 and it’s the only brand I trust. That’s inaccessible to a lot of people.
- meristem 4y agoAnd then there are UI/UX constraints. The Venn diagram of "knows how to use SMS", "knows how to use 2FA" and "knows how to use yubikey etc" does not have a lot of overlap outside a tech audience.
- seoaeu 4y agoThey used to offer an $18 yubikey, but the cheapest one today seems to be $25. So a bit better than $40 but still way more than say a house key costs
- SAI_Peregrinus 4y agoThe FIDO2/webauthn ones (the Security Key series) are $25 for USB A or $29 for USB C. You can't use them for storing OAUTH keys, they're not smart card compatible, they can't store your PGP keys, and can't create one-time passwords or store a static password securely... but they are cheaper.
- LeoPanthera 4y agoWhat happens when you lose it?
- quadrifoliate 4y agoFIDO keys should only be sold in 2-packs in my opinion. You should never have a single key as your second factor. That being said, one-time use backup codes are a standard way out of the problem.
- metaphor 4y agoDoes the recent 5th Circuit decision[1] related to civil penalties issued by administrative agencies have any relevance here? The article mentioned that the complaint was "filed by the Department of Justice on behalf of the FTC," which sounds a bit more involved than the FTC saying, "Hey Twitter, here's your sign, now pony up"...I have no idea how the game is actually played though. [1] https://news.ycombinator.com/item?id=31429091 https://news.ycombinator.com/item?id=31429091
- SubjectToChange 4y agoProbably not. > The 2010 complaint cited multiple instances in which Twitter’s actions – and inactions – led to unauthorized access of users’ personal information. To settle that case, the company agreed to an order that became final in 2011 that would impose substantial financial penalties if it further misrepresented “the extent to which [Twitter] maintains and protects the security, privacy, confidentiality, or integrity of any nonpublic consumer information.” The $150m fine is because twitter violated that settlement agreement.
- metaphor 4y agoThanks for the clarification.
- rdubs333 4y agoYeah but where does that water flow. We have guns, we have gravels, but where does it go!?
- frankfrankfrank 4y agoInteresting. Is this something that has been an ongoing investigation at the FTC? The timing seems extremely suspicious.
- elliekelly 4y agoYes. This is one of several similar cases the FTC has pursued against social media companies over the last few years. I believe Facebook had a bug that inadvertently outed their misuse of the 2FA phone numbers for advertising and that was what initially put the practice on the FTC’s radar. Around the start of the pandemic the FTC actually did a study[1] looking at the “secondary uses” of security data. They registered for 2FA with a bunch of websites and then tracked how many non-2FA related calls and text messages the phone numbers received. While the experiment was a great idea I think the way they structured it leaves much to be desired. [1][PDF] https://www.ftc.gov/system/files/attachments/office-technology-research-investigation/way2020-kim.pdf https://www.ftc.gov/system/files/attachments/office-technolo...
- wly_cdgr 4y agoIs this something unique to Twitter or is this just Biden or someone else trying to stop the Elon deal?
- consultSKI 4y agoCool. So the defense, "Facebook does much worse!" didn't fly? #justSayin
- aurizon 4y agoInteresting, a length of wiggle room for Musk to play with...
- soheil 4y agoWhen you can have Authenticator Chrome extensions [1] what is the point of 2FA? Who decided making it harder to login for an average user is worth the added security? I'm not arguing security is not improved. The question is who weighed the pros/cons of 2FA and decided the entire industry should adopt it? Can we shine some light on the orgs/individuals responsible for this. > This article is written like a personal reflection, personal essay, or argumentative essay that states a Wikipedia editor's personal feelings or presents an original argument about a topic. Wikipedia describes 2FA very matter of factly without any background on its history and its advocates [2]. [1] https://chrome.google.com/webstore/detail/authenticator/bhghoamapcdpbohphigoooaddinpkbai?hl=en https://chrome.google.com/webstore/detail/authenticator/bhgh... [2] https://en.wikipedia.org/wiki/Multi-factor_authentication https://en.wikipedia.org/wiki/Multi-factor_authentication
- dboreham 4y agoI may have some idea about this since I was kind of around the space at the time. But to be honest I don't understand your question. Are you asking about the benefit of TOTP as an authentication mechanism when users can install insecure browser-based TOTP implementations? As far as the history, and "who", I think this has a very long history in the "security-industrial complex", which probably means : NSA. Certainly the idea of 2FA goes back as far as smart cards (early 90s). Then came RSA SecurID which I saw as a hack to give you something similar to smart card security but without the need to roll out a PKI. TOTP seems like it is a generic version of SecurID. I don't particularly remember any vendor agenda on all of this, more like everyone was looking to fulfill government and bank requirements for security then the techniques employed leaked out into the corporate/enterprise world, and finally (like, around today), have become mainstream in the B2C use case. My perception has been that all of this was pretty much about "making things better" by some definition of better that depends on reasonable security for reasonable cost, in the context of typical user behavior.
- soheil 4y agoThis looks much more like showmanship than actually improving security. Again I'm not saying security is not improved. Now there are people who are happy they set standards for others to follow and IT managers who can show off to their bosses that they're following security standards like ISO27001 and SOC2. SOC2 standard is set by AICPA, the last A stands for Accountants. Of all people.
- yalogin 4y agoIt’s ok they are going to get 1billion from Musk so they can afford it. Jokes part I am glad they got fined. These kind of transgressions need to be dealt with publicly and Twitter is a big enough entity to send a message that this is serious. Of course I am sure you very company that got phone numbers already abused them :)
- giraffe333 4y agowhy aren't these fines percent of revenue, or a multiple of the number of people affected?
- asasidh 4y agoElon fixes everything. He is looking for reasons to back out and if this was not disclosed before, he found one more reason.
- ta988 4y agoNot a surprise, they were really insistent on getting a phone number for the account.
- de6u99er 4y agoTeitter wanted my phone number once, even by locking my account and asking me for my phone number to unlock it. It felt like blackmail and I threatened Twitter with a GDPR request, not only requesting my data but also the algorithms used for automated decision making. As soon as my account got restored I let their DPO know that I don't insist on the fulfillment of the GDPR request any more. And that I will follow through if Twitter pulls off this kind of blackmail again on me. Haven't had this issue any more.
- miked85 4y agoThese fines are meaningless and just looked at by the company as the cost of doing business.
- ls15 4y agoApart from security and privacy implications, phone numbers for 2FA are a major issue when you travel to a country where your number is not working. I had to communicate in a very complicated way with my health insurance because of this. Why is that entire practice not banned yet?
- mark336 4y agoThe fines should be paid the Twitter users
- bushbaba 4y ago150M just seems too low of a fine. The expected value of being fined is less than rewards and this encourages future abuse by other players.
- mjburgess 4y agogiven twitter isn't profitable, i'd imagine its more money than they've ever made
- callmeal 4y ago>given twitter isn't profitable, i'd imagine its more money than they've ever made But it's not as much money as they're making in ad sales to those phone numbers. Twitter will just see it as a cost of doing business and there won't be any meaningful change.
- mjburgess 4y agoThe cost, whatever it will be, is always just a cost of doing business. The purpose of the fine is to make the business unprofitable, which it is successful at doing.
- account42 4y agoThe purpose of the fine is not to make the business unprofitable, it is to make that particular endeavour unprofitable. If profit from violating law - fine for violating law > 0 then then any business not run by ethics will continue to violate the law because not doing so is less profitable. This does not change if the business is throwing out money elsewhere.
- birracerveza 4y ago$150 millions? Heckin wowerino, now that sure made it all not worth it huh, they're never going to do it again, no siree. The current state of the web is completely laughable.
- oxfordmale 4y agoTwitter is terrible sorry....for being caught. They promise to do better in the future /sarcasm
- aljungberg 4y agoApple could complement their existing “hide my email” with a “hide my number” feature that makes it easy to create disposable tracking protected phone numbers. This would help counteract the “oh something about your account is suspicious so give us your phone number” dark pattern.
- actuator 4y agoApple's feature is inherently a monopolistic feature and something not really new. Login with FB and Google already had options for not sharing email. I still prefer to signup using a spam email address.
- aljungberg 4y agoHide my email services are a dime a dozen, but for a “hide my phone number” service you need deeper pockets because phone numbers cost money.
- throwaway290 4y agoHere's hoping they get to Microsoft's fishing phone numbers from Minecraft players by threats and blackmail (alleging unauthorized account access that doesn't actually happen).
- netik 4y agoMany employees I talked to described years and years of trying to stop this but eventually the growth team took over. This is so sad.
- tempodox 4y agoThat's the problem I see with most of 2FA, you have to reveal more of yourself instead of less, increasing potential attack surface instead of minimizing it. If anything, recent history has shown that you cannot trust anybody on the internet. Even if they're not outright hostile or abusive, they can still get cracked and their data stolen. For myself, I'd rather rely on strong, well-protected passwords and no 2FA as far as possible, but most people might not know how to do that or find it too inconvenient.
- anamexis 4y agoWhere is this the case for 2FA other than SMS? It seems like the other common ones are either just verifying a shared key, or some type of one-time pad
- digb 4y agoInstagram used to do this too
- bobro 4y agoif your first thought is that the fine isn’t enough, often these fines go along with agreements to change business practices. in this case: >In addition to imposing a $150 million civil penalty for violating the 2011 order, the new order adds more provisions to protect consumers in the future: >Twitter is prohibited from using the phone numbers and email addresses it illegally collected to serve ads. >Twitter must notify users about its improper use of phone numbers and email addresses, tell them about the FTC law enforcement action, and explain how they can turn off personalized ads and review their multi-factor authentication settings. >Twitter must provide multi-factor authentication options that don’t require people to provide a phone number. >Twitter must implement an enhanced privacy program and a beefed-up information security program that includes multiple new provisions spelled out in the order, get privacy and security assessments by an independent third party approved by the FTC, and report privacy or security incidents to the FTC within 30 days.