4 ms·
For users it's probably a security improvement. For Twitters owner it's probably a matter of saving a few bucks on SMS fees (but that can't be much). Twitter
by arlcode 4y ago
For users it's probably a security improvement.
For Twitters owner it's probably a matter of saving a few bucks on SMS fees (but that can't be much).
Twitter Blue still makes very little sense for most people unless Twitter becomes fully paywalled.
- sigmar 4y agoFor any twitter user that goes from only-SMS-2FA to no 2FA, it isn't a "security improvement"
- toomuchtodo 4y agoYou can’t fix lazy users and Twitter is not so valuable (being social media) to mandate 2FA. Twitter still offers 2FA options, just not the low effort low security one (per NIST and CISA) for non paying subscribers. If you’re an unpaid user, you shouldn’t be surprised when the burden is being shifted to you (as SMS has a cost; TOTP and passkeys do not). With that said, they should implement passkeys and eliminate SMS auth entirely. 2FA is then a moot point, and everyone can move on to complaining about passkey edge cases. https://csrc.nist.gov/csrc/media/Presentations/2022/multi-factor-authentication-and-sp-800-63-digital/images-media/Federal_Cybersecurity_and_Privacy_Forum_15Feb2022_NIST_Update_Multi-Factor_Authentication_and_SP800-63_Digital_Identity_%20Guidelines.pdf https://csrc.nist.gov/csrc/media/Presentations/2022/multi-fa... https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf https://www.cisa.gov/sites/default/files/publications/fact-s...
- lxgr 4y agoYou‘d be surprised how much SMS to some countries cost! They‘re only (almost) free in the US and a few other places.