Twitter has announced that the platform will allow using the SMS-based two-factor authentication (2FA) only to its Blue subscribers.
To date, Twitter has offered three methods of 2FA: text message, authentication app, and security key. But now the company has announced that it will limit the use of SMS-based two-factor authentication (2FA) only to its Blue subscribers.
The move is the response of the company to the use/abuse of the authentication method by threat actors.
According to a post published by Twitter, even though historically a popular form of 2FA, unfortunately they have seen phone-number based 2FA be used – and abused – by bad actors. So starting now, the platform will no longer allow accounts to enroll in the text message/SMS method of 2FA unless they are Twitter Blue subscribers. The availability of text message 2FA for Twitter Blue may vary by country and carrier.
Non-Twitter Blue subscribers that are using the text message/SMS method of 2FA will have 30 days to enroll in another authentication method.
After 20 March 2023, they will no longer permit non-Twitter Blue subscribers to use text messages as a 2FA method. At that time, accounts with text message 2FA still enabled will have it disabled. The company added that disabling text message 2FA does not automatically disassociate the phone number from the user’s Twitter account.

















Comments