- Nov 15, 2013
- 62,106
- 15
- 0
Twitter has put the SMS-based two-factor authentication system behind its Twitter Blue paywall. Full story from the iMore Blog...
Nothing to report here. Unless you’re a Twitter Blue subscriber, nothing has changed.
I’m kind of confused on the statement. I would argue that it’s IF you’re a Twitter Blue subscriber that nothing changed.
Above notwithstanding, SMS 2FA is poor, security-wise, so no big loss there.
No offense intended Ed but that’s just not true. SMS text option for 2FA is not “poor” security wise. It isn’t an authenticator app but it’s many country miles from poor. We have been using it frequently as part of 2FA (when SSO isn’t applicable) it nearly wiped out users getting their accounts logged into by nefarious sources.
To mitigate an attacker’s ability to achieve authentication using a stolen credential, when possible, configure services to use multi-factor authentication. Ideally, the additional factor should be provided by a separate device than the one being used to perform primary authentication (e.g., laptop and mobile app). Further, avoid the use of SMS messages for 2FA codes, as SMS messages can be readily intercepted.