How to keep your Twitter secure without giving Elon Musk any money • TechCrunch

late fridayTwitter announced a new policy to remove two-factor authentication (2FA) for text messages from non-paying accounts.

In a blog post, Twitter said that only accounts subscribed to the premium Twitter Blue feature will be allowed to use text message-based 2FA. Twitter users who haven’t switched to another type of two-factor authentication for him will have the feature removed from their accounts by March 20.

This means that anyone who relies on Twitter sending a text message code to their phone to log in will have 2FA turned off and will be able to access their account with just their password. If you have an easily guessed Twitter password, or if you use the same password on different sites and services, sooner or later you need to take action.

Twitter claims it is “committed to keeping people safe on Twitter.” Not true. Instead, we’re looking at one of the dumbest security decisions companies make in real time.

It’s not clear for what reason this new 2FA policy was revealed in the first place. Platformer Zoe Schiffer It was later confirmed on Twitter and founded. Twitter has been bleeding cash and employees since his $44 billion acquisition by Elon Musk. The move to do away with SMS 2FA may have been to save the company money, given that sending text messages isn’t cheap. We reached out to Twitter for comment, but Musk fired the entire communications team.

Twitter justified its decision that blog post, stated that SMS 2FA can be abused by malicious actors. This may refer to her SIM swap attack, in which the hacker persuades the mobile operator to assign the victim’s phone number to a hacker-controlled device. Hackers can impersonate victims by hijacking personal phone numbers. You can also receive a text her message code that allows the hacker to access the victim’s online her account. But making SMS 2FA available only to her Twitter Blue subscribers doesn’t protect paying users from her SIM swap attacks. If anything, encouraging paying users to rely on her SMS 2FA makes it more likely that her Twitter account will be hijacked if her phone number is hijacked.

That said, it’s important to note that SMS 2FA offers accounts far better protection than not using 2FA at all. is not intended to encourage users to In fact, companies like Mailchimp take the opposite (but correct) approach, encouraging users to turn on 2FA for her by discounting their customers’ monthly bills.

The silver lining is that Twitter hasn’t done away with 2FA entirely. Even if he doesn’t pay Elon Musk a penny, the mighty guy can protect his account with 2FA.

Whether or not you abandoned your Twitter account in favor of an alternative decentralized service like Mastodon, secure your account in case someone breaks in and starts tweeting on your behalf by March 20th. must take steps to .

You want app-based 2FA instead of using a 2FA code sent by text message. It’s much more secure and as fast as receiving a text message. (Many online sites, services, and apps also offer app-based 2FA.) Instead of texting a code to your phone, use your phone’s authenticator app (Duo, Authy, Google Authenticator, etc.) You can generate code via To name a few. This is very secure as the code never leaves the device.

Screenshot of Twitter two-factor authentication settings

Image credit: TechCrunch (screenshot)

To set this up, first make sure you have an authenticator app installed on your phone. Go to your Twitter account, then go to Settings and privacyafter that Security and account accessafter that safetyIf you get on Two-factor authentication setting, selection Authenticator app. Follow the prompts carefully. You may need to enter your account password to get started. Once complete, you will be able to log in using your password and use the code generated from your authenticator app.

Keep in mind that this is a much more secure way to access your Twitter account, so if you lose your phone it can be very difficult to get back into your account. You should keep track of your backup codes. This will allow you to access your account if you are locked out, and will be safely stored in your password manager. The backup code is in the same place where you set up his 2FA on the app base.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *