Snapchat makes logging in more secure with two-factor authentication
Chris Welch / The Verge :
Context & Ripple Effects
Snapchat's move lands mid-wave: within months of each other in early 2015, Apple enabled two-step authentication for iMessages and FaceTime, Twitter added it to its Digits login service, and Venmo rolled out multi-factor authentication after publicized security problems. A consumer platform without a second factor had become the outlier, not the norm.
For Snapchat specifically, the stakes were reputational: the app's disappearing-message premise made account hijacking unusually damaging for its young user base, so login security was the obvious next hardening step.
First-order effects
- Snapchat users can now require a second factor at login, directly reducing the payoff of password theft and credential-guessing against their accounts.
Second-order effects
- Rival messaging and payments platforms face pressure to match the baseline — a pattern the coverage already shows with Venmo adding multi-factor authentication only after security incidents forced the issue.
Third-order effects
- Implementation quality becomes the real battleground: as The Verge's later reporting on the mess of inconsistent two-factor authentication shows, SMS-based rollouts like this era's left recovery paths vulnerable, pushing the industry toward app-based codes — a shift Twitter acknowledged by later letting users adopt 1Password or Authy instead of SMS.
The trend: Consumer platforms are racing to add two-factor authentication, but the first wave of SMS-based implementations is giving way to stronger app-based methods as the vulnerabilities of phone-number verification become clear.