Twitter says only Blue subscribers will be able to use SMS-based 2FA after March 20, 2023; non-Blue users can use an authenticator app or physical security key
In fact, if you don't start paying for Twitter Blue ($8 a month on Android; $11 a month on iOS) or switch your account to use …
The Verge Sean Hollister
Context & Ripple Effects
Twitter had already made phone-number-free 2FA available in 2019, letting users disable SMS and use authenticator apps instead. The new policy turns that earlier optional alternative into the route for non-paying accounts while reserving SMS for Blue.
The change follows Twitter Blue’s $8-per-month rollout with a blue checkmark, after reports that the subscription was being positioned around paid verification. It extends Blue from an identity marker into a tier that controls an account-security convenience.
First-order effects
- Non-Blue Twitter accounts using SMS-based 2FA must switch to an authenticator app or physical security key by March 20; Blue subscribers retain SMS-based 2FA.
- Twitter Blue gains another subscriber-only feature, alongside the paid-checkmark offering introduced in its initial rollout.
Second-order effects
- Authenticator-app and security-key use becomes more central to Twitter account protection for non-Blue users, reversing the practical default set by SMS-based enrollment.
- Twitter’s paid tier is more directly judged on whether users will pay for account-access convenience rather than only for the visibility and verification benefits associated with Blue.
Third-order effects
- The policy points to subscription tiers becoming a mechanism for segmenting core account-management features, not solely premium content or status signals.
- If platforms repeat this model, security design will increasingly be shaped by monetization choices even where free alternatives remain available.
The trend: Social platforms are broadening paid subscriptions from verification badges into differentiated access to account features.
Related: Ecosystem cyber defense · Twitter Blue · Twitter adds phone-number-free 2FA options · Twitter Blue rolls out with $8 checkmark
Related Coverage
- Twitter To Charge for SMS Two-Factor Authentication CNET · Queenie Wong
- Twitter will reserve text-message authentication for Twitter Blue subscribers because it's being ‘abused’ by ‘bad actors’ Insider · Stephanie Stacey
- Twitter to charge users to secure accounts via text message Reuters
- Twitter will charge users SMS two-factor authentication BGR · Andy Meek
- Elon Musk's Twitter Will Start Charging You to Verify Logins Using Text Messages Variety · Todd Spangler
- Twitter Makes SMS Two-Factor Authentication a ‘Premium’ Feature Appuals.com · Farhan Ali
- Twitter is going to make you pay for some elements of 2FA — act now to secure your account for free! BetaNews · Sofia Wyciślik-Wilson
- Twitter is making text-based two-factor authentication a paid feature Engadget · Mariella Moon
- Twitter's Making SMS Two-Factor Authentication a Twitter Blue Exclusive Feature Social Media Today · Andrew Hutchinson
- Twitter to charge for security... losers, or: pay to be more hackable Pocketables · Paul E King
- Twitter Takes Away Text Message Two-Factor Authentication From Non-Blue Users Inc42 Media · Hemant Kashyap
- Twitter to remove two-factor text authentication from accounts that don't subscribe to Twitter Blue The Apple Post · Tom Sykes
- Twitter will remove high-security login method from your account if you're not paying for Blue Techlusive · Shubham Verma
- Twitter Limits SMS-Based 2FA to Twitter Blue Members PCMag · Chloe Albanesius
- Twitter to charge for SMS-based two-factor authentication - How to use Google Authenticator instead 9to5Google · Ben Schoon
- No Twitter Blue Tick, No Privileges CoinGape · Divya Sinha
- Elon Musk's Twitter to charge users for securing account via text message Livemint · Neha Saini
- Twitter Limits SMS-Based 2-Factor Authentication to Blue Subscribers Only The Hacker News
- Twitter to limit SMS two-factor authentication to Blue users [Three methods of 2FA ] International Business Times
- Twitter Drops SMS-Based Two-Factor Authentication for Unpaying Accounts, Effective March 20 Pixel Envy · Nick Heer
- I'm completely baffled by this. #Twitter is ditching SMS codes for MFA ostensibly because it's easily abused...but is letting its paying customers continue to use the feature they also said was insecure? … @maxeddy@infosec.exchange
- If the person(s) who wrote this announcement are actually in charge of security at Twitter, I guarantee that there are already several state-sponsored threat actors making themselves at home inside Twitter's systems- … @DataDrivenMD@fedified.com · Dr. Jorge Caballero
Discussion
-
Twitter
Twitter
on x
An update on two-factor authentication using SMS on Twitter
-
Twitter Help Center
Twitter Help Center
on x
How to use two-factor authentication
-
@couts@mastodon.social
Andrew Couts
on mastodon
Here's Twitter's announcement about the end of SMS 2FA for non-Blue users. Authentication apps and security keys will still be an option for multi-factor authentication for people who don't want to pay Musk $8—and they're arguably better options than SMS 2FA. …
-
@dangillmor@mastodon.social
Dan Gillmor
on mastodon
Twitter should end SMS 2FA for everyone. It is crappy security. Hardware keys are best, authenticator apps less good. But SMS is a dumpster fire. — What I don't understand is why the company is charging for something inferior, or why anyone would pay to use it. …
-
@twittersupport
@twittersupport
on x
Effective March 20, 2023, only Twitter Blue subscribers will be able to use text messages as their two-factor authentication method. Other accounts can use an authentication app or security key for 2FA. Learn more here: https://blog.twitter.com/...
-
@racheltobac
Rachel Tobac
on x
This Twitter 2FA change is nerve-racking because: 1. Only ~2.6% of Twitter users have 2FA on at all (it's essential for preventing easy account takeover) Of those 2.6%, 74% use text message based 2FA (https://transparency.twitter.com/ ...) If they don't pay for Blue they auto los…
-
@tomaxwell
Thomas Maxwell
on x
lol i just got this alert on desktop https://twitter.com/...
-
@zoeschiffer
Zoë Schiffer
on x
Sources: Twitter plans to unveil a new policy that only Blue subscribers will be able to use SMS-based two-factor authentication
-
@mikeisaac
Rat King
on x
this is maybe the worst idea in a monthslong campaign of enormous missteps both intentional and unintentional? https://twitter.com/...
-
@jsrailton
John Scott-Railton
on x
Twitter about to give hackers a huge gift.... ... by *REMOVING text message authentication* for non paying accounts. Yes, there are better forms of #2FA. But this is blackmail. Expect waves of takeovers as hackers run through password dumps. 1/ https://blog.twitter.com/... https:…
-
@blgtylr
Brandon
on x
Blue Check going from Calvinism to Catholicism is kind of giving the Early Modern Drama I lowkey live for. https://twitter.com/...
-
@tomaxwell
Thomas Maxwell
on x
Next up you can only change your password once annually unless you have Twitter Blue https://twitter.com/...
-
@iancoldwater
Ian Coldwater
on x
normally I'm on team “better than nothing,” but this is a great time to tell the non-security professionals in your life that SMS is the least secure form of 2FA. use an authenticator app or a physical hardware key instead, and don't give this clown money to make security worse! …
-
@practicaltas
Andrew Nestico
on x
This is the stupidest fucking possible change I've ever heard of. Literally could not have imagined Twitter trying this. What the actual fuck. https://twitter.com/...
-
@billkuchman
Bill Kuchman
on x
“Give us $8 or we'll make your account less secure” is a wild customer service move. https://twitter.com/...
-
@vanbadham
Van Badham
on x
I would literally pay $800 at this point to never hear the name “Elon Musk” again. https://twitter.com/...
-
@kurtwagner8
Kurt Wagner
on x
The desperation to get people to pay for Twitter Blue is wild https://twitter.com/...
-
@mikeisaac
@mikeisaac
on x
i cannot imagine a competent security engineer on staff who would sign off on this if it actually is implemented i HOPE they still allow outside 2-factor apps like Google Authenticator but this is just wild if that's not the case
-
@modernistwitch
JJ Skolnik
on x
app-based 2fa is more secure anyway but unclear whether that'll also be affected. a good time to switch regardless. anyway wow this is terrible https://twitter.com/...
-
@dancow
Dan Nguyen
on x
Alright credit where credit's due: making 2-factor auth a paid feature is an idea so comically stupid that it's likely no one else has even imagined it to be possible 🫡 https://twitter.com/...
-
@ketanj0
Ketan Joshi
on x
Why is he making the least secure 2fa method paid?? https://twitter.com/...
-
@kevincollier
Kevin Collier
on x
And it's official: Twitter users can now choose to be less secure — to use text messages for 2FA rather than an app — but only if they pay the monthly fee. You pay for insecurity. The weirdest security decision I've ever seen from a major tech company. https://blog.twitter.com/..…
-
@themckenziest
Lauren McKenzie
on x
Coming soon: only Twitter Blue users will be able to reply to tweets https://twitter.com/...
-
@carnage4life
Dare Obasanjo
on x
That's one way to lower the SMS bill. 💀 https://twitter.com/...
-
@arawnsley
Adam Rawnsley
on x
Gee, I wonder what the impact will be when Twitter dumps the 99 percent of users who don't subscribe to Blue from the most convenient form of Two Factor will be. https://twitter.com/...
-
@evacide
Eva
on x
This is extremely dumb and it hurts me. Obviously, the right move here is to switch to an authentication app or a security key for your 2FA, but I suspect that most people will just turn 2FA off. https://blog.twitter.com/...
-
@goldman
Jason Goldman
on x
We continue to be committed ... just demonstrably less committed than before. https://twitter.com/... https://twitter.com/...
-
@edzitron
Ed Zitron
on x
Elon fundamentally does not understand free services, and perceives anything that costs Twitter money as something the user should pay for. The master of business is conducting his symphony https://twitter.com/...
-
@lolennui
@lolennui
on x
bro we are not giving you $8, let it go https://twitter.com/...
-
@damanr
Daman Rangoola
on x
While this is a pretty bad way to force it, a PSA to not use SMS 2FA anyway. Download Google Authenticator or Authy and transfer all your 2FA to that — it's much more secure https://twitter.com/...
-
@d4vsanchez
@d4vsanchez
on x
Nice! I ain't paying for that. https://twitter.com/...
-
@digiphile
Alex Howard
on x
If true, this is immoral. MFA/2FA protects the security & privacy of consumers & corporations & should be free to all, never a feature we must pay for! @twitter should immediately abandon this @policy, which I bet it did not submit to the @FTC for review under the consent decree.…
-
@asharangappa_
Ashley Rangappa
on x
Extorting users for the $8 now https://twitter.com/...
-
@flitteronfraud
Emily Flitter
on x
Am I wrong or is this the equivalent of saying 'nice Twitter account you got going there. Be a shame if something were to happen to it..." https://twitter.com/...
-
@ow
Owen Williams
on x
someone just found the Twilio bill and lost it when they saw it's costing $1m/month to log people in, guarantee it https://twitter.com/...
-
@helenkennedy
Helen Kennedy
on x
No other site charges you for password security. https://twitter.com/...
-
@nicoleperlroth
Nicole Perlroth
on x
So courageous of @elonmusk to wait for a Friday night to announce he's dismantling the most basic of security measures for anyone who doesn't pay $8 a month. Time to expand the @ftc Safeguards Rule to social media platforms. What a joke. 🤦🏼♀️ https://twitter.com/...
-
@dimensionmedia
David Bisset
on x
I've seen better ransom demands from international terrorists then this. https://twitter.com/...
-
@badastronomer
@badastronomer
on x
Holy crap this is official and true. The string of incredibly bad business decisions is beyond parody, beyond a joke. If your account is hacked and you aren't paying you'll be out of luck. All done. They can barely be roused to fix hacked accounts now as it is. https://twitter.co…
-
@zemotion
Jingna Zhang
on x
Gentle reminder that you should use 2FA AND a password manager. Please I beg you 🙏 https://twitter.com/...
-
@carnage4life
Dare Obasanjo
on x
Twitter is going to disable 2FA in a month unless you pay for Twitter Blue. Every product announcement from Twitter 2.0 sounds like a drunk joke or an intern's bad idea that shipped because everyone else had been fired. Real 🤡 💩 https://blog.twitter.com/...
-
@scottnover
Scott Nover
on x
Elon Musk hasn't introduced a single new product or feature since he took over Twitter in October. He has just poorly attempted to monetize every aspect of the service... including security features? in an eight buck a month subscription that, surprise, no one seems to want. http…
-
@summeranne
Summer Anne Burton
on x
I've seen a lot of subscription features and paywalls over the years but can't say I have *ever* seen a blackmail technique like “we'll make your account less secure if you don't pay us” & frankly it might be the embarrassingly desparate move that finally gets me off this site. h…
-
@mikeisaac
@mikeisaac
on x
i cant believe they did it this is clown shoes https://blog.twitter.com/...
-
@peteryared
Peter Yared
on x
@MikeIsaac Pay us or you will be phished
-
@atrupar
Aaron Rupar
on x
OLD: Everybody pays $8 for awesome new features, bells and whistles, & the best Twitter experience ever! NEW: Pay $11 or your account gets hacked, jerkface https://twitter.com/...
-
@nikillinit
Nikhil Krishnan
on x
Now I'm wondering how much money twilio makes in sms based 2FA lol https://twitter.com/...
-
@mgsiegler
M.G. Siegler
on x
Yeah. This is bullshit. https://twitter.com/...
-
@ivycomb
@ivycomb
on x
Hey, technology expert here. This is what we call in the industry “gross incompetence” Imagine locking the *worst* type of Two Factor authentication behind a paywall lmao https://twitter.com/...
-
@felixclc_
@felixclc_
on x
So Blue subscribers get the worse type of 2FA? https://twitter.com/...