Facebook says users can now use dedicated hardware or code-generating apps for two-factor authentication without having to register their phone number
Context & Ripple Effects
Facebook built this capability in stages: it added support for physical USB security keys including Yubico's NFC key in early 2017 (security-key support), but until now enrolling in two-factor authentication still required handing over a phone number — the same identifier Facebook had been actively collecting since it began letting Android apps match a login phone number against a user's profile (phone-number login matching).
The move closes that gap and aligns Facebook with where its peers were already heading: Twitter had allowed third-party authenticator apps like 1Password and Authy as an SMS alternative since late 2017, and Google had turned any Android 7.0+ device into a portable security key by April 2019. Security-conscious users who avoided 2FA rather than surrender a number now have no excuse.
First-order effects
- Users can now enable two-factor authentication with dedicated hardware or code-generating apps while keeping their phone number out of Facebook's records entirely — removing the privacy trade-off that previously deterred exactly the security-minded users 2FA is meant to protect.
- SMS-based codes shift from being the default enrollment path to one option among several, reducing Facebook's dependence on carrier-delivered verification.
Second-order effects
- Twitter faces direct competitive pressure on the same axis, and indeed within eighteen months it went further, letting users enroll in 2FA without a phone number and disabling SMS-based 2FA as the default (Twitter dropping the phone-number requirement).
- Authenticator-app vendors like Authy and 1Password, already integrated by Twitter, gain Facebook's user base as a distribution channel, while carriers see steady erosion of the per-message verification traffic that SMS 2FA generated.
Third-order effects
- If the pattern holds, the phone number stops being the de facto identity anchor for account security across major platforms — undercutting both the surveillance value of number collection and the SIM-swap attack vector that makes SMS codes the weakest link.
- Platform security converges on open standards (hardware keys, TOTP apps, phones-as-keys) rather than proprietary phone-number graphs, making strong authentication a baseline expectation rather than a premium behavior.
The trend: Major social platforms are progressively decoupling account security from phone numbers, with hardware keys and authenticator apps replacing SMS as the default second factor.