Twitter says it has “temporarily” turned off the SMS-to-tweet feature, after Jack Dorsey's account was compromised
Twitter has “temporarily” turned off the ability to tweet via text message just days after the feature was misused by hackers to tweet a racial slur, bomb threat …
The VergeJacob Kastrenakes
Context & Ripple Effects
The immediate trigger was the hijacking of Jack Dorsey's own account, where attackers posting under his name pushed out racist tweets and threats through the little-known text-message pathway. For Twitter, the embarrassment was acute because the compromise ran through a legacy feature on its founder's flagship account, echoing the earlier internal mistake that briefly suspended Dorsey in 2016 and compounding questions about how well core account protections are run.
The response fits a pattern rather than standing alone: months after this 'temporary' shutdown, Twitter went further and turned off SMS tweet alerts in most countries entirely. What began as an emergency pause on one feature became a broader retreat from tying accounts to text messages.
First-order effects
Users who tweeted by text message lose that pathway overnight, with Twitter offering no stated timeline for restoring it despite the word 'temporary'.
Twitter closes the specific hole the Chuckle Squad exploited — a command channel authenticated by a SIM/phone number rather than a password or two-factor app — directly on the account type it most needs to protect.
Second-order effects
The same SMS dependency extends to inbound notifications, which is why the company followed up by cutting SMS tweet alerts across most markets — shrinking carrier-based messaging revenue and usage for the telecom partners involved.
Security teams at other services built on similar text-message commands face pressure to audit whether their own phone-number-authenticated backdoors could be hijacked the same way.
Third-order effects
If the pattern holds, platforms systematically retire legacy features tethered to phone numbers, treating carrier-controlled identifiers as an untrustworthy authentication layer and consolidating access behind app-based credentials.
Regulators and security researchers gain a recurring case study — a CEO's account compromised through a side channel — that strengthens arguments for mandatory hardening of high-profile accounts beyond what companies volunteer.
The trend: Social platforms are dismantling SMS-era legacy features piece by piece, as each incident converts a convenience into a demonstrated account-security liability.
We're taking this step because of vulnerabilities that need to be addressed by mobile carriers and our reliance on having a linked phone number for two-factor authentication (we're working on improving this).
Its easy to criticize security decisions if you don't understand the tradeoffs involved. Let me explain why Twitter made various security decisions, right or wrong. Remember I was Twitter appsec tech lead a while back so I have some insight. https://twitter.com/...
what's ironic here is that the sms-to-tweet function—which is a central way that many orthodox/hassidic jews access this platform—is ultimately being powered down for spreading antisemitic content https://www.adweek.com/... https://twitter.com/...
Twitter: we designed the security on our service poorly, so now we're going to cripple it for everyone in countries with poor internet connectivity because someone inconvenienced our founder https://twitter.com/...
End of an era. Twitter was sms first and was always awesome. I remember it was originally some pirated windows software plugged in to a feature phone via USB and a prepaid T-Mobile phone when it launched. Nobody wanted to give us a shortcode for such a weird non-marketing service…
The entire cellular system should be considered untrusted in any application's threat model. I've been designing like this since GPRS was in beta. https://twitter.com/...
This is the end of an era: Twitter was originally designed around the capacities of SMS (140 chars as microblog, address book, broadcast capabilities) https://twitter.com/...
Twitter did not do this when a cybersecurity company (controversially) proved it was possible with high profile accounts recently; Twitter only acted after @jack's account was targeted https://twitter.com/...