/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Twitter says it has “temporarily” turned off the SMS-to-tweet feature, after Jack Dorsey's account was compromised

Twitter has “temporarily” turned off the ability to tweet via text message just days after the feature was misused by hackers to tweet a racial slur, bomb threat …

The Verge Jacob Kastrenakes

Context & Ripple Effects

The immediate trigger was the hijacking of Jack Dorsey's own account, where attackers posting under his name pushed out racist tweets and threats through the little-known text-message pathway. For Twitter, the embarrassment was acute because the compromise ran through a legacy feature on its founder's flagship account, echoing the earlier internal mistake that briefly suspended Dorsey in 2016 and compounding questions about how well core account protections are run.

The response fits a pattern rather than standing alone: months after this 'temporary' shutdown, Twitter went further and turned off SMS tweet alerts in most countries entirely. What began as an emergency pause on one feature became a broader retreat from tying accounts to text messages.

First-order effects

  • Users who tweeted by text message lose that pathway overnight, with Twitter offering no stated timeline for restoring it despite the word 'temporary'.
  • Twitter closes the specific hole the Chuckle Squad exploited — a command channel authenticated by a SIM/phone number rather than a password or two-factor app — directly on the account type it most needs to protect.

Second-order effects

  • The same SMS dependency extends to inbound notifications, which is why the company followed up by cutting SMS tweet alerts across most markets — shrinking carrier-based messaging revenue and usage for the telecom partners involved.
  • Security teams at other services built on similar text-message commands face pressure to audit whether their own phone-number-authenticated backdoors could be hijacked the same way.

Third-order effects

  • If the pattern holds, platforms systematically retire legacy features tethered to phone numbers, treating carrier-controlled identifiers as an untrustworthy authentication layer and consolidating access behind app-based credentials.
  • Regulators and security researchers gain a recurring case study — a CEO's account compromised through a side channel — that strengthens arguments for mandatory hardening of high-profile accounts beyond what companies volunteer.

The trend: Social platforms are dismantling SMS-era legacy features piece by piece, as each incident converts a convenience into a demonstrated account-security liability.

Discussion

  • @twittersupport @twittersupport on x
    We're temporarily turning off the ability to Tweet via SMS, or text message, to protect people's accounts.
  • @twittersupport @twittersupport on x
    We're taking this step because of vulnerabilities that need to be addressed by mobile carriers and our reliance on having a linked phone number for two-factor authentication (we're working on improving this).
  • @twittersupport @twittersupport on x
    We'll reactivate this in markets that depend on SMS for reliable communication soon while we work on our longer-term strategy for this feature.
  • @stevebellovin Steven Bellovin on x
    Thread. To;dr: security is a matter of engineering and trade offs, not absolute. And he's 100% correct. https://twitter.com/...
  • @0xcharlie Charlie Miller on x
    Its easy to criticize security decisions if you don't understand the tradeoffs involved. Let me explain why Twitter made various security decisions, right or wrong. Remember I was Twitter appsec tech lead a while back so I have some insight. https://twitter.com/...
  • @swodinsky @swodinsky on x
    what's ironic here is that the sms-to-tweet function—which is a central way that many orthodox/hassidic jews access this platform—is ultimately being powered down for spreading antisemitic content https://www.adweek.com/... https://twitter.com/...
  • @missig_geek Miss IG Geek on x
    Twitter: we designed the security on our service poorly, so now we're going to cripple it for everyone in countries with poor internet connectivity because someone inconvenienced our founder https://twitter.com/...
  • @rabble @rabble on x
    End of an era. Twitter was sms first and was always awesome. I remember it was originally some pirated windows software plugged in to a feature phone via USB and a prepaid T-Mobile phone when it launched. Nobody wanted to give us a shortcode for such a weird non-marketing service…
  • @cooperq SimJack Dorsey on x
    I think my theory that sms spoofing to the twitter long codes is how jack got hacked will turn out to be correct. https://twitter.com/...
  • @sub8u Subrahmanyam Kvj on x
    Basically, the trick to getting Twitter to listen to its users is to encourage Jack to use the service more. https://twitter.com/...
  • @lepp @lepp on x
    The entire cellular system should be considered untrusted in any application's threat model. I've been designing like this since GPRS was in beta. https://twitter.com/...
  • @docdre Thot Leedur on x
    This is the end of an era: Twitter was originally designed around the capacities of SMS (140 chars as microblog, address book, broadcast capabilities) https://twitter.com/...
  • @kevincollier Kevin Collier on x
    Weird, because I'm literally tweeting this by texting it to 40404 https://twitter.com/...
  • @josephfcox Joseph Cox on x
    Twitter did not do this when a cybersecurity company (controversially) proved it was possible with high profile accounts recently; Twitter only acted after @jack's account was targeted https://twitter.com/...
  • @caseynewton Casey Newton on x
    This gives me hope that someday Jack will have a typo in one of his tweets that inspires Twitter to prioritize editing https://twitter.com/...
  • @wongmjane Jane Manchun Wong on x
    To protect @jack's account https://twitter.com/...
  • @zeynep Zeynep Tufekci on x
    About time. It should not have taken @jack getting sim-jacked. https://twitter.com/...