/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Twitter says users can now enroll in 2FA without a phone number and disable SMS-based 2FA as default, allows other methods such as mobile authenticator apps

And it only took Twitter's CEO getting hacked to happen.  —  Twitter announced today that users will finally be able to disable SMS-based …

ZDNet Catalin Cimpanu

Context & Ripple Effects

This is the second step of a slow decoupling: back in 2017 Twitter already let users plug in third-party apps like 1Password or Authy for two-factor codes, and Facebook made a comparable no-phone-number move in 2018 (dedicated hardware and code-generating apps without registering a number). What changed now is that Twitter stopped treating SMS as the default factor at all — and, per ZDNet's framing, only after its own CEO's account was compromised.

The stakes are visible in Twitter's own data: its transparency report showed just 2.3% of active accounts had 2FA enabled, and nearly 80% of those leaned on SMS — so changing the default, not adding options, is what moves the population.

First-order effects

  • High-profile users who never wanted to hand Twitter a phone number can finally secure their accounts, and existing users can demote SMS from default to opt-in in favor of authenticator apps.

Second-order effects

  • Authenticator-app vendors like Authy become the path of least resistance for most of Twitter's user base, while carriers lose a slice of the verification traffic they had been riding on by default.

Third-order effects

  • The endpoint of this arc arrived in 2023, when Twitter went further and made SMS-based 2FA a paid perk reserved for Blue subscribers while steering everyone else to apps and physical keys — suggesting platform security factors migrate from universal free defaults to tiered product lines.

The trend: Major social platforms are systematically retiring SMS as an authentication factor — first de-defaulting it, then monetizing it — pushing users toward authenticator apps and hardware keys.

Discussion

  • @twittersafety @twittersafety on x
    We're also making it easier to secure your account with Two-Factor Authentication. Starting today, you can enroll in 2FA without a phone number. https://twitter.com/...
  • @kayvz Kayvon Beykpour on x
    Another 🔑 update today: you can now use Two Factor Authentication without linking a phone number. If you already have your phone number linked along with App-based 2FA, you can unlink your 📞 it in the “Account” section of your settings while still keeping 2FA on. https://twitter.…
  • @twittersupport @twittersupport on x
    We've updated how you can use two-factor authentication, allowing you to enable it with or without a phone number. Here's how to add extra security to your account using an authorization app, physical security key, or SMS text message: https://help.twitter.com/... https://twitte…
  • @eff @eff on x
    We're happy to see Twitter adopting this best practice and giving users more options to enable two-factor authentication on their accounts. https://twitter.com/...
  • @josephfcox Joseph Cox on x
    This is a big deal; can finally use 2FA on Twitter without a phone number (I just verified it works) - Greater protection against SIM jacking w/ no number linked - Some activists stopped using 2FA because SMS was a risk for them; better now https://twitter.com/...
  • @evacide Eva on x
    I'm glad that this day has come, but boy did it take a long time. https://twitter.com/...
  • @mrbond_zhp Adam Ziegler on x
    Excellent time to switch 2FA from SMS and also remove the phone number from your account entirely. https://twitter.com/...
  • @robpegoraro Rob Pegoraro on x
    Here's your chance to get your mobile number (meaning for most of you, your wireless carrier's front-line tech support) out of the critical path of your account's security. https://twitter.com/...
  • @agilethumbs Scott on x
    Big thanks to whoever hacked Jack's account. https://twitter.com/...
  • @nditech @nditech on x
    If you are reading this you're on Twitter, so take two minutes and click the your profile->settings->account-> security and turn on two factor now! If you're a political animal or human rights defender you're at particular risk, so no excuses! https://twitter.com/...
  • @peter_szilagyi Péter Szilágyi on x
    It. Does. Not. Work. Added Yubikey, removed phone number. Got an email that I just disabled 2FA and I must supply a phone number to reenable it.
  • @alexkoppelman Alex Koppelman on x
    Turns out all that needed to happen for Twitter to change this (super bad) policy was for its very own CEO to get hacked! https://twitter.com/...
  • @jcmi Jared Miller on x
    Congrats to my teammates who worked darn hard to get this out. Expect more to come! https://twitter.com/...
  • @dellcam Dell Cameron on x
    About a month ago, Twitter disclosed it was inadvertently helping advertisers target users based on phone numbers provided to secure their accounts with 2FA. (It declined to say how long it had been doing so): https://gizmodo.com/... https://twitter.com/...
  • @astepanovich Amie Stepanovich on x
    This is amazingly great news. https://twitter.com/...