Twitter says users can now enroll in 2FA without a phone number and disable SMS-based 2FA as default, allows other methods such as mobile authenticator apps
This closes a gap Twitter had been opening for two years: it first allowed third-party authenticator apps like Authy and 1Password as an alternative to SMS back in December 2017, and Facebook removed its own phone-number registration requirement for app- and hardware-based 2FA in May 2018. The 2019 change finishes the job on Twitter's side — no phone number required to enroll, and SMS demoted from mandatory default to an option.
First-order effects
Users who avoided 2FA specifically because it meant handing over a phone number can now enable it with only an authenticator app — directly expanding the set of accounts that can be secured.
SMS is no longer forced as the default method, so new enrollees land on stronger app-based codes unless they actively choose text messages.
Second-order effects
Twitter's own transparency data later showed why this matters: only 2.3% of active accounts had enabled any 2FA between July and December 2020, and 79.6% of those used SMS — meaning carrier-dependent text codes were the de facto security floor for nearly all protected accounts until alternatives were friction-free.
Facebook's earlier equivalent move and Twitter's follow-through put pressure on every major platform to treat phone-number collection as optional rather than a bundled requirement of account security.
Third-order effects
The end state arrived in 2023, when Twitter restricted SMS-based 2FA to Blue subscribers while keeping authenticator apps and security keys free — completing the arc from SMS-as-default to SMS-as-paid-feature, with carriers' OTP traffic on social platforms shrinking accordingly.
If the pattern holds across platforms, phone numbers get unbundled from identity verification entirely, shifting the industry toward app- and hardware-based factors as the baseline and leaving SMS as either a legacy fallback or a billable add-on.
The trend: Social platforms are progressively decoupling two-factor authentication from phone numbers — first as a privacy accommodation, ultimately as a way to push SMS costs onto paying tiers.
We're also making it easier to secure your account with Two-Factor Authentication. Starting today, you can enroll in 2FA without a phone number. https://twitter.com/...
Another 🔑 update today: you can now use Two Factor Authentication without linking a phone number. If you already have your phone number linked along with App-based 2FA, you can unlink your 📞 it in the “Account” section of your settings while still keeping 2FA on. https://twitter.…
We've updated how you can use two-factor authentication, allowing you to enable it with or without a phone number. Here's how to add extra security to your account using an authorization app, physical security key, or SMS text message: https://help.twitter.com/... https://twitte…
This is a big deal; can finally use 2FA on Twitter without a phone number (I just verified it works) - Greater protection against SIM jacking w/ no number linked - Some activists stopped using 2FA because SMS was a risk for them; better now https://twitter.com/...
If you are reading this you're on Twitter, so take two minutes and click the your profile->settings->account-> security and turn on two factor now! If you're a political animal or human rights defender you're at particular risk, so no excuses! https://twitter.com/...
We're happy to see Twitter adopting this best practice and giving users more options to enable two-factor authentication on their accounts. https://twitter.com/...
About a month ago, Twitter disclosed it was inadvertently helping advertisers target users based on phone numbers provided to secure their accounts with 2FA. (It declined to say how long it had been doing so): https://gizmodo.com/... https://twitter.com/...
Here's your chance to get your mobile number (meaning for most of you, your wireless carrier's front-line tech support) out of the critical path of your account's security. https://twitter.com/...