Twitter transparency report: only 2.3% of active accounts have enabled 2FA between July and December 2020; 79.6% of those who did used SMS-based 2FA
Sergiu Gatlan / BleepingComputer :
Context & Ripple Effects
Twitter's transparency report lands after years of the company widening non-SMS options: it first let users wire third-party apps like 1Password or Authy into two-factor authentication back in 2017, then in late 2019 removed the phone-number requirement entirely so people could enroll in 2FA without a phone number and drop SMS as the default. The 2.3% adoption figure is the receipt on all of that work — the alternatives existed, but almost nobody used them.
First-order effects
- With fewer than one in forty active accounts protected and nearly four in five of those still on SMS, Twitter's own preferred methods — authenticator apps and hardware keys — remain marginal at the exact moment the company is asking users to trust its account-security posture.
Second-order effects
- The SMS dependence exposed here foreshadows both of Twitter's later moves: monetizing SMS 2FA as a Blue subscriber perk in 2023 while pushing everyone else to authenticator apps or keys (restricting SMS-based 2FA to Blue), and the 2025 whistleblower disclosure that over a million 2FA text messages routed through Fink Telecom, a small Swiss firm linked to spy agencies — turning the dominant 2FA method into an interception surface.
Third-order effects
- If platform-reported adoption numbers keep lagging the threat model this badly, account security stops being a user-education problem and becomes a product-design mandate — defaults and paid tiers, not opt-in settings, decide whether two-factor protection reaches the population that needs it.
The trend: Platform authentication is shifting from user-elected SMS codes toward app- and key-based methods that operators control — first by default-setting, eventually by paywalling.