/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Twitter transparency report: only 2.3% of active accounts have enabled 2FA between July and December 2020; 79.6% of those who did used SMS-based 2FA

Sergiu Gatlan / BleepingComputer :

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Twitter's transparency report lands after years of the company widening non-SMS options: it first let users wire third-party apps like 1Password or Authy into two-factor authentication back in 2017, then in late 2019 removed the phone-number requirement entirely so people could enroll in 2FA without a phone number and drop SMS as the default. The 2.3% adoption figure is the receipt on all of that work — the alternatives existed, but almost nobody used them.

First-order effects

  • With fewer than one in forty active accounts protected and nearly four in five of those still on SMS, Twitter's own preferred methods — authenticator apps and hardware keys — remain marginal at the exact moment the company is asking users to trust its account-security posture.

Second-order effects

  • The SMS dependence exposed here foreshadows both of Twitter's later moves: monetizing SMS 2FA as a Blue subscriber perk in 2023 while pushing everyone else to authenticator apps or keys (restricting SMS-based 2FA to Blue), and the 2025 whistleblower disclosure that over a million 2FA text messages routed through Fink Telecom, a small Swiss firm linked to spy agencies — turning the dominant 2FA method into an interception surface.

Third-order effects

  • If platform-reported adoption numbers keep lagging the threat model this badly, account security stops being a user-education problem and becomes a product-design mandate — defaults and paid tiers, not opt-in settings, decide whether two-factor protection reaches the population that needs it.

The trend: Platform authentication is shifting from user-elected SMS codes toward app- and key-based methods that operators control — first by default-setting, eventually by paywalling.

Discussion

  • @pndc @pndc on x
    Given the frequent “nudges” demanding a phone number ostensibly for 2FA, pretty much all Twitter users must be aware of it. One can thus conclude that 97.7% of users do not trust Twitter to not leak it or otherwise misuse it. https://twitter.com/...
  • @db @db on x
    My Twitter account was hacked for over 1 year with no recourse and I only got it back when a friend pulled strings at Twitter. So YES I have multiple 2FA enabled. Just not text. My phone SIM was hacked twice. They want my username. 🤷‍♂️ 🥴 https://twitter.com/... https://twitter.c…
  • @quinnypig Corey Quinn on x
    This tracks. I *only* allow security-key authentication to this account; I don't have 2FA turned on for a couple of lesser / shitpost accounts because if they get compromised it just doesn't matter all that much. https://twitter.com/...
  • @michaelwilsonds Michael Wilson on x
    Some insight into just how many bots are really on social media platforms and how bad the average security is of the average actual human beings using the platforms. This should be setting off alarm bells. https://twitter.com/...
  • @karlbode Karl Bode on x
    wow that's far more pathetic than I would have imagined https://twitter.com/...
  • @thecrowdfundlaw Jossey Pllc on x
    It's only surprising for people who have never been in 2FA hell. https://twitter.com/...
  • @jake_mooreuk Jake Moore on x
    I actually can't believe it. I don't *want* to believe it! We need to up our awareness game 😬 Twitter reveals surprisingly low two-factor auth (2FA) adoption rate https://www.bleepingcomputer.com/ ...