Adding an extra layer of security to your online accounts is eroticism meaninga fundamental step to protect your digital life from hackers, but what's the point if the new methods are just as vulnerable as the old ones?
It's a question some Twitter users are asking after discovering that the two-factor authentication on their accounts isn't as secure as it seems.
SEE ALSO: The software that could prevent ISPs from selling your browsing history could also just make things worseBut let's back up for a second. No matter who you are, having your Twitter hacked would be a major bummer. In the case of political figures like Donald Trump, however, a hijacked account means more than just a headache — think of the havoc a fake policy pronouncement could wreak?
And so it was welcome news back in 2013 when Twitter rolled out two-factor authentication (2FA) to all of its users. This added layer of security allows users to protect their accounts, even if their passwords had been stolen, by requiring a second login credential sent via text message.
Great, right? Well, kinda.
While SMS-based 2FA does provide additional protection, there's a big problem with it. Namely, SMS itself isn't secure. A flaw in what is known as Signaling System 7 protocol (SS7) — something that allows different phone carriers to communicate back and forth — means that hackers can redirect texts to practically any number they want.
That means your SMS verification code could end up being sent directly to the cellphone of your hacker.
And this is not just theoretical. In January of 2017, reports Ars Technica, a group of criminals exploited this flaw to snatch victims' SMS verification codes and drain their bank accounts.
So, with text-based 2FA known to have a security hole so large you could drive a truck through it, Twitter helpfully introduced additional ways to set up 2FA. Users who already have access to their accounts via the Twitter mobile app can use something called a login code generator, but as this requires already being logged in on mobile it doesn't help if you're signed out.
The other method, a 3rd-party authenticator app, offers a better option. These apps, like Google Authenticator, generate a number sequence on your phone as your verification code — no vulnerable text message required.
Problem solved, right?
Not so fast. Because here's the thing, even with an authenticator app enabled Twitter still sends out SMS verification codes. That's right, the people that have taken the extra step to secure their Twitter accounts with an authenticator app — arguably the people most concerned about having their accounts hacked — are still just as vulnerable as those who rely on SMS-based verification codes.
And this has not gone unnoticed.
This Tweet is currently unavailable. It might be loading or has been removed.
This Tweet is currently unavailable. It might be loading or has been removed.
This Tweet is currently unavailable. It might be loading or has been removed.
This Tweet is currently unavailable. It might be loading or has been removed.
This Tweet is currently unavailable. It might be loading or has been removed.
Users are rightly wondering what's the point of having a 3rd-party authenticator app set up if Twitter still send out text messages with the codes.
Twitter, for its part, is staying silent on the matter.
We reached out to the company and exchanged multiple emails with numerous employees who all categorically refused to explain if there was any way to disable SMS-based 2FA verification codes while maintaining a 3rd-party authenticator app, as well as why that would be the case.
One spokesperson simply responded the company had "nothing to share on our 2FA beyond what's in our help center." To be clear, the help center does not address this issue.
What about just deleting your phone number from your Twitter account? Then it can't send you texts, right? Go ahead, but then you can no longer use the 3rd-party authenticator app.
The company, through spokespersons, also refused to comment on the SS7 exploit rendering SMS vulnerable to hackers.
For the average Twitter user, a text message-based verification code — despite its flaws — is a great added layer of security. However, as demonstrated by the criminals that emptied bank accounts in January, a determined hacker can bypass this security measure.
And maybe this just a bug affecting some users' accounts, and not each and every one of Twitter's users with 3rd-party 2FA apps. Twitter's refusal to discuss the matter, however, means we don't know.
For you and I, this might not be that big of a deal at the end of the day. For celebrities, politicians, and members of the Silicon Valley elite? Well, that's a different matter — and it's one that Twitter should quickly address.
Topics Cybersecurity X/Twitter
Intel debuts Core Ultra 200V series processors, Lenovo to unveil new AIChinese EV maker Xpeng reportedly turns to hybrids · TechNodeTesla China to introduce redesigned Model Y crossovers, including a sevenChina’s Xpeng Motors planning EV production in Europe · TechNodeSpain hands $146 million to Stellantis’s battery project with CATL · TechNodeBYD to introduce premium SUV, sedan, and more to Japan: report · TechNodeVolvo’s parent Geely to build $170 million joint factory in Vietnam · TechNodeKuaishou invites nine movie directors to produce clips using Kling model · TechNodeNokia cuts 2,000 jobs in China for costMeituan shifts focus from GMV to order volume amid declining sales · TechNode20% of NIO’s battery swap stations approach breakeven point · TechNodeNETA to mass produce first EV featuring CATL’s skateboard chassis · TechNodeKuaishou sees revenue growth slow in Q2, SoraChina calls on the Netherlands to uphold market principles amid new Dutch export controls on chipHuawei’s car business swings to firstVolkswagen, General Motors resume price war with steep price cuts in China · TechNodeChina vehicle sales to rise in September on stimulus measures, new models · TechNodeVolvo’s parent Geely to build $170 million joint factory in Vietnam · TechNodeTencent to launch mobile version Pokémon UNITE on Nov 7 · TechNodeXiaomi unveils tri Best Peacock deal: Save over $50 on 12 Webb discovers a distant moon has an intriguing similarity to Earth The internet can't stop thinking of Katy Perry Lego free Ninjago: How to get free Lego Ninjago Thunderfang Summer TV preview: All the TV shows you need to know, and where to stream them Best smartwatch deal: Get a Google Pixel Watch 3 for $299.99 at Amazon Best Apple deal: Save $69.01 on Apple AirPods Max (USB Acer Chromebook 516 GE deal: Get it for just $450 JetBlue "Book It Before It's Hot" sale: Cheap flights for as low as $59 each way Best robot vacuum deal: Save $140 on roborock Q7 Max Robot Vacuum Best Beats deal: Save $50 on Beats Pill Best TV deal: Save $100 on Amazon Fire TV 4 Microsoft is laying off 3 percent of employees How to unblock Pornhub for free in North Carolina NYT Connections hints and answers for May 14: Tips to solve 'Connections' #703. Best security camera deal: Get a Google Nest Security Cam for its lowest price yet Best espresso machine deal: Save 31% on the De'Longhi Magnifica Evo Best portable power station deal: Save $179.01 on the EcoFlow River 2 Max Coinbase confirms data breach with hackers demanding $20 million ransom How Black Girls Code is preparing underrepresented kids for the AI revolution
2.5687s , 10193.734375 kb
Copyright © 2025 Powered by 【eroticism meaning】,Exquisite Information Network