Skip to main content

Twitter finally getting serious about security, considering two-step authentication

twitter lock
Image used with permission by copyright holder

Twitter passwords are just too easy to crack. But according to Wired, the platform is finally getting its act together and working on a sorely-needed two-step authentication system.

We’ve even taken an inside look at the flourishing black market for hacked Twitter accounts, and it’s clear that much of this activity is being controlled by inexperienced hackers who are willing to compromise and takeover an account for less than $100, in most cases. 

Recommended Videos

While hacking Twitter accounts isn’t terrible difficult, the consequences are very real. Recently, we witnessed the effects a falsified tweet can have in the real world. The Associated Press’ Twitter account was surreptitiously hacked and in turn tweeted out something that would make you jump in your seat. At least it made investors very, very nervous. The @AP account, which was temporarily suspended (but is now back up) tweeted, “Breaking: Two Explosions in the White House and Barack Obama is injured.” The stock market took a dive in response to the hoax and a hacker group calling itself the Syrian Electronic Army claimed responsibility.

That White House hoax is just the latest public hack since NPR’s Twitter accounts were compromised, along with CBS’s account. And if it’s of any concern, North Korea’s Twitter account was recently hacked by Anonymous.

So what is Twitter to do? When pressed in the past about its security vulnerabilities, it’s done little more than throw around generic PR statements talking about how security is a priority at Twitter.

Ironically for a company that was mobile first, you’d think that two-factor authentication (which sends a code to a mobile device when logging in using a new device or a device in a new country) would be a feature they would have implemented from the get-go. Thankfully, it should be on the way. There’s no release date for the feature, but we’ve reached out to Twitter for comment and will update this space with the company’s reply.

The one issue though that poses a problem when it comes to two-step authentication is when there are multiple managers of one account. One account is tied to one mobile phone number so in the case of a two-step authentication process, one person would have to receive the SMS from Twitter and relay that code to the person trying to access the account from a different device. That could be one solution, but we’ll leave it up to Twitter’s engineers to solve that problem more efficiently.

Topics
Francis Bea
Former Digital Trends Contributor
Francis got his first taste of the tech industry in a failed attempt at a startup during his time as a student at the…
I paid Meta to ‘verify’ me — here’s what actually happened
An Instagram profile on an iPhone.

In the fall of 2023 I decided to do a little experiment in the height of the “blue check” hysteria. Twitter had shifted from verifying accounts based (more or less) on merit or importance and instead would let users pay for a blue checkmark. That obviously went (and still goes) badly. Meanwhile, Meta opened its own verification service earlier in the year, called Meta Verified.

Mostly aimed at “creators,” Meta Verified costs $15 a month and helps you “establish your account authenticity and help[s] your community know it’s the real us with a verified badge." It also gives you “proactive account protection” to help fight impersonation by (in part) requiring you to use two-factor authentication. You’ll also get direct account support “from a real person,” and exclusive features like stickers and stars.

Read more
Here’s how to delete your YouTube account on any device
How to delete your YouTube account

Wanting to get out of the YouTube business? If you want to delete your YouTube account, all you need to do is go to your YouTube Studio page, go to the Advanced Settings, and follow the section that will guide you to permanently delete your account. If you need help with these steps, or want to do so on a platform that isn't your computer, you can follow the steps below.

Note that the following steps will delete your YouTube channel, not your associated Google account.

Read more
How to download Instagram photos for free
Instagram app running on the Samsung Galaxy Z Flip 5.

Instagram is amazing, and many of us use it as a record of our lives — uploading the best bits of our trips, adventures, and notable moments. But sometimes you can lose the original files of those moments, leaving the Instagram copy as the only available one . While you may be happy to leave it up there, it's a lot more convenient to have another version of it downloaded onto your phone or computer. While downloading directly from Instagram can be tricky, there are ways around it. Here are a few easy ways to download Instagram photos.

Read more