Everyone I know who works in security has seen Some Stuff. But I've never seen a website that told users you must remove two-factor authentication.

@mshelton

It's costing Twitter too much to send the codes via SMS allegedly so the're turning it off.

I doubt it's saves a huge amount but it's another step to bankruptcy.

@simonzerafa @mshelton Not wanting to be a Twitter apologist, but from https://blog.twitter.com/en_us/topics/product/2023/an-update-on-two-factor-authentication-using-sms-on-twitter:

unfortunately we have seen phone-number based 2FA be used - and abused - by bad actors.

They do state they are removing phone 2FA because it poses security issues.

@sfwrtr @mshelton

That's a phone charges issue. BAs set up accounts and request lots of SMS 2SA tokens which are chargeable to Twitter 🫤

@sfwrtr @simonzerafa @mshelton Don't be. This was done this way solely to shill his eight buck plan; otherwise he'd disable SMS completely and force everyone to token MFA.
@timjclevenger @simonzerafa @mshelton This is a reasonable explanation for keeping text 2FA for T-blue. The idea that money should allow you the ability to do something otherwise considered stupid is rather an interesting tell about Twitter's management, however.

@sfwrtr @simonzerafa @mshelton That’s an utter falsehood on their part. If that were their motivation, they’d remove SMS 2FA entirely rather than restrict to paid accounts.

In reality, humans dislike TOTP 2FA and prefer SMS codes for lots of reasons. So they’re making the less secure, but preferred, option s premium feature.

@simonzerafa @mshelton it is lost to history but Twitter used to be an SMS first service with the web interface as secondary.

Makes this move even more ironic.