Twitter grants account protection via SMS only to subscription customers
Security experts warn against protecting logins with only one password. They recommend securing access with a second factor. The SMS function is often used for this. At Twitter, this security feature is now only available for paying customers.

"So starting today, we will no longer allow accounts to sign up for the SMS method of two-factor authentication unless they are subscribers to Twitter Blue."
Twitter users, however, still have the option of using an authentication app or a security key to secure the account. The change was not well received in the Twitter community. Many users suspected that the change was just an attempt by Elon Musk to push the switch to the paid subscription Twitter Blue.
Twitter owner Musk indirectly justified the policy change by accusing unspecified telecommunications companies of abusing the SMS system. He confirmed a report that companies had used robot accounts to drive up the sending of 2FA SMS. Twitter must bear the cost of the SMS. It said it loses $60 million a year from fraudulent SMS. In a tweet, Musk confirmed these statements with a quick "Yup."
On Saturday, security experts were also able to take something positive away from the omission of the SMS method in two-factor authentication. Among the various 2FA methods, SMS is the weakest, they said. Frank Rieger, spokesman for the Chaos Computer Club, explained that Twitter's motive for only letting paying users use SMS-based two-factor authentication was obviously financial: "SMS costs money." But in the end, he said, it could actually improve security by pushing users toward better authentication methods. (SDA/swi)
