Skip to main content

Twitter finally getting serious about security, considering two-step authentication

twitter lock
Image used with permission by copyright holder

Twitter passwords are just too easy to crack. But according to Wired, the platform is finally getting its act together and working on a sorely-needed two-step authentication system.

We’ve even taken an inside look at the flourishing black market for hacked Twitter accounts, and it’s clear that much of this activity is being controlled by inexperienced hackers who are willing to compromise and takeover an account for less than $100, in most cases. 

While hacking Twitter accounts isn’t terrible difficult, the consequences are very real. Recently, we witnessed the effects a falsified tweet can have in the real world. The Associated Press’ Twitter account was surreptitiously hacked and in turn tweeted out something that would make you jump in your seat. At least it made investors very, very nervous. The @AP account, which was temporarily suspended (but is now back up) tweeted, “Breaking: Two Explosions in the White House and Barack Obama is injured.” The stock market took a dive in response to the hoax and a hacker group calling itself the Syrian Electronic Army claimed responsibility.

That White House hoax is just the latest public hack since NPR’s Twitter accounts were compromised, along with CBS’s account. And if it’s of any concern, North Korea’s Twitter account was recently hacked by Anonymous.

So what is Twitter to do? When pressed in the past about its security vulnerabilities, it’s done little more than throw around generic PR statements talking about how security is a priority at Twitter.

Ironically for a company that was mobile first, you’d think that two-factor authentication (which sends a code to a mobile device when logging in using a new device or a device in a new country) would be a feature they would have implemented from the get-go. Thankfully, it should be on the way. There’s no release date for the feature, but we’ve reached out to Twitter for comment and will update this space with the company’s reply.

The one issue though that poses a problem when it comes to two-step authentication is when there are multiple managers of one account. One account is tied to one mobile phone number so in the case of a two-step authentication process, one person would have to receive the SMS from Twitter and relay that code to the person trying to access the account from a different device. That could be one solution, but we’ll leave it up to Twitter’s engineers to solve that problem more efficiently.

Topics
Francis Bea
Former Digital Trends Contributor
Francis got his first taste of the tech industry in a failed attempt at a startup during his time as a student at the…
Bluesky barrels toward 1 million new sign-ups in a day
Bluesky social media app logo.

Social media app Bluesky has picked nearly a million new users just a day after exiting its invitation-only beta and opening to everyone.

In a post on its main rival -- X (formerly Twitter) -- Bluesky shared a chart showing a sudden boost in usage on the app, which can now be downloaded for free for iPhone and Android devices.

Read more
How to make a GIF from a YouTube video
woman sitting and using laptop

Sometimes, whether you're chatting with friends or posting on social media, words just aren't enough -- you need a GIF to fully convey your feelings. If there's a moment from a YouTube video that you want to snip into a GIF, the good news is that you don't need complex software to so it. There are now a bunch of ways to make a GIF from a YouTube video right in your browser.

If you want to use desktop software like Photoshop to make a GIF, then you'll need to download the YouTube video first before you can start making a GIF. However, if you don't want to go through that bother then there are several ways you can make a GIF right in your browser, without the need to download anything. That's ideal if you're working with a low-specced laptop or on a phone, as all the processing to make the GIF is done in the cloud rather than on your machine. With these options you can make quick and fun GIFs from YouTube videos in just a few minutes.
Use GIFs.com for great customization
Step 1: Find the YouTube video that you want to turn into a GIF (perhaps a NASA archive?) and copy its URL.

Read more
I paid Meta to ‘verify’ me — here’s what actually happened
An Instagram profile on an iPhone.

In the fall of 2023 I decided to do a little experiment in the height of the “blue check” hysteria. Twitter had shifted from verifying accounts based (more or less) on merit or importance and instead would let users pay for a blue checkmark. That obviously went (and still goes) badly. Meanwhile, Meta opened its own verification service earlier in the year, called Meta Verified.

Mostly aimed at “creators,” Meta Verified costs $15 a month and helps you “establish your account authenticity and help[s] your community know it’s the real us with a verified badge." It also gives you “proactive account protection” to help fight impersonation by (in part) requiring you to use two-factor authentication. You’ll also get direct account support “from a real person,” and exclusive features like stickers and stars.

Read more