https://twitter.com/TwitterSafety/status/1197621020229804054
- TwitterSafety
Previously, in fact, right before this announcement, SMS-based verification was the only method supported by Twitter for two-factor authentication. And, to use this method, users should have to register their mobile phone numbers with Twitter.
This strategy posed a threat to the security and integrity of Twitter accounts owing to the risks associated with phone numbers, such as SIM swapping.
This is the same method that triggered the hacking of Jack Dorsey’s Twitter account via SIM swapping a few months ago. Moreover, this method has also caused numerous other high-profile account hacks as well.
Though, the users could enable the use of a security key for authentication. They still needed to have SMS-based 2FA enabled. Hence, the security risks still posed threat to the accounts.
However, after Jack-Dorsey’s account hacking incident, it seems Twitter took the matter seriously to come up with an alternative.
Twitter have also confessed in the previous month about the ‘inadvertent’ use of users’ 2FA numbers for ad targeting. Perhaps, this might be another reason contributing to the new decision.
https://twitter.com/peter_szilagyi/status/1197630898486861824
- peter_szilagyi
https://twitter.com/ThrowTheComp/status/1197623481405448206
- ThrowTheComp
Though, a software engineer at Twitter, Jared Miller, swiftly elaborated on the matter.
https://twitter.com/jcmi/status/1197649884645511168
- jcmi
So, for now, the new feature is in the testing phase. Therefore, the users eager to get rid of this phone number restriction shall have to wait for a few days before the feature becomes fully functional.
Let us know your thoughts in the comments.