Twitter upgrades two-factor authentication options by allowing third party apps
Full article457 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Twitter users can upgrade in the settings and privacy section of their profiles.
After a decade of prodding, Twitter drastically improved its two-factor authentication on Wednesday, expanding an important security tool widely adopted elsewhere online, including Google and Facebook.
The social media company announced support for apps like Google Authenticator and Authy that work offline, independent of carrier or location and are more resistant to eavesdropping or hijacking. Crucially, users can now turn off SMS authentication for the first time. It’s considered one of the least-secure methods of two-factor authentication.
Two-factor authentication typically works by requiring a password as well as a second method to log in. Commonly used second factors include SMS codes, small pieces of hardware — such as USB keys or dongles — or even biometric authenticators like fingerprints or face scans.
Security experts strongly recommend all users turn on two-factor authentication for important internet accounts including email, banking and social media.
Twitter users can upgrade in the settings and privacy section of their profiles.
https://twitter.com/TwitterSafety/status/943542421698125824
Twitter still lacks support for hardware authenticators like Yubikeys, another tool supported by Facebook and Google among other services.
Hardware authentication dongles are considered more secure by experts but require a purchase and a learning curve. Apps like Google Authenticator are free and still offer significant security benefits for users over Twitter’s previous options.
It wouldn’t be a high-profile rollout without some glitches: Within hours of the new feature’s arrival, some users complained of bugs like Twitter mistakenly removing their entire two-factor setup.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/twitter-upgrades-two-factor-authentication-options/