Twitter’s SMS Two-Factor Authentication Is Melting Down

RonSwanson

Honorary Master
Joined
May 21, 2018
Messages
21,582
Reaction score
28,830
Following two weeks of extreme chaos at Twitter, users are joining and fleeing the site in droves. More quietly, many are likely scrutinizing their accounts, checking their security settings, and downloading their data. But some users are reporting problems when they attempt to generate two-factor authentication codes over SMS: Either the texts don't come or they're delayed by hours.

The glitchy SMS two-factor codes mean that users could get locked out of their accounts and lose control of them. They could also find themselves unable to make changes to their security settings or download their data using Twitter's access feature. The situation also provides an early hint that troubles within Twitter's infrastructure are bubbling to the surface.

 

Twitter Two-Factor Authentication Has a Vulnerability - UPDATED​


Update Nov. 18, 2022 1:36 UTC: Information Security Media Group has become aware that another security researcher, @BetoOnSecurity, also identified the ability to turn off Twitter SMS 2FA via a texted "STOP" command as a vulnerability, given the potential for spoofing. Our source independently identified the vulnerability. Twitter's ability to support two-factor authentication via SMS appeared to glitch the day before, generating increased interest in the mechanics of Twitter's SMS 2FA system.

 
Top
Sign up to the MyBroadband newsletter
X