Twitter transgression proves why its flawed 2FA system is such a privacy trap

Peter Reutemann <[email protected]> Wed, 9 Oct 2019 14:44:16 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12LEamqenT9wjG5+mxrEvMEruJ0pugcYvf1i0XwJ+K0DVA@mail.gmail.com>
'If ever there was a surefire way to sour users against a two-factor
authentication system that was already highly flawed, Twitter has
found it. On Tuesday, the social media site said that it used phone
numbers and email addresses provided for 2FA protection to tailor ads
to users.

Twitter requires users to provide a valid phone number to be eligible
for 2FA protection. A working cell phone number is mandatory even when
users' 2FA protection is based solely on security keys or
authenticator apps, which don't rely on phone numbers to work.
Deleting a phone number from a user's Twitter settings immediately
withdraws account from Twitter 2FA, as I confirmed just prior to
publishing this post.'

-- sources: https://arstechnica.com/information-technology/2019/10/twitter-used-phone-numbers-provided-for-2fa-to-match-users-to-advertisers/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz