What the Cybersecurity Community is Saying About SMS Authentication and Password Recovery

Twitter CEO, Jack Dorsey, had his Twitter account info hacked on August 30. This incident has the cybersecurity community wondering if SMS Authentication and sites forcing you to provide a phone number are doing more harm than good.

His phone number was stolen via SIM swapping, where a hacker can bribe or convince a mobile carrier employee to give the phone number over to the hacker’s mobile device. This could allow the hacker to tweet directly to your account by using an old Twitter feature that lets users text 40404, which published a tweet to your account without needing any of your login information.

Vice President Global Communications at Twitter also spoke out on the issue on Twitter.

Cybersecurity blogger, Graham Cluley, posted shortly after stating that Twitter had made an official statement that they would be turning this feature off for all accounts until they could find a solution to this issue. He believes that Twitter will eventually reinstate this feature because there are parts of the world who don’t use smartphones that need this feature to be able to tweet from their mobile devices, but he hopes that the company is now more aware of the implications of it.

You might be thinking, well I’ll just removed my phone number then, but it’s not that simple. If you use two-factor authentication to login, a phone number is required. Brian Krebs, another cybersecurity blogger, suggests getting a Google Voice number for your two-factor authentication across all of your important accounts.

Another major service provider, Facebook, also experienced a breech in which phone numbers were stolen. In Cluley’s blog post about this breech, he includes the statement from Facebook on the breech, and they seem pretty unbothered, stating that this hack happened before they took away the feature that allowed users to find friends via phone number. Facebook claims they saw no evidence of accounts being affected. The only problem here, Cluley states, is that people don’t change their phone numbers very often, so this information could still be used to harm them.

Twitter users have sounded off about the breech as well.

Overall, the cybersecurity community seems to lean towards not recommending using a phone number to “secure” any of your accounts. If you’re anything like me, if someone had access to my phone it would be an absolute disaster. Take it from the experts, and look into some of the recommendations from this post to better protect your info.