Skip to content
by
  • Products
  • Free Tools
  • Search
  • Free Sophos Home
XG Firewall
Next-Gen Firewall
Intercept X
Next-Gen Endpoint
  • Sophos Cloud Optix
  • Sophos Central
  • Sophos Mobile
  • Intercept X for Server
  • Secure Wi-Fi
  • Phish Threat
  • SafeGuard Encryption
  • Secure Email
  • SG UTM
  • Secure Web Gateway
For Home Users

Sophos Home protects every Mac and PC in your home

Learn More
Free Security Tools
Free Trials
Product Demos
Have you listened to our podcast? Listen now

Why Twitter’s two-factor authentication isn’t going to stop media organisations from being hacked

23 May 2013 6 Mobile, Phishing, Privacy, Twitter

Post navigation

Previous: NYPD detective charged with hiring email hackers to break into colleagues’ personal accounts
Next: Cyber security in US power system suffering from reactive, self-policed rules
by Graham Cluley

Twitter has announced the availability of two factor authentication (2FA) for its service, meaning that users can opt-in to something stronger than just a username and password to protect their accounts.

Twitter login code

In a blog post, Twitter explains how the new security measure works.

If you decide to turn 2FA on for your Twitter account, every time you try to log into the site you will be prompted to enter a six-digit code that Twitter sends to your phone via SMS.

Here is a video Twitter released, demonstrating the feature:

So, the big question is this… is this going to help media organisations such as The Guardian, NPR, the Financial Times, and others who have found their Twitter accounts hijacked by the likes of the Syrian Electronic Army?

Sadly, I don’t think it’s going to help them at all.

Media organisations who share breaking news via social media typically have many staff, around the globe, who share the same Twitter accounts.

2FA isn’t going to help these companies, because they can’t all access the same phone at the same time.

Either those people will have to leave themselves permanently logged into Twitter (which is itself unwise from the security perspective), or one central trusted person will have to “own” the phone – and share the six-digit code with journalists as they try to log in to share breaking news stories.

Twitter verification

It’s a complex problem to fix, and for that reason many media organisations may choose not to enable Twitter’s additional security at this time.

Of course, *another* solution would be to have an intermediary service, acting as a proxy, to which journalists could post their Twitter updates (using appropriate authentication) and then have *that* service feed the official Twitter account.

If you take that approach, just ensure that you have proper security systems in place for that proxy service – to keep out hackers and mischief-makers.

Corporations with “shared accounts” on Twitter would be wise to keep their defences updated, educate their staff on security and best practice, and learn the lessons of how Twitter accounts have been hacked in the past.

If you do enable Twitter two-factor authentication, whether you are Joe Public or a multinational corporation, realise that the technology isn’t going to help if you have users who are easily phished.

Determined online criminals could use “man-in-the-middle” techniques to grab the six digit passcode alongside your password and username if they are determined.

So, even if you do turn on Twitter’s 2FA, you still need to double-check that when you enter your username and password, or your six digit code, that you are *really* on Twitter’s https website.

HTTPS on Twitter's website

Otherwise, the crooks can just use all three items to log in as you…

In time, Twitter will surely mature and offer appropriate security, and mechanisms which recognise how many corporate brands and news organisations are using Twitter today.

Maybe they will one day adopt a system like Facebook has, where multiple users can have access to an account – all with different levels of authority, all with different usernames and passwords.

Right now Twitter’s 2FA is more likely to be welcomed by individuals who own personal accounts, and small companies with a Twitter presence, than embraced by the high profile victims attacked by the Syrian Electronic Army in the past.

  • Follow @NakedSecurity on Twitter for the latest computer security news.

  • Follow @NakedSecurity on Instagram for exclusive pics, gifs, vids and LOLs!

Free tools

Sophos Firewall Home Edition

Boost your home network security.

Sophos Scan & Clean

Free second-opinion scanner for PCs.

Sophos Cloud Optix

Monitor 25 cloud assets for free.

Post navigation

Previous: NYPD detective charged with hiring email hackers to break into colleagues’ personal accounts
Next: Cyber security in US power system suffering from reactive, self-policed rules

6 comments on “Why Twitter’s two-factor authentication isn’t going to stop media organisations from being hacked”

  1. dougmet says:
    May 23, 2013 at 5:38 pm

    Wish they'd offer Google Authenticator as well (or do what Facebook does and build your own token system into the mobile app). I'm sick of giving companies my phone number.

    Reply
  2. Dave says:
    May 23, 2013 at 8:31 pm

    Why not just have one phone in a central location that all the staff can access (locked drawer idea)? If they had a single token (i.e. RSA) they would have to do the same thing.

    Reply
    • Cameron says:
      May 27, 2013 at 3:04 am

      Because often staff aren't in a central building. They're in the field, or working from home, etc.

      Reply
  3. @banerjek says:
    May 23, 2013 at 9:51 pm

    Seems like it would be easy enough to implement in a corporate environment if they really wanted — all you need is for the phone number that receives the code to forward it to accounts that have access. Annoying, yes, but doable if the number of tweets is modest.

    It's nuts that they actually require you to receive the code via SMS since those out of cell range but with network connections would not be able to tweet unless they have wifi calling. Apps like Google Authenticator are much better in that they can be used on multiple phones and do not require cell reception.

    Reply
  4. artesea says:
    May 24, 2013 at 11:31 am

    Twitter do have a system in which users can tweet from their own accounts on behalf of the company account. However for over a year it appears to be in a closed beta.
    See the API for hints about contributors https://dev.twitter.com/docs/api/1.1/get/statuses…

    Reply
  5. Scott Maxwell says:
    January 14, 2014 at 9:46 pm

    Didn’t work. See google’s announcement today.

    Reply

What do you think? Cancel reply

Recommended reads

Mar14
by Paul Ducklin
6

Firefox 111 patches 11 holes, but not 1 zero-day among them…

Feb20
by Paul Ducklin
6

Twitter tells users: Pay up if you want to keep using insecure 2FA

Feb21
by Paul Ducklin
5

Coinbase breached by social engineers, employee data stolen

  • About Naked Security
  • About Sophos
  • Send us a tip
  • Cookies
  • Privacy
  • Legal
  • Intercept X
  • Intercept X for Server
  • Intercept X for Mobile
  • XG Firewall
  • Sophos Email
  • Sophos Wireless
  • Managed Threat Response
  • Cloud Optix
  • Phish Threat
© 1997 - 2023 Sophos Ltd. All rights reserved. Powered by WordPress VIP