{"id":753118,"date":"2013-05-24T14:47:44","date_gmt":"2013-05-24T18:47:44","guid":{"rendered":"http:\/\/betanews.com\/?p=154438"},"modified":"2013-05-24T14:47:44","modified_gmt":"2013-05-24T18:47:44","slug":"stop-twitter-two-factor-verification-can-be-hacked-in-less-than-140-characters","status":"publish","type":"post","link":"https:\/\/mereja.com\/index\/753118","title":{"rendered":"STOP: Twitter two-factor verification can be hacked in less than 140 characters"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" class=\"alignright size-medium wp-image-141443\" title=\"face palm head in hands embarassed\" src=\"https:\/\/i0.wp.com\/betanews.com\/wp-content\/uploads\/2013\/04\/face-palm-head-in-hands-embarassed-200x300.jpg?resize=200%2C300\" alt=\"\" width=\"200\" height=\"300\" \/>Fans of social media were reassured this week as Twitter finally <a href=\"http:\/\/betanews.com\/2013\/05\/22\/twitter-follows-the-flock-introduces-two-factor-authentication\/\" >rolled out<\/a> two-step verification, ostensibly making the service more secure for its millions of customers. This is a feature that other major companies like Microsoft, Google, and Facebook have already implemented and, on the surface, seemed a victory.<\/p>\n<p>Not so fast. Security researchers at F-Secure are taking a closer look and deem the implementation \"not great\". The problem, <a href=\"http:\/\/www.f-secure.com\/weblog\/archives\/00002560.html\" >according<\/a> to Sean Sullivan, is that \"an attacker could use\u00a0SMS spoofing\u00a0to disable 2FA if he knows the target's phone number\".<\/p>\n<p>\"The STOP command removes the phone number from the account -- and that in turn disables Twitter's 2FA\", says Sullivan, who did extensive testing on this.<\/p>\n<p>The problem is this: Twitter uses SMS\u00a0as a way to send and receive Tweets. The social network also makes use of SMS for its new authentication service. However, in a statement BetaNews\u00a0received from Mr. Sullivan, it is pointed out that \"Microsoft uses SMS for 2FA, but Twitter is trying to have its cake and eat it too: social security.\u00a0Twitter added 2FA SMS, but *didn't* adjust how it uses SMS for Tweeting\".<\/p>\n<p>Sullivan went on to also point out that \"Facebook confirms with a code when you add a phone and it shifted focus from posting status messages via SMS a few years ago\". He wraps up his statement by explaining \"Microsoft, Google, and Facebook all have account recovery processes. Twitter has just a password reset page. Nothing else. No security words. Nothing\".<\/p>\n<p>Twitter, in the course of its announcement, points out this feature is a means of paving the way for future security enhancements. Perhaps those will be better implemented than what has rolled out this week.<\/p>\n<p>Image Credit: <a href=\"http:\/\/www.shutterstock.com\/\" >Shutterstock<\/a> \/\u00a0<a id=\"portfolio_link\" href=\"http:\/\/www.shutterstock.com\/gallery-838690p1.html\">Denis Belyaevskiy<\/a><\/p>\n<div class=\"feedflare\">\n<a href=\"http:\/\/feeds.betanews.com\/~ff\/bn?a=Yw89Ra2i34U:Tj4ecjDghGo:qj6IDK7rITs\"><img src=\"http:\/\/feeds.feedburner.com\/~ff\/bn?d=qj6IDK7rITs\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.betanews.com\/~ff\/bn?a=Yw89Ra2i34U:Tj4ecjDghGo:yIl2AUoC8zA\"><img src=\"http:\/\/feeds.feedburner.com\/~ff\/bn?d=yIl2AUoC8zA\" border=\"0\"><\/img><\/a>\n<\/div><img src=\"http:\/\/feeds.feedburner.com\/~r\/bn\/~4\/Yw89Ra2i34U\" height=\"1\" width=\"1\"\/>","protected":false},"excerpt":{"rendered":"<p>Fans of social media were reassured this week as Twitter finally rolled out two-step verification, ostensibly making the service more secure for its millions of customers. This is a feature that other major companies like Microsoft, Google, and Facebook have already implemented and, on the surface, seemed a victory. Not so fast. Security researchers at [&hellip;]<\/p>\n","protected":false},"author":4801,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[4821],"tags":[],"class_list":["post-753118","post","type-post","status-publish","format-standard","hentry","category-news"],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p9NivD-39V4","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/mereja.com\/index\/wp-json\/wp\/v2\/posts\/753118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mereja.com\/index\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mereja.com\/index\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mereja.com\/index\/wp-json\/wp\/v2\/users\/4801"}],"replies":[{"embeddable":true,"href":"https:\/\/mereja.com\/index\/wp-json\/wp\/v2\/comments?post=753118"}],"version-history":[{"count":0,"href":"https:\/\/mereja.com\/index\/wp-json\/wp\/v2\/posts\/753118\/revisions"}],"wp:attachment":[{"href":"https:\/\/mereja.com\/index\/wp-json\/wp\/v2\/media?parent=753118"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mereja.com\/index\/wp-json\/wp\/v2\/categories?post=753118"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mereja.com\/index\/wp-json\/wp\/v2\/tags?post=753118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}