Vitalik Buterin
@vitalik.eth
Finally got back my T-mobile account (yes, it was a sim swap, meaning that someone socially-engineered T-mobile itself to take over my phone number).
48 replies
75 recasts
388 reactions
Vitalik Buterin
@vitalik.eth
Main learning re twitter was: > A phone number is sufficient to password reset a Twitter account even if not used as 2FA. Can completely remove phone from Twitter. I had seen the "phone numbers are insecure, don't authenticate with them" advice before, but did not realize this
10 replies
11 recasts
65 reactions
Steve
@stevehere.eth
https://twitter.com/settings/account/login_verification 'Authentication app' or 'Security key' should be the only 2 options there. So far have had no troubles with using my 2fa app.
1 reply
0 recast
0 reaction
Ryan Lackey
@rdl
The issue is no good way to do account recovery for low value accounts at scale and no separation of high value accounts from low value accounts at services like twitter.
1 reply
0 recast
2 reactions
Varun Srinivasan
@v
this as much as i'd like to get rid of phone verification entirely, there's a whole class of people who will then just opt to have no recovery, which is worse
1 reply
1 recast
3 reactions
Ryan Lackey
@rdl
I’ve thought about doing a startup in this space but it isn’t super fun.
0 reply
0 recast
0 reaction