Vitalik Buterin pfp
Vitalik Buterin
@vitalik.eth
Finally got back my T-mobile account (yes, it was a sim swap, meaning that someone socially-engineered T-mobile itself to take over my phone number).
48 replies
75 recasts
388 reactions

Vitalik Buterin pfp
Vitalik Buterin
@vitalik.eth
Main learning re twitter was: > A phone number is sufficient to password reset a Twitter account even if not used as 2FA. Can completely remove phone from Twitter. I had seen the "phone numbers are insecure, don't authenticate with them" advice before, but did not realize this
10 replies
11 recasts
65 reactions

Steve pfp
Steve
@stevehere.eth
https://twitter.com/settings/account/login_verification 'Authentication app' or 'Security key' should be the only 2 options there. So far have had no troubles with using my 2fa app.
1 reply
0 recast
0 reaction

Ryan Lackey pfp
Ryan Lackey
@rdl
The issue is no good way to do account recovery for low value accounts at scale and no separation of high value accounts from low value accounts at services like twitter.
1 reply
0 recast
2 reactions

Varun Srinivasan pfp
Varun Srinivasan
@v
this as much as i'd like to get rid of phone verification entirely, there's a whole class of people who will then just opt to have no recovery, which is worse
1 reply
1 recast
3 reactions

Ryan Lackey pfp
Ryan Lackey
@rdl
I’ve thought about doing a startup in this space but it isn’t super fun.
0 reply
0 recast
0 reaction