news.volyx.in

FTC fines Twitter $150M for using 2FA phone numbers for ad targeting (ftc.gov)

1362 points by averysmallbird · 1572 days ago · 325 comments on HN

Article summary

Twitter has been fined $150M by the FTC for using 2FA phone numbers for ad targeting. The FTC has also ordered Twitter to provide multi-factor authentication options that don't require a phone number. The fine and order are intended to protect consumers from misuse of their personal data. The incident has sparked a discussion about the use of 2FA and data privacy.

Main themes

  • 2FA security
  • data privacy
  • ad targeting
  • regulatory action
  • user authentication
  • technological complexity

What commenters say

  • The use of 2FA phone numbers for ad targeting is a serious breach of trust and should result in severe consequences for the company.
  • TOTP is a more secure alternative to SMS-based 2FA, but it can be cumbersome for non-technical users to set up and use.
  • Some services, such as Steam, require the use of a specific authenticator app, limiting user choice and potentially creating security risks.
  • The use of authenticator apps can also raise privacy concerns, as some apps may collect location data or other personal information.
  • Data should be treated as a liability, and companies should prioritize user privacy and security over profit.
  • The FTC's fine and order may set a precedent for future cases involving misuse of personal data, but its applicability may be limited to similar cases.
  • The default 2FA method should be an authenticator app or WebAuthn, rather than SMS, to improve security and reduce the risk of data breaches.
  • The complexity of 2FA systems can be a barrier to adoption, particularly for non-technical users, and simpler solutions are needed to achieve mass adoption.