NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Chris Keall: Privacy Commissioner gives Twitter the bash - but Elon Musk actually has a point on two-factor authentication

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
21 Mar, 2023 04:28 AM9 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

The alleged man behind mass drug shipment appears in court, the Government’s plans to slash driving in Auckland and Donald Trump anticipates arrest in the latest New Zealand Herald headlines. Video / NZ Herald
Chris Keall
Opinion by Chris Keall
Chris Keall is the technology editor and a senior business writer for the NZ Herald.
Learn more

OPINION:

Twitter is disabling a key security precaution this week - one designed to make it harder for scammers to hijack your account.

Unless you shell out $19 per month for Twitter Blue, you’ll lose access to 2FA (two-factor authentication) by SMS - or a text message sent to your phone - either every time you log on or, selectively; for example, when you (or a baddie) tries to sign in to your Twitter account from a new device.

It’s true the move will save new owner Elon Musk around US$60 million per year (by his own count) - the money his firm paid to phone companies to send authentication texts. But Musk also argues that 2FA by text is prone to exploitation by bad actors (more on which shortly).

Use of free authentication apps for 2FA will remain free and are much more secure than SMS https://t.co/pFMdxWPlai

— Elon Musk (@elonmusk) February 18, 2023
Advertisement
Advertise with NZME.

Regardless, the Office of the Privacy Commissioner took a swipe at Musk on Wednesday with a release titled “Getting flipped by the bird”.

“The free and easy SMS two-factor authentication (2FA) to log into your Twitter account ends today,” the OPC said.

“That concerns Privacy Commissioner Michael Webster because it takes away one of the most common ways to verify who users are on their free accounts, which puts their privacy at risk.

“All social media platforms have a responsibility to their users in New Zealand and operate here under the Privacy Act... my office deals with privacy breaches daily... it is disappointing to see a readily-accepted, free, easy to use, and easy-to-understand verification step is being taken out of a platform that people enjoy using.”

Advertisement
Advertise with NZME.

Paul Brislen, head of the Telecommunications Forum has posted that “2FA is your friend” - but also “use an authenticator not text message to access it”. 2FA by text is convenient - but the text message system was not designed for it.

And the New York Times’ technology correspondent Brian Chen wrote: “Twitter’s announcement of this change was initially confusing and alarming for many. But to be clear, Twitter is pushing users to adopt stronger safeguards - and it has created an opportunity for us all to bite the bullet and improve the security of our online accounts.”

Discover more

Banking and finance

'Imposter' bank scam warning on dodgy term deposit offers

20 Mar 04:37 AM
Business

Twitter breaks with barrage of new problems soon after new Elon Musk job cuts

06 Mar 06:29 PM
Technology

Elon Musk apologises after mocking disabled employee laid-off at Twitter

08 Mar 02:09 AM

Both Brislen and Chen use a code sent by Google’s (free) Authenticator app as what they say is a safer alternative to 2FA by text (see instructions below).

The Privacy Commissioner did not immediately respond to a query over whether Musk had a point that app-based authentication is safer.

But his original release addressed that point by saying 2FA by text is “free, easy to use, and easy to understand... Twitter said they have taken this step because they had seen phone-number-based two-factor authentication abused. But we are still seeing major institutions that are internet-safety-aware use SMS two-factor authentication”.

Maybe so, but their customers aren’t using it. Going by figures in a 2021 Twitter security report, only 2.6 per cent of Twitter accounts had any form of 2FA enabled (of that subset, 74.4 per cent used SMS as their 2FA, 28.9 per cent used an authenticator report and 0.5 per cent used a security key - which involves plugging in a USB key).

I asked if the Privacy Commissioner had put his concerns to Twitter. A spokesperson said his office did not have a contact at Twitter (where Musk has culled nearly all comms staff and many internet safety and regulatory roles, as part of his push to halve the firm’s workforce). The spokesperson noted that “Musk has said that any inquiries about this are being sent the poo emoji”. The Musk-era Twitter is also snubbing Netsafe.

‘Odd thing’

The Privacy Commissioner’s stance does have support from a leading academic.

Advertisement
Advertise with NZME.

“Text-based 2FA does have some potential issues. Basically, someone could access your phone or convince the provider to swap the number,” said David Parry, dean of the School of IT at Western Australia’s Murdoch University (and until recently head of computer science at AUT).

“However, this is pretty low-risk for Twitter since it’s not used for sending cash. So getting rid of it seems like an odd thing to do and would reduce security overall,” he said.

“This will make it harder for normal users to use 2FA at all, which is not good. Security measures are always a tradeoff between convenience and protection - and SMS 2FA seems reasonable for Twitter.”

Parry says it will drive revenue for Twitter if more people pay $19 per month for verification (which will let them keep text-based 2FA), and increase the marketability of Twitter Blue. At the same time, the move would reduce Twitter’s payments to telcos for text-based SMS.

The Privacy Commissioner also gets backing from Auckland University Computer Science Department senior lecturer Dr Rizwan Asghar, who says: “If Musk thinks that phone-number based 2FA can be abused by bad actors then why are they offering it to Twitter Blue subscribers, who actually deserve better security services in my opinion?”

Asghar adds: “Using phone-number-based 2FA is offered by millions. I think Twitter should take a step forward to mitigate issues that result in potential abuses instead of stopping it.”

What is 2FA - and why is authentication via an app better?

“Currently many companies use text messages for two-factor authentication (2FA), which is a great way to prove you are who you say you are. Not only do you know the username and password to the service but you also have that person’s phone and can enter a secret code the bank or service provider sends to you,” Brislen explains.

“While someone might have access to your username and password without you being aware, it’s highly unlikely they’ll also have access to your mobile device, making them an ideal way to provide authentication.

Twitter is getting scammed by phone companies for $60M/year of fake 2FA SMS messages

— Elon Musk (@elonmusk) February 18, 2023

“But text messages were never designed with this kind of security element in mind. Sure, they’re encrypted, but many of us have our phones set so urgent messages pop up on the home screen, which means anyone can see them. That’s great for convenience but not so good for security.

“Enter the Authenticator - an app from a third-party provider (mine is from Google but there are others) that provides a rolling screen of authentication codes linked to various accounts. These codes are synchronised with each provider I’ve signed up to, so instead of waiting for a text message I just log on to the app and get them from there. No messages to intercept, no home screen issues, no loss of convenience but much higher levels of secrecy.

“Marketing departments are going to have to make the leap from the exciting world of email and text message spam to a more secure environment to protect their customers. It’s not impossible but it will need a lot of retraining for marketing teams and customers alike. But when you compare that with our current system that allows fake emails, text message scams and increasing fraud, it’s something that we need to do sooner rather than later.”

No 2FA perfect

“No single method of online authentication is perfect, but two-factor authentication remains a great way to quickly boost the security of online accounts - even by text. Cybercriminals have used certain phishing messages to work their way around 2FA login processes. Like most online activities, there are ways that criminals can bypass 2FA security and access your account. For example, lost password recovery usually resets your password via email, and it can completely bypass 2FA,” Norton managing director, ANZ Mark Gorrie said.

“But what is important for Kiwis to understand is the extra step to access an account means thieves have more work to do to successfully breach an account. Even sophisticated cybercriminals look for easy targets and having 2FA enabled makes [cybercriminals] harder work. Norton recommends that you turn on two-factor authentication. Even though it’s not 100 per cent secure, 2FA can bolster your cybersecurity and is a recommended practice.”

Losing your phone - or switching to a new one - can be a hassle

Chen noted: “The big downside to using authenticators is that if you lose your phone or switch to a new one, it can be a pain to regain access to your accounts. Typically a site or app like Twitter will let you regain access to your account with a back-up code. In Twitter’s two-factor authentication settings, one menu labelled ‘back-up codes’ will generate a code to let you log back in. Make sure to jot this code down and store it in a safe place.

“This technique takes some time and mental bandwidth to set up properly and get used to, but it’s better overall. It’s much tougher for someone to hijack your device to see your security codes than it is to intercept a text message.”

Getting started with an authenticator

  • The Times’ Chen notes there are a number of authenticator apps, but uses Google Authenticator as an example.
  • First, download the Google Authenticator app onto your phone (it’s available via Apple and Google’s app stores, for iPhone or Android). Then, on Twitter.com from a computer, click More→Security and Account Access→Two-Factor Authentication→Authentication App.
  • From here, follow the steps on Twitter. You’ll be asked to use the Authenticator app to scan a QR code with your phone camera, which will link the app with your Twitter account and start generating security codes.
  • When you log in to Twitter, you’ll enter your username and password and then open the Authenticator app to find the temporary code.

If you want to use your iPhone’s built-in two-factor authenticator specifically with Twitter, here’s what you need to do. In the Twitter app, tap on your profile icon in the top-left and then go to Settings and Support > Settings and privacy > Security and account access > Security > Two-factor authentication.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Markets|shares

Market close: Interest rate-sensitive stocks drive NZ sharemarket higher

02 Jul 06:26 AM
Business

Eric Watson's bid to stymie insider trading charges thrown out

02 Jul 05:48 AM
Retail

‘We absolutely got this wrong and we're sorry’: The Warehouse responds to ad criticism

02 Jul 05:06 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Market close: Interest rate-sensitive stocks drive NZ sharemarket higher

Market close: Interest rate-sensitive stocks drive NZ sharemarket higher

02 Jul 06:26 AM

Expectations of interest rate cuts helped push NZ stock values up.

Eric Watson's bid to stymie insider trading charges thrown out

Eric Watson's bid to stymie insider trading charges thrown out

02 Jul 05:48 AM
‘We absolutely got this wrong and we're sorry’: The Warehouse responds to ad criticism

‘We absolutely got this wrong and we're sorry’: The Warehouse responds to ad criticism

02 Jul 05:06 AM
Premium
Film producer declared bankrupt after leaky Auckland penthouse dispute

Film producer declared bankrupt after leaky Auckland penthouse dispute

02 Jul 04:00 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP