The Phone Number You Gave Twitter "For Security" Was Never Just For Security

The Phone Number You Gave Twitter "For Security" Was Never Just For Security

Tech News 2fa advertising ftc privacy twitter

So this happened Wednesday and I've been chewing on it since: the FTC and the DOJ announced Twitter is paying $150 million to settle a case over exactly the thing a bunch of us assumed was happening and got told, repeatedly, was not happening.

Quick version if you missed it. Back in 2011 Twitter signed a consent order with the FTC promising not to misrepresent how it handles your personal data. Fine, standard stuff, every big platform has one of these somewhere. Then from 2013 to 2019, according to the complaint, Twitter asked users for phone numbers and email addresses specifically for account security, two-factor authentication, password reset, that whole bucket, and then turned around and fed that same data into its ad-targeting system so advertisers could match their own customer lists against Twitter users. Over 140 million accounts worth of phone numbers and emails, used for something the company told people it wasn't using them for. That's not a gray area, that's just a lie with a settlement number attached now.

I turned on 2FA on basically every account I own somewhere around 2015, back when it felt like a slightly paranoid thing to do and my one non-tech friend asked why I was "making Twitter harder to use." And even then, typing my actual cell number into that box always came with this tiny flicker of "yeah okay but what's this actually for." Not because I had evidence, just because giving a free ad-supported company your phone number and trusting it stays in a security silo requires a kind of faith I don't have in software companies, and apparently I was right not to have it. I don't get any satisfaction pointing that out, or, okay, a little.

What actually annoys me isn't even the ad targeting, it's the mechanism. Security features are supposed to be the one part of these apps where the incentives are aligned with the user. You give up a phone number, you get a harder-to-hack account, everybody wins. The second a company starts treating that box as just another data field to monetize, it poisons the whole idea of opting into security measures at all. If turning on 2FA quietly enrolls you in ad matching, then the honest move for a lot of people is to not turn on 2FA, which is a genuinely bad outcome for account security industry-wide, not just for one company's numbers.

$150 million sounds like a lot until you remember Facebook paid $5 billion to the FTC back in 2019 over Cambridge Analytica and mostly just kept doing what it was doing with a bigger legal budget afterward. I don't expect this fine changes much about how any of these companies operate day to day. It's the cost of doing business, and the business made way more than $150 million off however many years of that ad matching ran. The settlement also makes Twitter build out a real privacy program with independent assessments, which is the part that might actually matter more than the check, if anyone ever bothers to check the checking.

Practical note, since I know some of you reading this are going to go do something about it today: if you've got 2FA set up with a phone number anywhere, on Twitter or otherwise, moving to an authenticator app (I use Authy, some people swear by a hardware key like a Yubikey) at least gets a number out of a database that has a demonstrated track record of doing something other than what it said with it. It's a bit more setup, maybe fifteen minutes per account if you're doing several at once on a lazy Friday, but it's fifteen minutes you get back the first time you switch phones and don't have to fight a carrier over a SIM transfer either.

None of this touches the other Twitter story everyone's been staring at all month, the one with the buyer and the bot-count argument, and I'm deliberately not getting into that today because everyone else already has, at length, from every angle. This one felt like the smaller, quieter story that actually says more about how these companies treat the data you hand them without thinking twice.