April 26, 2023 By Jennifer Gregory 2 min read

Customers pay for additional features along with their purchases all the time. You can upgrade a car’s seats from fabric to leather, or pay for more analytics on a marketing automation platform. But the new upcharges for security features on social media accounts have experts concerned about the overall impact on cybersecurity.

Many increasingly wonder whether basic security should be accessible to all users, regardless of whether they pay for it.

Twitter and Meta announce paid features

As of March 20, 2023, only subscribers to Twitter Blue, which is an upgraded account that starts at $8 a month, can use two-factor authentication through text messages. In addition to the security features, Twitter Blue verifies the user’s identity and prioritizes their tweets.

Previously, all users could set their accounts to send a text code for new logins to prevent unauthorized access. Twitter’s blog explained that the decision was made because they have seen phone-number-based 2FA be used — and abused — by bad actors.

Meta also recently announced that its new subscription bundle, Meta Verified, offers impersonation protection for Facebook and Instagram users as part of its paid features. Meta Verified will cost $11.99 on the web and $14.99 on iOS and Android. Other features include a verified badge, increased visibility and human support.

Experts concerned about inaccessibility to security

Because many cyber crimes originate through social media, experts are concerned about the impact of this shift. While all accounts will have basic protection, only users who can afford to pay will have the higher-level protections. Additionally, other users who do not understand the benefits may not opt to subscribe to the premium accounts.

“The thing that strikes me is that security should be baked into everything we do, not a paid-for service,” Charles Henderson, global head of IBM’s X-Force threat management division, told the Washington Post. “It should be on by default.”

To make the issue even more concerning, Twitter Blue is only offered in the U.S., Canada, Australia, New Zealand, Japan, the U.K., Saudi Arabia, France, Germany, Italy, Portugal, Spain, India, Indonesia and Brazil.  This means users simply no longer have access to 2FA without having to use a separate app, which further compromises the cybersecurity of the social media platforms. While the platform plans to expand the premium account to other countries, there is no definitive timeline.

Less security, more risk

Based on these factors, experts predict that limiting security features to premium accounts will increase the overall cybersecurity risk. The effect of fewer users having full protection will affect the overall state of cybersecurity. As fewer social media users have access to additional security features, social media platforms will increasingly become more vulnerable. Because cyber criminals use social media to access other systems as well as personal information, decreased security may have a cumulative effect on cybersecurity overall.

However, the cybersecurity community can work to reduce the overall risk through continued user education. By providing information on other ways to improve security, experts can help users reduce their risk on social media platforms. That will be an important step towards improving global cybersecurity.

More from News

Exploring the 2024 Worldwide Managed Detection and Response Vendor Assessment

3 min read - Research firm IDC recently released its 2024 Worldwide Managed Detection and Response Vendor Assessment, which both highlights leaders in the market and examines the evolution of MDR as a critical component of IT security infrastructure. Here are the key takeaways. The current state of MDR According to the assessment, “the MDR market has evolved extensively over the past couple of years. This should be seen as a positive movement as MDR providers have had to evolve to meet the growing…

Regulatory harmonization in OT-critical infrastructure faces hurdles

3 min read - In an effort to enhance cyber resilience across critical infrastructure, the Office of the National Cyber Director (ONCD) has recently released a summary of feedback from its 2023 Cybersecurity Regulatory Harmonization Request for Information (RFI). The responses reveal major concerns from critical infrastructure industries related to operational technology (OT), such as energy, transport and manufacturing. Their worries include the current fragmented regulatory landscape and difficulty adapting to new cyber regulations. The frustration appears to be unanimous. Meanwhile, the magnitude of…

Why the Christie’s auction house hack is different

3 min read - Christie's, one of the world's leading auction houses, was hacked in May, and the cyber group RansomHub has claimed responsibility. On May 12, Christie’s CEO Guillaume Cerutti announced on LinkedIn that the company had “experienced a technology security incident.” RansomHub threatened to leak “sensitive personal information” from exfiltrated ID document data, including names, dates of birth and nationalities. On the group’s dark website, RansomHub claims to possess 2GB of data on “at least 500,000” Christie’s clients from around the world.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today