April 26, 2023 By Jennifer Gregory 2 min read

Customers pay for additional features along with their purchases all the time. You can upgrade a car’s seats from fabric to leather, or pay for more analytics on a marketing automation platform. But the new upcharges for security features on social media accounts have experts concerned about the overall impact on cybersecurity.

Many increasingly wonder whether basic security should be accessible to all users, regardless of whether they pay for it.

Twitter and Meta announce paid features

As of March 20, 2023, only subscribers to Twitter Blue, which is an upgraded account that starts at $8 a month, can use two-factor authentication through text messages. In addition to the security features, Twitter Blue verifies the user’s identity and prioritizes their tweets.

Previously, all users could set their accounts to send a text code for new logins to prevent unauthorized access. Twitter’s blog explained that the decision was made because they have seen phone-number-based 2FA be used — and abused — by bad actors.

Meta also recently announced that its new subscription bundle, Meta Verified, offers impersonation protection for Facebook and Instagram users as part of its paid features. Meta Verified will cost $11.99 on the web and $14.99 on iOS and Android. Other features include a verified badge, increased visibility and human support.

Experts concerned about inaccessibility to security

Because many cyber crimes originate through social media, experts are concerned about the impact of this shift. While all accounts will have basic protection, only users who can afford to pay will have the higher-level protections. Additionally, other users who do not understand the benefits may not opt to subscribe to the premium accounts.

“The thing that strikes me is that security should be baked into everything we do, not a paid-for service,” Charles Henderson, global head of IBM’s X-Force threat management division, told the Washington Post. “It should be on by default.”

To make the issue even more concerning, Twitter Blue is only offered in the U.S., Canada, Australia, New Zealand, Japan, the U.K., Saudi Arabia, France, Germany, Italy, Portugal, Spain, India, Indonesia and Brazil.  This means users simply no longer have access to 2FA without having to use a separate app, which further compromises the cybersecurity of the social media platforms. While the platform plans to expand the premium account to other countries, there is no definitive timeline.

Less security, more risk

Based on these factors, experts predict that limiting security features to premium accounts will increase the overall cybersecurity risk. The effect of fewer users having full protection will affect the overall state of cybersecurity. As fewer social media users have access to additional security features, social media platforms will increasingly become more vulnerable. Because cyber criminals use social media to access other systems as well as personal information, decreased security may have a cumulative effect on cybersecurity overall.

However, the cybersecurity community can work to reduce the overall risk through continued user education. By providing information on other ways to improve security, experts can help users reduce their risk on social media platforms. That will be an important step towards improving global cybersecurity.

More from News

Recent CrowdStrike outage: What you should know

3 min read - On Friday, July 19, 2024, nearly 8.5 million Microsoft devices were affected by a faulty system update, causing a major outage of businesses and services worldwide. This equates to nearly 1% of all Microsoft systems globally and has led to significant disruptions to airlines, police departments, banks, hospitals, emergency call centers and hundreds of thousands of other private and public businesses. What caused this outage in Microsoft systems? The global outage of specific Microsoft-enabled systems and servers was isolated to…

White House mandates stricter cybersecurity for R&D institutions

2 min read - Federal cyber regulation is edging further into research and development (R&D) and higher education. A recent memo from the Office of Science and Technology Policy (OSTP) states that certain covered institutions will be required to implement cybersecurity programs for R&D security. These mandates will also apply to institutions of higher education that support R&D. Beyond strengthening the overall U.S. security posture, this move is also in direct response to growing threats posed by the People's Republic of China (PRC), as…

New memo reveals Biden’s cybersecurity priorities through fiscal year 2026

2 min read - On July 10, 2024, the White House released a new memo regarding the Biden administration’s cybersecurity investment priorities, initially proposed in July 2022. This new memorandum now marks the third time the Office of the National Cyber Director (ONCD), headed by Harry Coker, has released updated priorities and outlined procedures regarding the five core pillars of the National Cybersecurity Strategy Implementation Plan (NCSIP), now relevant through fiscal year 2026. Key highlights from the FY26 memorandum In the latest annual version…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today