April 26, 2023 By Jennifer Gregory 2 min read

Customers pay for additional features along with their purchases all the time. You can upgrade a car’s seats from fabric to leather, or pay for more analytics on a marketing automation platform. But the new upcharges for security features on social media accounts have experts concerned about the overall impact on cybersecurity.

Many increasingly wonder whether basic security should be accessible to all users, regardless of whether they pay for it.

Twitter and Meta announce paid features

As of March 20, 2023, only subscribers to Twitter Blue, which is an upgraded account that starts at $8 a month, can use two-factor authentication through text messages. In addition to the security features, Twitter Blue verifies the user’s identity and prioritizes their tweets.

Previously, all users could set their accounts to send a text code for new logins to prevent unauthorized access. Twitter’s blog explained that the decision was made because they have seen phone-number-based 2FA be used — and abused — by bad actors.

Meta also recently announced that its new subscription bundle, Meta Verified, offers impersonation protection for Facebook and Instagram users as part of its paid features. Meta Verified will cost $11.99 on the web and $14.99 on iOS and Android. Other features include a verified badge, increased visibility and human support.

Experts concerned about inaccessibility to security

Because many cyber crimes originate through social media, experts are concerned about the impact of this shift. While all accounts will have basic protection, only users who can afford to pay will have the higher-level protections. Additionally, other users who do not understand the benefits may not opt to subscribe to the premium accounts.

“The thing that strikes me is that security should be baked into everything we do, not a paid-for service,” Charles Henderson, global head of IBM’s X-Force threat management division, told the Washington Post. “It should be on by default.”

To make the issue even more concerning, Twitter Blue is only offered in the U.S., Canada, Australia, New Zealand, Japan, the U.K., Saudi Arabia, France, Germany, Italy, Portugal, Spain, India, Indonesia and Brazil.  This means users simply no longer have access to 2FA without having to use a separate app, which further compromises the cybersecurity of the social media platforms. While the platform plans to expand the premium account to other countries, there is no definitive timeline.

Less security, more risk

Based on these factors, experts predict that limiting security features to premium accounts will increase the overall cybersecurity risk. The effect of fewer users having full protection will affect the overall state of cybersecurity. As fewer social media users have access to additional security features, social media platforms will increasingly become more vulnerable. Because cyber criminals use social media to access other systems as well as personal information, decreased security may have a cumulative effect on cybersecurity overall.

However, the cybersecurity community can work to reduce the overall risk through continued user education. By providing information on other ways to improve security, experts can help users reduce their risk on social media platforms. That will be an important step towards improving global cybersecurity.

More from News

ITG05 operations leverage Israel-Hamas conflict lures to deliver Headlace malware

12 min read - As of December 2023, IBM X-Force has uncovered multiple lure documents that predominately feature the ongoing Israel-Hamas war to facilitate the delivery of the ITG05 exclusive Headlace backdoor. The newly discovered campaign is directed against targets based in at least 13 nations worldwide and leverages authentic documents created by academic, finance and diplomatic centers. ITG05’s infrastructure ensures only targets from a single specific country can receive the malware, indicating the highly targeted nature of the campaign. X-Force tracks ITG05 as…

650,000 cyber jobs are now vacant: How to tackle the risk

4 min read - How far is the United States behind in filing cybersecurity jobs? As per Rep. Andrew Garbarino, R-N.Y., Chairman of the HHS Cybersecurity and Infrastructure Protection Subcommittee, overseas adversaries have a workforce advantage over FBI cyber personnel of 50 to one. His statements were made during a recent subcommittee hearing titled “Growing the National Cybersecurity Talent Pipeline.” Meanwhile, recent CyberSeek data shows over 650,000 cyber jobs to fill nationwide. Given the rising rate of cyberattacks, these numbers are truly alarming. How…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today