back to article X says passkey reset isn't about a security issue – it's to finally kill off twitter.com

X (formerly Twitter) sparked security concerns over the weekend when it announced users must re-enroll their security keys by November 10 or face account lockouts — without initially explaining why. The cryptic mandate from X Safety on Friday led many to suspect a security breach was behind it. When a platform forcibly rotate …

  1. A Non e-mouse Silver badge

    They're going to have to carry on paying for all the Twitter domains for as long as they exist. They'll never be able to release them back out for someone else to register.

    1. Dan 55 Silver badge
      Go

      If they were silly enough to release it, it would be great if Nitter snapped it up.

      1. DS999 Silver badge

        xcancel is better than nitter (just add "cancel" to the link to x.com) because it uses the same URL format. Seems to have fewer issues than nitter does, or at least did at the time I switched because I was annoyed by nitter not always working properly.

        1. Dan 55 Silver badge

          nitter.net also has the same URL format. You can use LibRedirect browser plug-in to re-direct to xcancel.com or nitter.net.

          xcancel has a problem with my work VPN.

          1. DS999 Silver badge

            Nitter doesn't work right on image links, only if linked to the whole tweet. At least it didn't a year ago, I haven't used it since.

      2. Roland6 Silver badge

        Expect it to be released with an announcement of the humungous saving that will be made, only for those savings never to materialise, just as we see with DOGE.

    2. Dwarf Silver badge

      Just wait

      They will hang onnto it, then once Must has given up on X and is an, er, Ex, X, undoubtably the next sensible person in the chair will just rename it back to twitter again.

  2. heyrick Silver badge

    Hmmm?

    When the Twitter domain stops working, I wonder how much stuff will suddenly point to nothing.

    1. ABugNamedJune

      Re: Hmmm?

      Thank god for Archive.org. There was such a push for multi-platform integration between 2012 and ~2018 that all of the sites from that era are just totally broken from stuff like twitter dropping the twitter domain, and I can only imagine the effort it takes to archive some notable examples of those sites. Oh to be a fly on the wall watching historians try to detangle it all in a hundred years or so.

      (past 2018 it's not that there was less of a push for multi-platform integration, it's just that Facebook, Twitter, Amazon etc. decided that there should be no other platforms than theirs :/ )

      1. Valeyard

        Re: Hmmm?

        Thank god for Archive.org

        you say that as if there'd be any great loss if twitter or indeed X stopped existing

  3. Joe Dietz

    I'm all for getting rid of passwords, but passkeys != security

    Passkeys have security value because it stops password reuse across domains and eliminates the need to write them down if I didn't and forces the attacker to shift tactics. But stopping credential theft outright, not as much.

    For years now attacks have shifted focused on post-authentication credentials. It doesn't matter at all how you authenticate an account if you leave the resulting shared secret lying about on your local device waiting for somebody to drop by and read it/use it. OAuth tokens are particularly bad here because they are frequently not validated against other factors like the sending host (or even if they are, clever reverse proxies are not that unheard of), or even password resets (looking at YOU Gmail password resets!), have a long lifespan (again Google) and are frequently renewable (Google).

    1. Former Certificate Authority CTO

      Re: I'm all for getting rid of passwords, but passkeys != security

      Your subject title discounts passkeys and then the body of your comment states all the reasons why passkeys are better. Which one is it? Passkeys still have problems but if you are concerned with security get a Yubikey.

  4. Tron Silver badge

    Long, unique passwords are fine.

    Passkeys are just more of a fiddle, exclude more people/tech/vendors and offer a new point of failure/hacking option.

  5. James O'Shea Silver badge

    it's fine until it stops working

    "Microsoft has long told customers they won't have the option to forgo the passwordless push,"

    One of my cousins has a Mac, and MS Office. Over the weekend, he got a message from his personal OneDrive that he needed to sign in. Except that there was a problem: the password did NOT unlock OneDrive. He got an error message (8004de44, he called me to fix the damn thing) and a request for a 'security key' (the Mac doesn't have a fingerprint reader) and could not activate. Changing the password made no difference. He could access OnDrive in his web browser, just as he could access his MS account, and MS Office; he had a OneDrive Business account, which works. MS 'support' were less than helpful. The personal OneDrive works on a Windows machine and on an iPad as well as in Firefox, Brave, and Vivaldi. Apple support said that this is an MS problem, not theirs, especially as it works on the iPad.

    In Ye Olden Daze of just passwords there would have been no problem. Probably.

  6. gormful

    "Passwords can be, and all too often are, stolen through various means."

    I'd rather use passwords than a security token. Misplacing my all-eggs-in-one-basket token would keep me from accessing *anything* on the Internet. It's like losing your wallet, and having to replace *all* of your credit and ID cards, but worse. Having *one* of my randomly-generated passwords (say, for an e-commerce site) compromised seems to be lower impact overall.

  7. Blackjack Silver badge

    Whwt happens if someone buys the twitter.com domain once it expires?

    1. I am David Jones Silver badge

      I think for a fiver a year they’ll probably keep it on their books…

    2. VicMortimer Silver badge

      Same thing that happens to other expired domains - porn site.

  8. Anonymous Coward
    Anonymous Coward

    If passkeys = providing a mobile phone number

    Then.

    No

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon