X (Twitter) 2FA : pourquoi il n’y a pas d’option SMS sur un compte gratuit
Si vous avez cherché la double authentification par SMS sur X sans la trouver, rien n'est cassé. Depuis mars 2023, les SMS sont réservés aux abonnés payants. Voici ce qu'un compte gratuit peut réellement activer, et pourquoi le code de secours compte plus que la méthode elle-même.
Sarah JohnsonYou opened the two-factor settings on X, expected to pick text message because that is what every other site offers first, and it was not there. Nothing is broken and you have not missed a step.
Text-message two-factor on X was restricted to paying subscribers with effect from 20 March 2023. Accounts already using it were given thirty days to move to another method before it was switched off. On a free account today the SMS option is simply not offered.
One honest note on where that comes from, because it is relevant to how much weight to put on it. X's help pages and its company blog both refuse automated requests, so we could not read the original announcement first-hand. The date and the thirty day window are reported consistently by several outlets that are independent of one another, and later coverage still describes the restriction as current. Where we rely on secondary reporting we say so rather than presenting it as settled. The screen that actually binds you is your own: Settings, then Security and account access, then Security, then Two-factor authentication. Whatever that screen offers you is the real answer for your account today.
What a free account can actually turn on
Two methods, and the useful thing to understand is that both of them are stronger than the one you were looking for. This is not a consolation prize.
- An authenticator app. Generates a six digit code that changes every thirty seconds, on your device, with no mobile network involved. Setup takes about two minutes. There is a longer explanation of what the six digit code actually is in our guide to TOTP generators.
- A security key or passkey. Hardware, or a passkey held by your device. This is the strongest option because it is bound to the real address of the site, which means it simply does not work on a convincing copy of the login page. Against phishing it is the only second factor that genuinely holds.
The reason SMS was worth losing is the reason security teams had been arguing against it for years. A text message goes to a phone number, and a phone number can be moved to a different SIM by someone who persuades a mobile operator to do it. Neither an authenticator app nor a hardware key can be redirected that way.
The backup code is the part people skip, and it is the part that locks them out
When you enable either method X shows you a backup code. Write it down somewhere that is not the device you are securing, and somewhere you will still be able to find in a year.
This is not a footnote. In practice the common way people lose an account to two-factor is not losing the phone. It is having no record of the backup code when they eventually do. A lost phone with a saved backup code is a five minute problem. A lost phone without one is a support form with no published response time.
Worth knowing if you buy accounts: on our own X shelf, out of more than nine hundred live listings, backup codes are named in only four. So if you are taking over an account, assume the code does not exist and that you will be generating your own.
What the signs of a compromised account actually look like
Takeovers are rarely dramatic at the start. Four things show up before the obvious damage does, and all four tend to get dismissed as noise.
- A login notification you did not cause. Check it inside the app, not by clicking the link in the email. Those notification emails are a heavily copied phishing template, and the copy is often the actual attack.
- A password reset code you did not request. Somebody knows your address or number and is trying. Do not click anything in it, but do change the password and check your second factor.
- Follows or likes that are not yours. Usually the first visible move on a taken-over account, because it draws less attention than posting does.
- An app in the connected apps list you do not recognise. An authorisation granted through the official flow does not depend on your password and survives you changing it, so this one needs revoking by hand.
One distinction that gets muddled constantly: a restricted or suspended account is not a compromised one. If the platform itself has acted, the route back is different, and that is covered in our guide to restricted and suspended accounts. A drop in reach on its own is not evidence of a break-in, so look for a restriction notice on the account before you start treating it as one.
Sessions and connected apps, which are two different lists
Two-factor protects the front door. It does nothing about a session already open at the back. Both lists live in the same place, under Security and account access.
Sessions are devices currently logged in. There is a control that signs out every session except the one you are using, and it is the reliable way to end access you no longer want. Use it on suspicion; it costs you nothing but logging back in if the suspicion was wrong.
Connected apps are separate authorisations you granted, and they do not end when a session does. A scheduling tool you tried once years ago still holds whatever permission you gave it. Reviewing this list takes a minute and is worth doing once a year.
If the account is one you just took over
Treat every credential that came with it as known to somebody else, because it is. The order here matters more than most guides admit, and getting it wrong is what locks people out of accounts they legitimately own.
- Check you can receive mail at the address on the account before you touch anything. Without that, every later step is a guess.
- Sign out the other sessions. This is the step that actually removes the previous holder, and it is under your control.
- Replace the recovery email and phone number with your own. This is what transfers control. A password protects against future logins; the recovery address decides who can take the account back.
- Then change the password, at which point a verification challenge is no longer a problem, because it arrives with you. The sequence and the things that go wrong in it are covered in changing an X password without locking yourself out.
- Then set up your own second factor, and remove the seller's if one was configured.
A note on what a listing that advertises 2FA is really telling you. On our X shelf roughly seven in ten live listings mention it, and those listings sit right at the middle price for the shelf rather than above it. It is the default, not a mark of quality, and on an account you are taking over it is closer to a chore than a benefit, because somebody else's second factor has to come off before yours goes on. Listings, and what each seller discloses about handover, are on the X account listings page. Two other things worth checking there while you are looking: only a handful of listings mention that the phone number has been removed, and fewer than twenty mention supplying a recovery email at all.
Passwords, briefly, because the boring advice is still right
Reusing a password from another site is what turns somebody else's breach into a working key for this account. A password manager solves that with less ongoing effort than inventing variations does. Length does more work than punctuation: a long passphrase with nothing personal in it beats a short string of symbols you will not remember next month.
Before you call the account secured
- A second factor is on, and it is an authenticator app or a security key, because those are the two a free account can choose
- The backup code is written down somewhere other than the device you just secured
- Every other session has been signed out at least once since you took the account over
- The connected apps list contains nothing you do not currently use
- The recovery email and phone number are yours, and you have confirmed you can receive mail at that address
- The password is unique to this account
X's own help pages are the first-party reference. We could not read them from here, so we are not going to tell you what they say.
