Instagram Announces Support for Two-Factor Authentication Apps and Streamlined Account Verification

by

Instagram today announced several new security enhancements that are being implemented to make the social network safer for all users.

Starting soon, Instagram is implementing support for third-party authenticator apps, which will allow them to be used for two-factor verification purposes in lieu of a phone number.

Instagram has supported two-factor authentication for some time, but it was tied to a phone number and required users to receive text messages, which has proven to be insecure and left some Instagram users vulnerable to SIM hacking.


SIM hacking is a method hackers use to gain access to a person's phone number, using it to get into high-profile social media accounts. Some instagram accounts with short handles are valuable and have been stolen through this method, something a third-party authenticator app can protect against.

Instagram says that users can go to the Settings section of the Instagram app, choose Two-Factor Authentication, and then select "Authentication App" to implement two-factor authentication that does not involve a phone number.

Support for third-party authenticator apps is rolling out and will be available globally "in the coming weeks."

Along improved two-factor authentication, Instagram is also enhancing security through a new "About This Account" section that will be added to high-profile Instagram accounts. This feature will allow users to see more information about accounts that reach large audiences, allowing users to "evaluate the authenticity of the account."

To see more about an Instagram account, users can tap on a profile, tap the hamburger menu option and then select "About This Account." Information displayed will include the date the account joined Instagram, the country where it is located, recent username changes, and ads the account is running.

Starting in September, people who have accounts that reach large audiences will be able to review the information that will be available, and after that, the feature will roll out worldwide.

Instagram also plans to make it easier for Instagram users to earn a blue verified badge that lets people know an account is the "authentic presence of a notable public figure." Verification has been available on Instagram, but prior to now, there was no streamlined process for requesting account verification.

To be verified, an account must comply with Instagram's Terms of Service and Community Guidelines. We will review verification requests to confirm the authenticity, uniqueness, completeness and notability of each account. Visit the Help Center to learn more about Instagram's verification criteria.

Instagram users who want to apply for verification can do so by accessing the Settings app and choosing "Request Verification." Username, full name, and a copy of legal or business identification will be required. Like the other features announced today, the verification option is rolling out to users but could take some time to show up for everyone.

Top Rated Comments

(View all)
Avatar
28 months ago
Wonder what they consider "large accounts". Nearly every one of my accounts has over 20k followers, with most well over 100k. Certainly the +100k will be considered large but I wonder what the cutoff is on the lower end.
[doublepost=1535478415][/doublepost]

Never understand authentication apps. I was using one for a while for 3 accounts. Got a new iPhone installed the app and it was reset. Lost 3 accounts because I couldn’t get back into them. For the average user phone number should be more than enough. I mean seriously who the hell is going to hack my SIM card. Come on.... I can see a use for it for users not wanting to hand over their phone number to shady services but maybe you shouldn’t be using those services anyway, just a thought.

Just last week several apps made headlines for being hacked through SIM exploitation. This type of news (that Mac Rumors also publishes) puts these apps in the spotlight, necessitating moves like this from Instagram, Twitter, and others.

The fact that we're seeing accounts exploited this way is a great indicator that these additional measures are needed.
Score: 2 Votes (Like | Disagree)
Avatar
28 months ago

Wonder what they consider "large accounts". Nearly every one of my accounts has over 20k followers, with most well over 100k. Certainly the +100k will be considered large but I wonder what the cutoff is on the lower end.
[doublepost=1535478415][/doublepost]

Just last week several apps made headlines for being hacked through SIM exploitation. This type of news (that Mac Rumors also publishes) puts these apps in the spotlight, necessitating moves like this from Instagram, Twitter, and others.

The fact that we're seeing accounts exploited this way is a great indicator that these additional measures are needed.

I have 8k and I got the notification about being a high-reach account
Score: 2 Votes (Like | Disagree)
Avatar
28 months ago

I frankly don't understand why important features like this are "rolling out in coming weeks" as opposed to now.

Facebook (and Instagram as part of it) are so huge that they don't roll out new features all at once. Instead, they roll out to smaller areas at a time. This allows them to be sure things are working correctly before continuing to push new features out to everyone. It's a smart way to do things.

If you've ever wondered (or are one of those that gets upset) about Facebook, Instagram, and others who release new updates to their apps every week and just have "Bug fixes and other updates." in the release notes, these updates are what add the ability to push those new features. They don't want to announce those new features in the update because then they can't roll them out gradually. You'd have a bunch of people complaining "WHY ISN'T IT WORKING ON MINE!!!! ‽??!!"
Score: 2 Votes (Like | Disagree)
Avatar
28 months ago

Google Authenticator doesn't have the recovery code in all cases. I remember having to guess whether wiping and restoring my phone from a backup would save it... turns out it does but only if I encrypt my backup. This kind of thing can't be left undocumented!

Not the authenticator, the service you’re using it for. If you use an authenticator app for gmail, you get recovery codes, same with Dropbox, Facebook, and others.


Being pedantic, if there is a recovery code, technically it's 1-factor auth and not 2. But still safer because you'll likely keep that code more securely than you would a password.

It’s still 2 factors.
Factor 1: your password
facror 2: the one time password OR the recovery code.
Score: 1 Votes (Like | Disagree)
Avatar
28 months ago

Never understand authentication apps. I was using one for a while for 3 accounts. Got a new iPhone installed the app and it was reset. Lost 3 accounts because I couldn’t get back into them. For the average user phone number should be more than enough. I mean seriously who the hell is going to hack my SIM card. Come on.... I can see a use for it for users not wanting to hand over their phone number to shady services but maybe you shouldn’t be using those services anyway, just a thought.

You can switch the Google Authenticator app from phone to phone. Just follow the process on the Google Authentication webpage to transfer everything over to the new phone and it'll work just fine.
[doublepost=1535482405][/doublepost]

Wonder what they consider "large accounts". Nearly every one of my accounts has over 20k followers, with most well over 100k. Certainly the +100k will be considered large but I wonder what the cutoff is on the lower end.

Well, that answers my question. Logged into one of my accounts and got this message for "high engagement accounts like yours."

Score: 1 Votes (Like | Disagree)
Avatar
28 months ago

While you aren't wrong, features like two factor isn't something most people use (they should but they don't). More people pay attention to new features on a launch date. And if the feature cannot be used, they tend to be forgotten.

And besides, Instagram's parent company Facebook had TOTP authentication for years. While things can always go wrong and rolling out in phases is safer, I think Instagram is taking more precaution than is warranted.

Also, let's not forget that some big companies, such as Apple, roll out major features to everyone on day 1.

It's not like this change is making major news. Most will never see this announcement on sites like this.

Instagram is already putting announcements within the app and they'll likely add a Story about it too when it rolls out to those chosen users.



I'll be surprised if they don't prompt users to enable it when it becomes available to them too.
[doublepost=1535495722][/doublepost]

Interesting! Did you get the notification recently?

I got the above notification the most recent time I opened the Instagram app.
Score: 1 Votes (Like | Disagree)

Top Stories

Early iPhone 12 Tests Show Ceramic Shield is Stronger and More Scratch Resistant Than iPhone 11 Glass

Friday October 23, 2020 1:21 pm PDT by
Apple's new iPhone 12 models are protected by a Ceramic Shield cover glass that has nano-ceramic crystals infused right into the glass to improve durability. According to Apple, Ceramic Shield offers four times better drop protection than the glass used for the iPhone 11 models. YouTube channel MobileReviewsEh conducted some tests on the iPhone 12 using a force meter to compare its performance ...

iPhone 12 Pro Allows You to Measure Someone's Height Instantly Using LiDAR Scanner

Saturday October 24, 2020 11:12 am PDT by
iPhone 12 Pro models feature a new LiDAR Scanner for enhanced augmented reality experiences, but the sensor also enables another unique feature: the ability to measure a person's height instantly using the Measure app. You can even measure the seated height of a person in a chair, according to Apple. When the Measure app detects a person in the viewfinder, it automatically measures their...

Google Reportedly Pays Apple $8-12 Billion Per Year to be Default iOS Search Engine

Sunday October 25, 2020 2:59 pm PDT by
The United States Justice Department is targeting a lucrative deal between Apple and Google as part of one of the U.S. government's largest antitrust cases, reports The New York Times. On Tuesday, the Justice Department filed an antitrust lawsuit against Google, claiming the Mountain View-based company used anticompetitive and exclusionary practices in the search and advertising markets to ...

Apple References Unreleased 2020 16-Inch MacBook Pro in Boot Camp Update

Monday October 26, 2020 8:42 am PDT by
Last week, Apple released an update for Boot Camp, its utility for running Windows on a Mac. While this update would typically be unremarkable, several of our readers noticed that the release notes reference an unreleased 2020 model of the 16-inch MacBook Pro. While this could easily be a mistake, the 16-inch MacBook Pro is nearly a year old, so it is certainly a worthy candidate for a...

Apple Warns MagSafe Charger Can Leave Circular Imprints on Leather Cases

Friday October 23, 2020 3:23 pm PDT by
If you keep your iPhone in a leather case while charging with Apple's new MagSafe Charger, the case might show circular imprints from contact with the accessory, according to a new Apple support document published today. Apple's leather cases for the iPhone 12 and iPhone 12 Pro are not available until November 6, but a MacRumors reader has already shared a photo of a circular imprint on...

iPhone 11 Pro Outlasts iPhone 12 and 12 Pro in Extensive Battery Life Test

Friday October 23, 2020 8:36 am PDT by
Arun Maini today shared a new side-by-side iPhone battery life video test on his YouTube channel Mrwhosetheboss, timing how long the new iPhone 12 and iPhone 12 Pro models last on a single charge compared to older models, with equal brightness, settings, battery health, and usage. All of the devices are running iOS 14 without a SIM card inserted. In the test, the iPhone 11 Pro outlasted both ...

PSA: Non-iPhone 12 Models Charge Super Slowly With MagSafe Charger

Friday October 23, 2020 4:11 pm PDT by
Alongside the iPhone 12 models, Apple introduced a new $39 MagSafe Charger that's meant to work with the magnets in the iPhone 12 Pro models to charge them up at a maximum of 15W. The MagSafe Charger is technically able to be used with older iPhones, but it's not a good idea because the charging with non-iPhone 12 devices is so slow. We did two tests with the iPhone XS Max, draining the...

MagSafe Charger Teardown Reveals Simple Design With Magnets and Charging Coil Encircling a Small Circuit Board

Friday October 23, 2020 7:50 am PDT by
iFixit has today shared a teardown of Apple's new MagSafe charger for the iPhone 12 and iPhone 12 Pro. An X-ray of the MagSafe charger courtesy of Creative Electron reveals the internal charging coil surrounded by a circular arrangement of magnets within the puck. The only seam that iFixit was able to leverage to open the device was where the white rubber circle meets the metal rim,...

Apple VP Kaiann Drance Interview Addresses Battery Life, MagSafe, and Power Adapter Concerns

Friday October 23, 2020 3:37 am PDT by
Apple's Vice President of iPhone Marketing, Kaiann Drance, has provided a new interview to Rich DeMuro on the Rich on Tech Podcast, to discuss the iPhone 12 and iPhone 12 Pro. Although much of the interview repeated points from Apple's "Hi, Speed" event, there were a number of interesting tidbits regarding the affect of 5G on battery life, MagSafe concerns, and the lack of a power adapter in...

iFixit Shares Full iPhone 12 and 12 Pro Teardown Revealing Interchangeable Displays and Batteries

Saturday October 24, 2020 1:48 pm PDT by
After live streaming a teardown of the iPhone 12 and iPhone 12 Pro earlier this week, iFixit today provided a more in-depth teardown that goes through all of the components in the new devices, revealing several similarities between the two. Early testing conducted by iFixit shows that the iPhone 12 and 12 Pro displays are interchangeable and can be swapped without issue, though the max...