Conversation

Replying to and
Twitter doesn't even allow you to use a security key if you don't have app-based 2FA. If you disable app-based 2FA, it disables your security key. They've historically pushed people to use SMS 2FA with TOTP as an additional step. They used to treat TOTP as they do security keys.
2
6
Compare to how companies like Google or even Blizzard have deployed and promoted 2FA. Blizzard gives their users in-game incentives to enable it. Twitter has a mobile app and could make it act as a security key via the hardware keystore. No need for users to buy new hardware.
1
Their choice to force users to buy specialized hardware to use security keys and to disallow using keys without enabling SMS or TOTP. Needing to input a code is a terrible user experience. It's less convenient in addition to being far less secure. SMS has availability issues too.
1
1
Every modern Android phone and iPhone has a secure element and/or TEE with the necessary algorithms and physical confirmation support. Anyone with recent smartphones owns security keys already. A lot of people have multiple phones around usable as backup security keys too.