Screenshotting your 2FA backup code can put a bypass in your cloud photo sync
eyishazyer · x · 2026-09-19
Two common X account security mistakes, per the author:
- Backup code screenshots: X's help page suggests screenshotting your backup code, but that code logs you in without your phone — and many phones sync screenshots to the cloud, effectively placing a 2FA bypass in your photo backup. Store it in a password manager or on paper instead.
- Weakest method sets the limit: X's login screen lets you pick a different 2FA method than your last one, so your weakest enabled method defines your security. A security key can be your only method; with two keys registered, you should turn off SMS and authenticator.
More from Safety
- Every AI agent needs a human sponsor liable for its actions, argues tech commentator — binarybits · 2026-09-19
- Sovereign AIs may be impossible to regulate, argue researchers — leaving 'nuisance' path open — binarybits · 2026-09-19
- Ex-DOJ antitrust chief Kanter tells Decoder why AI labs don't need an antitrust exemption for safety — The Verge AI · 2026-09-19
- Social engineering, not hacking, is ASI's likeliest escape route from secure labs — ronbodkin · 2026-09-19
- Gary Marcus: Dario picked auditors with ties to Anthropic and hasn't slowed down at all — GaryMarcus · 2026-09-19
- AI-generated video shows famous actress interviewing massacre survivors — blm1973 · 2026-09-19