Random Image Display on Page Reload

How to Turn Off Facebook’s Two-Factor Authentication Change

Mar 5, 2024 5:28 PM

How to Turn Off Facebook’s Two-Factor Authentication Change

With Meta’s updated 2FA process, the company now automatically trusts devices you often use.

Illustration of a thumbs down

Illustration: Smart/Getty Images

Meta changed how two-factor authentication works for Facebook and Instagram last year. You might have received notifications about this, but it was easy to miss in the platform’s sea of red alerts. OK, so what’s different? “Any devices you’ve frequently used Facebook on in the past two years will be automatically trusted,” reads Meta’s updated settings page. Your smartphone and laptop may not need a 2FA code to log in, unless you go into your settings and opt out.

Over time, Meta has made multiple tweaks to how it deploys 2FA. In 2018, it started to allow 2FA codes generated by third-party apps. A few years later, the company began requiring more vulnerable accounts to activate 2FA protection. The company faces a tricky balance between making it easy to log in to your account and protecting users from losing control of their online identities.

Enabling 2FA is a basic way to improve the security of any online profile, since it adds an extra layer of difficulty for hackers trying to break into your account. “The role two-factor plays is, basically, to assume that at some point your password is going to be known by someone else,” said Casey Ellis, founder and chief strategy officer at Bugcrowd, a crowdsourced security company that has previously collaborated with Facebook. “You don’t have control over when or how that happens.” For users, this fallback measure is often as easy as copying and pasting a quick code from within a smartphone app, like Google Authenticator.

Anyone with a social media account on Facebook or Instagram needs to turn on two-factor authentication in their privacy settings. No shame if you haven’t, but do it right now by logging in to your Account Center, clicking Password and security, then Two-factor authentication.

Now that you’ve got it all set up, here’s what was changed with Meta’s 2FA process: It’s no longer activated anywhere you often used Facebook or Instagram in the past two years, from previous-generation smartphones to hand-me-down laptops.

What’s the reasoning for this adjustment? “As part of our continuous work to balance account security and accessibility, we’re letting people know that we’ll be treating the devices they frequently use to log in to Facebook as trusted,” said Erin McPike, a Meta spokesperson.


Screenshot of a Facebook settings menu
Facebook via Reece Rogers

Want to activate a 2FA check for every device, even where you use Facebook or Instagram the most? While Meta previously offered an option to opt out completely, you now need to manually remove any devices that you don’t want to be trusted. Do this by opening the Account Center, then going to Password and security. You may need to enter your password after choosing Two-factor authentication and the account you want to adjust. Scroll all the way down to the Authorized logins section and choose Recognized devices.

Here you’ll see every device where Meta won’t require a login code. You may be surprised by some of the old devices on the list. While the company claims it’s just for devices you used in the past two years, one option on my trusted list was an iPad accessed all the way back in 2013.


Screenshot of a Facebook settings menu
Facebook via Reece Rogers

Yes, it’s common for social media platforms to trust certain devices for users, and security measures beyond 2FA may continue to provide protection for your account, but the automatic aspect makes experts uneasy. “My immediate security reaction is that it’s going to lock in long-term access to all of those logged-in things,” said Ellis, around the time of the update. Any change that puts more onus on the user to protect their security opens up more opportunities for mistakes and potential breaches.

After you’ve revoked trust for all the random iPads you used forever ago, what else can you do to improve the security for your Meta accounts? Always use a new, complex password. Also, make sure to wipe the data from your dusty smartphones and laptops with a factory reset before selling or otherwise getting rid of them.

Updated 3/5/2024, 5:30 pm EST: Included new details about how Facebook’s 2FA process works for users.

Reece Rogers is WIRED's service writer, focused on explaining crucial topics and helping readers get the most out of their technology. Prior to WIRED, he covered streaming at Insider.
Service Writer

More from WIRED

Russian Hackers Stole Microsoft Source Code—and the Attack Isn’t Over

Plus: An ex-Google engineer gets arrested for allegedly stealing trade secrets, hackers breach the top US cybersecurity agency, and X’s new feature exposes sensitive user data.

Dhruv Mehrotra

Meta Abandons Hacking Victims, Draining Law Enforcement Resources, Officials Say

A coalition of 41 state attorneys general says Meta is failing to assist Facebook and Instagram users whose accounts have been hacked—and they want the company to take “immediate action.”

Dell Cameron

How a Right-Wing Controversy Could Sabotage US Election Security

Republicans who run elections are split over whether to keep working with the Cybersecurity and Infrastructure Security Agency to fight hackers, online falsehoods, and polling-place threats.

Eric Geller

The Privacy Danger Lurking in Push Notifications

Plus: Apple warns about sideloading apps, a court orders NSO group to turn over the code of its Pegasus spyware, and an investigation finds widely available security cams are wildly insecure.

Andy Greenberg

Signal Finally Rolls Out Usernames, So You Can Keep Your Phone Number Private

We tested the end-to-end encrypted messenger’s new feature aimed at addressing critics’ most persistent complaint. Here’s how it works.

Andy Greenberg

How to Not Get Scammed Out of $50,000

Plus: State-backed hackers test out generative AI, the US takes down a major Russian military botnet, and 100 hospitals in Romania go offline amid a major ransomware attack.

Andrew Couts

A Celebrated Cryptography-Breaking Algorithm Just Got an Upgrade

Two researchers have improved a well-known technique for lattice basis reduction, opening up new avenues for practical experiments in cryptography and mathematics.

Madison Goldberg

The UK’s GPS Tagging of Migrants Has Been Ruled Illegal

The UK’s privacy regulator says the government did not take into account the intrusiveness of ankle tags that continuously monitor a person’s location.

Morgan Meaker

*****
Credit belongs to : www.wired.com

Check Also

As AI becomes more human-like, experts warn users must think more critically about its responses

Companies like OpenAI and Google are trying to dominate the quickly emerging market for AI …