Photo: Jaap Arriens/NurPhoto via Getty Images

Facebook is facing a new wave of criticism for letting users identify individuals by phone number even when they only gave Facebook the number for the purpose of two-factor authentication.

Why it matters: Critics are saying a measure that users take in order to protect their security is instead, in Facebook's hands, exposing their privacy.


  • Two-factor authentication (2FA) is a security measure that helps protect access to user accounts by tying that access not only to a password, but also to a secondary device — often a phone.
  • Reports last year showed that Facebook was already targeting ads based on phone numbers users shared for two-factor authentication.
  • A Twitter thread detailing the latest issue went viral on Sunday.
  • Last year, Facebook blocked users from searching directly for profiles by typing in phone numbers. But Facebook will still link phone numbers and profiles under other circumstances, including when you upload an address book to help Facebook find your friends, users say.
  • Facebook allows you to change a default setting in order to hide your phone number, but even when you do, users have reported that some kinds of searches based on the phone number will still come up with your name.
  • Last year, Facebook began offering alternatives to phone-number based 2FA and no longer requires a phone number.

What they're saying:

  • A Facebook spokesman said in a statement: "The 'Who can look me up?' settings are not new and are not specific to two-factor authentication. ... Today, the 'Who can look me up?' settings control how your phone number or email address can be used to look you up in other ways, such as when someone uploads your contact info to Facebook from their mobile phone. We appreciate the feedback we've received about these settings and will take it into account.”
  • New York Times columnist Zeynep Tufekci said on Twitter: "For years I urged dissidents at risk to use 2FA on Facebook. They were afraid of this. @Facebook doesn't care about their safety."

Go deeper

Updated 7 mins ago - Politics & Policy

Coronavirus dashboard

Illustration: Eniola Odetunde/Axios

  1. Global: Total confirmed cases as of 9 a.m. ET: 19,128,901 — Total deaths: 715,555— Total recoveries — 11,591,028Map.
  2. U.S.: Total confirmed cases as of 9 a.m. ET: 4,884,406 — Total deaths: 160,111 — Total recoveries: 1,598,624 — Total tests: 59,652,675Map.
  3. Politics: Trump floats executive action even if stimulus deal is reached.
  4. Business: U.S. economy adds 1.8 million jobs in July — Household debt and credit delinquencies dropped in Q2.
  5. Sports: The pandemic's impact on how sports are played.
  6. 1 🎮 thing: Video gaming growth soars.

Trump floats executive action even if stimulus deal is reached

Photo: Samuel Corum/Getty Images

The White House is finalizing a series of executive orders addressing key coronavirus stimulus priorities if negotiations with Congress fall apart, and it's leaving the door open for President Trump to use them even if a deal is reached that doesn't encompass all of his priorities, two administration officials tell Axios.

What we’re hearing: “I wouldn't be surprised that, if something gets left off the table, we’d be like ‘we can take this executive action too and be able to win on it anyway,’” one official said.

28 mins ago - Technology

TikTok responds to Trump executive order: "We are shocked"

Photo: Jakub Porzycki/NurPhoto via Getty Images

TikTok said Friday that it was "shocked" by President Trump's executive order that will ban Americans from dealing with ByteDance, its China-based owner, in 45 days.

Why it matters: TikTok argued that Trump's move "risks undermining global businesses' trust in the United States' commitment to the rule of law, which has served as a magnet for investment and spurred decades of American economic growth."