Article Details

Scrape Timestamp (UTC): 2025-10-27 16:18:03.607

Source: https://thehackernews.com/2025/10/x-warns-users-with-security-keys-to-re.html

Original Article Text

Click to Toggle View

X Warns Users With Security Keys to Re-Enroll Before November 10 to Avoid Lockouts. Social media platform X is urging users who have enrolled for two-factor authentication (2FA) using passkeys and hardware security keys like Yubikeys to re-enroll their key to ensure continued access to the service. To that end, users are being asked to complete the re-enrollment, either using their existing security key or enrolling a new one, by November 10, 2025. "After November 10, if you haven't re-enrolled a security key, your account will be locked until you: re-enroll; choose a different 2FA method; or elect not to use 2FA (but we always recommend you use 2FA to protect your account!)," the company's Safety handle wrote in a post on X. The move is part of the company's efforts to formally retire the twitter[.]com. Twitter, which was acquired by SpaceX and Tesla CEO Elon Musk in October 2022, was rebranded to X in July 2023. In a follow-up post, X noted that the change does not apply to users who have enrolled for 2FA using other methods, such as authenticator apps. "Security keys enrolled as a 2FA method are currently tied to the twitter[.]com domain," it added. "Re-enrolling your security key will associate them with x[.]com, allowing us to retire the Twitter domain." X also supports 2FA using text messages, but the option is limited to non-Premium subscribers as of March 20, 2023. To enroll for 2FA, users can follow the steps below -

Daily Brief Summary

VULNERABILITIES // X Urges Security Key Users to Re-Enroll Before November Deadline

Social media platform X is advising users with security keys to re-enroll by November 10, 2025, to prevent account lockouts.

This re-enrollment is necessary due to the rebranding from Twitter to X, affecting the domain association of security keys.

Users who fail to re-enroll will face account access issues unless they choose an alternative two-factor authentication (2FA) method.

The change is specific to users utilizing hardware security keys, not affecting those using authenticator apps for 2FA.

X's initiative aims to phase out the twitter[.]com domain, aligning security keys with the new x[.]com domain.

Text message-based 2FA remains available but is restricted to non-Premium subscribers since March 2023.

The company's proactive approach emphasizes the importance of maintaining secure access through updated authentication methods.