Instagram today announced several new security enhancements that are being implemented to make the social network safer for all users.

Starting soon, Instagram is implementing support for third-party authenticator apps, which will allow them to be used for two-factor verification purposes in lieu of a phone number.

Instagram has supported two-factor authentication for some time, but it was tied to a phone number and required users to receive text messages, which has proven to be insecure and left some Instagram users vulnerable to SIM hacking.

instagramtwofactor
SIM hacking is a method hackers use to gain access to a person's phone number, using it to get into high-profile social media accounts. Some instagram accounts with short handles are valuable and have been stolen through this method, something a third-party authenticator app can protect against.

Instagram says that users can go to the Settings section of the Instagram app, choose Two-Factor Authentication, and then select "Authentication App" to implement two-factor authentication that does not involve a phone number.

Support for third-party authenticator apps is rolling out and will be available globally "in the coming weeks."

Along improved two-factor authentication, Instagram is also enhancing security through a new "About This Account" section that will be added to high-profile Instagram accounts. This feature will allow users to see more information about accounts that reach large audiences, allowing users to "evaluate the authenticity of the account."

To see more about an Instagram account, users can tap on a profile, tap the hamburger menu option and then select "About This Account." Information displayed will include the date the account joined Instagram, the country where it is located, recent username changes, and ads the account is running.

Starting in September, people who have accounts that reach large audiences will be able to review the information that will be available, and after that, the feature will roll out worldwide.

Instagram also plans to make it easier for Instagram users to earn a blue verified badge that lets people know an account is the "authentic presence of a notable public figure." Verification has been available on Instagram, but prior to now, there was no streamlined process for requesting account verification.

instagramverification

To be verified, an account must comply with Instagram's Terms of Service and Community Guidelines. We will review verification requests to confirm the authenticity, uniqueness, completeness and notability of each account. Visit the Help Center to learn more about Instagram's verification criteria.

Instagram users who want to apply for verification can do so by accessing the Settings app and choosing "Request Verification." Username, full name, and a copy of legal or business identification will be required. Like the other features announced today, the verification option is rolling out to users but could take some time to show up for everyone.

Top Rated Comments

OldSchoolMacGuy Avatar
92 months ago
Wonder what they consider "large accounts". Nearly every one of my accounts has over 20k followers, with most well over 100k. Certainly the +100k will be considered large but I wonder what the cutoff is on the lower end.
[doublepost=1535478415][/doublepost]
Never understand authentication apps. I was using one for a while for 3 accounts. Got a new iPhone installed the app and it was reset. Lost 3 accounts because I couldn’t get back into them. For the average user phone number should be more than enough. I mean seriously who the hell is going to hack my SIM card. Come on.... I can see a use for it for users not wanting to hand over their phone number to shady services but maybe you shouldn’t be using those services anyway, just a thought.
Just last week several apps made headlines for being hacked through SIM exploitation. This type of news (that Mac Rumors also publishes) puts these apps in the spotlight, necessitating moves like this from Instagram, Twitter, and others.

The fact that we're seeing accounts exploited this way is a great indicator that these additional measures are needed.
Score: 2 Votes (Like | Disagree)
Prospekt Avatar
92 months ago
Wonder what they consider "large accounts". Nearly every one of my accounts has over 20k followers, with most well over 100k. Certainly the +100k will be considered large but I wonder what the cutoff is on the lower end.
[doublepost=1535478415][/doublepost]

Just last week several apps made headlines for being hacked through SIM exploitation. This type of news (that Mac Rumors also publishes) puts these apps in the spotlight, necessitating moves like this from Instagram, Twitter, and others.

The fact that we're seeing accounts exploited this way is a great indicator that these additional measures are needed.
I have 8k and I got the notification about being a high-reach account
Score: 2 Votes (Like | Disagree)
OldSchoolMacGuy Avatar
92 months ago
I frankly don't understand why important features like this are "rolling out in coming weeks" as opposed to now.
Facebook (and Instagram as part of it) are so huge that they don't roll out new features all at once. Instead, they roll out to smaller areas at a time. This allows them to be sure things are working correctly before continuing to push new features out to everyone. It's a smart way to do things.

If you've ever wondered (or are one of those that gets upset) about Facebook, Instagram, and others who release new updates to their apps every week and just have "Bug fixes and other updates." in the release notes, these updates are what add the ability to push those new features. They don't want to announce those new features in the update because then they can't roll them out gradually. You'd have a bunch of people complaining "WHY ISN'T IT WORKING ON MINE!!!! ‽??!!"
Score: 2 Votes (Like | Disagree)
Mr. Heckles Avatar
92 months ago
Google Authenticator doesn't have the recovery code in all cases. I remember having to guess whether wiping and restoring my phone from a backup would save it... turns out it does but only if I encrypt my backup. This kind of thing can't be left undocumented!
Not the authenticator, the service you’re using it for. If you use an authenticator app for gmail, you get recovery codes, same with Dropbox, Facebook, and others.

Being pedantic, if there is a recovery code, technically it's 1-factor auth and not 2. But still safer because you'll likely keep that code more securely than you would a password.
It’s still 2 factors.
Factor 1: your password
facror 2: the one time password OR the recovery code.
Score: 1 Votes (Like | Disagree)
OldSchoolMacGuy Avatar
92 months ago
Never understand authentication apps. I was using one for a while for 3 accounts. Got a new iPhone installed the app and it was reset. Lost 3 accounts because I couldn’t get back into them. For the average user phone number should be more than enough. I mean seriously who the hell is going to hack my SIM card. Come on.... I can see a use for it for users not wanting to hand over their phone number to shady services but maybe you shouldn’t be using those services anyway, just a thought.
You can switch the Google Authenticator app from phone to phone. Just follow the process on the Google Authentication webpage to transfer everything over to the new phone and it'll work just fine.
[doublepost=1535482405][/doublepost]
Wonder what they consider "large accounts". Nearly every one of my accounts has over 20k followers, with most well over 100k. Certainly the +100k will be considered large but I wonder what the cutoff is on the lower end.
Well, that answers my question. Logged into one of my accounts and got this message for "high engagement accounts like yours."

MacRumors content image
Score: 1 Votes (Like | Disagree)
OldSchoolMacGuy Avatar
92 months ago
While you aren't wrong, features like two factor isn't something most people use (they should but they don't). More people pay attention to new features on a launch date. And if the feature cannot be used, they tend to be forgotten.

And besides, Instagram's parent company Facebook had TOTP authentication for years. While things can always go wrong and rolling out in phases is safer, I think Instagram is taking more precaution than is warranted.

Also, let's not forget that some big companies, such as Apple, roll out major features to everyone on day 1.
It's not like this change is making major news. Most will never see this announcement on sites like this.

Instagram is already putting announcements within the app and they'll likely add a Story about it too when it rolls out to those chosen users.

MacRumors content image

I'll be surprised if they don't prompt users to enable it when it becomes available to them too.
[doublepost=1535495722][/doublepost]
Interesting! Did you get the notification recently?
I got the above notification the most recent time I opened the Instagram app.
Score: 1 Votes (Like | Disagree)

Popular Stories

iPhone 17 Pro Dark Blue and Orange

iPhone 17 Release Date, Pre-Orders, and What to Expect

Thursday August 28, 2025 4:08 am PDT by
An iPhone 17 announcement is a dead cert for September 2025 – Apple has already sent out invites for an "Awe dropping" event on Tuesday, September 9 at the Apple Park campus in Cupertino, California. The timing follows Apple's trend of introducing new iPhone models annually in the fall. At the event, Apple is expected to unveil its new-generation iPhone 17, an all-new ultra-thin iPhone 17...
xiaomi apple ad india

Apple and Samsung Push Back Against Xiaomi's Bold India Ads

Friday August 29, 2025 4:54 am PDT by
Apple and Samsung have reportedly issued cease-and-desist notices to Xiaomi in India for an ad campaign that directly compares the rivals' devices to Xiaomi's products. The two companies have threatened the Chinese vendor with legal action, calling the ads "disparaging." Ads have appeared in local print media and on social media that take pot shots at the competitors' premium offerings. One...
iPhone 17 Pro Iridescent Feature 2

iPhone 17 Pro Clear Case Leak Reveals Three Key Changes

Sunday August 31, 2025 1:26 pm PDT by
Apple is expected to unveil the iPhone 17 series on Tuesday, September 9, and last-minute rumors about the devices continue to surface. The latest info comes from a leaker known as Majin Bu, who has shared alleged images of Apple's Clear Case for the iPhone 17 Pro and Pro Max, or at least replicas. Image Credit: @MajinBuOfficial The images show three alleged changes compared to Apple's iP...
maxresdefault

The MacRumors Show: iPhone 17's 'Awe Dropping' Accessories

Friday August 29, 2025 8:12 am PDT by
Following the announcement of Apple's upcoming "Awe dropping" event, on this week's episode of The MacRumors Show we talk through all of the new accessories rumored to debut alongside the iPhone 17 lineup. Subscribe to The MacRumors Show YouTube channel for more videos We take a closer look at Apple's invite for "Awe dropping;" the design could hint at the iPhone 17's new thermal system with ...