cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
197 Views
Message 101 of 103

Re: Is two-step authentication now mandatory? No option to switch it off.

Go to solution

Let's look at this logically.

BT has decided that a user ID plus password is no longer sufficient for a secure access...and has added 2FA.

This may be because BT believes that BT user ID's and passwords are no longer known only to each user.

One wonders if there has been a data leak which has divulged BT user information.

It would not be the first time this has happened to a large corporation.

Having said that, we now have a suggestion that users' devices can become 'trusted' and 2FA will not be needed.

What is the difference in security level between the original system where a user ID and password is the only requirement and an unattended 'trusted' device which is accessed by someone who knows the user's ID and password.

If BT believes that user ID's plus passwords are probably no longer secure then the concept of 'trusted device' , in some circumstances, compromises the intention of 2FA whilst also imposing a burdensome overhead on the user

0 Ratings
Reply
193 Views
Message 102 of 103

Re: Is two-step authentication now mandatory? No option to switch it off.

Go to solution

@daveattavistockwrote:

Let's look at this logically.

BT has decided that a user ID plus password is no longer sufficient for a secure access...and has added 2FA. BT have not added 2FA, it has been a feature for a number of years. What the have done is make it compulsory when using webmail or MyBT.

This may be because BT believes that BT user ID's and passwords are no longer known only to each user.  

One wonders if there has been a data leak which has divulged BT user information.

It would not be the first time this has happened to a large corporation. 

BT, like many large companies such as banks, online retailers etc has moved with the times and now requires that their webmail email system should be better protected with 2FA.

It has nothing to do with any data leak/hack. If they were aware of a data leak and did not inform the Information Commissioner within 72 hours of becoming aware of the leak they would be in very serious trouble when it was found out.

Having said that, we now have a suggestion that users' devices can become 'trusted' and 2FA will not be needed. It is not a new suggestion, I pointed that out in message two of this thread which you have either not read or have forgotten about. It has always been the case with the BT 2FA system. I have had it running since it was first available a number of years ago from BT and after using it for a while it then was not required on my trusted devices. After that it was only required when I used a "new/unknown" device.

What is the difference in security level between the original system where a user ID and password is the only requirement and an unattended 'trusted' device which is accessed by someone who knows the user's ID and password. None but any breach in that instance is because the account owner either left the device open/unprotected and able to be used by an unauthorised person or they have given someone their username and password. That means any breach of the account is down to the account user.

If BT believes that user ID's plus passwords are probably no longer secure then the concept of 'trusted device' , in some circumstances, compromises the intention of 2FA whilst also imposing a burdensome overhead on the user You are missing the point of 2FA. It is not because BT believes your ID/Password is no longer secure. It is to keep it secure and to prevent unauthorised people/ hackers from accessing and using your email account to gather information that could be detrimental to you such as access to your bank accounts or other information. If you find it "burdensome" to use 2FA you would find it even more of a burden should your email account be hacked. 

In any event 2FA is here and I would be very surprised if BT decide to do away with it.

If you do not want to use 2FA you should install and use an email client which do not require 2FA. This will not stop 2FA on webmail which can be used on any device anywhere in the world by any person with access to any computer/mobile phone etc. I will not go into all the reasons why it does not need 2FA because I have already posted that information a number of times on the forum as have other users.


0 Ratings
Reply
157 Views
Message 103 of 103

Re: Is two-step authentication now mandatory? No option to switch it off.

Go to solution

@gg30340wrote:

It has nothing to do with any data leak/hack.



Hmmm, semantics I know but...  Nothing?  Any?

0 Ratings
Reply