Increase Login Security

I don’t have any particular incident but just come to realize we should probably beef up security. Can be done multiple ways – Multifactor authentication (MFA) or two-factor (2FA).  

1 Like

I vote no… I’m good with a strong password. I’d rather not have to use my phone to log in at Z. 

@powskers  
It’s hard enough to login sometimes with recaptcha randomly acting up.

Why add to the stress.
Don’t want to depend on and have to constantly use my phone to login…just nope.
Big thumbs down.
:-1:

Since a lot of us are working hard with our stores and earning money from this, I do believe that security needs to be increased. Once someone gets a hold of your account, what prevents them from changing the payment method or any other details? Someone can take our stores for ransom and threaten to delete all of our stores in one click.

Setting it up is not rocket science. Does anyone logout and login everyday?

@powskers  
I am one of those of us who have been here awhile (since 2008). I have never had any issues,  and I can’t recall ever on the old defunct forum, or this new forum, ever reading a post from a member having security issues with their account. If there ever has been, some other forum poster will chime in.

If you are doing your due diligence with your zazzle account info, login p/w etc., you should basically have no problems.
Going even further, you can log out, close your browser and clear your cache on a daily/regular basis. If you live in a condo complex/apt complex, make sure your wifi is password protected. Ipad, password protected, same w/computer, phone. Accessing your account on a public computer,such as a library isn’t the greatest idea. Or accessing your account anywhere in public…

To the point of using your phone for security login, what happens if someone accesses and/or steals your phone? There is probably no failsafe method.

You assume that we don’t work hard or earn money then… ok… 

I get automatically logged out fairly often, and yeah, I’d be annoyed if I had to get a text every time that it happens. I have every confidence that if Z believed their passwords to be compromised, they’d let us know. 

Also, I think it’s a pretty big assumption to make that everyone who uses the platform has a smart phone… 

Z, if you do decide to do this, definitely make it an opt in.

I have a dumb phone only, so this sounds as something undoable to me.

No. 😖

Hi @PenguinPower  – not sure when I assumed about not working hard. If I offended you, I am sorry.

Yes, I agree Z should make it disabled by default and people can opt in if they want to. I think that would work for everyone.  

Hi @PenguinPower  - there are a lot of other ways for authentication and not just thru smart phones. An SMS verification will do too.

@powskers  
About SMS verification:
https://www.authgear.com/post/sms-authentication-should-you-implement

Why Using SMS Authentication for 2FA Isn’t Ideal—
SMS Messages are not Encrypted
SMS messages are not end-to-end encrypted. Therefore, governments and cellular providers can actually see your messages. The messages are stored in the systems for days while the metadata stays longer.
Secondly, SMS messages can be intercepted by hackers. Mobile phone networks connect through a signaling protocol launched before cyber crimes were a huge deal. The signaling system has been breached before and information such as bank verification codes stolen in the past, making it the less secure method of communication or authentication.
SMS Spoof
Criminals use SMS messages trick users as they have to click on the link to ascertain its authenticity. By the time you click on it, you may have been hacked.
SMS Authentication can be Quite Costly
SMS authentication depends on providers’ services and will charge as per the provider rates. The prices vary among providers and can change depending on the location and time. The costs can quickly pile up if your user base grows exponentially and have to send thousands of authentication code on a daily basis.

@powskers  How can you receive SMS without a phone? 

I’m not opposed to increased security, but I’m VERY opposed to anything that requires use of a phone. Some of us (odd ducks that we are) don’t actually want to be available to the world 24/7. My phone stays off unless I’m leaving the house. If I have to get a text or push notification EVERY time I log in to Zazzle (which is every time I sit down at my computer to work) it means I have to go find the phone, turn the thing on, hope that it’s charged, wait for it to boot, and hope I didn’t miss the text or notification (which seems to happen when they come in while my phone is off.) It’s generally at least a 15 minute ordeal whenever some entity wants to verify my identity. 

If I could do it once and then tell it to remember me on this computer like my bank does, then that’s fine. But if I have to deal with that nonsense on a regular basis like my security camera company requires, I will be a very unhappy camper.

Just my 2 cents.

@Cat  - Any cellphone can receive SMS, not just smart phones. 

I do understand some people will not like the hassle and that is why this feature if Z chooses to do it should be disabled by default. People can opt to not use it. 

@powskers  I guess I’m one of the few dinosaurs left who still uses a landline - which, as far as I know, cannot receive SMS. I think there are many designers here who are in the same boat.

Anyhow, as I said, I’m not opposed to security measures for those who really want them, but my security camera company went this route, and it’s been nothing but hassles ever since. I really don’t understand why they think that the camera watching my feral cats requires more security than my bank does! (That’s what everybody uses their security cameras for, isn’t it? 😃)

As long as I don’t have to fight with the stupid phone multiple times per day, I’m fine with whatever.

Hey all,

thanks for all your suggestions and feedback here.

Pádraig

Just was trying to post about this.

It’s definitely a lot safer to optionally allow some form of 2FA for people’s Zazzle account. Seeing a lot of social media accounts, and other accounts, get hacked the current form of username/email and password isn’t very secure in this age.

For those that prefer only password, it could be optional. But IMO the simple extra step of adding a code received to email/ SMS or using the Google Authenticator app gives a lot more peace of mind. You wouldn’t want to think about people breaking into your account.