Results 1 to 5 of 5
  1. #1
    Pokerface's Avatar
    Pokerface is offline Public Member
    Join Date
    August 2016
    Posts
    3,132
    Blog Entries
    1
    Thanks
    668
    Thanked 1,003 Times in 742 Posts

    Default Two-Factor Authentication - Unrealistic Code/Password Request Expirations

    Received an e-mail from RioBet Affiliates that they have initiated a Two-Factor Authentication code for accounts. It also states that the code expires in "10 minutes".

    Really? Do these programs really think we sit at our computers every minute of the day checking e-mails and expect us to "jump"? 10 minute expiration?

    Whoever thinks these things up really must re-evaluate how people work and set more realistic time frames before expiring codes and passwords.

    Same goes for requesting new passwords. When we need a new password and the program says it will be sent shortly and we wait and wait and wait. It eventually arrives and expires in 30 minutes but in the meantime you have gone off and doing other things and now have to request another password and so the circle continues.

    Security is important to everyone but there must be a better process than unrealistic expiration of codes and passwords.

    Just a thought ...... Think from a users perspective also.
    nousviz.com

    What's Nous?

    StatsDrone now offers Freemium plan to connect up to 30 programs - FREE!.

  2. #2
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,886
    Thanks
    4,517
    Thanked 9,271 Times in 5,961 Posts

    Default

    10 minutes is enough, as long as the code comes immediately.

    Rick
    Universal4

  3. #3
    Pokerface's Avatar
    Pokerface is offline Public Member
    Join Date
    August 2016
    Posts
    3,132
    Blog Entries
    1
    Thanks
    668
    Thanked 1,003 Times in 742 Posts

    Default

    Very true, 10 minutes for passwords is sufficient. In the case of RioBet no request is made, they are just sending the two-factor code that expires in 10 minutes. Just worse when they are sent at 3am EST when we are still sleeping. LOL
    nousviz.com

    What's Nous?

    StatsDrone now offers Freemium plan to connect up to 30 programs - FREE!.

  4. #4
    TheGooner's Avatar
    TheGooner is offline Private Member
    Join Date
    March 2007
    Location
    New Zealand
    Posts
    4,562
    Thanks
    2,090
    Thanked 4,533 Times in 2,175 Posts

    Default

    Quote Originally Posted by Pokerface View Post
    Very true, 10 minutes for passwords is sufficient. In the case of RioBet no request is made, they are just sending the two-factor code that expires in 10 minutes. Just worse when they are sent at 3am EST when we are still sleeping. LOL
    That sentence raises huge alarm bells for me.

    It's unlikely that they are sending these codes randomly as you suggested.
    It's far more likely that someone has entered your userID / email and asked for a password reset.

    You're possibly in the first stages of being hacked - and should discuss with your AM immediately

  5. The Following 3 Users Say Thank You to TheGooner For This Useful Post:

    Nenad (3 September 2020), Renee (3 September 2020), universal4 (2 September 2020)

  6. #5
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,886
    Thanks
    4,517
    Thanked 9,271 Times in 5,961 Posts

    Default

    Was my thoughts after reading his reply also.

    Rick
    Universal4

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •