General Topics

Not sure where to look? Browse general posts, topics, conversations and more.
N
Multi-factor authentication using SMS is the least secure
two-step-verification

Hello. When are we getting the option to use an authenticator app or a physical security key for the MFA? The SMS option are still the least secure way of MFA out there. 1. SMS are not encrypted 2. SMS codes are vulnerable to phishing 3. You are in need of a phone service, which can down or out of reach. 4. SMS will most likely not get any more secure . I see peoples have been asking this question a while now, but not much have been done as far as I can see/ find info about. So for a company who are in the security business it dont give a very good commercial value I think. Please get some of your tech guys on this and come up with a safer solution. regards Rune

1964

0

2

12-02-2021 11:14:12

Responses (4)

  • E

    Case in point, the issue on Jan 23 where T-Mobile users couldn't receive the 2FA token for 7 hours. https://status.ring.com/incidents/dld9gyfk7tv3

    0

    12-02-2021 11:54:54

    • T

      Thank you for your feedback, @noruse. At Ring we value your security and your safety. While 2SV cannot be turned off, you can pick between text message or email verification codes, whichever is easier for you. In addition, we allow for a Remember Me option from the browser when using Ring.com, and if you are logged into your Ring app on your phone and open the app at least once every 30 days, it should keep you logged in. Check out our [Community post](https://community.ring.com/t5/Ring-Device-Tips-and-How-To-s/How-to-Ring-Account-Security/ba-p/23161%20) about account security for more information. As we always value our neighbors' feedback, I will ensure that this experience and your feedback is passed onto the appropriate teams here. Thank you, neighbor!

      0

      15-02-2021 03:50:39

        O

        Ring won't even send my wife a verification code via email because she hasn't logged in for nearly 1 year. They want to do a device verification or a utility bill verification. WTF? We moved and are setting up a new house, and my wife cannot log into her account unless she has access to the old device at the old house (we have no access to that) or unless we provide a utility bill from the old house (we also don't have this b/c we were living with family and all utility were under their names). Someone really dropped the ball on the authentication process.

        0

        30-07-2021 09:37:58

    • D

      Except the email option is now being taken away. Leaving SMS as the only option is a joke and clear data grab by Ring/Amazon. Even Facebook came around to adding an authenticator app as an option. If Ring is truly concerned about security they'd do the same. As the OP said, SMS is the least secure way to do 2FA.

      0

      30-07-2021 08:02:55

      • M

        Hey neighbors. Over the past year we have been making various efforts to ensure our neighbor’s safety when using their Ring products and services. In an effort to stay in line with industry’s best practices, Ring is phasing out email as a method of account verification as a part of [Two-Step Verification](https://support.ring.com/hc/en-us/articles/360052326012-Changing-your-method-of-receiving-a-verification-code-from-email-to-text-message), and the options that neighbors have now to log in are the SMS or an Authenticator App. If you are unable to use SMS verification, we recommend [using an Authenticator App](https://support.ring.com/hc/en-us/articles/360061508852-How-to-Download-and-Use-an-Authenticator-App-), which can be installed on a mobile device, PC, or laptop.

        1

        12-08-2021 06:36:38

        Didn't find an answer ?

        Log in or create your Ring account to post a question and join in the on the conversation.

        Most Helpful Members