Provide an authenticator MFA for Lifehub

Mike3
Mike3 Quicken Windows Other Unconfirmed ✭✭✭

The only option now is SMS

3
3 votes

Reviewed · Last Updated

Comments

  • RMJErdman
    RMJErdman Member ✭✭

    This is essential if you want people to be able to own their own info, along with a statement that says that the data is ONLY accessible using the MFA and not behind the scenes by the company offering the product. It'd be nice to know we're paying for protection and organization services, not paying to be pillaged for data scalping for marketing purposes.

  • mpdoherty
    mpdoherty Quicken Windows Subscription Member ✭✭

    I agree that you need to add 3rd party authenticators for MFA (my personal preference would be DUO).

    ALSO…. currently, even when MFA is enabled, once you authenticate to a specific machine/browser, you are no longer challenged going forward. This is NOT good. If a bad actor compromised that machine then simply by opening that browser then they would have full access to the confidential information stored in LifeHub. My suggestion is that you add a user configurable button to enable/disable "auto-logoff" after each browser session. That way when I close the browser, then I am automatically logged off of LifeHub and will be MFA challenged upon the next session. For those concerned with left-open browsers, you could also offer a "time-out" function (e.g. auto logoff of LifeHub if browser session is inactive for X minutes).

    Bottom line is that I want to be MFA challenged EVERY time I open LifeHub in a new browser session! Please make this happen!!!