Community
Wiki Posts
Search

BAEC now forcing SMS authentication?

Thread Tools
 
Search this Thread
 
Old Jun 1, 2023, 1:08 pm
  #1  
Original Poster
 
Join Date: Oct 2021
Location: London (née Melbourne)
Programs: Qantas Platinum (Oneworld Emerald)
Posts: 988
BAEC now forcing SMS authentication?

Logging on to my account today, was forced to add a phone number and receive a code by SMS to login.

Was then given a long 'recovery code' which would be needed to access my account if I changed phone numbers or couldn't receive SMS.

Not sure if this is being rolled out to everyone or just some, but there seemed no way to opt-out or postpone.
LondonAussie is offline  
Old Jun 1, 2023, 1:20 pm
  #2  
 
Join Date: Nov 2018
Location: BER
Programs: BA GGL, Hilton Diamond
Posts: 1,843
Originally Posted by LondonAussie
Logging on to my account today, was forced to add a phone number and receive a code by SMS to login.

Was then given a long 'recovery code' which would be needed to access my account if I changed phone numbers or couldn't receive SMS.

Not sure if this is being rolled out to everyone or just some, but there seemed no way to opt-out or postpone.
i read this
i got curious
i wanted to check if same for me...


tadaaaaaaa

sorry, cant help. even if i want to... but 2FA always sounds nice.
nancypants and fluffymitten like this.
Nephoi is offline  
Old Jun 1, 2023, 1:29 pm
  #3  
 
Join Date: Nov 2018
Location: BER
Programs: BA GGL, Hilton Diamond
Posts: 1,843
could log in now. nothing on my end.
Markie likes this.
Nephoi is offline  
Old Jun 1, 2023, 3:04 pm
  #4  
Hilton Contributor Badge
 
Join Date: Feb 2014
Location: ±38,000 feet
Programs: LH HON, BA GGL, AF Plat, EK Plat
Posts: 6,428
I do get SMS OTP sometimes (rarely though)
nufnuf77 is offline  
Old Jun 2, 2023, 2:49 am
  #5  
 
Join Date: Jan 2013
Programs: BAEC GfL
Posts: 336
Originally Posted by Nephoi
i read this
i got curious
i wanted to check if same for me...


tadaaaaaaa

sorry, cant help. even if i want to... but 2FA always sounds nice.
I also go this message today, logged out and back in again and all worked ok, still no bookings showing in MMB as usual these days
Royalscot is offline  
Old Jun 2, 2023, 3:08 am
  #6  
 
Join Date: Oct 2013
Location: BMA
Programs: SAS Eurobonus Gold Card
Posts: 324
Originally Posted by Royalscot
I also go this message today, logged out and back in again and all worked ok, still no bookings showing in MMB as usual these days
I've had this for the past two days. Click on the BA logo at the top and then the site seems to work.
KARFA likes this.
citiflyerUK is offline  
Old Jun 2, 2023, 3:14 am
  #7  
 
Join Date: Mar 2014
Location: Leicestershire / Dubai
Programs: BA Silver, Marriott Bonvoy Titanium Elite & Lifetime Gold, Heathrow Rewards Premium, Tesco Clubcard
Posts: 663
About time if they are rolling this out.

I've previously mentioned that the security for accounts is awful, especially as they don't even allow me to set a secure password for my account as the website does not like special characters.

I kind of wish that they allowed MFA using a verification code generated by apps such as the iOS Passwords app rather than SMS (since the verification code can be automatically filled in), but at least it's a step in the right direction by BA.
Paren is offline  
Old Jun 2, 2023, 3:21 am
  #8  
formerly JackDann
 
Join Date: Oct 2017
Location: Northern Ireland
Posts: 1,659
Originally Posted by Paren
About time if they are rolling this out.

I've previously mentioned that the security for accounts is awful, especially as they don't even allow me to set a secure password for my account as the website does not like special characters.

I kind of wish that they allowed MFA using a verification code generated by apps such as the iOS Passwords app rather than SMS (since the verification code can be automatically filled in), but at least it's a step in the right direction by BA.
Those apps are terrible for User Experience in my opinion. 2FA I'm fine with, aslong as you are able to authenticate your device so that you don't need to do it every single time.
JD1905 is offline  
Old Jun 2, 2023, 3:53 am
  #9  
FlyerTalk Evangelist
 
Join Date: Feb 2009
Location: From ORK, live LCY
Programs: BA Silver, EI Silver, HH Gold, BW Gold, ABP, Seigneur des Horaires des Mucci
Posts: 14,217
2FA over SMS is horrible for security, TOTP is the way forward.
fluffymitten and Hydebear like this.
stifle is offline  
Old Jun 2, 2023, 3:54 am
  #10  
 
Join Date: Jul 2006
Location: Glasgow, UK
Programs: BA, UA, Marriot
Posts: 2,196
No requirement for me this morning either on desktop or for the App on the phone.
Captain Schmidt is offline  
Old Jun 2, 2023, 4:48 am
  #11  
 
Join Date: Dec 2014
Location: London, UK
Programs: BAEC Gold-GGL
Posts: 1,191
Originally Posted by stifle
2FA over SMS is horrible for security, TOTP is the way forward.
Agreed and it's also dependent on being somewhere with mobile signal and there's no guarantee the message will arrive even then.
camdentown likes this.
fluffymitten is offline  
Old Jun 2, 2023, 4:53 am
  #12  
 
Join Date: Aug 2006
Location: Switzerland
Posts: 1,593
Originally Posted by stifle
2FA over SMS is horrible for security, TOTP is the way forward.
And, of course, requires a mobile and a consistent number. Often when travelling I've swapped my SIM for a local one, although as esims become more popular that problem should diminish.
camdentown likes this.
adrianlondon is offline  
Old Jun 2, 2023, 5:27 am
  #13  
 
Join Date: Apr 2018
Location: LON, between FAB and EGTD
Programs: OWS - AA Lifetime Platinum, BA nobody (blue)
Posts: 867
Not required for me today. And I hope never. For goodness sake, Shell requires 2-factor authorization to claim the £1.50 petrol discount or even my free mars bar !
tjcxx is online now  
Old Jun 2, 2023, 5:27 am
  #14  
FlyerTalk Evangelist
 
Join Date: Jul 1999
Location: ORD/MDW
Programs: BA/AA/AS/B6/WN/ UA/HH/MR and more like 'em but most felicitously & importantly MUCCI
Posts: 19,719
Originally Posted by stifle
2FA over SMS is horrible for security, TOTP is the way forward.
I go through a TOTP step with a five-minute clock whenever I log on to pay a modest electricity bill. Absurd that there is nothing analogous to protect BA bookings worth thousands, Avios balances, embedded CC data, etc. The front door is as good as ajar.

A few years ago I had all my Hilton Honors points stolen via a flawed Amazon backdoor on what was then a similarly loosey-goosey site. Hilton have tightened things up somewhat since with 2FA. (Though it should be noted that NIST in the States has warned for years of 2FA's inadequacies.)
BearX220 is offline  
Old Jun 2, 2023, 5:53 am
  #15  
 
Join Date: Nov 2004
Location: ORD, LHR, FCO
Programs: BA Gold, etc. etc.
Posts: 1,402
Originally Posted by Paren
About time if they are rolling this out.

they don't even allow me to set a secure password for my account as the website does not like special characters.
That's odd.. My 16-letter BAEC password contains an @..
London Dude is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.