FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   Delta Air Lines | SkyMiles (https://www.flyertalk.com/forum/delta-air-lines-skymiles-665/)
-   -   Delta 2FA is now live (https://www.flyertalk.com/forum/delta-air-lines-skymiles/2175289-delta-2fa-now-live.html)

Spent_All_My_Miles Oct 17, 2024 10:00 am

Delta 2FA is now live
 
I just went to Delta.com on a laptop to log in and got a 2FA message - a message with a six-digit code was sent to my email (no option was provided to have it sent to my phone).
After I entered it. I then got what is probably a one-time prompt to confirm contact information on file for recovery purposes.

United starting doing this sometime in the past year or so. Not sure about AA.

I imagine that most of the time, 2FA is not a problem, but occasionally it would be a real pain, like when on an airplane.

Just went to the Delta app, did not get a 2FA message.

emma dog Oct 17, 2024 10:03 am

This has been in existence for a while for certain functions, such as looking up e-tickets/e-credits by phone number.

I just did a general log in on the website and did not get 2FA.

rylan Oct 17, 2024 11:25 am

Nothing here either... just logged in as normal with no 2FA prompt/options.

WillBarrett_68 Oct 17, 2024 11:51 am

these sorts of fake 2FAs are only marginally better than no 2FA, most of the time someone compromises a delta dot com password they probably already have the email compromised as well (probably because the user has the same password on both)

Colaholiker Oct 17, 2024 1:09 pm

My app did it... yesterday? Which is somewhat ridiculous, as it is protected by my fingerprint anyway. No such thing happening on the website though.

WillBarrett_68 Oct 17, 2024 2:36 pm


Originally Posted by Colaholiker (Post 36604460)
My app did it... yesterday? Which is somewhat ridiculous, as it is protected by my fingerprint anyway.

are you using andriod? I am not sure but on iOS at least, using touchID or faceID would not protect your account, as anyone with the password can get in.

Colaholiker Oct 17, 2024 2:37 pm

Android.

Technically yes, you could also use the password.
However, my password is so cryptic and complicated that I don't even know it and have to rely on a password manager. 🤣

DrMilano Oct 17, 2024 4:40 pm

Delta should go to using a Passkey log-in, as this method is slowly gaining traction/acceptance. On Apple products can use FaceID (iPhones and iPads) and Touch ID (Macs/older iPhones/iPads).

SDQBound Oct 17, 2024 7:53 pm

I thought this thread was about 2 Delta FAs going live on TikTok or Instagram :D

DenverBrian Oct 17, 2024 7:56 pm

I got the 2FA prompt but there was an option to Skp. So I did. :D :D :D

itamex Oct 17, 2024 10:14 pm

from what i understand the 2fa will send the sms or mail code when you login on a new device
so if you logout and login in the app you use daily, nothing changes, it should be a "recognized" device, so no additional security needed

DrMilano Oct 17, 2024 11:17 pm


Originally Posted by itamex (Post 36605412)
from what i understand the 2fa will send the sms or mail code when you login on a new device
so if you logout and login in the app you use daily, nothing changes, it should be a "recognized" device, so no additional security needed

Last month I did my annual dual iPhone upgrade from a 15 pro -> 16 pro and 15 pro max -> 16 pro max with the data transferred over WiFi. Both iPhones had a a new MAC address and Delta did not prompt me for a 2FA with these 2 new devices.

WillBarrett_68 Oct 18, 2024 5:30 am


Originally Posted by DrMilano (Post 36604934)
Delta should go to using a Passkey log-in, as this method is slowly gaining traction/acceptance. On Apple products can use FaceID (iPhones and iPads) and Touch ID (Macs/older iPhones/iPads).

neither of these do what 2FA does. They allow you to basically login easier with your known device, and both are completely out of the loop when you're logging in on a new device. An attacker with your password won't be slowed down at all if you are using faceID or passkeys but might be slowed down or even completely stopped if the site uses 2FA (depends on the implementation).

WillBarrett_68 Oct 18, 2024 5:32 am


Originally Posted by DrMilano (Post 36605484)
Last month I did my annual dual iPhone upgrade from a 15 pro -> 16 pro and 15 pro max -> 16 pro max with the data transferred over WiFi. Both iPhones had a a new MAC address and Delta did not prompt me for a 2FA with these 2 new devices.

MAC addresses aren't going to be seen by the website

WillBarrett_68 Oct 18, 2024 5:33 am


Originally Posted by itamex (Post 36605412)
from what i understand the 2fa will send the sms or mail code when you login on a new device
so if you logout and login in the app you use daily, nothing changes, it should be a "recognized" device, so no additional security needed

this is generally the idea, there are of course a lot of wrinkles that might cause 2FA to be triggered even when you're on the same device, but yeah this is directionally correct


All times are GMT -6. The time now is 2:16 pm.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.