Go Back  FlyerTalk Forums > Miles&Points > Airlines and Mileage Programs > Air France, KLM, and Other Partners | Flying Blue > KLM Flying Dutchman
Reload this Page >

KLM.com moving from FB Pin/existing password to new password for log-in

Community
Wiki Posts
Search

KLM.com moving from FB Pin/existing password to new password for log-in

Thread Tools
 
Search this Thread
 
Old Feb 9, 2018, 12:10 am
  #16  
Moderator: Aegean Miles+Bonus
 
Join Date: Oct 2009
Location: AMS / ATH
Programs: AFKL Plat, A3 Gold
Posts: 7,339
Originally Posted by Kaasschaaf
And to people who ask for two factor authentication: if you need that, your passwords are probably bad. Use a long password and a different password for every account you create. And if possible, even a different email address per account.
Strongly disagree here. A password can leak, even a long and unique (for that site) one.

2FA requires to have access to both the password AND a separate device (eg phone), which is going to be much harder for somebody to get access to remotely.
irishguy28 likes this.
Xandrios is offline  
Old Feb 9, 2018, 3:28 am
  #17  
 
Join Date: Sep 2005
Location: NL
Programs: FB M&M AA Amex HH SPG and others
Posts: 1,929
Originally Posted by bodory
+1

For people travelling and switching between various phone numbers it is painful to change sim cards just to get 2FA on the right phone.

It is not like KL day to day business was to deal with travellers after all
Why don't you use a program like Authy ? AFAIK you can use this on different phones, so I guess it will work with different sim cards also.

No personel experience though.
Brobbel is offline  
Old Feb 9, 2018, 3:59 am
  #18  
 
Join Date: Jun 2005
Location: 🇸🇬 🇭🇰 🇫🇷
Programs: Many
Posts: 4,749
Originally Posted by Brobbel
Why don't you use a program like Authy ? AFAIK you can use this on different phones, so I guess it will work with different sim cards also.

No personel experience though.
Hi Brobbel

Thanks for the suggestion. Authy is great indeed. But should a merchant (or KLM) decide to implement 2FA through SMS I must comply with that unless I am mistaken.

Sorry for OT
bodory is offline  
Old Feb 9, 2018, 8:01 am
  #19  
 
Join Date: Sep 2005
Location: NL
Programs: FB M&M AA Amex HH SPG and others
Posts: 1,929
Originally Posted by bodory
Hi Brobbel

Thanks for the suggestion. Authy is great indeed. But should a merchant (or KLM) decide to implement 2FA through SMS I must comply with that unless I am mistaken.

Sorry for OT
Yeah, that's right. SMS will work only on the right number - so only on that simcard.
Brobbel is offline  
Old Feb 10, 2018, 4:24 am
  #20  
 
Join Date: Feb 2018
Programs: FlyingBlue
Posts: 15
MFA is a must. Different MFA options, the option to set up more than one is also desired.
Me personally love my LastPass+LastPass Authenticator setup. With this I also enforce my important family members online security
ocsi is offline  
Old Feb 12, 2018, 4:09 am
  #21  
 
Join Date: May 2009
Location: AMS
Posts: 2,062
Originally Posted by Brobbel
Yeah, that's right. SMS will work only on the right number - so only on that simcard.
Phone numbers and SIM cards are not directly related to one another. The phone network routes one to the other, but can change that on a whim.
CyBeR is offline  
Old Feb 12, 2018, 4:15 am
  #22  
 
Join Date: Jan 2018
Location: Canada
Programs: Flying Blue Platinum
Posts: 91
My phone provider sends me my sms to my phone and in their app. So depending on how secure their infrastructure is, these SMS messages might be intercepted elsewhere.
Kaasschaaf is offline  
Old Feb 15, 2018, 2:50 pm
  #23  
 
Join Date: Mar 2016
Location: CPT,AMS
Posts: 4,412
Apparently now if you mistype your password 3 times (or if you try to use the app which was logged in previously and didn't change the password...) it locks you out and you have to go to the "Forgotten password" page, and you are asked to answer your secret question before a new PIN is e-mailed to you.

This is compared to the previous behaviour where the account magically unlocked itself after a few minutes.
Ditto is offline  
Old Feb 16, 2018, 1:47 am
  #24  
Moderator: Aegean Miles+Bonus
 
Join Date: Oct 2009
Location: AMS / ATH
Programs: AFKL Plat, A3 Gold
Posts: 7,339
I hate secret questions. The question is either too simple (in a way that everyone who knows you could answer it), or, too difficult (In the way that you will have forgotten the exact phrasing one year later).

Why don't they just send an SMS or reset-email like the rest of the world does?
Xandrios is offline  
Old Feb 16, 2018, 2:37 am
  #25  
FlyerTalk Evangelist
Original Poster
 
Join Date: Mar 2008
Location: Netherlands
Programs: KL Platinum; A3 Gold
Posts: 28,721
What is the airspeed velocity of an unladen swallow?

irishguy28 is online now  
Old Feb 16, 2018, 5:59 am
  #26  
 
Join Date: Mar 2016
Location: CPT,AMS
Posts: 4,412
Originally Posted by Xandrios
I hate secret questions. The question is either too simple (in a way that everyone who knows you could answer it), or, too difficult (In the way that you will have forgotten the exact phrasing one year later).

Why don't they just send an SMS or reset-email like the rest of the world does?
Because having a secret question is more secure?
Ditto is offline  
Old Feb 16, 2018, 6:05 am
  #27  
Moderator: Aegean Miles+Bonus
 
Join Date: Oct 2009
Location: AMS / ATH
Programs: AFKL Plat, A3 Gold
Posts: 7,339
Originally Posted by Ditto
Because having a secret question is more secure?
It is only more secure if an attacker already has access to a secondary communication path like your phone or email. Is that something common enough to add the extra step for?

I'd say that somebody re-using the same password on multiple sites, and allowing an attacker to get access that way, is way more of a risk. Which is what 2FA can help to prevent. And really there is no excuse to not implement 2FA as even a 3rd party system (eg Google API) can offer that functionality. I'd say it is a similar effort to implementing the Facebook-authentication...which they have already added years ago.
Xandrios is offline  
Old Feb 16, 2018, 6:07 am
  #28  
FlyerTalk Evangelist
Original Poster
 
Join Date: Mar 2008
Location: Netherlands
Programs: KL Platinum; A3 Gold
Posts: 28,721
Just use your Aegean Miles+Bonus number as the answer to all the secret questions

Secret questions become even more secret when your answer is to a question of your own choosing...
irishguy28 is online now  
Old Feb 16, 2018, 6:09 am
  #29  
 
Join Date: Mar 2016
Location: CPT,AMS
Posts: 4,412
Originally Posted by Xandrios
It is only more secure if an attacker already has access to a secondary communication path like your phone or email. Is that something common enough to add the extra step for?
Many times a hacker obtain access to an e-mail account, and from there starts to cause damage by 'reset password' in other websites, so yes I would consider that common enough.
Ditto is offline  
Old Feb 16, 2018, 3:47 pm
  #30  
 
Join Date: Aug 2016
Location: MAN
Programs: FB Platinum
Posts: 500
Originally Posted by irishguy28
What is the airspeed velocity of an unladen swallow?

African or European?
rosensfole is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.