UA initiates Account Security Update (Security Q&A authentication added 2016)
#631
Join Date: Jun 2004
Posts: 555
We can argue about the first assertion, but the second is most definitely false. I've had my credentials stolen (from another site that had an IT breach) and identity used illegally elsewhere after that. It was not a low-impact event to correct. While the theft of information in that case would not have been prevented by 2FA, the results were the same. The costs were substantial in terms of time and financial consequences.
#632
Join Date: Jan 2007
Location: Bellingham/Gainesville
Programs: UA-G MM, Priority Club Platinum, Avis First, Hertz 5*, Red Lion
Posts: 2,553
it still needs an authentication of the passkey, so the authentication (password/pin etc) moves from the site level to the device level. really does not change the need for a password/login security just where authentication happens.
#633
Moderator, Omni, Omni/PR, Omni/Games, FlyerTalk Posting Legend
Join Date: Oct 2004
Location: Between DCA and IAD
Programs: UA 1K MM; Hilton Diamond
Posts: 64,992
The thing I really dislike about 2FA (and MFA) is that not everyone has a cell phone at their side every moment. When I'm at the office, logging into any MFA site means rushing out to the phone lockers, bringing phone out of airplane mode, grabbing the code, then rushing back and hoping I jotted the code down correctly and that it hasn't been too long. Or if I'm on a plane using wifi and for some reason my web browser decides it needs to re-authenticate and only offers a voice call or text message for 2FA. Then the MFA authenticator apps also have their own issues, as I found when I upgraded my phone and had major issues moving Duo to the new phone for a couple of the sites & apps I use it for--one I essentially had to de-register the authenticator, then go through the rigmarole of adding it anew.
I get that I don't want to have to deal with the issues of someone stealing my miles, my Plus Points, messing with my existing reservations, etc., but the hassle of 2/MFA is too much for me.
I get that I don't want to have to deal with the issues of someone stealing my miles, my Plus Points, messing with my existing reservations, etc., but the hassle of 2/MFA is too much for me.
#634
Join Date: Jul 2003
Location: BOS, PVG
Programs: United Global Services and 1MM, Marriott Ambassador
Posts: 9,825
The thing I really dislike about 2FA (and MFA) is that not everyone has a cell phone at their side every moment. When I'm at the office, logging into any MFA site means rushing out to the phone lockers, bringing phone out of airplane mode, grabbing the code, then rushing back and hoping I jotted the code down correctly and that it hasn't been too long. Or if I'm on a plane using wifi and for some reason my web browser decides it needs to re-authenticate and only offers a voice call or text message for 2FA. Then the MFA authenticator apps also have their own issues, as I found when I upgraded my phone and had major issues moving Duo to the new phone for a couple of the sites & apps I use it for--one I essentially had to de-register the authenticator, then go through the rigmarole of adding it anew.
I get that I don't want to have to deal with the issues of someone stealing my miles, my Plus Points, messing with my existing reservations, etc., but the hassle of 2/MFA is too much for me.
I get that I don't want to have to deal with the issues of someone stealing my miles, my Plus Points, messing with my existing reservations, etc., but the hassle of 2/MFA is too much for me.
Other than SQ, is any airline using 2FA?
#635
Join Date: Sep 2006
Location: HNL
Programs: UA GS4MM, MR LT Plat, Hilton Gold
Posts: 6,206
We can argue about the first assertion, but the second is most definitely false. I've had my credentials stolen (from another site that had an IT breach) and identity used illegally elsewhere after that. It was not a low-impact event to correct. While the theft of information in that case would not have been prevented by 2FA, the results were the same. The costs were substantial in terms of time and financial consequences.
#636
Moderator: United Airlines; FlyerTalk Evangelist
Join Date: Jun 2007
Location: SFO
Programs: UA Plat 1.9MM, Hyatt Discoverist, Marriott Plat/LT Gold, Hilton Silver, IHG Plat
Posts: 63,082
We can argue about the first assertion, but the second is most definitely false. I've had my credentials stolen (from another site that had an IT breach) and identity used illegally elsewhere after that. It was not a low-impact event to correct. While the theft of information in that case would not have been prevented by 2FA, the results were the same. The costs were substantial in terms of time and financial consequences.
Identity theft is a major, major pain, I handled my wife's incident, her issue likely came from one of the credit rating agencies breaches). But your UA profile will not be the source of that. I standby the comment of low consequences.
UA implemented the security questions less to protect you and more to protect UA from users' poor password habits -- and UA having to restore hacked miles.
#637
FlyerTalk Evangelist
Join Date: Sep 2002
Location: Between AUS, EWR, and YTO In a little twisty maze of airline seats, all alike...
Programs: CO, NW, & UA forum moderator emeritus
Posts: 33,786
As someone who is challenged in the use of opposable digits I find the chat feature frustratingly challenging. Between autocorrection features and having difficulty walking and focusing on a handheld device I’m helpless. When I need to talk with an agent I need to talk.

#638
Join Date: Sep 2006
Location: HNL
Programs: UA GS4MM, MR LT Plat, Hilton Gold
Posts: 6,206
The amount of amount PI accessible from your UA account of use to identity theft is low, Name, birthday and residence is about the limit and all those are fairly available on the web with a google search (hence should be insufficient to open a damaging account).
I standby the comment of low consequences.
I standby the comment of low consequences.
If you could steal an identity based on United info we'd have all had our identities stolen long ago as the information is so easily found without hacking the United site.
#639
A FlyerTalk Posting Legend
Join Date: Apr 2004
Location: GVA (Greater Vancouver Area)
Programs: DREAD Gold; UA 1.034MM; Bonvoy Au-197; PCC Elite+; CCC Elite+; MSC C-12; CWC Au-197; WoH Dis
Posts: 51,448
#640
Join Date: Jun 2001
Location: Orlando, FL
Programs: UA 2mm 1K, Marriott Lifetime Platinum, Hilton Diamond, National Executive Elite
Posts: 261
When your account is hacked for 6 Home Depot Gift Cards ([email protected],000) you will appreciate any increased security measures. :
#641
Join Date: Sep 2006
Location: HNL
Programs: UA GS4MM, MR LT Plat, Hilton Gold
Posts: 6,206
When your account is hacked for 6 Home Depot Gift Cards ([email protected],000) you will appreciate any increased security measures. :