Skip to content
  • Categories
  • Recent
  • Popular
  • Support
  • MyRoute-app
Collapse
Brand Logo

MRA Community Forum

  1. Home
  2. MyRoute-app Routeplanner
  3. [Web] Suggestions and Discussion
  4. Implement 2FA for login

Implement 2FA for login

Scheduled Pinned Locked Moved [Web] Suggestions and Discussion
12 Posts 8 Posters 929 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ConiKostundefined ConiKost

    I would like to see for enhanced security an option for enabling 2FA on web login.

    Corjan Meijerinkundefined Offline
    Corjan Meijerinkundefined Offline
    Corjan Meijerink
    Developer
    wrote on last edited by
    #2

    @ConiKost Though I appreciate the idea, I don't think it will happen in the nearby future.

    Users just store routes and tracklogs really. Not much security risk in that.

    The amount of tickets we get from people simply forgetting how they signed up / password they choice is already incredible 🙂 Complicating that with (optional) 2FA does not seem like the current priority.

    Dae 0undefined 1 Reply Last reply
    2
    • Corjan Meijerinkundefined Corjan Meijerink

      @ConiKost Though I appreciate the idea, I don't think it will happen in the nearby future.

      Users just store routes and tracklogs really. Not much security risk in that.

      The amount of tickets we get from people simply forgetting how they signed up / password they choice is already incredible 🙂 Complicating that with (optional) 2FA does not seem like the current priority.

      Dae 0undefined Offline
      Dae 0undefined Offline
      Dae 0
      wrote on last edited by
      #3

      @Corjan-Meijerink

      Most users will have a home address in there though…

      Just a thought😀

      RetiredWingManundefined Guzzistundefined 2 Replies Last reply
      0
      • Dae 0undefined Dae 0

        @Corjan-Meijerink

        Most users will have a home address in there though…

        Just a thought😀

        RetiredWingManundefined Offline
        RetiredWingManundefined Offline
        RetiredWingMan
        Valued contributor
        wrote on last edited by
        #4

        @Dae-0 putting a home address in any GPS device, including Google Maps, is never a good idea. My home address is a location "near" my actual home.

        2010 GL1800 Goldwing using Samsung Galaxy S20 5G Android 13.

        Dae 0undefined 1 Reply Last reply
        1
        • Tony 13undefined Offline
          Tony 13undefined Offline
          Tony 13
          wrote on last edited by
          #5

          I suppose as an option 2FA is OK. Can't see me using it though, and would hate to be forced to use it. I really don't think I put anything that sensitive into MRA

          1 Reply Last reply
          1
          • RetiredWingManundefined RetiredWingMan

            @Dae-0 putting a home address in any GPS device, including Google Maps, is never a good idea. My home address is a location "near" my actual home.

            Dae 0undefined Offline
            Dae 0undefined Offline
            Dae 0
            wrote on last edited by
            #6

            @RetiredWingMan said in Implement 2FA for login:

            @Dae-0 putting a home address in any GPS device, including Google Maps, is never a good idea. My home address is a location "near" my actual home.

            Absolutely, but people do a lot of things without thinking about the possible consequences. Just like those that reuse passwords etc.

            As an IT security consultant I really hate anything that doesn’t offer MFA. Lots of compromises start with accounts that contain what appears to be low value information (so it’s less protected) which are then used to move up the chain to the big value stuff.

            1 Reply Last reply
            0
            • ConiKostundefined Offline
              ConiKostundefined Offline
              ConiKost
              wrote on last edited by
              #7

              IMHO, 2FA is a must in modern days and should be implemented in future. I understand, that this won't happen fast, but I still think, this should be a must in future. Since also MRA accounts can have a paid subscription or one-time purchase, 2FA would help to protect more.

              Even not having a home address as POI, someone could always have other different POIs, which should no leak into public.

              2FA shouldn't be mandatory, but an option for users.

              Shiny!

              1 Reply Last reply
              3
              • Dae 0undefined Dae 0

                @Corjan-Meijerink

                Most users will have a home address in there though…

                Just a thought😀

                Guzzistundefined Offline
                Guzzistundefined Offline
                Guzzist
                wrote on last edited by
                #8

                @Dae-0 said in Implement 2FA for login:

                @Corjan-Meijerink

                Most users will have a home address in there though…

                Just a thought😀

                ...please don't over complicate it. Also with 2FA - if a user isn't carefully with his hone adress - others can see his address. So, if a user makes a route, including his home address public - no 2FA will protect it...

                Nothing is impossible ;-)
                In past: GARMIN Zumo 210->GARMIN Zumo 395->GARMIN XT=> now: DMD T865-X + MyRoute-App, LocusMaps, OsmAnd.
                In past: GARMIN MapSource ->GARMIN BaseCamp->Tyre->Kurviger->Calimoto=> now: MRA-Routplanner.

                1 Reply Last reply
                2
                • RetiredWingManundefined Offline
                  RetiredWingManundefined Offline
                  RetiredWingMan
                  Valued contributor
                  wrote on last edited by
                  #9

                  The biggest problem with security is people.

                  2010 GL1800 Goldwing using Samsung Galaxy S20 5G Android 13.

                  1 Reply Last reply
                  2
                  • Don Staufferundefined Offline
                    Don Staufferundefined Offline
                    Don Stauffer
                    wrote last edited by
                    #10

                    I would see 2FA as a step backwards in ease of use. If I am modifying a route on the road, it is usually with limited bandwidth and a short timeline, and a 2FA requirement would increase my blood pressure!

                    RetiredWingManundefined 1 Reply Last reply
                    3
                    • Don Staufferundefined Don Stauffer

                      I would see 2FA as a step backwards in ease of use. If I am modifying a route on the road, it is usually with limited bandwidth and a short timeline, and a 2FA requirement would increase my blood pressure!

                      RetiredWingManundefined Offline
                      RetiredWingManundefined Offline
                      RetiredWingMan
                      Valued contributor
                      wrote last edited by
                      #11

                      @Don-Stauffer said in Implement 2FA for login:

                      I would see 2FA as a step backwards in ease of use. If I am modifying a route on the road, it is usually with limited bandwidth and a short timeline, and a 2FA requirement would increase my blood pressure!

                      I agree, I don't like 2FA except for critical apps.

                      2010 GL1800 Goldwing using Samsung Galaxy S20 5G Android 13.

                      1 Reply Last reply
                      1
                      • Rainer Treichelundefined Online
                        Rainer Treichelundefined Online
                        Rainer Treichel
                        wrote last edited by
                        #12

                        I agree as well!
                        Incidentally, 2FA is also no longer up to date.
                        I like to wait until passkeys are so well established that they can be implemented by Corjan without any problems.
                        I'm happy to wait for that and use a decent password, and a unique one.
                        You can expect that from every user today, and anyone who doesn't do that doesn't deserve 2FA.
                        RT

                        1 Reply Last reply
                        0
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        ACTIVE USERS
                        Rainer Treichelundefined
                        Rainer Treichel
                        Guzzistundefined
                        Guzzist
                        RetiredWingManundefined
                        RetiredWingMan
                        Don Staufferundefined
                        Don Stauffer
                        Corjan Meijerinkundefined
                        Corjan Meijerink
                        Tony 13undefined
                        Tony 13
                        Dae 0undefined
                        Dae 0
                        ConiKostundefined
                        ConiKost
                        POPULAR TOPICS
                        • Waypoint / Viapoint Icons
                          Hans van de Ven MR.MRAundefined
                          Hans van de Ven MR.MRA
                          2
                          23
                          354

                        • Waypoints (Again!)
                          Marinus van Deudekomundefined
                          Marinus van Deudekom
                          0
                          6
                          132

                        • MRA is only speaking with French accent??
                          Nick Carthewundefined
                          Nick Carthew
                          0
                          15
                          666

                        • Clear Directions
                          Lex.Kloet.RXundefined
                          Lex.Kloet.RX
                          0
                          3
                          32

                        • MyRoute-App macht was sie will - aber nicht was sie soll!
                          Rainer Treichelundefined
                          Rainer Treichel
                          0
                          40
                          945

                        • SilverFox Controller C 1
                          Arjan de Vriesundefined
                          Arjan de Vries
                          0
                          83
                          12.4k

                        • Scenic routing & RouteXpert library improvements
                          Con Hennekensundefined
                          Con Hennekens
                          14
                          32
                          8.4k

                        • Tracklog omzetten naar route geeft veel verschillen
                          Bouke Entundefined
                          Bouke Ent
                          0
                          16
                          188
                        MY GROUPS
                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Popular
                        • Support
                        • MyRoute-app