Afrihost - One Time Pin (OTP) - SMS the only method available ?

BCR

Expert Member
Joined
Jun 19, 2010
Messages
2,030
Reaction score
613
I've searched this forum, via Google search, and also Afri. Help - https://help.afrihost.com/topic/clientzone , but don't come across the info. I'm looking for.

Far as I'm aware, SMSs are the only way to receive OTPs from you at Afrihost ; much like some of the banks and other websites as well.

Is it possible for you at Afrihost to add additional two / 2nd step verification options for signing into the ClientZone, as SMS's are vulnerable, more so than any other way/s from what I understand. Like for eg., using Google Authenticator (that would be my preference) or even an option to send the OTPs to the email address signed in with or an alternative email address ?

If you get something like this sorted out on your platform, maybe you can get Axxess (part of your Co. group) to do so at the same time ?
Right now I (one) can log into my (their) Axxess account without even any two-step verification required.

I'd like to know if you at Afri. are willing to implement this, and if so, how soon ?

This was recently reported ; surely SA nos. also affected by this though they only list what were probably 3 of the biggest leaked nos. of countries involved ? Got me thinking about locking down my logins all over, using stronger authentication methods.


Still, the massive leak of 419 million Facebook users’ phone numbers presents an incredible security risk for those users. SIM-hacking is becoming a more common way of targeting users for identity theft, and all a bad actor needs is a person’s phone number and some basic information that could be gleaned from social engineering.
 
I've searched this forum, via Google search, and also Afri. Help - https://help.afrihost.com/topic/clientzone , but don't come across the info. I'm looking for.

Far as I'm aware, SMSs are the only way to receive OTPs from you at Afrihost ; much like some of the banks and other websites as well.

Is it possible for you at Afrihost to add additional two / 2nd step verification options for signing into the ClientZone, as SMS's are vulnerable, more so than any other way/s from what I understand. Like for eg., using Google Authenticator (that would be my preference) or even an option to send the OTPs to the email address signed in with or an alternative email address ?

If you get something like this sorted out on your platform, maybe you can get Axxess (part of your Co. group) to do so at the same time ?
Right now I (one) can log into my (their) Axxess account without even any two-step verification required.

I'd like to know if you at Afri. are willing to implement this, and if so, how soon ?

This was recently reported ; surely SA nos. also affected by this though they only list what were probably 3 of the biggest leaked nos. of countries involved ? Got me thinking about locking down my logins all over, using stronger authentication methods.

Not sure if I fully understand, but I know we do offer Google Sign-In now for ClientZone. You should also be able to set your OTP to be sent by email. You'll need to set that in ClientZone.
 
What about business users? We have an Afrihost account that we use for business and at least 3 different people need access to the account, 2 techies and our finance person. Ever since the OTP has been enforced it has been a nightmare to allow other people to access the account.
 
What about business users? We have an Afrihost account that we use for business and at least 3 different people need access to the account, 2 techies and our finance person. Ever since the OTP has been enforced it has been a nightmare to allow other people to access the account.

You could use the email facility in that sense and set up systems or access to receive the mails.
 
Not sure if I fully understand, but I know we do offer Google Sign-In now for ClientZone. You should also be able to set your OTP to be sent by email. You'll need to set that in ClientZone.

If I login to ClientZone, under :
My Account (which is most reasonable to assume what you've outlined above is where these things can be changed, then) ---> Access Details - underneath it says "Change your login credentials", there are 3 options, to change :
Primary Email Address , Update ClientZone Password & Expire Login Links.

Please advise where in "Preferences" (or elsewhere in the ClientZone ?) I should click on, to make use of "Google Sign-In" and / or change to OTP to be sent by e-mail (only?) because I'd love to avoid using SMS for logging in, as much as possible.

The latest re SIM / SMS issues (from 12th Sept 2019) :


Security researchers have disclosed today an SMS-based attack method being abused in the real world by a surveillance vendor to track and monitor individuals.

"We believe this vulnerability has been exploited for at least the last 2 years by a highly sophisticated threat actor in multiple countries, primarily for the purposes of surveillance."

Researchers described this attack as "a huge jump in complexity and sophistication" compared to attacks previously seen over mobile networks and "a considerable escalation in the skillset and abilities of attackers."
 
If I login to ClientZone, under :
My Account (which is most reasonable to assume what you've outlined above is where these things can be changed, then) ---> Access Details - underneath it says "Change your login credentials", there are 3 options, to change :
Primary Email Address , Update ClientZone Password & Expire Login Links.

Please advise where in "Preferences" (or elsewhere in the ClientZone ?) I should click on, to make use of "Google Sign-In" and / or change to OTP to be sent by e-mail (only?) because I'd love to avoid using SMS for logging in, as much as possible.

The latest re SIM / SMS issues (from 12th Sept 2019) :

Scroll down to the bottom where is says "Social Accounts" - you can link your Google or Facebook accounts for login purposes.
 
Top
Sign up to the MyBroadband newsletter
X