Leon M
Member
- Joined
- Aug 20, 2018
- Messages
- 11
- Reaction score
- 2
On Thursday I logged into my account or dashboard as MWEB's calls it, and I discovered to my shock and horror that when you login via you username (primary email address) and password, MWEB sends you the OTP, not only to your cellphone, but also to the very same email address you are logging in with. So if you login to your account with [email protected], then MWEB also sends you an email with the OTP to [email protected]. So if your email account was hacked, which happened to me twice this year, the hacker can simply go to your account, login with your email address and password, and then wait for MWEB to kindly send the OTP. Viola, your whole account stolen. So I phoned MWEB and the agent could actually reproduce this behaviour and admitted that is a major security risk. But wait, there's more. So MWEB does allow you to activate 2 step verification for your email address, which should make it safer. However, if you enable it, the IMAP password they provide you with doesn't work with anything other than their own mail portal. So in my case I can no longer receive emails on the go on my iPhone and iPAD since the IMAP password doesn't work. The agent even told me that they are still working on it. So I cannot use 2 step verification to make my email account more secure, and at the same time when I use that email address and password to login into my main account, MWEB emails the OTP to email address. MWEB sent me an email confirming that this is by design and that they deliberately send your OTP to you cellphone and login email address simulataneously with no option in your account settings to disable it or change the email address to something else to serve as a recovery email address.