Update -Improved Security- 2FA changes

Moso2023
3 Posts
User

3Posts

5Kudos

0Solutions

Re: Update -Improved Security- 2FA changes

Hi MYOB,

 

Just another post regarding MYOB login concerns. Three of us from the same company, sitting in the same room,  have completely different MYOB AR login processes since the upgrade that threw MYOB security out of whack. One of us is not required to sign in at all - just open MYOB and they are in - zero security which is a concern. One of us has not had their process changed at all, just the password required - normal security which is great. One of us now has to enter their email address and password everytime we they open MYOB AR - excessive & not needed security which is annoying. 

 

What would Goldilocks do?

cmagaya
2 Posts
User

2Posts

1Kudos

0Solutions

Re: Update -Improved Security- 2FA changes

I like to demand that the 2FA Authentication be re-introduced. I dont see this as an improvement! This I honest reckon is not appropriate especially for your clients who make online payments. Anyone that may access to any computer will have access to payment approvals and so forth. Please do something about it immediatedly!

echokim
Experienced Cover User
77 Posts
Experienced Cover User
Australia
Experienced Cover User

77Posts

6Kudos

0Solutions

Re: Update -Improved Security- 2FA changes

Trust this device for 30 days has disappeared.

I am having to sign in and password EVERY DAY ???

echokim
Experienced Cover User
77 Posts
Experienced Cover User
Australia
Experienced Cover User

77Posts

6Kudos

0Solutions

Re: Update -Improved Security- 2FA changes

mine is the complete opposite.

I had no sign on at all   (work from home, remote area)

and now I have to sign on and password EVERY TIME ???

 

how can this be ???

TSGTanya
Trusted Cover User
255 Posts
Trusted Cover User
Australia
Trusted Cover User

255Posts

66Kudos

4Solutions

Re: Update -Improved Security- 2FA changes

I use a home pc for my bookwork and having to enter my email and password all the time is a pain. There is no option for me to "Trust this device for 30 days" or even an option to save email and password if I so desire.  Is something missing my end or is this just MYOB? Running MTOB Accountright

Judy01
Trusted Cover User
67 Posts
Trusted Cover User
Trusted Cover User

67Posts

4Kudos

2Solutions

Re: Update -Improved Security- 2FA changes

Your article says that you still allow the option to trust thgis device for 30 days. I di not have that option.

JillL1
Experienced User
47 Posts
Experienced User
Experienced User

47Posts

21Kudos

0Solutions

Re: Update -Improved Security- 2FA changes

@PriyaSelvaraj & other moderators - please note that I have had to go to a formal complaints process to get a clear, or at least clearer, answer on this.  Why?   

 

MYOB state - 

 

Please be advised customers should not be choosing the ‘File’ menu then ‘Exit’ as this has never been the intended correct sign out process for AccountRight. This simply closes off the software but doesn’t log a user out, unlike the process from the 'Services' menu.

 

If we choose File & exit or simply select the "x" then there is NIL security when we log back in within 12 hours.   MYOB are not listening to users and do not intend to change that.   No problem with no 2FA within the 12 hours as a default however the default of no seucirty via the two common ways of exiting a program is a clear security risk, and one that we as users have no control over.    In the instructions here  MYOB helpfully tell us "It’s good security practice to log out at the end of every session"  however we need to drill down at the bottom of that article to find out that we need to use the Services menu to do that.    

 

If MYOB are a serious Accounting Software provider, how about being a little more serious about security?    Back to basics - every time a file is accessed it needs a password!

melbdesk
Experienced Cover User
20 Posts
Experienced Cover User
Australia
Experienced Cover User

20Posts

28Kudos

0Solutions

Re: Update -Improved Security- 2FA changes

With regards to:

Please be advised customers should not be choosing the ‘File’ menu then ‘Exit’ as this has never been the intended correct sign out process for AccountRight. This simply closes off the software but doesn’t log a user out, unlike the process from the 'Services' menu.

I do not understand why if signing off by exit or X has never been the intended method, why then is it that it always worked before to let us sign out and be secure. I have been using MYOB for years and have only now just found out about using the services menu to sign out.  Also it took a week or two of everyone complaining that someone from MYOB mentioned this method of siging out.

PriyaSelvaraj
MYOB Moderator
311 Posts
MYOB Moderator
MYOB Moderator

311Posts

50Kudos

16Solutions

Re: Update -Improved Security- 2FA changes

Hey @JillL1 ,

 

Thanks for raising your concern and we do take the customer feedbacks seriously.

We understand your concern about security risk, and I would like to assure that our team is actively working on to improve the experience.     

I will personally ensure to pass on your feedback and  check whether our help article can be modified to clearly highlight the logout process.

 

Regards

Priya Selvaraj


MYOB Community Forum

Online Help| Forum Search| my.MYOB| Download Page

Did my answer help?

Accept it as a Solution
Leave a to tell others

CHutchinson
Experienced Cover User
14 Posts
Experienced Cover User
Australia
Experienced Cover User

14Posts

14Kudos

0Solutions

Re: Update -Improved Security- 2FA changes

@PriyaSelvaraj 

 

This is the first time i have even heard of "loggin out" through the Service tab.  I have worked on MYOB for so many years now and have never ever ever even been told that i need to do that.

 

In fact, if that is the case and we should not log out of MYOB (and backup each time) through the normal system either by X or "File" "Exit"....then why have we not had the security problem for years.

 

It has only been the last three months that the 2FA and the security "email and password" logging in has changed. And still, there is NO 2FA on log in no matter which way you sign out.

 

Cheryl Hutchinson

 

Didn't find your answer here?

Try using advanced search to find a post more easily Advanced Search
or
Get the conversation started and make a new post Start a Post