<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mandatory Two-Step Authentication (Verification) a Bad Idea in Arlo</title>
    <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1799471#M78189</link>
    <description>&lt;P&gt;A few days ago I was invited to a conference call with Arlo engineers and management who are responsible for implementing the 2FA solution.&amp;nbsp; Brevity isn't my strong suit but I'll try to be succinct:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;(as you have now seen), they confirmed that 2FA will not be enforced in October -- they are now targeting November.&amp;nbsp; I believe that this is largely so that they can find a solution for PC access.&amp;nbsp; Browser authentication was neither working properly, nor persistent.&amp;nbsp; They are aware of this issue and trying to find a solution that will be acceptable.&lt;/LI&gt;
&lt;LI&gt;As of our conversation, they were not planning to use "cookies" or any other non-persistent method for PC/browser trusted-device authentication (this is a very good thing and at least demonstrates that they understand the problem).&lt;/LI&gt;
&lt;LI&gt;They acknowledge that even with a working "trusted device" authentication, it will eventually need to be re-authenticated and could cause users to need to re-authenticate at the very worst time (e.g. while your house is being broken into).&amp;nbsp; Although this might only be an annual re-authentication, this should worry users.&amp;nbsp; I rent vacation properties and, while I was traveling in Africa, I was forced into the yearly 2FA for my account with VRBO.&amp;nbsp; I was unable to complete the authentication from abroad and was locked out of my account.&amp;nbsp; Subsequently, I was unable to send critical check-in information to my guests.&amp;nbsp; The takeaway?&amp;nbsp; Even if you think the current 2FA authentication is working for you, be prepared for nasty surprises at the very worst time.&lt;/LI&gt;
&lt;LI&gt;One question I had was: "What is the reason this is being pushed on us?"&amp;nbsp; I suggested that "it is obviously to protect Arlo from legal liability..".&amp;nbsp;&amp;nbsp;&amp;nbsp; No, they said.&amp;nbsp; Their position was that this is to protect our data (login information, remote access to cameras, stored video, etc.)&amp;nbsp; They did reassure that all data is encrypted and there is absolutely no way even for Arlo to access user passwords or user data including video.&amp;nbsp;&amp;nbsp; So, I call B.S. on their reason for pushing this out.&amp;nbsp; If it's to protect me from me, then 2FA needs to be a choice, not a mandate.&amp;nbsp; Despite their answer, I believe this is motivated strictly from a corporate CYA mandate.&lt;/LI&gt;
&lt;LI&gt;I brought up the desire to have local access and not rely on the cloud.&amp;nbsp; They are aware of this user desire but made no commitment.&lt;/LI&gt;
&lt;LI&gt;I brought up the desire to be able to view video streams from more than one device at a time.&amp;nbsp; They are aware of this common user request as well but made no commitment. &lt;/LI&gt;
&lt;LI&gt;I brought up that many users are using the Python API (see: &lt;A href="https://github.com/jeffreydwalter/arlo" target="_blank"&gt;https://github.com/jeffreydwalter/arlo&lt;/A&gt;) and that the 2FA will likely break this.&amp;nbsp; They seemed unaware of this and suggested it was probably using non-approved APIs.&amp;nbsp; I'm not familiar enough with the GitHub API -- perhaps someone else can comment -- does the GitHub API rely on a previously officially published Arlo API?&amp;nbsp; If so, a strong case can be made that Arlo needs to provide a solution such that this functionality continues to work.&amp;nbsp; At minimum, I sent them the link to the GitHub repository.&lt;/LI&gt;
&lt;LI&gt;I sent them a link to this forum so that they could read user feedback.&amp;nbsp; I didn't post for quite a few days after our conversation with hopes that they would address concerns directly.&amp;nbsp; The engineers I spoke did not seem to previously be aware of this thread.&lt;/LI&gt;
&lt;LI&gt;My own issue was that the iPad we are using would force me to authenticate every darn time I picked it up -- even if I didn't log off.&amp;nbsp; They said that probably meant I didn't make it a "trusted device".&amp;nbsp; I still don't quite understand this -- I thought the fact that I went through the 2FA hassle would make it a trusted device automatically.&amp;nbsp; Apparently there is another step that I missed.&amp;nbsp; I don't have access to the iPad for another few days to dig deeper but they have offered another call to help me with it if it's not working.&lt;/LI&gt;
&lt;LI&gt;I think that it would be helpful if we in the forum here come up with a list of use-cases that will fail once 2FA is forced on us. (For example, I feel that if I'm forced to re-authenticate at some random time within 365 days, that is a complete failure if I'm using the system for security monitoring due to risk of getting randomly locked out). &lt;/LI&gt;
&lt;LI&gt;Note that the management &amp;amp; engineers that I spoke with seemed entirely competent, understood the technology, were working hard on solutions, and sincerely wanted to solve the issuesdd.&amp;nbsp; I get the feeling that this whole fiasco is being driven from a higher management who put down an edict "thou shall implement 2FA" when what they should have done was to identify specific threats and problems and use-cases and allow the technical team to find solutions that solve the problems without hobbling the product.&amp;nbsp; I feel for them.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I'm not sure if the above was helpful at all.... but it captures my interaction with the Arlo team.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2020 16:27:20 GMT</pubDate>
    <dc:creator>OttToyBoy</dc:creator>
    <dc:date>2020-11-04T16:27:20Z</dc:date>
    <item>
      <title>Mandatory Two-Step Authentication (Verification) a Bad Idea</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760863#M74807</link>
      <description>&lt;P&gt;Making this mandatory is an exceedingly bad idea since it will slow down authentication and when it breaks—and it occasionally &lt;EM&gt;will&lt;/EM&gt;—it will prevent access completely.&amp;nbsp; At least give the end-user the option of deciding how much protection to require for the account.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 14:51:28 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760863#M74807</guid>
      <dc:creator>ChrisKay</dc:creator>
      <dc:date>2020-03-07T14:51:28Z</dc:date>
    </item>
    <item>
      <title>Two-step verification</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760876#M74810</link>
      <description>&lt;P&gt;As suggested in the recent email, I set up two-step verification on my Android phone. But every time I log in from my desktop and laptop, I have to go through the authorization. There is no way to make them trusted devices. I cannot understand why this is so difficult. I will be turning off the two-step until this is resolved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Instead of implementing a poorly executed security method, it's time to get rid of Flash in the browser!&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 16:51:14 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760876#M74810</guid>
      <dc:creator>Retired_Member</dc:creator>
      <dc:date>2020-03-07T16:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Two-step verification</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760890#M74811</link>
      <description>&lt;P&gt;Having issues too with SMS, but email works.&lt;/P&gt;
&lt;P&gt;But every time , come on!&lt;/P&gt;
&lt;P&gt;But, to be honest, I'm not going to use email every time I access via the web... it's a pain ( since I do 80% of access via web )&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 18:55:55 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760890#M74811</guid>
      <dc:creator>TomMac</dc:creator>
      <dc:date>2020-03-07T18:55:55Z</dc:date>
    </item>
    <item>
      <title>two step verificaton</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760911#M74827</link>
      <description>&lt;P&gt;I just read the email about the 2step verification and did it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know if I am going to have to do this EVERYTIME we sign in? Seems like it will be a BIG time waster when you need to get on in a hurry.&amp;nbsp; Our phones are not conjoined to our bodies like most people these days and seems like this is going to be an unnecessary hurdle to jump when we need to go 'live"&amp;nbsp; quickly.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 21:30:17 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760911#M74827</guid>
      <dc:creator>ksss11</dc:creator>
      <dc:date>2020-03-07T21:30:17Z</dc:date>
    </item>
    <item>
      <title>2FA needs additional options for Arlo to remain accessible to me and others.</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760915#M74809</link>
      <description>&lt;P&gt;While 2FA is a worthwhile addition, the current implementation, once required, will make Arlo useless at work for me. Ring has already made it mandatory, and has ruined Ring for me. Here's why.&lt;/P&gt;
&lt;P&gt;You can have a code sent via text. I work on a secure enclave and cannot have my cell phone in the building at all, so this is not an option.&lt;/P&gt;
&lt;P&gt;You can have a code sent to your registered e-mail. This is of course my personal e-mail, and this is blocked at work for security reasons. I cannot access my personal e-mail. (keeps people from clicking bad links in their e-mail. Work e-mail is highly filtered)&lt;/P&gt;
&lt;P&gt;So, I will no longer be able to access Arlo at all from work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are options that could be implemented. 1) offer to use a different verified phone number, but the code would have to be delivered via voice.&amp;nbsp; Synthesized is fine. 2) Allow additional e-mail addresses to be entered and selected. This would not let me enter any e-mail, just select from 1 or 2 that were pre-vetted. Some systems even ask for the e-mail and then compare it to any on file. If it matches one the code is sent there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Without one of these additional options, when 2FA becomes mandatory, Arlo will be useless to me for the majority of the day.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can tell you I am not unique in not being able to have a cell phone, or access personal e-mail at work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 22:39:43 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760915#M74809</guid>
      <dc:creator>SJohannsen</dc:creator>
      <dc:date>2020-03-07T22:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: Two-step verification</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760933#M74812</link>
      <description>&lt;P&gt;Clearly they have rolled this out before its been fully baked.&amp;nbsp; I too get prompted to verify two step verification every time.&amp;nbsp; Its not saving my device.&amp;nbsp; Please fix this before you force everyone to 2 step.&amp;nbsp; I want to use it, but will turn it on after you have fixed the defect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 04:01:04 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760933#M74812</guid>
      <dc:creator>Kevin_In_Ky</dc:creator>
      <dc:date>2020-03-08T04:01:04Z</dc:date>
    </item>
    <item>
      <title>Two-step verification</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760953#M74814</link>
      <description>&lt;P&gt;Two-step verification is a great security measure for many applications, but will be very problematic for some Arlo users like myself. Unless you can set the verification up so that more than one device receives the code, this will not work for many people. Most households have more than one person in them who need awareness when a device detects movement. Same-account users in different places at the same time need to all be able to see the code, or this will not work. Not a great solution for this tech unless you can set the account up to send the verification code to more than one device.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 13:03:06 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760953#M74814</guid>
      <dc:creator>Schemer</dc:creator>
      <dc:date>2020-03-08T13:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Two-step verification</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760954#M74815</link>
      <description>&lt;P&gt;Several threads on this, here's one;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.arlo.com/t5/Community-Feedback/Two-step-verification/m-p/1760890#M4454" target="_blank"&gt;https://community.arlo.com/t5/Community-Feedback/Two-step-verification/m-p/1760890#M4454&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 13:17:00 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760954#M74815</guid>
      <dc:creator>TomMac</dc:creator>
      <dc:date>2020-03-08T13:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: two step verificaton</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760979#M74828</link>
      <description>&lt;P&gt;Yes this is a waste of time.&amp;nbsp;&amp;nbsp; For example on my PC, I have to login TWICE to get get logged in once.&amp;nbsp; Why, Arlo still requires the use of Flash player, which all modern day browsers require permissions to use Flash Player.&amp;nbsp; That means I log in select permission to use Flash Player, I get logged out immediately and have to log in again to actually start a live recording. &amp;nbsp; Now with 2step verification, I will have to receive 2 authorization codes before I can get logged in.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sad state.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 16:34:13 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1760979#M74828</guid>
      <dc:creator>storgeman</dc:creator>
      <dc:date>2020-03-08T16:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Mandatory Two-Step Authentication (Verification) a Bad Idea</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761009#M74808</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.arlo.com/t5/user/viewprofilepage/user-id/356007"&gt;@ChrisKay&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Making this mandatory is an exceedingly bad idea&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I agree, and I hope they reconsider.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 20:58:19 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761009#M74808</guid>
      <dc:creator>StephenB</dc:creator>
      <dc:date>2020-03-08T20:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Two-step verification</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761015#M74816</link>
      <description>&lt;P&gt;I think mandatory 2FA is a mistake (even if they actually get it to work properly).&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 21:22:28 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761015#M74816</guid>
      <dc:creator>StephenB</dc:creator>
      <dc:date>2020-03-08T21:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: two step verificaton</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761016#M74829</link>
      <description>&lt;P&gt;yes this is not user friendly anymore.&amp;nbsp; My bank and some other sites automatically register this device just once and I do not have to do this.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 21:28:49 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761016#M74829</guid>
      <dc:creator>ksss11</dc:creator>
      <dc:date>2020-03-08T21:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: two step verificaton</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761092#M74830</link>
      <description>&lt;P&gt;I agree. When on my iMac, and want to see a camera quickly, this 2 step stinks. On my iPhone, I can use face recognition but not on the iMac. I don't like this.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 12:09:21 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761092#M74830</guid>
      <dc:creator>Puterwade</dc:creator>
      <dc:date>2020-03-09T12:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Two-step verification</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761098#M74813</link>
      <description>&lt;P&gt;I had to disable 2 step because Arlo required using every time. I will be replacing Arlo with Simply Safe if this problem is not fixed by the time the roll out at the end of the year.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 12:40:35 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761098#M74813</guid>
      <dc:creator>Chris53</dc:creator>
      <dc:date>2020-03-09T12:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Mandatory Two-Step Authentication (Verification) a Bad Idea</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761310#M74840</link>
      <description>&lt;P&gt;I agree strongly.&amp;nbsp; I'm a huge fan of 2FA but am really disappointed by the Arlo implementation.&amp;nbsp; I was excited to enable it this morning but turned it off after 30 minutes or so because it is really flawed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Everyone seems to be in agreement that the main flaw is that the web-based login requires you to re-authenticate every single time.&amp;nbsp; That's a nuisance because the sessions are so short-lived.&amp;nbsp; For example this morning I logged in, left the tab for a little while (roughly 15-20 minutes) and the session was already expired.&amp;nbsp; The solution is to identify the device (app, browser, etc) as "trusted" for some period like 30 days.&lt;/LI&gt;
&lt;LI&gt;It's also problematic that the primary 2FA approach is SMS, since that's known to be easier to hack than other approaches (like Authy / Google Authenticator / etc).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If Arlo keeps makes 2FA mandatory without fixing these problems, I will definitely consider replacing our Arlo cameras with more Simplisafe cameras (we have a mix of both).&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 16:33:39 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761310#M74840</guid>
      <dc:creator>jimmccabe</dc:creator>
      <dc:date>2020-03-10T16:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Mandatory Two-Step Authentication (Verification) a Bad Idea</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761328#M74843</link>
      <description>&lt;P&gt;Please:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let the users decide, if they want to have 2FA or not. In addition to the arguments listed already in the messages before, I have integrated my Arlo Cams and Lights into my Home Automation system by making Web calls against the Arlo API. I know that this is a use case which might not be officially supported, however it is working great and it is one of my reasons to use Arlo and not another cam. Certainly a mandatory 2FA will break that integration as I cannot log in unattended. Maybe, some kind of application password might solve that issue (as it is normaly done with other providers using 2FA, like e.g. Google etc.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The other reason is that it is time intensive if you need to put in your second factor every time you login. And you always need to be able to receive the second factor so what you are doing if you want to login from a remote computer without having access to your smartphone?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It really would be a bad idea to force users to use 2FA, so PLEASE re-think your decision again!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 18:06:46 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761328#M74843</guid>
      <dc:creator>MichaelUrs</dc:creator>
      <dc:date>2020-03-10T18:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Mandatory Two-Step Authentication (Verification) a Bad Idea</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761352#M74846</link>
      <description>&lt;P&gt;2FA is a good idea as we need to be secure. However, most systems that require 2FA also have a way to get a device (or app) specific passcode that can be entered and used without having to re - enter it every time.&lt;/P&gt;
&lt;P&gt;Please add this functionality before this is mandatory.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 00:55:24 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761352#M74846</guid>
      <dc:creator>JohnV81</dc:creator>
      <dc:date>2020-03-11T00:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Mandatory Two-Step Authentication</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761485#M74859</link>
      <description>&lt;P&gt;Mandatory 2FA is a bad idea.&amp;nbsp; Here's why;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a growing wireless camera business.&amp;nbsp; When time matters, 2FA hinders a response.&amp;nbsp; For example, when viewing an active situation of any kind (fire, water damage, etc.) or equipment failures (HVAC, chillers, boilers, etc); taking time to execute 2FA will delay and possibly inhibit a response.&amp;nbsp; Business clients prefer simplicity over two-step verification; They want live video that's easy to access.&amp;nbsp; Mandatory 2FA is not that.&amp;nbsp; As such, we would drop Arlo because of this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Further, I don't see a need for simpler use cases.. a simple construction site or animals in the wild (&lt;A href="https://www.arlo.com/en-us/products/arlo-go/default.aspx" target="_self"&gt;Arlo Go website).&lt;/A&gt;&amp;nbsp; We should have the option; but a blanket requirement puts undue hardship on users.&amp;nbsp; If you purchase a house, your not required to install 5 locks on your front door.&amp;nbsp; It's your house, you secure it how you want.&amp;nbsp; Same applies for cameras and portals purchased from Arlo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have demand for many Arlo cameras.&amp;nbsp; In the end, I'll have to switch to another solution; turning down all Arlo wireless devices and LTE coverage tied with it, and request refunds as this isn't what was originally promoted.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Arlo is a broad spectrum and multi-use.&amp;nbsp;&amp;nbsp;This would put financial hardship on my business. Please reconsider mandatory 2FA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 18:24:26 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761485#M74859</guid>
      <dc:creator>BP2</dc:creator>
      <dc:date>2020-03-11T18:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Mandatory Two-Step Authentication (Verification) a Bad Idea</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761798#M74888</link>
      <description>&lt;P&gt;I agree mandating 2FA is a bad idea. 2FA is generally good and Arlo can implement it BUT I believe accounts should have the ability to turn it off or Arlo should support 'app passwords' like Google and most other 2FA providers do. If this becomes mandatory my family will lose much of the benefit of Arlo's flexibility.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this gets implemented I will need to cancel my Arlo smart subscription.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Mar 2020 16:23:03 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1761798#M74888</guid>
      <dc:creator>k_glasik</dc:creator>
      <dc:date>2020-03-14T16:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Mandatory Two-Step Authentication (Verification) a Bad Idea</title>
      <link>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1762001#M74915</link>
      <description>&lt;P&gt;"Bad Idea" is an understatement.&amp;nbsp; With the Flash run around it takes me a couple of minutes to check a camera. I try to log in, but have to authorize Flash *each* *time* and that makes it so that my session expires and I have log in again and wait for an authorization code again.&amp;nbsp; What a mistake.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 18:55:59 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Mandatory-Two-Step-Authentication-Verification-a-Bad-Idea/m-p/1762001#M74915</guid>
      <dc:creator>friuliveneto</dc:creator>
      <dc:date>2020-03-16T18:55:59Z</dc:date>
    </item>
  </channel>
</rss>

