Two Factor Authentication for ALL STs environments?

IFTTT has just added optional 2FA for their accounts. If you want it, you turn it on, otherwise your account still just uses a password. I like this approach:

4 Likes

Any update on this being on the roadmap for a future release? Would love to see Authy or something similar used for MFA.

how about getting things that are not working working first and working reliably before adding more functionality? all for 2fa, but get the basics down first

2 Likes

Disagree. Iā€™d start wtih security. Itā€™s a little unnerving when you see how much data is available via IDE with only a password as protection.

Re-awakening because this is becoming increasingly important to me.

1 Like

Bright Eyed and Bushy Tailed.

Totally - when do we get two factor for SmartThings? Wanting this more and more every day.

1 Like

One of the biggest gaps I see is the lack of ability to have two factor authentication (2FA). Two factor is one of the best ways to ensure security. I have put barriers to my deployment, like no video or microphone in my house, to ensure that it gets hacked, the information they get is limited. At the very least we should have the ability to add 2FA to the IDE and when new accounts are create or account information is changed.

It could utilize a third party 2FA like googleā€™s 2FA, which is free, but we really need to ensure that something that can be so powerful is secure and 2FA is one of the best ways to do that. I highly recommend 2FA on all financial accounts and anywhere security is a must.

2FA is on the Feature Request list for ActionTiles. The only implementation we are currently considering is to link it to your Gmail account (possibly otherā€™s like GitHub, Twitter, and/or Facebookā€¦) because those logins can already be associated with 2FA.

3 Likes

Hi, Iā€™ve had some issues with my Yale Conexis appearing to randomly lock and unlock. I am unable to see if my ST account has been accessed from any unrecognised IPs (showing if Iā€™ve been hacked) but ST app shows it wasnā€™t a keytag or manual unlock. It appears to have come from ST.

Changing password, but unnerving that I can neither confirm if I have been hacked nor increase security. If I havenā€™t been hacked obviously there is an issue with the lock but again impossible to verify given the data I am able to access.

If I had been hacked Iā€™d have thought theyā€™d mess with more than just the one lock (lights? Other locks?)

The likelihood that you have been ā€œhijackedā€ in any form is extremely unlikely.

However, if you think your SmartThings Account is possibly compromised by a "hijackerā€™ just:

  1. Change your SmartThings password.
  2. Contact Support@SmartThings.com to request all Access Tokens be invalidated for your Account.
  3. Uninstall ALL SmartApps from your Location.
1 Like

I agree. Just seems bizarre the lock would lock and unlock itself at random on some days. Unfortunately I am away until January so canā€™t check if it is actually locking or just a false reading.

1 Like

YO!!!
please up security aka 2FA.
We are in 2021 ffsā€¦!
/thomas

You are responding to a post which is 4 years old, and a lot has changed in that time. Specifically SmartThings does now have 2FA for both the app and the web interface. This happened after Samsung migrated all SmartThings users to Samsung accounts. So itā€™s now there if you want it.

In fact, in the ST mobile app, you will receive a pop up suggesting you enable 2FA every 7 days if you donā€™t already have it turned on. :sunglasses:

:rofl:

No pop ups or settings in the new ST app on my android phone, about 2fa.
/thomas

Once you set it up on your Samsung account, it will apply to all SmartThings sign ons.

https://account.samsung.com/membership/guide/2step/gate

If you havenā€™t gotten the pop up yet, you should within a week, itā€™s a 7 day cycle.

Okay, iā€™ll wait and seeā€¦ thanks :slight_smile:

You can turn it on now if you want at the link I gave above, the settings are in your Samsung account profile. Since a Samsung account is now required for ST, that covers it.

done, thank you! :slight_smile:

1 Like

Any update on 2FA for actiontiles since this post 5 years ago?