<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Account Security in Security</title>
    <link>https://community.ee.co.uk/t5/Security/Account-Security/m-p/1624124#M17146</link>
    <description>&lt;P&gt;It's absolutely rubbish if you use multiple systems&lt;/P&gt;&lt;P&gt;ie: I've just logged in my computer using my passkey, it then wants to send me a passcode via sms which is valid for 20 minutes.&lt;/P&gt;&lt;P&gt;This is a poor implementation of the system. I've used my passkey I shouldn't then need to have my mobile with me to receive a passcode just to then finally login to the website, it defeats the object of using passkeys.&lt;/P&gt;&lt;P&gt;EE have made it more convoluted than what it should be&lt;/P&gt;&lt;P&gt;Not only that both SMS and EMAIL are not secure ways of getting 2FA that is why it is recommended to use passkeys as it emliminates the use of these. Even Microsoft no longer use SMS for authenication if passkeys are setup. So why is EE using passkeys with insecure methods for account security&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jun 2026 17:58:34 GMT</pubDate>
    <dc:creator>walkerx</dc:creator>
    <dc:date>2026-06-17T17:58:34Z</dc:date>
    <item>
      <title>Account Security</title>
      <link>https://community.ee.co.uk/t5/Security/Account-Security/m-p/1624094#M17144</link>
      <description>&lt;P&gt;why does the ee system make it so hard for someone to update passkeys, after being enforced on your account and passkeys not being synced across devices causing problems&lt;/P&gt;&lt;P&gt;What is the point of forcing this if they are just going to send code via sms anyway to do what you want&lt;/P&gt;&lt;P&gt;SMS is insecure, so is email for sending codes, so why not allow users to fallback to password and use a 2FA app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 15:50:42 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Account-Security/m-p/1624094#M17144</guid>
      <dc:creator>walkerx</dc:creator>
      <dc:date>2026-06-17T15:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Account Security</title>
      <link>https://community.ee.co.uk/t5/Security/Account-Security/m-p/1624118#M17145</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/2054535"&gt;@walkerx&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Passkey works fine on my device. I use my phone to log in.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You only tend to receive a text if you're using a VPN from my experience or abroad.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 17:27:28 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Account-Security/m-p/1624118#M17145</guid>
      <dc:creator>Northerner</dc:creator>
      <dc:date>2026-06-17T17:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Account Security</title>
      <link>https://community.ee.co.uk/t5/Security/Account-Security/m-p/1624124#M17146</link>
      <description>&lt;P&gt;It's absolutely rubbish if you use multiple systems&lt;/P&gt;&lt;P&gt;ie: I've just logged in my computer using my passkey, it then wants to send me a passcode via sms which is valid for 20 minutes.&lt;/P&gt;&lt;P&gt;This is a poor implementation of the system. I've used my passkey I shouldn't then need to have my mobile with me to receive a passcode just to then finally login to the website, it defeats the object of using passkeys.&lt;/P&gt;&lt;P&gt;EE have made it more convoluted than what it should be&lt;/P&gt;&lt;P&gt;Not only that both SMS and EMAIL are not secure ways of getting 2FA that is why it is recommended to use passkeys as it emliminates the use of these. Even Microsoft no longer use SMS for authenication if passkeys are setup. So why is EE using passkeys with insecure methods for account security&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 17:58:34 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Account-Security/m-p/1624124#M17146</guid>
      <dc:creator>walkerx</dc:creator>
      <dc:date>2026-06-17T17:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Account Security</title>
      <link>https://community.ee.co.uk/t5/Security/Account-Security/m-p/1624128#M17147</link>
      <description>&lt;P&gt;I sometimes only have to use the passkey and others it’s the passkey and then the text. &amp;nbsp; Yes texts are not secure, but you’re using the passkey first so even without using the passkey you ain’t gonna get the text so it’s still secure as you have to passkey first. &amp;nbsp; &amp;nbsp;&lt;BR /&gt;I notice it does improve until I wipe out my IP addresses via my account profile on here then it’s passkey and text for a while then it’s just the passkey.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 18:42:26 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Account-Security/m-p/1624128#M17147</guid>
      <dc:creator>Chris_B</dc:creator>
      <dc:date>2026-06-17T18:42:26Z</dc:date>
    </item>
  </channel>
</rss>

