<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why hasn't EE enabled 2FA on MyEE accounts? in Security</title>
    <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1308654#M9642</link>
    <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/153893"&gt;@Funk&lt;/a&gt;&amp;nbsp;I would not hold your breath, I raised this issue with them back in March 2021 and they still have done nothing to implement this.&lt;/P&gt;&lt;P&gt;It is a disgrace.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.ee.co.uk/t5/Security/2FA-Google-Authenticator-for-EE-log-in/m-p/1039989#M5634" target="_blank"&gt;https://community.ee.co.uk/t5/Security/2FA-Google-Authenticator-for-EE-log-in/m-p/1039989#M5634&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Oct 2023 10:59:14 GMT</pubDate>
    <dc:creator>JustinUK</dc:creator>
    <dc:date>2023-10-03T10:59:14Z</dc:date>
    <item>
      <title>Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1302546#M9572</link>
      <description>&lt;P&gt;I see several years-old posts asking about 2FA - why hasn't this been implemented yet?&amp;nbsp; A simple username/password combo is NOT good enough.&lt;/P&gt;&lt;P&gt;Come on EE - this is 'security 101' stuff.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2023 23:28:37 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1302546#M9572</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2023-09-24T23:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1302933#M9575</link>
      <description>&lt;P&gt;Hi &lt;SPAN&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/153893"&gt;@Funk&lt;/a&gt;&lt;/SPAN&gt;,&lt;/P&gt;
&lt;P&gt;We have strict security measures in place to protect your account. You can view our privacy policy here: &lt;A href="https://ee.co.uk/eeprivacycentre/ee-privacy-policy" target="_blank" rel="noopener"&gt;https://ee.co.uk/eeprivacycentre/ee-privacy-policy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 12:45:42 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1302933#M9575</guid>
      <dc:creator>James_B</dc:creator>
      <dc:date>2023-10-03T12:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1303770#M9590</link>
      <description>&lt;P&gt;James,&lt;/P&gt;&lt;P&gt;Whatever security measures EE / BT have put in place are obviously inadequate. I highlighted this issue several years ago now and nothing has been done to rectify this blatant hole in security.&lt;/P&gt;&lt;P&gt;Daily I get many phishing attempts from scammers pretending to be EE on the phone offering me upgrades and incentives. I report these to 7726 but not everyone is as tech savvy as me, some are going to fall for it.&lt;/P&gt;&lt;P&gt;MFA should be a option for all who are security conscious. It creates a barrier for any potential hacker who has discovered my username and password without my knowledge. It also locks the account from anyone pretending to be me on the phone / in the shop attempting a SIM swap.&lt;/P&gt;&lt;P&gt;When I look at my security, it all starts with my Mobile and ISP accounts as this is such a key part of any system, along with email, banking, utility providers etc. These all need locking and the fact I cannot lock my EE/BT mobile and broadband accounts in this day and age is most annoying.&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Justin&lt;/P&gt;&lt;P&gt;PS: here is a nice little video showing how we are at risk -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=lc7scxvKQOo&amp;amp;t=33s" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.youtube.com/watch?v=lc7scxvKQOo&amp;amp;t=33s&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PPS By the way what I am asking for is full MFA (Hard Token e.g. YubiKeys, Google Authenticator etc) not SMS text based where codes are sent to the mobile. This is easily hacked if they have access to your phone.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 13:26:52 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1303770#M9590</guid>
      <dc:creator>JustinUK</dc:creator>
      <dc:date>2023-09-26T13:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1306782#M9633</link>
      <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/224807"&gt;@James_B&lt;/a&gt;&amp;nbsp;You're wrong - and the link you've posted doesn't even actually cover anything regarding site login security/protection. It's frankly not good enough.&amp;nbsp; Perhaps you could ask some other folks with some actual security knowledge to take a look, hmm?&lt;/P&gt;&lt;P&gt;I work in IT and sell security solutions; the implementation of&amp;nbsp;&lt;EM&gt;robust&lt;/EM&gt;&amp;nbsp;2FA for ANY site/login is an absolute must.&amp;nbsp; And for goodness' sake if EE ever decides to implement even basic site security please DO NOT make it SMS-based - it MUST be using a separate authenticator app (ideally one that us as users can choose) or a physical key (such as YubiKey etc).&lt;/P&gt;&lt;P&gt;Any site login should be protected with 2FA - please sort it out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: I see that&amp;nbsp;@JustinUK understands the issue too, at least there's someone else in the room who realises the importance of this.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Oct 2023 01:36:06 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1306782#M9633</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2023-10-01T01:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1308638#M9641</link>
      <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/224807"&gt;@James_B&lt;/a&gt;&amp;nbsp; - James, please can you confirm that this has been escalated to a team with the knowledge and ability to take action on this?&lt;/P&gt;&lt;P&gt;Not having 2FA isn't acceptable when it comes to the security of login credentials.&amp;nbsp; Even my SMARTY account has basic 2FA.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 10:47:54 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1308638#M9641</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2023-10-03T10:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1308654#M9642</link>
      <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/153893"&gt;@Funk&lt;/a&gt;&amp;nbsp;I would not hold your breath, I raised this issue with them back in March 2021 and they still have done nothing to implement this.&lt;/P&gt;&lt;P&gt;It is a disgrace.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.ee.co.uk/t5/Security/2FA-Google-Authenticator-for-EE-log-in/m-p/1039989#M5634" target="_blank"&gt;https://community.ee.co.uk/t5/Security/2FA-Google-Authenticator-for-EE-log-in/m-p/1039989#M5634&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 10:59:14 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1308654#M9642</guid>
      <dc:creator>JustinUK</dc:creator>
      <dc:date>2023-10-03T10:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1309601#M9644</link>
      <description>&lt;P&gt;I've made it an official complaint.&amp;nbsp; I have very little confidence it'll make any difference but at least it's on record.&lt;/P&gt;&lt;P&gt;It shouldn't have to fall to customers to be requesting their mobile provider enables a fairly basic level of site security.&amp;nbsp; IF my login credentials were somehow compromised, a threat actor would have access to my account which would allow them to get a&amp;nbsp;copy of my bill which includes:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Name&lt;/LI&gt;&lt;LI&gt;Home address&lt;/LI&gt;&lt;LI&gt;EE account number&lt;/LI&gt;&lt;LI&gt;My mobile number&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;They would also have half of my bank account number and full sort code, the date of my DD and - somewhat incredibly - my date of birth (why is this even required to be visible on my EE account?).&lt;/P&gt;&lt;P&gt;That all of this is NOT adequately protected with 2FA is&amp;nbsp;unconscionable.&amp;nbsp;&amp;nbsp;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/224807"&gt;@James_B&lt;/a&gt;&amp;nbsp;- it's all well and good saying "..we have strict security measures..." but you actually DON'T.&amp;nbsp; If someone gains access to my account, they already have all of the above personally-identifiable information.&amp;nbsp; I use a unique and lengthy password which is basic common sense, however many people don't; using the same email address and password across multiple sites is sadly still all-too-common amongst those who are not tech-savvy.&lt;/P&gt;&lt;P&gt;Why is this not being taken seriously?&amp;nbsp; Can someone from EE please step up, admit it's not good enough and do something to sort it?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 16:37:33 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1309601#M9644</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2023-10-04T16:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1312132#M9700</link>
      <description>&lt;P&gt;The silence is deafening....&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 16:00:21 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1312132#M9700</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2023-10-09T16:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1313807#M9725</link>
      <description>&lt;P&gt;It'll be interesting to see what the outcome of the official complaint is.&amp;nbsp; I've not heard anything yet - and to be honest I'm not holding my breath either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Come on EE, be better.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 11:22:34 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1313807#M9725</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2023-10-12T11:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1317818#M9784</link>
      <description>&lt;P&gt;It's been a couple of weeks now. Seems EE couldn't give a f*ck.&amp;nbsp; Security concerns aren't going away.&lt;/P&gt;&lt;P&gt;Can ANYONE representing EE respond...?&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2023 12:28:46 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1317818#M9784</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2023-10-22T12:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1326162#M10032</link>
      <description>&lt;P&gt;Thanks EE.&lt;/P&gt;&lt;P&gt;Another month down the line; good to know you don't give a f**k.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2023 12:44:42 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1326162#M10032</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2023-11-12T12:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1351649#M10919</link>
      <description>&lt;P&gt;Am still waiting for a response on this one, EE...&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 08:54:50 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1351649#M10919</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2024-01-26T08:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1352238#M10957</link>
      <description>&lt;P&gt;Here's what happens when you don't have 2FA enabled and rely solely on passwords:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theregister.com/2024/01/27/microsoft_cozy_bear_mfa/" target="_blank"&gt;https://www.theregister.com/2024/01/27/microsoft_cozy_bear_mfa/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 17:18:06 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1352238#M10957</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2024-01-27T17:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1354428#M11043</link>
      <description>&lt;P&gt;Still can't believe this has not been implemented nor any comms regarding this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 18:19:29 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1354428#M11043</guid>
      <dc:creator>Scottatsea</dc:creator>
      <dc:date>2024-02-02T18:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1356380#M11113</link>
      <description>&lt;P&gt;It's appalling. I hope it doesn't take a security breach for them to finally wake up and protect our data properly.&lt;/P&gt;&lt;P&gt;EE - this is p*ss-poor.&amp;nbsp; F*&lt;SPAN&gt;cking sort it the **bleep** out.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 20:07:49 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1356380#M11113</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2024-02-08T20:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1356508#M11118</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/153893"&gt;@Funk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have strict security measures in place to protect your account. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For full information please see our privacy policy here:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://ee.co.uk/eeprivacycentre/ee-privacy-policy" target="_blank" rel="noopener noreferrer" data-di-id="di-id-10bfee4c-58ba47f6"&gt;https://ee.co.uk/eeprivacycentre/ee-privacy-policy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Leanne.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 08:48:48 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1356508#M11118</guid>
      <dc:creator>Leanne_T</dc:creator>
      <dc:date>2024-02-09T08:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1356543#M11119</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/224806"&gt;@Leanne_T&lt;/a&gt;&amp;nbsp;many thanks for the reply.&lt;/P&gt;&lt;P&gt;I have seen a similar response a few times and to clarify it DOES NOT address the questions here. It does open more questions....you talk about encryption, is that at rest and / or in transit? What level is that encryption may I ask. The remainder looks like it's standard privacy / GDPR stuff. Can you confirm if 2FA / MFA is on the EE roadmap? If it is, then great, if not, read on please.&lt;/P&gt;&lt;P&gt;However none of the above addresses the issue in hand here. The processes you suggest are NOT enough. Your organisation really needs to look at modern attack methods and defend against them appropriately as other credible organisations - and many significantly smaller than EE currently do. 2FA or MFA really should be enabled quickly. If it is not, despite what is claimed in your response, you will be unconsciously exposing your organisation and your customers to unacceptable risk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;With respect, I find it something of a matter of wonder that this privacy policy (note the name, you should really be pointing us to a security policy) is repeatedly regurgitated in response, yet does not come close to the security that you imply. PLEASE ensure that those that make decisions are aware of this. If they really do not understand what the point is here, there is plenty of information available out there - and similarly, I would be happy to point your security team in the right direction if they were so inclined to have a conversation re this pressing issue.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please do all you can to quickly escalate and ultimately resolve this. This is real and companies globally are hurriedly implementing this fundamental security feature. EE is a good network in my experience, this is a major achilles heel however that will be exploited competitively and probably (but hopefully not - although hope is not a robust defence) by those with malicious intent. I appreciate these forum conversations can descend into verbal turmoil quickly, I just hope you see this for what it is - a genuine cry for help and a friendly yet firm offer of globally accepted advice.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 10:08:00 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1356543#M11119</guid>
      <dc:creator>Scottatsea</dc:creator>
      <dc:date>2024-02-09T10:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1356564#M11120</link>
      <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/224806"&gt;@Leanne_T&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I initially raised this issue way back in March 2021, to date no Multi Factor Authentication options exist to log into your EE account creating a huge security flaw.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Peoples broadband and mobile phone is a goldmine for any bad actors out there, you keep regurgitating the same old Privacy Policy which is NOT related in any way to this security flaw.&lt;/P&gt;&lt;P&gt;I ask that you please take some steps to secure our online accounts, if requested by the customer to do so. Leaving accounts open to attack like this is just not acceptable in this day and age.&lt;/P&gt;&lt;P&gt;Original Post on this issue:&lt;BR /&gt;&lt;A href="https://community.ee.co.uk/t5/Security/2FA-Google-Authenticator-for-EE-log-in/m-p/1039989#M5634" target="_blank" rel="noopener"&gt;https://community.ee.co.uk/t5/Security/2FA-Google-Authenticator-for-EE-log-in/m-p/1039989#M5634&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 10:50:54 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1356564#M11120</guid>
      <dc:creator>JustinUK</dc:creator>
      <dc:date>2024-02-09T10:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1357044#M11127</link>
      <description>&lt;P&gt;&lt;A href="https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1356508/highlight/true#M11118" target="_blank"&gt;https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1356508/highlight/true#M11118&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You EE folks keep posting this but all it does is demonstrate that unfortunately you have no idea what you're talking about.&lt;/P&gt;&lt;P&gt;EE accounts are fundamentally insecure when protected by only an email address and password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;THIS IS NOT ACCEPTABLE.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Feb 2024 17:00:29 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1357044#M11127</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2024-02-10T17:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why hasn't EE enabled 2FA on MyEE accounts?</title>
      <link>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1360027#M11191</link>
      <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/224806"&gt;@Leanne_T&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/224807"&gt;@James_B&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to help make this all a little more real for you.&amp;nbsp; THIS is why we need more security on our EE accounts (and NOT using SMS but a proper, separate 2FA app or key!):&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theguardian.com/money/2024/feb/19/sim-swap-how-your-bank-account-can-be-emptied-by-phone" target="_blank" rel="noopener"&gt;https://www.theguardian.com/money/2024/feb/19/sim-swap-how-your-bank-account-can-be-emptied-by-phone&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Within a week, the fraudsters were able to bypass O2’s security checks. Once in control, they ordered an e-sim (a virtual, rather than physical, version of a sim card), which O2 sent as a QR code. Once activated, they had, in effect, taken over her number.&amp;nbsp;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;EM&gt;“I lost all O2 services around lunchtime, but thought that a mast was faulty in the area,” says Nevin. “I now know that the fraudsters – in effect using my phone – called my bank and were able to answer security questions, such as what town I was born in, which is on my passport, or my address, which is on my driving licence.&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;EM&gt;“They then got Barclays to send a one-time passcode to the phone. With that, the bank allowed them to transfer £2,400 from my savings into my current account, then make a payment of £3,500 to a Halifax bank account. This cleaned me out and took me to my overdraft limit.”"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;This shows how easily fraudsters can piece together bits of information (many of which are publicly-available such as 'address') or may have been compromised in a previous hack/attack (such as town of birth/date of birth) to compromise phone and bank accounts. The rewards for a successful hack can be highly lucrative for fraudsters.&lt;/P&gt;&lt;P&gt;Now - will SOMEONE with half a brain at EE PLEASE make our account (and personal data security) a priority?&amp;nbsp; Will it take a data breach or hack for you to do something about it?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;O2 - offers 2FA for customer accounts&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Vodafone&amp;nbsp;- offers 2FA for customer accounts&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Three&amp;nbsp;- offers 2FA for customer accounts&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;GiffGaff&amp;nbsp;- offers 2FA for customer accounts&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Tesco Mobile - offers 2FA for customer accounts&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Smarty&amp;nbsp;- offers 2FA for customer accounts&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;............EE - thinks a 'privacy policy' page on their website = security and has no idea what 2FA is.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 13:03:46 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Security/Why-hasn-t-EE-enabled-2FA-on-MyEE-accounts/m-p/1360027#M11191</guid>
      <dc:creator>Funk</dc:creator>
      <dc:date>2024-02-20T13:03:46Z</dc:date>
    </item>
  </channel>
</rss>

