Frequency of Auto-Logout / 2FA

exceladdict

Established Member
Joined
Mar 26, 2014
Posts
4,907
Qantas
Platinum
Virgin
Silver
Hi @support,
Could we consider extending the auto-logout period to 60 or 90 days, or make it customisable?
I use AFF across a few trusted devices and after turning on 2FA I seem to be logged out quite frequently.
 
I’ve not seen a setting that enables me to customise 2FA but I can certainly take a look. Generally, I would expect more frequent logouts through 2FA - otherwise it would seem less useful a feature to enable in the first place.

It would appear others share both your views and my views, but it’s not an option I can select. There is an add on… but that requires spending money and testing it doesn’t break other add ons.

 
I’ve not seen a setting that enables me to customise 2FA but I can certainly take a look. Generally, I would expect more frequent logouts through 2FA - otherwise it would seem less useful a feature to enable in the first place.

It would appear others share both your views and my views, but it’s not an option I can select. There is an add on… but that requires spending money and testing it doesn’t break other add ons.

Thanks for checking. The main use case for 2FA for my sake (perhaps different for others) is to prevent the account being hacked by a third party if my password and email were both compromised; figure it's less likely to be compromised via a lost trusted device where an auto-logout would assist (as many corporate policies employ).
 
Elevate your business spending to first-class rewards! Sign up today with code AFF10 and process over $10,000 in business expenses within your first 30 days to unlock 10,000 Bonus PayRewards Points.
Join 30,000+ savvy business owners who:

✅ Pay suppliers who don’t accept Amex
✅ Max out credit card rewards—even on government payments
✅ Earn & transfer PayRewards Points to 10+ airline & hotel partners

Start earning today!
- Pay suppliers who don’t take Amex
- Max out credit card rewards—even on government payments
- Earn & Transfer PayRewards Points to 8+ top airline & hotel partners

AFF Supporters can remove this and all advertisements

Thanks for checking. The main use case for 2FA for my sake (perhaps different for others) is to prevent the account being hacked by a third party if my password and email were both compromised; figure it's less likely to be compromised via a lost trusted device where an auto-logout would assist (as many corporate policies employ).

This!

In fact, every 30 days I need to enter a new MFA token but I haven't actually been logged out.

Most websites will allow you to not require entering the MFA token again as an option. That is, as long as you're on the same computer and browser and haven't cleared the site cookies. The idea of MFA isn't to secure a login session should you lose your device that you're logged in on, but rather to prevent someone accessing the site should your password be compromised.

While re-entering every 30 days is a PITA, I can't imagine it will be worth the site owners spending money on it. Although it does discourage people from using MFA.
 

Become an AFF member!

Join Australian Frequent Flyer (AFF) for free and unlock insider tips, exclusive deals, and global meetups with 65,000+ frequent flyers.

AFF members can also access our Frequent Flyer Training courses, and upgrade to Fast-track your way to expert traveller status and unlock even more exclusive discounts!

AFF forum abbreviations

Wondering about Y, J or any of the other abbreviations used on our forum?

Check out our guide to common AFF acronyms & abbreviations.

Currently Active Users

Back
Top