20-02-2025 19:52 - edited 20-02-2025 20:08
20-02-2025 19:52 - edited 20-02-2025 20:08
Hi everyone, I've just noticed something when logging in to the Community on my smartphone which concerns the OTP (One Time Password).
I logged in, I entered my password, it then took me to the OTP security check page and asked me to select my mobile phone number to send a OTP code via text, like it usually does. I DIDN'T. Instead I pressed the Home button, on Google Chrome, it took me back to the Google Homepage. I then went into 'Bookmarks'. I selected the same O2 Community bookmark as I have done for many years, and suddenly I'm back into my O2 account, not having entered any password or OTP code at all. I have effectively broken into my own MyO2 account bypassing the text code completely, despite it asking me for it. If the hackers had your password they can effectively log in bypassing the OTP code. It didn't work on the MyO2 accounts page, but it has worked this evening when logging in to this Community website.
I draw this to your attention. The OTP needs looking at.
@Cleoriff you had problems with your grandsons MyO2 account hacked into. It could be that OTP failed, as it's failing me tonight. I've made several attempts to log into my account and have been successful at each occasion bypassing entering the OTP despite it supposed to protect my account.
on 20-02-2025 20:21
If you're logged in to the community it's the same as it's all linked.
on 20-02-2025 20:05
I've been doing the same and bypassing the OTP for the last 12 months.
Only works on previously used devices though as it sets cookies.
20-02-2025 20:13 - edited 20-02-2025 20:22
20-02-2025 20:13 - edited 20-02-2025 20:22
Is it supposed to do that? It does seem a bit silly that I can do that. If a hacker had your log in details they could log in and bypass the text code? I've cleared the cookies on my web browser and it still does it.
It would be useful if you had the option to choose OTP and could switch it off, like on my Microsoft account, rather than it flung upon us. Only to find we can bypass it! It's a bit like finding the school gates are locked and going round the back way into school through the wire fence at the back! (We've all done that!)
on 20-02-2025 20:21
If you're logged in to the community it's the same as it's all linked.
on 20-02-2025 20:24
on 20-02-2025 20:24
on 20-02-2025 20:26
For sure @koala321
on 20-02-2025 23:30
on 20-02-2025 23:30
on 21-02-2025 15:27
on 21-02-2025 15:27
Hi @Cleoriff maybe you should complain about it to O2's Head Office. I think MyO2 is supposed to ask for the OTP everytime you log in. I agree, it didn't ask to start with , but now it does, or at least, is supposed to. Sorry you had problems with it. I hope you and your grandson get it all sorted 😃
21-02-2025 18:57 - edited 21-02-2025 18:57
21-02-2025 18:57 - edited 21-02-2025 18:57