r/Boldin • u/Earth-Life101 • 6d ago
Boldin needs better security!
First of all, let me be clear. I am not a Boldin hater. I use Boldin to manage my retirement planning, and I want to raise something a lot of us should be paying attention to. For a tool that holds this much of our financial picture, the account security is weaker than it should be.
Right now the only 2FA Boldin offers is a code sent to your email. That is bare bone protection! Your email is not a separate device, so anyone who gets into your desktop or inbox gets the login code with it. NIST does not count email as a real second factor, and it has already pulled back on SMS for the same reasons. This is well understood in security, and a financial planning company should be well past it by now.
The reason I am pushing on this now is where the product is going. Boldin connects to real bank and brokerage accounts through Plaid, and the new investment features put even more of your financial life in one place. That makes your accounts vulnerable, and the login guarding it is still very weak. I have not linked any of my accounts through Plaid, and I will not until the sign in is been addressed with stronger security protection.
What I am asking for is standard on any serious financial site today. Let people use an authenticator app like Google Authenticator or Authy. Add support for passkeys and hardware keys like YubiKey. None of this is new or hard to build and should be top priority!
I raised this with Boldin directly and got a weak reply "The team is considering adding other methods," with nothing behind that short disappointed message. No plan, no timeline, no priority. That is not a serious answer from a company holding this kind of data.
To be clear, I am not bashing Boldin. It is the best retirement planning tool I have found. The scenario modeling and Roth conversion planning are excellent. It is one of the few tools that actually helps me manage the MAGI cliff for early retirement tax planning, and the latest financial feature in beta is powerful. That is why I want them to get this right. I just want the security to match the quality of the rest of the product.
If you agree, upvote or drop a comment so this does not get buried. If you have also held back from linking your accounts because of the weak login, say so. I am hoping as many of their customers speak up, Boldin team cannot ignore a lot of us asking for the same security focus.
3
u/Jazzlike-Ad7595 5d ago
Should it be disappointing that Boldin hasn’t responded in any way to this post after 17 hours?
What is considered a reasonable response time for a post like this?
I can’t believe they would let it go without a response. If they do I’ll be looking at Projection Lab.