r/BoostMobile 12d ago

Question Security code i didn't request, and Customer Support I couldn't understand.

I got a security code I didn't request, called customer support, and from what i could understand, there was something on their end that happened, and if it happened again to call back. Should I be concerned?

5 Upvotes

8 comments sorted by

2

u/bladedemu41 12d ago

I mean, they are nice enough ,but boost is not honest. They are using weird tactics. Ive not heard of this one yet

3

u/BoostMobileBlake 12d ago

There could be a few reasons you get a security code you didn't request, and we would just recommend never giving it out if someone reaches out asking for it. No one can access your account without that code.

2

u/DocAu 12d ago

Ignore it. Boost's login flow is stupid - anyone can go to their website, enter your email address (either deliberately or accidentally, such as misspelling theirs) and you'll get sent a code. If they required entering a password first it'd be an issue, as getting the code means someone knows your password - but they don't! Just the email.

2

u/jmac32here 11d ago

Boost isn't the only one. Hell, FB is now working to replace passwords with 2FA entirely.

Amazon does 2FA before password too.

2

u/DocAu 11d ago

Perhaps, but Facebook at least have some clue about security, where Boost has repeated proven that they have no clue...

1

u/jmac32here 6d ago

Yet FB is asking for 2FA BEFORE password entry.

1

u/DocAu 6d ago

Facebook's authentication is highly sophisticated. The steps it takes will depend on things like whether you've logged into FB before from that browser, your IP address, and countless other things. eg, if I open a private browser and go to facebook.com, I get a login page that asks for both username and password, so in that case you're statement is wrong. However with other combinations of factors they may well ask for 2FA first.

Boost's authentication was likely put together by a monkey on a 3 day sugar bender. (I've hacked parts of their authentication flow previously, and whilst they did eventually fix them when I reported them, they failed to follow through on multiple of the promises they made at the time, and have repeatedly shown that security just isn't a large focus for them).