Call for Industry standard 2FA

Your help page has declared that you will implement 2FA via SMS for months now, with no progress.

I will not install your app for this. I only allow world-class organisations such as google or Microsoft to handle security matters on my phone. Maybe eventually you will rank to that level, but until then insisting on a home grown app is poor.
I am not interested in the other features your app may have.

The alternative industry standard is to use SMS, which all the other banks use.

I’m sure we customers would welcome an official response that InvestEngine take security more seriously.

Hello!

Currently, you can download the app, set up 2FA and then you will be able to use 2FA via SMS. After that, you won’t need to use an app for 2FA.

If you have any questions or require any further assistance, please do not hesitate to reach out to us via email support@investengine.com

Thank you for the indication this is possible.

For me to have confidence in apps, the workflow needs to be flawless. Although I got this to function, it is not flawless.

The following is missing from the help pages, posting as it might help others.

After installing the app, and setting up.

The web site login will then send 2FA authorisation requests to the app on the phone. I can find no option to default this to SMS, instead a workaround is necessary.

Click “Didn’t receive” to access the SMS screen, each time you want to log in via 2FA…

This gives the option…

The need to perform a workaround every time feels like a lack of transparency.
It’s OK I suppose, but what further undermines confidence is that when I repeated the workflow to test it, I found a bug…

Now that 2FA is enabled, I logged out of the app and then logged in to it again.
And found that the app required me to pass 2FA to log into the app, by sending a 2FA to the app that I’m trying to log in to.

This could be better. No guesses should be necessary.

(Apologies for multiple replies, I could only attach 1 image per post).

Hi @CalmEddie - thanks for this! I’ve passed it on to the team to have look through.