Add 2-Factor Authentication/Multi-Factor Authentication to App [edited] (2 Merged Votes)

124»

Comments

  • Please deploy OTP Multi-factor (Google Authenticator, Authy, etc.) as soon as possible. Quicken's existing multi-factor methods (SMS, phone, or email) are readily compromised. This is a finance app after all. Quicken is not following NIST best practices and this puts Quicken customer information at risk of being stolen.

  • +1 for this feature.

  • beans
    beans Member
    edited April 2024

    Rocket Money supports MFA [removed - accuracy]. Maybe you guys can copy paste their like 3 lines of code to support this PLEASE. FOR THE LOVE OF GOD. SMS sucks as a second factor.

  • ajbopp
    ajbopp Member ✭✭✭✭
    edited April 2024

    It's not the same parent company, as far as I can tell. I'm pretty sure Rocket is from Intuit. Quicken is from...Quicken.

    Also, it's not three lines of code. It's hundreds. Plus extensive database changes. Plus hundreds of hours of testing. It's a big, big deal. Not that I don't support this change, but SMS doesn't suck so much that it warrants prioritizing this over, say, watchlist projection accuracy.

    Anthony Bopp
    Simplifi User Since July 2022
    Money talks. But all my paycheck ever says is goodbye

  • DG1993
    DG1993 Member
    edited May 2024

    Any update on this feature request?

  • RobWilk
    RobWilk Superuser ✭✭✭✭✭

    Not only is it not there yet, but on new logins (*cleared cookies) it's no longer doing text message verification as it was.


    Rob Wilkens - RobWilkens.com

  • kash80
    kash80 Member ✭✭

    I tried with a different browser and it did ask for text message.

  • RiversideKid
    RiversideKid Member ✭✭✭

    I use 1password which is a HUGE convenience as I only need one password for all of my financials. the app keeps a really strong password and my 2fa challenge for most financial sites. I know there is some security built into the Simplifi by Quicken app, but I would feel more comfortable if Simplifi used passkeys with an app generated multi factor authentication.

    I sign in from multiple computers, often computers that were just built as I am a PC Tech. I am RARELY asked for anything except the username and password. (I also clean my pc with a script every time I close the browser so that the computer looks fresh each time I open a browser.) I would hate to think that Simplifi will allow login from any computer just because my history indicates that I often sign in from computers that have no history.

    Lots 1-2-3 (1984-1988)
    MYM (Managing Your Money by Andrew Tobias) for DOS (1988-1994)
    Quicken for Windows user since (1994-2024) (Still wanting to IMPORT!)
    Simplifi by Quicken since (2023-Today)

  • Can we please get an update or a time-frame on when MFA will be implemented into Simplifi? The fact that anything tied to financial data and does NOT have MFA is astonishing. Considering this thread started in 2019 and it is now 2024 with no ETA on a core security function to protect customer data does not make me feel comfortable.

  • Mountain Man
    Mountain Man Member ✭✭

    I realize the Simplifi is the new kid in the block. But please add more security, just SMS/TEXT pin code is not enough. can we include MFA Google Authenticator or Microsoft auth, etc.. Also Email pin as an option would be great too.
    Also if you had an option to send email notification or even SMS whenever we login to let us know so and so/from some where just logged in, that would be great. Since all our financial data is centralized in one place as you can see it makes sense to be little freaked out ;)

  • madmoondog
    madmoondog Member ✭✭

    Would be nice to see an update on this considering security should be number 1 on the list of things an app like this embraces.

  • kash80
    kash80 Member ✭✭

    My SO and I share the login and having 2FA with SMS sucks as one is dependent on the other person being around. Having MFA using an authenticator app is a no brainer. It would be great if the the app team can provide an update on this.

  • SRC54
    SRC54 Superuser ✭✭✭✭✭

    I don't want it frankly. It is already enough for me that I have to reply to a text message whenever I download the app again. But it's ok with me as long as we can turn it off.

    Steve
    Quicken Simplifi (Safari & iOS) Since 2021
    Quicken Classic (MacOS) Since 2009
    MS Money (1991-2009) and Dollars & Sense (1987-1991)

  • pst
    pst Member ✭✭✭

    As Simplifi starts asking to review the app on a grade of 0 to 10 via a popup, I suggest you all factor in the fact that - for an app that aggregates all your personal finances - SMS 2FA is absolutely not enough. I voted on my satisfaction accordingly.

  • CR Fort Nine
    CR Fort Nine Member ✭✭

    @Humanleg86 I'd agree except in 2024 most financial institutions are still using SMS and email 2FA if they have anything at all. Really disappointed in the financial sector's stance on security. 🤦‍♂️

  • kash80
    kash80 Member ✭✭

    I work for a financial product company that deals with banking data. Our clients started requesting us to support 2FA even though none of our product services are exposed to the open internet. We started building it and are able to deploy it within 3 months supporting many forms of MFA, and we are a small company. A company as big as quicken should have been able to implement this feature by now. I have constantly argued with product owners who prioritize new features over security improvements as there's no ROI on the latter, until the crap hits the fan.

  • 1280x720
    1280x720 Member
    edited April 16

    2025 and we still don't have this in a financial information app? this is crazy.

  • Glennms
    Glennms Member

    PLEASE ADD AUTHENTICATOR MFA TO THE APP!

  • I am new to Quicken as it was highly recommended. I started to set up my information but found that Quicken only offers antiquated 2FA using email, SMS and phone calls. These are susceptible to hacking and SIM swapping. Since these vulnerabilities are well known and since the information we are uploading is highly personal I was expecting to see OTP 2FA ( I use Microsoft Authenticator and Google Authenticator) and I was also expecting to see software and hardware passkeys offered (I use Yubikey).

    I don't understand why the more secure 2FA methods are not offered as they have been around for a long time.

    I see many comments on this subject here in the community and it looks like Quicken is not interested in protecting their customers data.

    I am not interested in using the older methods and though Quicken is an amazing product, I am seriously considering cancelling my account.

  • pst
    pst Member ✭✭✭

    It would be good to learn from Coaches or whoever has ownership of Simplifi why this is not on the roadmap. Are there technical blockers? Or is it that they think SMS is fine?

  • KP_9
    KP_9 Member ✭✭✭✭

    Quicken team,

    For years, companies and consumers have been warned by NIST, CISA, the FBI, and other trusted entities that SMS-based MFA is weak - NIST removed it as a recommended method 9 years ago. Authenticator apps generating revolving tokens are better (still not foolproof), while new methods like FIDO passkeys are recommended path forward.

    Financial institutions in the US are increasingly being required to implement stronger MFA requirements than the old SMS method by evolving regulations (GLBA Safeguards rule, NYDFS Part 500, etc.) and Quicken should be aligning to these practices even if it's not technically a covered entity under the regs; Simplifi holds our sensitive financial data, and now, with your new A2A feature that enables the actual movement of funds, it's imperative you are keeping pace with modern cybersecurity best practices like phishing-resistant MFA.

    Short term, please add support for Authenticator App-based OTP MFA instead of SMS and then fast-follow with passkey support. A product that involves connections into users' banking & investment institutions needs to follow MFA best practices, period. Continuing to offer us only a known-weak MFA solution that's been warned against for nearly a decade sends a bad signal to your customer base about Quicken's priorities in protecting our data.

  • There absolutely needs to be a secondary verification appliance built into the login system.

    I do not feel safe even having my bank information here, let alone my retirement and investment accounts without it. It might be that I should use YNBA instead.

    +infinity votes to add MFA to the login.

  • pr@dk
    pr@dk Member

    How is this acceptable for a finance app not to have proper MFA support in 2025? It's a big mistake switching to your app. It worked initially and got a SMS at least, and for any new logins from a different workstation or a different phone, it's not forcing MFA at all. Speaking with support hasn't been productive either and they are just saying they are aware and working on resolution. Please fix MFA first and add app based MFA instead of SMS.

  • Dognose
    Dognose Member ✭✭✭

    Another month ticked by without this issue being addressed. The strange part to me is that Quicken wants users to use this product for Account to Account (A2A) transfers.

    Some people are comfortable with SMS I suppose.

  • colearseneault3
    colearseneault3 Member
    edited October 9

    Simplifi Personal, Simplifi Business and Personal, and Quicken LifeHub rely solely on SMS, phone calls, and email codes for verification. This security model might have worked back when “multi-factor authentication” and “cloud computing” were still buzzwords, but those days are long gone.

    Since NIST (2017), CISA (2022), and the FFIEC (2021) all formally recognized SMS, PSTN, and email codes as “restricted” or phishable, every major standard-setting body has warned against relying on them for high-risk systems. These outdated methods are unsafe for products that connect to or store sensitive personal and financial data since they remain vulnerable to SIM-swaps, call interception, social engineering, and phishing.

    This is especially alarming for LifeHub, which is marketed as a secure storage platform for personal IDs, insurance policies, powers of attorney, tax returns, and more; where a single email breach could expose everything in that vault.

    Nearly every direct competitor has moved beyond SMS/Calls/Email only authentication; including personal finance, accounting, and password management platforms. Quicken remains one of the few major financial platforms that has not implemented modern, phising-resisent MFA.

    This concern has been raised repeatedly over several years, yet I still cannot find a clear roadmap or implementation timeline. Without phishing-resistant MFA (Passkeys, Hardware Security Keys, or at least App-Based Authenticators - TTOP), users remain exposed to attacks that no encryption can stop. Several colleagues of mine in the accounting and financial professions have advised clients to transition to platforms that adhere to current industry security standards and actively prioritize user protection (Industry Standard MFA/Access Controls).

    Can you provide an update on the development timeline for implementing these baseline security protocols across Simplifi and LifeHub platforms? Would love to continue using both the Simplifi Business and Personal and LifeHub platforms!

  • New user here also requesting a more secure OTP MFA authentication solution. Email/SMS MFA is inadequate. Thanks.