Jump to content

Cannot close MFA prompt after clicking on Email Address section in Account Settings

Oshino Shinobu

Browser, version and OS: Chrome 95.0.4638.69, Windows 10 64 Bit.

 

Steps to reproduce/what were you doing before it happened?

Open account settings and click on the Email Address section.

 

What happened?

MFA prompt immediately appears and there is no way to close it or move to any other settings section without navigating to a different URL.

 

What did you expect to happen?

Either have a button to close it or only prompt for MFA when submitting the request to change email address, not as soon as you click on the Email Address section as it prevents you from clicking to the other settings sections if you accidentally click on Email Address like I did.

 

Link to a page where it happened, if applicable: 

https://linustechtips.com/settings/email/

 

Screenshots of the issue, if applicable: 

image.thumb.png.be235fbda1a8f8273859a2cddc0bc354.png

 

Any other relevant details:

Obviously, MFA needs to be enable for this to happen. I am using Google Authenticator, not sure if this is the same when using other MFA methods. 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Thats expected behavior to prevent account hijacking and an extra layer of security. In order to reach this page, you have to enter your 2FA code. Only way around this is to navigate to a different page, or enter the code. 

Community Standards | Fan Control Software

Please make sure to Quote me or @ me to see your reply!

Just because I am a Moderator does not mean I am always right. Please fact check me and verify my answer. 

 

"Black Out"

Ryzen 9 5900x | Full Custom Water Loop | Asus Crosshair VIII Hero (Wi-Fi) | RTX 3090 Founders | Ballistix 32gb 16-18-18-36 3600mhz 

1tb Samsung 970 Evo | 2x 2tb Crucial MX500 SSD | Fractal Design Meshify S2 | Corsair HX1200 PSU

 

Dedicated Streaming Rig

 Ryzen 7 3700x | Asus B450-F Strix | 16gb Gskill Flare X 3200mhz | Corsair RM550x PSU | Asus Strix GTX1070 | 250gb 860 Evo m.2

Phanteks P300A |  Elgato HD60 Pro | Avermedia Live Gamer Duo | Avermedia 4k GC573 Capture Card

 

Link to comment
Share on other sites

Link to post
Share on other sites

33 minutes ago, Skiiwee29 said:

Thats expected behavior to prevent account hijacking and an extra layer of security. In order to reach this page, you have to enter your 2FA code. Only way around this is to navigate to a different page, or enter the code. 

Just a button that takes you back to https://linustechtips.com/settings/ seems like it would make sense, rather than locking the page, or only prompt once you've hit save. 

 

You can unlock the page by just removing the popup element, so don't see how this is really any additional layer of security (ban the F12 key /s). I haven't entered my MFA code here but the page is unlocked by just removing the popup element. If I hit save, it prompts for MFA as you'd expect (which again, locks the page with no way to back out). 

 

image.thumb.png.2e589d9f13e1b4c8fef815b5f2f203a1.png

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, Oshino Shinobu said:

You can unlock the page by just removing the popup element, so don't see how this is really any additional layer of security (ban the F12 key /s). I haven't entered my MFA code here but the page is unlocked by just removing the popup element. If I hit save, it prompts for MFA as you'd expect (which again, locks the page with no way to back out).

If you try to submit, it will fail unless you completed the MFA prompt, so it's not just client side security. I agree that there should be a cancel option though.

HTTP/2 203

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, colonel_mortis said:

If you try to submit, it will fail unless you completed the MFA prompt, so it's not just client side security. I agree that there should be a cancel option though.

Yeah that's what I'd expect. MFA should obviously be required to change the email address for the account. 

 

The problem is that it appears as soon as you click on the Email Address section and cannot be cancelled without navigating (outside of the web page, so enter a new URL) or entering your MFA code. It shouldn't really ask for MFA until you actually hit save and even when it does, it should still have a cancel option. The prompt locking the page doesn't serve as any layer of security as you can just remove it to unlock it again, so seems an option to cancel should be there instead. 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×