New login security measure?

KAT4DISNEY

Glad to be a test subject
Joined
Mar 17, 2008
Messages
28,417
Yesterday after a session timed out and I went to log back in I was asked for verification code that had been sent to my email. Never had gotten that one before just the standard emails of a new sign in (on the devices I always use) or back a year or so ago when they would say you needed to reset your password which then changed the password across all Disney accounts. I won't go into my thoughts of how insecure that is to have the same password for every single account nor that you can change them all by changing one. :rolleyes:

The code surprisingly worked fine but I must confess my thoughts turned towards stop worrying about my DVC login so much and fix the actual website functionality.

Others have gotten this code?
 
Yea i got the code yesterday at one point.

Got our tix for our March trip and was trying to make park res. What a nightmare that was. Still not sure how i finally got it to work. It kept giving an error when trying to load the park selection bit. Combo of clicking random days and the retry button to load finally got it to work and I got our park res done.

Long story short, Disney IT stinks.
 
On and off (maybe 2% of logins) for several months now. So annoying, especially when I was stalking my Xmas reservation and logged in 1-2 dozen times /day (wish that were an exaggeration, but 🤪).
 
I have gotten it for DVC and have gotten it for logging in at WDW as well. Probably 3 or 4 times total in the past few years.
 

If you use an ad blocker you may get this more frequently. I finally had to disable mine on Disney websites.
 
Yesterday after a session timed out and I went to log back in I was asked for verification code that had been sent to my email. Never had gotten that one before just the standard emails of a new sign in (on the devices I always use) or back a year or so ago when they would say you needed to reset your password which then changed the password across all Disney accounts. I won't go into my thoughts of how insecure that is to have the same password for every single account nor that you can change them all by changing one. :rolleyes:

The code surprisingly worked fine but I must confess my thoughts turned towards stop worrying about my DVC login so much and fix the actual website functionality.

Others have gotten this code?
I have since the beginning and still do randomly (usually when I login from a different computer or browser)

They did this for two reasons:
1. For account protection, if the system thinks its not you either due to IP address changes, session cookie/browser changes, etc.. it can prompt for this to make sure it is you. The login is not DVC, its the SSO (single sign on) system for the umbrella Disney go.com site for all their web properties. The code verification was done when Disney+ came out and lots of people where getting hacked.
2. Stop the website scrappers, if the site detects a different login (from say a scraper site with your login info that you gave them), it will do a code prompt to your email in which the scrapping site cant get the code (unless you give it to them or they have access to your email) and thus cannot login.
 
/
I have since the beginning and still do randomly (usually when I login from a different computer or browser)

They did this for two reasons:
1. For account protection, if the system thinks its not you either due to IP address changes, session cookie/browser changes, etc.. it can prompt for this to make sure it is you. The login is not DVC, its the SSO (single sign on) system for the umbrella Disney go.com site for all their web properties. The code verification was done when Disney+ came out and lots of people where getting hacked.
2. Stop the website scrappers, if the site detects a different login (from say a scraper site with your login info that you gave them), it will do a code prompt to your email in which the scrapping site cant get the code (unless you give it to them or they have access to your email) and thus cannot login.

I had been logged in and it timed out. Logging back in from the exact same location, exact same computer. I understand the theories but Disney "security" doesn't actually seemed based on any of them but instead is more of a "we've heard websites do this so lets throw it out there".
 
I have gotten it for DVC and have gotten it for logging in at WDW as well. Probably 3 or 4 times total in the past few years.
I’ve gotten for both sties a lot more times than this in past year. I get it at least twice a month. Only the DCL site doesn’t seem to send me one.
 
I'm now surprised that this was the first time I ever needed the code!
 
I’ve gotten it several times. Apparently people are even getting it when trying to reserve a G+ LL or purchase an individual LL…..and by the time they get logged in the slot is gone…..
 



















DIS Facebook DIS youtube DIS Instagram DIS Pinterest

Back
Top