Getting push notifications with expired tokens - security?

I’m getting push notifications for characters with expired tokens - security issue?

What’s the purpose of expiring tokens if they do not get honored? BTW, this is major inconvenience that they expire.

I can’t figure out what you’re talking about.

Every once in a while, I’ll have to relog into my accounts in the launcher and have to go through 2FA again. But I’ve never seen any notifications for expired tokens or whatever. Are you talking about the 2FA codes that you get through your email? Yeah, they’re only good for like 15minutes or something. And they do that for security purposes. It’s a small inconvenience, but it’s a lot better than getting your accounts hacked.

Oh, I bet you’re talking about eve portal. Have you tried reauthenticating or whatever? Does the problem not go away, or they expiring extremely frequently?

Yes, this is EVE Portal category so the problem is with EVE Portal :slight_smile: The tokens are honored in UI (frontend) but seems they slip in the backend or from server, hence security issue. So I assume they expire in my phone but not on server side and I get notifications about events that include my chars that are not in app anymore (expired token).

As for general security. I’m 200% into 2FA/MFA and CCP does it pretty good except Singularity server when you get mail2FA. If I can accept the risk (I can remember tokens in EVE launcher on my secure machine) then why I can’t do that in EVE Portal? I assume that EVE Portal app is outsourced app but I should also expect the security is inline with “big app”.

The expiration of tokens and no option to remember it, irritates a lot of app users. Surely it can be done better that that.

@Developers want a bug report as if they were unaware of this, moreover EVE Portal seems abandoned

To the point that owner of restarted it after initial closure when EVE Portal was launched.

Hello! We recommend you to remove the character from the login list and re-add it again to see if the issue gets resolved.

The problem is: there is no character in the login list because of expired tokens in app :slight_smile:

But I’ll add them again and get back to you if the issue persists.

Note to self:

@CCP_Magician I’ve added all chars again. Now I get double push notifications for the same action.

Looks like this

Hello! Thanks for the feedback. Our dev team is aware of the issue and working on a fix. As a temporary solution, we recommend you to uninstall the APP and then have a fresh reinstall from Google Play. We sincerely apologize for any inconvenience this may have caused.