Better balance of security and convenience for logging in?
Hi. I find the QBO login security / session timeout setup to be a bit on the aggressive side. I have already extended the "Sign me out if inactive for" setting to 3 hours, but I still find myself going through this process multiple times per day from the same static business IP address and browser when using QBO:
- Load login screen
- Click continue after confirming username is correct
- Check "I'm not a robot"
- Find all the bikes or traffic lights or crosswalks, sometimes multiple rounds (5-10 clicks each)
- Enter password
- Enter 2FA code
- Wait for various spinners and redirects and company info to load, sometimes another 10+ seconds of assets loading and Javascript calls and screen redraws. (Very fast internet connection on a modern computer.)
All in all it's about 30-60 seconds of my day, but it becomes a bit tedious over time. I appreciate the attention to security, but I would think that the presence of an expired session cookie and/or previous logins from the same IP just hours before might allow me to at least avoid the captcha/puzzle solving step multiple times per day, and maybe to increase the time between requiring 2FA.
Just me?
