Skip to main content

Longer password share expiration

I feel dirty asking for weaker security… but… I fear 24 hours on the share link is not long enough.
Just now, I got a ticket from a client that they are going on holiday and can't remember their PIN to a system - can I make the change and send them the pin - They won't be back in until Monday.
I get limiting to 24 hours, but, it would be good if we can have some longer options - including possibly 1 week and 1 month, or, a text box to specify the number directly.
I feel really bad asking, but, even an indefinite/expire on first view only option would be great.

Lastly, another related addition that I really hate asking for is the ability to expire on second view. (possibly as an option on a per company basis). We have a couple of companies that have server side "AI" malware scanning which opens links and tests/classifies pages. This unfortunately makes the Hudu link expire if this option is set.

For my clients, I'll whitelist my hudu site so it won't scan, but, we won't always be in the position where we can… We can easily just set to a time based expiry, but equally, having a 2 view limit would bypass this need.

Status: Complete6 comments

Log in to comment and vote

Comments6

  • Indigo Magnetosphere changed status to Complete
    •

    Apr 6, 2020

    In Hudu 2.1.1, you have a bunch more options!

  • Indigo Magnetosphere changed status to In Review
    •

    Mar 12, 2020

  • Magenta Sun

    •

    Mar 12, 2020

    William H. It's interesting that the link scanning expires the password share for you. Sending the password link to a client via text message on an iOS device lists the page as being accessed both by your device and the customer's device in the access log because iOS displays the favicon and webpage title as a preview before they click on it (which is perfectly branded as the password share and your company name). The password share is not actually expired until you click on the "reveal password" option within the password sharing webpage, not by just viewing the share webpage itself. If your link scanner is testing every button on the webpage by pressing the button in a sandbox-type environment and seeing what happens, there isn't really a way around that unless you could note that on that customer's account and then specify the amount of times the password could be revealed before it is expired instead of it just being the first access. You could count on the link being accessed once by the link scanner and a second time by the client and adjust for that, although this would have to be on a per-client basis so that your clients that do not have this feature could have the password share expire like normal.
    Perhaps The Hudu Team can provide input on this or you should raise a support ticket about it.

    • Indigo Magnetosphere

      •

      Mar 13, 2020

      Michael S.: The scanner does click buttons in order to test for fake login pages, redirects and many many more aspects. I don't want to take time away from proper development and it certainly isn't worth a support request… I've only started to use this feature and I've whitelisted our Hudu instance.
      However, as per what you said, this is why I was asking for an optional 2 view limit flag on customers, however, I feel this is too much work for a very small use case.

  • Magenta Sun

    •

    Mar 12, 2020

    I also agree on this, although I feel that the options should be 24 hours, 48, 72, and 7-days. After that, the user should have to call back in and explain why they didn’t view it.

  • Bronze Narwhal

    •

    Mar 11, 2020

    I sadly agree with this, I've had to share a link 3 times over 3 days due to timing issues.