Security Concern - TPLink / Tapo/ Community Forum Logins & 2FA
I raised this within another thread on the Deco section as a side issues on another problem. I feel it warrants a proper thread and also some serious attention.
I have a mixed setup of Tapo Cameras and TPLink Deco stations. I also use this community forum. I started off with a TPLink account for administering a old router and using the community. Later I got Tapo cameras which then used the same account.
The single ID I have seems to be shared across ALL these areas, automatically, without the ability to seperate them?
However there is a security concern I have re this that I feel needs looking at as a matter of urgency,
If I use the Tapo or TPLink iOS apps then I need to supply an ID and passsword and approve my iOS device as a trusted one to use it going forward.
I have enabled 2FA for the ID and this is via an in-app approval.
HOWEVER, if you log on to this community with the ID and password there is NO 2FA approval AND the forum User Profile allows password changes!
The general TPLink website login also does this but does not give the ability to change the password.
Given that the ID is shared across the Tapo and TPlink app plus this forum it seems incredibly worrying that if the password was compromised then simply using it to login to the community forum would give the ability to gain control of the ID with NO 2FA.
I appreciate that a new device cannot be approved easily and there is no access to Tapo footage or the Deco system via the internet but its still a serious oversight.
It needs to be corrected so ANY login to ANY system using this primary ID is authenticated properly by 2FA.
I'd be very interested to know if anyone else share my concerns or has any information to put my mind at ease.
Regards
Radar
