This review would be a 5 on account of the great staff, especially Misty. Recent changes to the website system from the corporate office lower my approval. The company has changed the web interface twice in a handful of months, first to require my cc be stored (I could still manually delete at the time), and second to seemingly require a phone number to *first* identify my account, and *if* that is done to *then* give me access to the account login screen. Ok, I finally noticed that I could scroll down to use the direct login method, but most people will fall into the first method b/c of the way you structure the webpage. Most people use the SMS system which is horribly insecure. See:
https://www.cnet.com/news/privacy/do-you-use-sms-for-two-factor-authentication-heres-why-you-shouldnt/
https://www.zdnet.com/article/why-sms-two-factor-authentication-codes-arent-safe-and-what-to-use-instead/
... and for the more geeky:
https://security.stackexchange.com/questions/11493/how-hard-is-it-to-intercept-sms-two-factor-authentication
I use keepass (who keeps their branding promises), so unlike many people, using SMS probably makes me *less secure*. The company should at least warn not to use SMS, but how do I know that the storage company is not now in the business of tracking their customers? Anyway, how about using more secure two-factor methods? I will try switching to VOIP to avoid the risk. Finally, back to storing my cc: I don't like it, but at the least, not storing the security code on the back (requiring it each time) might be better before the next (inevitable?) data breach. Having to work with the bank over scams and account fraud is costing Americans a lot of time, and I do not appreciate companies' "going with the flow" on financial corruption! Thank you for fixing the problem. I am definitely willing to click a few extra buttons for a lot more security! read more