Altru Ideas

Remove the 5.26 Altru user requirement to change their password every 90 days

Our members typically log in once or twice a year (membership renewal and an annual event ticket purchase), so the requirement to change their password every 90 days on our web forms would be burdensome for them - would basically require a password reset every time they log in. And we have a member pre-sale that requires Altru log-in for an annual event, so 1000+ members would be logging in at the same time and all getting the password reset requirement which would result in pre-sale delays and disgruntled members.

  • Guest
  • Jul 19 2022
  • Shipped
  • Attach files
  • Campbell Reiter commented
    August 01, 2022 13:46

    Please see the following update which was posted as a comment to our What's New In Altru 5.26 announcement:

    Dear Altru Customers,

    First and foremost we want to thank all of you for providing this incredibly valuable feedback. We greatly value your feedback and partnership and are writing to let you know that we have heard your concerns regarding some of the security updates in the latest Altru 5.26 release. While password security is an important priority for both us and you, we listened to your concerns and have revisited the Web Form password expiration timing. We will be able to extend the expiration to 365 days (once per year) while still ensuring we meet rigorous security and privacy standards. We hope this will improve the online experience for your members and patrons.

    With that in mind we have made the decision to pause our rollout of the Altru 5.26 release so we can make this happen. Our team will be in touch soon with information around revised release timing for Altru 5.26 including an update for customers that have already received the Altru 5.26 update.

    In addition, we have also noted key feedback regarding areas of the password reset user experience that could be improved for simplicity and clarity. We have captured that feedback and will be incorporating additional updates to that user experience in our next Altru release, Altru 5.27 which is slated for later this Fall.

    Please know that we greatly value your partnership and feedback and will continue to improve and evolve the Altru solution together!

    Finally, please keep an eye out for a follow-up email communication in the coming days.

  • Amanda Kepner commented
    July 27, 2022 19:30

    We have over 21,000 webform users. There is no way our staff can handle the call volume we will get if this is implemented. We have enough issues with getting people registered and forgetting their passwords and emails as it is. You need to allow people to opt out of this.

  • B Hoover commented
    July 27, 2022 15:45

    Our members typically use this once or twice a year at best- if that. It's not like the account is even protecting anything, there's no information, saved credit card stuff etc. This is going to lead to a ton of frustration when our various camps go live and we have 1000+ people dealing with this all at the same time.

  • Jason Hinkle commented
    July 21, 2022 23:58

    Not sure what to add to what has not been said here or on the previous threads. Every 90 days? we only got a 20 day notice to prepare and figure out what to do and set up plans. Not a good roll out. Work on chip readers and other things we ask for that don;t require an additional service fee.

  • Guest commented
    July 21, 2022 23:47

    We already have a lot of members who struggle with their passwords, get locked out and are confused by how to sign in to get member tickets. This change will just compound the problem, especially with our older members who are are technically challenged to begin with. There is a lot of frustration as it is.