04-02-2023 12:53 PM
I get what toast was trying to do with logging in mobile, letting your devices security (fingerprint or face) log you in "faster" but it's literally now an EXTRA step to login EVERY time.
Why if I authenticate with my fingerprint, do I STILL get the captcha stuff? How dumb is that, I just proved I am not a robot, also it's not integrated into my phones platform so it doesn't of course just populate my authentication then login no, my phone has to ask if its okay every time then loads to a new screen then of course can't forget the Captcha my god no what if the robot's got my face somehow.
Seriously, the webapp isn't great but logging in before was at least somewhat easy. How long do we need to wait till there is a dedicated app for us to check/see toast reports? Square and Lightspeed both have these and they're slick as all get out. Toast could do this if they want but they just continue to not or say "oh we're working on one" bull.
Please, I am begging you, make it faster to login on mobile. Cut the incessant captcha stuff after it's been even an hour. Even my bank in't that bad.
/rant
3 weeks ago
You're right, it is a fairly long process to log in, but the way I look at it is that Toast is helping not only protect my business's security, but the security of all my employees information (bank account numbers in payroll, tax forms, etc). I know this isn't the solution you were looking for, but it really does help to think about it in the way that I know we're doing everything we can to keep us all safe!
3 weeks ago
I don't expect Toast to care about he how inefficient of a system it is when it comes to security. Protecting our information is top importance. My problem is that it has made things MUCH LESS secure. I have and will continue to put in customer care cases with Toast support until something changes. The way it is less secure, is if someone forgets to logout or steps away from the computer and how Toast Payroll and ToastTab are now linked.
Let me explain:
I know most restaurants operate under these circumstances. Many managers using the same back office computers- Assistant Managers to ADMIN using the same computers at different times. Restaurant people also don't spend a lot of time at the computer, they need to jump onto toasttab to pull numbers from sales summary, or review time entries, product mix reports, lookup a ticket. Most things are about 5-10 min on the computer and then jumping off it, usually under a time constraint. And about 50% of that time you're on the computer you get interrupted because of one thing or another (customer issue, repair issue, staff issue, etc.).
If a manager forgets to close out their toasttab then payroll is now accessible through their toasttab and toasttab doesn't TIME OUT. Toast Payroll used to time out and close out if you were inactive for 15-30 min. Toasttab however just stays open. So it doesn't matter if there is a mulit-factor authentication if toasttab is left open for any reason everything is open for whoever sits at that computer next.
I have seen this happen in multiple ways. Here is one: My general manager logged into her toasttab to do the drawers at night and got pulled away at the end to take care of a closing issue and forgot to log out. The computer went to sleep and I came in the next morning and her toasttab was still open. I wanted to test the security. I clicked on the payroll link in her toasttab and no problem it opened up her payroll account which is an HR+ and asked for no multi-factor authentication. I then closed the browser tab with toast payroll. Went back to toasttab and logged her out. I logged myself back in with multi-factor authentication in toasttab. Clicked on Toast payroll and once again HER TOAST PAYROLL access opened up.
The are a few more examples that I have given to toast that are just as alarming.
I am saying all this because I am pleading with Toast POS and Toast Payroll almost daily to fix this serious lack of security. Toast listens if we speak up as customers. They are made for restaurants and they change to make us better. This change is not better and the more I can be a squeaky wheel I will do it. As much as the login process is inefficient that is not the point.
Toast engineers, this system has had unintended consequences that can be solved by making Toasttab time out of sessions.
2 weeks ago
I am monitoring this thread and relaying feedback to teams, If anyone else has found that things are less secure because of this change, please post in this thread. As I continue to learn more, I will update this thread. I apologize for the security issues this update has created and will continue to monitor and report back if I receive any information around this!
2 weeks ago
Thank you so much Rob!
2 weeks ago
HEY EVERYONE!
I hope I'm not getting excited too soon but I just LOGGED INTO TOASTTAB, TOAST CENTRAL, TOAST COMMUNITY, AND TOAST PAYROLL and NONE asked for multi-factor authentication!
(It's concerning that Toast Payroll isn't asking for a second authentication but I'm going to assume they are just still working out the kinks).
Not sure all this is legit or a fluke but it feels like progress!