Security of my Acronis account when managing multiple installs of ATI 2018
Hi
This question is about the security of my Acronis account which I use to manage the installation and operation of multiple PCs.
Using my Acronis account, and one of my ATI subscription licenses, I have installed ATI 2018 on a PC (not owned by me) and got it configured and running. I note that in the ACCOUNT tab of ATI2018 on this PC, that my account is still logged in. This means the person using the PC (not myself) can access my Acronis account, which is not what I would like. But if I sign out of my account on this PC, ATI reverts to trial mode, which is not what I want either!
I'd be grateful for any comments/suggestions you may have on how to deal with this situation.
ArtyW


- Accedi per poter commentare

Hello ArtyW,
As Steve correctly outlined in his comment, every Acronis True Image subscription is tied to a personal account at acronis.com and you'll need to stay signed in to your account, where the service is registered, in order to use the product. It's supposed, that Acronis True Image licenses for 3 and 5 PC are applied within a single household and the account might be shared\one person takes care of all protected devices.
In your case there are two possible ways, either to give access to a personal account, or to suggest purchasing a personal license for 1 PC to an end-user.
- Accedi per poter commentare

This is the issue I lodged with Acronis Customer Service:
"In the ACCOUNT tab of ATI2018 on any of my managed PCs, my Acronis account is still logged in. This enables any user of that PC to click on my email address, select "My Account" where a new browser Window is opened which allows that person to manage my Acronis account. i.e. to change my Acronis password or to manage any of the Acronis activated computers.
The person using the PC (not myself) can access my Acronis account which is not what I would like. But if I sign out of my account on this PC, ATI reverts to trial mode, which is not what I want either!
I hope you are able to consider this issue as a security loophole for managers of Acronis subscriptions and advise on how to avoid it."
This is the response I received:
"Unfortunately, we will not be able to remove "My account" which allows user to auto login to Acronis account. This product is build for specific user and this is generic behaviour.
However, I will take this as feedback. This must be very frustrating. To ensure that the management team is aware of this, I am going to enter your comments into our ‘Customer Listening System’. The feedback we submit is used to drive major changes in support and Acronis as a whole. It is a vital initiative in Acronis and is taken very seriously. I am sorry, your experience did not meet your expectations, as I said; I will make sure your concerns are reviewed by the management team."
- Accedi per poter commentare

ArtyW, thanks for sharing your feedback from your support case.
The only thought that I can offer in this area, is to suggest that Acronis should implement 2 Phase Authentication before allowing any changes to user account details such as passwords or changes to activated devices. This happens with other accounts that I use such as my Amazon user, my Twitter account etc and means that the person attempting any change then has to provide a code which is either sent to my mobile or is generated by an authentication app on the phone.
- Accedi per poter commentare

I agree two-factor authentication is the way to go.
Ian
- Accedi per poter commentare