Skip to Main Content
IBM Cloud - Structured Ideas


This portal is to open public enhancement requests against IBM Cloud and its products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

IBM Cloud Support Center (https://cloud.ibm.com/unifiedsupport/cases/form) – Use this site for any IBM Cloud defect or support need.

Stack Overflow (https://stackoverflow.com/questions/tagged/ibm-cloud) – Use this site for IBM Cloud technical Q&A using the tag "ibm-cloud".

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Not under consideration
Created by Guest
Created on Aug 9, 2019

Multi factor auth (MFA) web UI prompts should not have history enabled.

All the prompts for MFA codes store previous results, which is useless and gets in the way, since there is almost no chance that you will ever re-use the same code. Please disable this, so that the UI stops making suggesting and showing previous results.

 

In theory, it is also a security risk, although the likely hood of that actually being exploited are likely very low.

Idea priority Medium
  • Guest
    Reply
    |
    Sep 23, 2019

    Obviously you can decide to never fix it, but this behavior can not be realistically switched off for a single form in the browser. Suggesting the fix for everyone is to broadly disable the functionality of their browser for the whole IBM site or all sites in general instead of labeling the field correctly in the HTML/javascript seems silly. In general this should be as easy as this: 

    <input type="text" autocomplete="off"/>

    And this basic use-case is undeniable the exact reason that the autocomplete option exists in forms.

  • Guest
    Reply
    |
    Sep 23, 2019

    Marking as will not implement. This can be switched off in the browser, and there is no real vulnerability here as far as codes being reused goes. No development resources are available to address this at present.

  • Guest
    Reply
    |
    Aug 12, 2019

    MFA for IBM cloud (cloud.ibm.com), Softlayer (control.softlayer.com) and likely Bluemix (control.bluemix.com). A picture has been attached showing the issue on the IBM Cloud login screen.

  • Admin
    GILLY DEKEL
    Reply
    |
    Aug 11, 2019

    Is this in references to MFA for the platform or with the App ID service ?