BLN release notification [ BLN security enhancements]

Resolved
Resolved

BLN SECURITY ENHANCEMENTS

Key Information • We have released this work item to Production!! Passwords will expire every 90 days. • Stricter requirements for all new passwords going forward. • Sessions will expire after 30 minutes of inactivity. • Those using our WordPress plugin will need to update it on their website. Password Expiration • Users will be notified (via email) to reset their passwords every 90 days starting from the last day they logged in. • The email notification will be sent 10 days before it expires. This notification/reminder will also repeat 5 days before your password expires. • If a user hasn't logged in the past 90 days, then automatically they'll be required to reset their password the next time they attempt to log back into BLN. • This process would require the user to first enter an old password, then a new password, and finally the same new password again to verify it’s correct. (The 2 new passwords must match). Password Strength • We will be enforcing stricter requirements for all new passwords created in BLN. • Password length must contain a minimum of 8 characters. • Password must not contain more than 3 consistent letters from user's First or Last name or username. • Password must contain an uppercase letter. • Password must contain a lowercase letter. • Password must contain a number. • Password must contain a special character. • User must not repeat or re-use password (last 3 passwords). Session Expiration • User sessions in BLN will expire after 30 minutes of inactivity. • Users will receive a warning 60 seconds prior to being auto logged out of BLN. • A message displaying “Are you still there?” will pop up prompting the user to continue if applicable. BLN API • Lenders and brokers using the Bridge Loan Network WordPress plugin will need to update the plugin on their website to the latest version (1.3.31). • Instructions on how to update a WP plugin can be found here; https://www.wpbeginner.com/beginners-guide/how-to-properly-update-wordpress-plugins-step-by-step/

If any issues arise, please contact support@bridgeloannetwork.com

Thank you,

Erin Genlot Junior Product Owner ––––––––––––––– D — 860.288.1209

BridgeLoanNetwork.com 54 Hartford Turnpike. PO Box 2524 Vernon, CT 06066

Avatar for
Began at:

Affected components
  • BLN - API