Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Bob_Zimmerman
MVP Gold
MVP Gold

Support Center Login Timeout Driving Me Insane

The notifications around CVE-2026-85102 and CVE-2026-85103 have been handled extremely poorly. I've gotten at least twelve email threads from Check Point about them, inspiring several managers to forward them to me and ask about them in separate email threads. Then the managers get this "You need to install it on the management, too" separate email thread and they forward it to me asking if it's the same thing. Way too many separate messages, and I have to read all of them to make sure they're actually the same thing, and not some new third CVE. This terrible handling of communications around urgent issues is a running issue.

While dealing with this, I'm trying to get information from SK articles. Trying to download packages to install on various firewalls. Every single time I click on anything or try to search for anything, my session has timed out and I have to log in again!

WHY?! Why is the timeout this insanely short? We start with a stressful situation, make it worse through awful communications, then add more stress on top by having the website constantly interrupt users to make them log in again.

This is a recipe to get admins to deeply loathe a company.

0 Kudos
5 Replies
JozkoMrkvicka
Authority
Authority

I already used to it. Logging into Support Center many times during working day is my daily routine job. It reminds me that my Check Point password is still known, is not expired and there is no risk I forgot it within a couple of hours ! I already learnt to type my Check Point password even with closed eyes.

PS: Try to use browser auto-refresh extension.

Kind regards,
Jozko Mrkvicka
0 Kudos
Lesley
MVP Platinum
MVP Platinum

All went well here, one e-mail to notify about the CVE's and next day 1 e-mail as follow-up. I had no issues reading or downloading a thing from the support center. Somehow you get signed up 12 times? I don't understand tbh. If other people receive the notification and forward it to you that is not something that can be changed from CP side. So I don't think this deserve the terms terrible and awful communication if there is no proper feedback shared by you. 

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

It actually is something Check Point could change.

Instead of emailing every single user on the account individually, send one email which includes all of them!

Instead of starting a new thread for an update, send a reply to the original message!

Instead of every single diamond rep and sales rep and SE and ATAM and account exec emailing us separately, CC them on the main thread, so they all know we got it!

And we need them to tell us how the flaw can actually be reached so we can prioritize fixes! Most of my firewalls don't have VPN enabled at all. Do we still need to update them as urgently? No idea, because Check Point hasn't given us ANYTHING.

They overcommunicate trivialities while not giving us (or our support reps, sales reps, account reps, etc.) the information we need to make informed arguments to our management about why we need to patch out of cycle.

0 Kudos
Alex-
MVP Silver
MVP Silver

Why? Thank AI scrapers, probably, which pound Internet sites constantly, so CP is likely ensuring they can't siphon the entire SK's in one go. This is just a guess.

OTHO, I use Proton Pass which logs me back in no time. If passkeys could also be implemented on the Support Center, that would be even faster. 😏

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

Blocking scrapers is just rate limiting. We already have to log in to search and view stuff. Limit accounts to viewing one article per second, for example. To deal with residential botnets, scale the limit up with the number of observed source IPs for the requests in the last hour (e.g, if the same user is hitting from two IPs makes it two seconds per article, three IPs makes it four seconds per article). Humans aren't going to hit that, but scrapers absolutely would.

The password manager we're allowed to use also has a short timeout. I'm separately complaining to our internal team about that, but there's really no reason to need to log in more than once per day in the first place.

Yeah, I'd love to see passkey authentication, especially if it didn't require interaction more than once a week or so. Just silent asymmetric refreshes in the background.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events