"Doesn't ISN Free WiFi trust my password? And if you already send me a code, why push the authenticator app?"
Fair questions. Let's go through the real reasoning.
Why a code after your password at all
This is called 2FA, two-factor authentication (sometimes called MFA, multi-factor authentication). The idea: your password is "something you know," and the code is "something you have," a second, separate proof that it's really you. Two independent proofs instead of one.
Why does that matter? Passwords fail in ways you'd never notice. They get reused across sites, so a breach on some unrelated app can hand your ISN password to an attacker. They get phished, tricked out of you via a fake login page. They get pulled from mass credential stuffing attacks, where attackers try millions of leaked username-and-password pairs against random sites, including ours, automatically. In every one of those cases, your password alone gets compromised without you ever knowing. The second factor is what stops the login anyway.
That's why every owner login gets a mandatory code by default. Not optional, on purpose.
So why push the authenticator app instead of the email code we already send?
Here's the part most guides skip: an emailed code and an authenticator app are not equally strong, even though both technically count as "a second factor."
The problem is where the email code lives: your inbox. If an attacker ever compromises that same email account (phishing, a reused password, an old breach), they don't just get your password reset link, they now also receive your 2FA code, in the same place. Your "second factor" collapses into the same single point of failure as everything else. Two supposedly independent checks, one shared weak point.
An authenticator app breaks that link on purpose. It uses something called TOTP, Time-based One-Time Password: a 6-digit code generated locally on your phone every 30 seconds, using a secret key your phone and our server agreed on when you set it up. It never travels over email, never touches your inbox, and works completely offline, no signal, no SMTP delivery delay, no dependency on a mailbox that might already be compromised. Even if your email account is fully taken over, your authenticator app is untouched.
That's the actual difference: the email code is a real second factor, but it shares a failure point with your account recovery. The app is a genuinely independent one.
Why we default to secure instead of optional
Most of our clients are business owners, not security people. You're running a hotel, a mall, a residence, a hundred other things, and reading a security checklist isn't on your list. So we made the decision for you, the way we'd want it made for us. Security isn't a setting you opt into on our platform. It's the starting point everything else is built on.
A guest WiFi platform that's easy to break into isn't actually easy to run. It's a liability waiting to happen. We'd rather you never have to think about it, because we already did.
Discover more: https://isnfreewifi.co.za/
