Your account is the key to remote access. While it is safe, your devices stay under your control; once it is lost, every bound device is exposed.
Basic hardening
Use a strong unique password, enable two-factor authentication, verify your phone number and email, and keep recovery codes safe.
- A strong password not reused elsewhere
- Enable SMS or one-time-code 2FA
- Verify phone and email
- Store recovery codes offline
Alerts and review
Turn on unusual-location alerts, review signed-in devices regularly, and if something unfamiliar appears, force it offline and change the password.
- Enable unusual-location alerts
- Review the signed-in device list regularly
- Remove unknown devices immediately
- Change the password promptly
Incident response
If you suspect compromise: change the password, force every device offline, review device authorisations and access codes, then read the session logs.
- Change the account password immediately
- Force all sessions offline
- Review device and member authorisations
- Rotate access codes and inspect logs
FAQ
I got an unusual-location alert. What now?
First check whether it was you. If not, change the password, force sign-out everywhere, and review device authorisations and session records.
Why not reuse the same password?
A breach elsewhere lets attackers try the same credentials here, which would put every bound device at risk.