Security and sign-in
How Maketools protects your account, and why some actions ask you to confirm it's you.
Confirm it's you
Sensitive actions ask you to prove, right before, that you are the account owner:
- changing your email address or your password;
- turning off two-step verification;
- deleting your account;
- in an organization: deleting it, or showing players' names in reports.
You can confirm with your password, or with a 6-digit code we email you (Send me a code). The code is valid for 10 minutes and works once. This protects your account if someone uses a computer you left signed in.
How your account is protected
- Passwords are never stored: we keep only a strong one-way fingerprint (scrypt).
- Codes and links are single-use, expire quickly, and are limited in attempts.
- Repeated failed sign-ins are slowed down, per account and per network address.
- Error messages never reveal whether an email address has an account.
- Your session lives in a secure cookie that scripts cannot read, and every sign-in, change and failure is recorded in a tamper-evident security log.
Two-step verification
Two-step verification (TOTP) adds a code from an authenticator app at sign-in. It is optional, except to manage the security of an organization or when your organization requires it. See Two-step verification.
See also Sessions.