Two Factor Authentication on Anubis Market
A password alone offers limited protection against brute force attacks or database leaks. Adding a second layer ensures that even if your credential is stolen, an attacker cannot enter your account without the additional token. On Anubis, this layer acts as a gatekeeper between your balance and the outside world.
You have two choices for this secondary step: Time-Based One-Time Passwords or PGP signing. Both methods require a device or file you must possess every time you log in. Choosing one depends on whether you prefer an app-based workflow or a crypto-native solution integrated into your existing tools.
TOTP
Standard TOTP uses apps like Authy or Google Authenticator to generate a six-digit code every thirty seconds. During setup, scan the QR code displayed in your dashboard settings. Once active, you enter this changing number along with your password upon each login attempt. The code expires quickly, making it useless if captured mid-transmission.
This method suits users comfortable with mobile applications. Ensure your phone battery does not die completely while logged out, as some devices disable background processes aggressively. If you switch phones often, transfer the seed correctly or you will lock yourself out entirely until support intervenes.
PGP two factor
For those who prefer staying within the OpenPGP ecosystem, Anubis allows you to sign a unique login challenge with your private key. Instead of typing a number, you cryptographically prove ownership of the private key pair associated with your account. This removes reliance on a potentially compromised mobile device or cloud-synced authenticator list.
This option fits well for users who already manage multiple PGP identities for different services. It adds a few extra clicks during login compared to TOTP, but it ties your security directly to your cryptographic identity rather than an ephemeral token generated by a third-party app server.
Backup codes
Upon enabling either method, the system generates a set of single-use recovery codes. These strings allow you to bypass the second factor if you lose access to your primary device or key. Print them on paper or store them in an encrypted offline vault. Do not save them in a spreadsheet on a shared computer.
If your phone breaks or is stolen, you consume one of these codes to regain entry. After logging in, regenerate a fresh batch immediately. Running low on backup codes is a warning sign that you are relying too heavily on emergency procedures instead of normal maintenance routines.
If you lose access
Losing both your 2FA method and all backup codes triggers a recovery request involving your original registration phrase or verified contact details. The speed of restoration depends on how complete your initial record was. Incomplete records may result in a lengthy manual review period before access is restored.
You can recover your account and balances, but any pending orders or complex wallet structures may need manual reconciliation. This delay ranges from hours to several days depending on complexity. Avoid losing your factors preemptively through better storage habits.
When to turn it on
Activate two factor authentication the same day you register your account. Delaying this step leaves your growing balance vulnerable during the critical early phase when you are testing features and moving funds around. There is no penalty for doing it first; there is only regret if you wait until you hold a significant amount.