Two-factor authentication asks for a six-digit code from an authenticator app after the password, so a stolen password alone is not enough to open the panel. It is set up in Settings › Two-factor authentication.
Standard six-digit authenticator codes. Off by default, and it needs the sign-in page mode, because the browser’s own prompt has no second step to put a code in. Set it up in Settings, not by hand:
- Press Set up two-factor authentication. It mints a fresh secret and shows a QR code — drawn on your own server, in pure PHP. No chart-server URL, no third-party encoder: sending the shared secret to somebody else to have a picture of it drawn would hand them your second factor.
- Scan it with any standard authenticator app, or type the key in by hand — it is shown grouped in fours for exactly that.
- Enter the code the app shows now in Six-digit code and press Turn on two-factor. Nothing is stored until this is accepted, so closing the tab half way through leaves two-factor off and locks nobody out.
- Save the ten recovery codes. Shown once, downloadable, and only their hashes are stored. Each works once. They are the only way back in if you lose the phone, and you can issue a fresh set at any time, which invalidates the old one.
An unconfirmed enrollment expires fifteen minutes after you press the button, on the clock and not on the session — because staying signed in means a session can now last forever, and a pending secret must not inherit that. A code is accepted within one step either side of now for clock drift, and once: the last accepted step is recorded and anything at or below it is refused, so a code read over your shoulder is worth thirty seconds of nothing.
The sign-in second step, the enrollment confirmation, turning two-factor off, and reissuing recovery codes. A recovery code counts the same as a six-digit one, and a wrong code costs exactly what a wrong password costs — so no endpoint is the cheaper place to guess, and alternating between them buys no extra attempts. Six digits is a million possibilities, and that limiter is the only thing between a stolen password and a guessed code.
Turning two-factor off requires a current code or a recovery code, and so does reissuing recovery codes — never just being signed in. If a stolen session were enough to strip the second factor, the second factor would be protecting nothing; and ten fresh recovery codes are a standing way past the phone, so minting them is the same act by a quieter route.
Lost the phone and the recovery codes? Run the setup wizard on the server and set a new password. That turns two-factor off and revokes every remembered browser. Being able to run it is already proof of who you are — which is also why there is no reset by email: Loghound has no mail path and would not use one for this.
Signing in
- Sign-in modes & lockout
- Stay signed in
- Two-factor