All articles

Two-factor authentication

How to turn on two-factor authentication, what backup codes are for and why you must save them, how the email recovery channel works, what trusted devices do, and exactly what to do if you lose your phone.

Your Open Lance account can move money. A password alone is a single point of failure, and passwords leak constantly through breaches on unrelated sites. Two-factor authentication means that knowing your password is not enough to get in.

It takes about five minutes to set up. This article covers all of it, including the part people skip and regret.

How it works here

Open Lance uses TOTP, the six-digit rotating code produced by an authenticator app. You register the app once, and afterwards signing in asks for your password and a current code.

There are three ways to satisfy the second factor:

  • Your authenticator app, the normal route.
  • A backup code, single-use, for when you cannot reach the app.
  • An emailed code, a recovery channel for when you have neither.

Setting it up

Go to Settings, then Security, and start two-factor setup. You will need an authenticator app on your phone. Any standard one works — Google Authenticator, Authy, 1Password, Microsoft Authenticator, or the one built into your password manager.

  1. Open your authenticator app and add a new account.
  2. Scan the QR code shown on screen. If you cannot scan, there is a text key you can type instead.
  3. The app immediately starts producing six-digit codes that change roughly every thirty seconds.
  4. Type the current code back into Open Lance to confirm.

That last step matters: it proves the app is genuinely working before anything is locked to it. Two-factor is not enabled until you complete it.

Backup codes, and why you must actually save them

The moment two-factor is confirmed, you are shown a set of one-time backup codes. Each works exactly once, in place of an app code.

They are shown once and never again. Not because we are being difficult, but because storing them in a form we could show you again would mean storing them in a form an attacker could read. They exist as one-way hashes on our side, so nobody at Open Lance can look yours up.

Save them somewhere that is neither your phone nor your email:

  • In a password manager, as a secure note. Best option for most people.
  • Printed, in a drawer at home. Genuinely fine.
  • In an encrypted file on a computer you control.

Not in your phone's notes app, because the phone is the thing you are protecting against losing. Not in your email, because your email is the other thing an attacker targets.

If you use one, cross it off. If you run low or think they have been exposed, regenerate the set from the security settings. Regenerating invalidates every old code immediately, so update wherever you stored them.

Trusted devices

You can mark a device as trusted when signing in, and Open Lance will stop asking for a code on that device for a period. It is a convenience for a laptop only you use.

Do not trust a shared or public computer. And if a device is lost or you simply want to reset the situation, turning two-factor off and on again clears every trusted device along with everything else.

If you lose your phone

This is the situation two-factor makes worse if you have not prepared, and entirely survivable if you have. Work through these in order.

Use a backup code. This is what they are for. One code gets you in. Once inside, go straight to security settings, disable two-factor, and set it up again on your new phone.

Use the emailed recovery code. On the two-factor prompt, choose the option to send a code to your email instead. This works if you still have access to your registered inbox. It exists precisely for people who lost the phone and did not save their backup codes.

If you have neither, contact support. This is the slow path, and deliberately so. Support will ask questions to establish the account is genuinely yours, and the bar is high because an account-recovery process that is easy to talk your way through defeats the point of having two-factor at all. Expect it to take time and to be asked things only the real owner could answer.

Before you wipe or trade in a phone, either transfer your authenticator to the new device using your app's own migration feature, or disable two-factor on Open Lance first and re-enable it afterwards. Most people who get locked out do it to themselves during a phone upgrade.

Codes that are rejected

If the app is producing codes but Open Lance rejects them, it is almost always one of two things.

Clock drift. TOTP is based on the current time, and if your phone's clock has drifted, the codes it makes are for a moment that has passed. Set your phone's date and time to update automatically. This fixes it far more often than anything else.

Using an old code. Codes expire in about thirty seconds. If you typed one just as it rotated, wait for a fresh one rather than retrying the same digits.

Genuinely wrong codes are also rate-limited, so hammering the form makes it worse. Slow down, get a fresh code, and enter it carefully.

Turning it off

You can disable two-factor from security settings, and doing so wipes the secret, the backup codes and every trusted device.

Please think about it first. If you are disabling it because changing phones is awkward, disable and immediately re-enable on the new device instead of leaving it off. An account that can move money, protected by a password that may already be in a breach dump somewhere, is a bad position to be in and the consequences land on you.

Where two-factor does not help

It protects sign-in. It does not protect against everything, and it is worth knowing the gaps.

It does not help if you approve a payment you should not have, or send money off-platform, or hand your codes to someone who asked convincingly. Nobody at Open Lance will ever ask for a two-factor code, a backup code or your password. Anyone who does is attacking you, regardless of what the message looks like or which channel it arrived on.

It also does not protect a compromised email account. If someone controls your inbox, they can trigger the email recovery path. Put two-factor on your email as well — it is the account everything else recovers through.

What good looks like

If you want the short version of a sensible setup:

  1. Two-factor on, using an authenticator app rather than only the email channel.
  2. Backup codes saved in a password manager, not on the phone that holds the authenticator.
  3. Two-factor on your email account as well, because that is the account everything else recovers through.
  4. A trusted device marked only on hardware nobody else uses.

That takes about ten minutes once and removes the most common way accounts are lost.

The email channel, and its limits

The emailed code is a genuine convenience and it is also the weakest of the three routes, for one reason: it is only as strong as your email account.

If somebody controls your inbox, they can request an emailed code and use it. That is why the advice to secure your email is not filler — for most people, the email account is the real master key to everything else they own online, and it is frequently the least protected.

Use the emailed channel as a recovery route rather than as your everyday second factor. If you find yourself using it every time because the authenticator app is inconvenient, the fix is a better app or a password manager that holds codes, not accepting the weaker route permanently.

Two-factor when someone else works on your account

If you have delegated work to a bidder, do not give them your login and do not share your codes. A bidder seat is a separate account with its own password and its own two-factor, which is exactly why it exists.

Sharing credentials means sharing or disabling two-factor, which removes the protection from the account that holds your money, and makes every action indistinguishable from your own. See Bidders: letting someone bid on your behalf.

If you think somebody is already in your account

Act in this order and do not stop to investigate first.

  1. Change your password. This ends other sessions.
  2. Turn two-factor on, or off and on again if it was already enabled, which wipes trusted devices.
  3. Check your payout methods. This is what an attacker changes, because it is how money leaves. Remove anything you do not recognise.
  4. Check for withdrawals you did not request.
  5. Open a support ticket describing what you found and when.

Speed matters more than completeness here. Change the password first and investigate afterwards.

Common questions

Can I use the same authenticator app for several accounts? Yes, that is what they are for.

What if I have no phone at all? Most password managers can hold codes on a desktop.

Does two-factor slow down every sign-in? Only on devices you have not marked as trusted.

Can support turn it off for me? Only after establishing that the account is genuinely yours, which is deliberately demanding. Backup codes are much faster.

Related

Did this answer your question?

Did this not answer it?

Open a ticket and a person will read it. You do not need an account.

Two-factor authentication · Open Lance