OmxusHelp

HelpAccount security

Create a strong password

A strong password is long, unique to this account, and hard for anyone else to guess. It can still be easy for you to remember.

Password requirements

  • At least 8 characters. Longer is better.
  • Not a password that has appeared in a known data breach.

Tips for a good password

Make it long

Length matters more than symbols. A few unrelated words strung together, like a small scene only you would picture, is longer and easier to remember than a short jumble.

Use it only here

When one site leaks passwords, attackers try the same email and password on other sites. People reuse or lightly change passwords across many accounts, which makes this work far too often (Das et al., 2014; FlorĂȘncio & Herley, 2007). A password you use only for Omxus stays safe when another site leaks.

Leave out personal details

Avoid your name, birthday, phone number, street, pet's name, or anything on your social media. People who know you, or find you online, can guess those.

Use a password manager

A trusted password manager can create and remember a different strong password for every site, and many can store passkeys too.

How the breach check works

When you choose a new password, the sign-in screen checks it against Have I Been Pwned, a public collection of passwords from past data breaches. It sends only the first 5 characters of a scrambled fingerprint of your password. The service returns every breached fingerprint that starts the same way, and your device checks the list itself. Your password and its full fingerprint never leave your device. Researchers have studied this style of check and how to keep it private (Li et al., 2019).

If the service can't be reached, you can still set your password.

Even better: a passkey

A passkey can't be guessed, reused or phished. Add one alongside your password.

How Omxus stores your password

Your device runs your password through PBKDF2, a standard way to slow down guessing (Moriarty et al., 2017), 600,000 times before sending it. We then run the result through PBKDF2 again with a random salt of its own before storing it. We never receive or keep your actual password.

Research referred to

  1. Das, A., Bonneau, J., Caesar, M., Borisov, N., & Wang, X. (2014). The tangled web of password reuse. Network and Distributed System Security Symposium (NDSS). doi.org/10.14722/ndss.2014.23357
  2. FlorĂȘncio, D., & Herley, C. (2007). A large-scale study of web password habits. Proceedings of the 16th International Conference on World Wide Web. doi.org/10.1145/1242572.1242661
  3. Li, L., Pal, B., Ali, J., Sullivan, N., Chatterjee, R., & Ristenpart, T. (2019). Protocols for checking compromised credentials. ACM Conference on Computer and Communications Security (CCS). doi.org/10.1145/3319535.3354229
  4. Moriarty, K., Kaliski, B., & Rusch, A. (2017). PKCS #5: Password-Based Cryptography Specification Version 2.1 (RFC 8018). doi.org/10.17487/RFC8018

Need more help?

Ask the site you were signing in to about its own service. For your Omxus account, try these next steps.