OmxusHelp

HelpAccount security

How Omxus protects your account

Every Omxus account gets the same protections, whether or not you change any settings. Here's what they do.

Your password stays on your device

Your device scrambles your password with PBKDF2 600,000 times before sending it, and we scramble that again with a random salt before storing it (Moriarty et al., 2017). We never receive or store your password. Codes and sign-in tokens are stored only as one-way fingerprints, so a copy of our database wouldn't reveal them.

Guessing gets nowhere

  • After 3 failed tries in 15 minutes, each answer takes longer, up to 4 seconds.
  • After 10 failed tries in 15 minutes, that address, account or network pauses for 15 minutes.
  • Each code allows 5 tries and lasts 10 minutes.

Nobody can check whether you have an account

Sign-in, codes and sign-up give the same answer whether or not an address has an account, and take the same time. If someone tries to sign up with your address, your account stays untouched and you get a note about it. The one deliberate exception is checking whether a username is free, which is limited per network.

Sign-ins that expire and can't be copied

  • The key a site uses for your sign-in lasts 15 minutes and renews in the background.
  • Each renewal works once. If an old one is used again, which can mean someone copied it, we end that whole sign-in.
  • Every sign-in ends after 90 days at most.
  • Changing your password signs out every other device. Changing your email or mobile, or deleting your account, signs out every device.

These follow current best practice for sign-in tokens (Lodderstedt et al., 2025).

Changes need you to confirm

Changing your password, email or mobile, removing a passkey, and deleting your account all ask you to confirm with your password or a code, unless you signed in within the last 10 minutes. A change of email or mobile sends a code to the new address and a notice to the old one.

Passkeys checked carefully

We require your fingerprint, face or PIN for every passkey sign-in, and we check each passkey is the same one you saved, so a cloned passkey stands out.

Sites can only use Omxus from their own addresses

A site registers the web addresses it signs in from. Sign-in requests from anywhere else are refused, and Omxus never sends a sign-in to an address the site didn't register.

A record for you

Your account keeps 90 days of security events you can review.

Research referred to

  1. Moriarty, K., Kaliski, B., & Rusch, A. (2017). PKCS #5: Password-Based Cryptography Specification Version 2.1 (RFC 8018). doi.org/10.17487/RFC8018
  2. Lodderstedt, T., Bradley, J., Labunets, A., & Fett, D. (2025). Best Current Practice for OAuth 2.0 Security (RFC 9700). doi.org/10.17487/RFC9700

Need more help?

Ask the site you were signing in to about its own service. For your Omxus account, try these next steps.