Why Omxus exists
People keep a different username and password for almost every site they use. Most of those sites store the password, ask for more personal details than they need, and give each person an ID other companies can match. Omxus exists to make signing in simpler for people and safer by design.
The name
Omxus is said OHM-SHUSS. The x sounds like the x in pinyin, a soft "sh". The name reads as Om, the sound of everything, times us. It also helped that omxus.com was available for $11.
What we believe
One account, every site
You shouldn't need a new password for every site you visit. One Omxus account signs you in wherever you see the ring.
Your identity is yours
Signing in proves it's you. It shouldn't hand a record of your life to the service that checks it, or to anyone else.
A private ID for each site
Sites that sign you in through the Omxus sign-in page each get their own ID for you, so they can't match you up by it.
Hold what we need, say exactly what
We keep the few things signing in requires, and we list every one of them in plain words.
Why these choices
Fewer passwords, less reuse
People reuse passwords across sites because remembering dozens of them is hard. When one site leaks, attackers try those passwords everywhere else (FlorĂȘncio & Herley, 2007; Das et al., 2014). One account with a strong password or passkey means one thing to protect well.
Passkeys, because fake pages work
Careful people still fall for convincing fake pages (Dhamija, Tygar & Hearst, 2006). A passkey only works on the site it was made for, so a fake page gets nothing. Security guidance treats this as a strong protection (Grassi et al., 2017).
Private IDs, because records link easily
Separate records can often be joined into one picture of a person using only a few details they share (Narayanan & Shmatikov, 2008). Giving each site its own ID removes one easy join.
Checking breached passwords without seeing them
We can warn you about a password from a past breach without your password leaving your device, using a range check that shares only a small part of a scrambled fingerprint (Li et al., 2019).
An option with nothing to reset
Omxus also offers a way to sign in with your name, date of birth and secret words. Your device turns them into a key, so there's no password stored anywhere to steal or reset. It's optional, and most people start with an email and a passkey. Learn how it works.
Read Our approach to privacy.
Research referred to
- FlorĂȘncio, D., & Herley, C. (2007). A large-scale study of web password habits. Proceedings of the 16th International Conference on World Wide Web. doi.org/10.1145/1242572.1242661
- Das, A., Bonneau, J., Caesar, M., Borisov, N., & Wang, X. (2014). The tangled web of password reuse. Network and Distributed System Security Symposium (NDSS). doi.org/10.14722/ndss.2014.23357
- Dhamija, R., Tygar, J. D., & Hearst, M. (2006). Why phishing works. Proceedings of the SIGCHI Conference on Human Factors in Computing Systems. doi.org/10.1145/1124772.1124861
- Grassi, P. A., Fenton, J. L., Newton, E. M., et al. (2017). Digital Identity Guidelines: Authentication and Lifecycle Management (NIST Special Publication 800-63B). National Institute of Standards and Technology. doi.org/10.6028/NIST.SP.800-63b
- Narayanan, A., & Shmatikov, V. (2008). Robust de-anonymization of large sparse datasets. IEEE Symposium on Security and Privacy. doi.org/10.1109/SP.2008.33
- Li, L., Pal, B., Ali, J., Sullivan, N., Chatterjee, R., & Ristenpart, T. (2019). Protocols for checking compromised credentials. ACM Conference on Computer and Communications Security (CCS). doi.org/10.1145/3319535.3354229
Need more help?
Ask the site you were signing in to about its own service. For your Omxus account, try these next steps.