OmxusHelp

HelpAbout Omxus

Why Omxus exists

People keep a different username and password for almost every site they use. Most of those sites store the password, ask for more personal details than they need, and give each person an ID other companies can match. Omxus exists to make signing in simpler for people and safer by design.

The name

Omxus is said OHM-SHUSS. The x sounds like the x in pinyin, a soft "sh". The name reads as Om, the sound of everything, times us. It also helped that omxus.com was available for $11.

What we believe

One account, every site

You shouldn't need a new password for every site you visit. One Omxus account signs you in wherever you see the ring.

Your identity is yours

Signing in proves it's you. It shouldn't hand a record of your life to the service that checks it, or to anyone else.

A private ID for each site

Sites that sign you in through the Omxus sign-in page each get their own ID for you, so they can't match you up by it.

Hold what we need, say exactly what

We keep the few things signing in requires, and we list every one of them in plain words.

Why these choices

Fewer passwords, less reuse

People reuse passwords across sites because remembering dozens of them is hard. When one site leaks, attackers try those passwords everywhere else (FlorĂȘncio & Herley, 2007; Das et al., 2014). One account with a strong password or passkey means one thing to protect well.

Passkeys, because fake pages work

Careful people still fall for convincing fake pages (Dhamija, Tygar & Hearst, 2006). A passkey only works on the site it was made for, so a fake page gets nothing. Security guidance treats this as a strong protection (Grassi et al., 2017).

Private IDs, because records link easily

Separate records can often be joined into one picture of a person using only a few details they share (Narayanan & Shmatikov, 2008). Giving each site its own ID removes one easy join.

Checking breached passwords without seeing them

We can warn you about a password from a past breach without your password leaving your device, using a range check that shares only a small part of a scrambled fingerprint (Li et al., 2019).

An option with nothing to reset

Omxus also offers a way to sign in with your name, date of birth and secret words. Your device turns them into a key, so there's no password stored anywhere to steal or reset. It's optional, and most people start with an email and a passkey. Learn how it works.

Read Our approach to privacy.

Research referred to

  1. FlorĂȘncio, D., & Herley, C. (2007). A large-scale study of web password habits. Proceedings of the 16th International Conference on World Wide Web. doi.org/10.1145/1242572.1242661
  2. Das, A., Bonneau, J., Caesar, M., Borisov, N., & Wang, X. (2014). The tangled web of password reuse. Network and Distributed System Security Symposium (NDSS). doi.org/10.14722/ndss.2014.23357
  3. Dhamija, R., Tygar, J. D., & Hearst, M. (2006). Why phishing works. Proceedings of the SIGCHI Conference on Human Factors in Computing Systems. doi.org/10.1145/1124772.1124861
  4. Grassi, P. A., Fenton, J. L., Newton, E. M., et al. (2017). Digital Identity Guidelines: Authentication and Lifecycle Management (NIST Special Publication 800-63B). National Institute of Standards and Technology. doi.org/10.6028/NIST.SP.800-63b
  5. Narayanan, A., & Shmatikov, V. (2008). Robust de-anonymization of large sparse datasets. IEEE Symposium on Security and Privacy. doi.org/10.1109/SP.2008.33
  6. Li, L., Pal, B., Ali, J., Sullivan, N., Chatterjee, R., & Ristenpart, T. (2019). Protocols for checking compromised credentials. ACM Conference on Computer and Communications Security (CCS). doi.org/10.1145/3319535.3354229

Need more help?

Ask the site you were signing in to about its own service. For your Omxus account, try these next steps.