# Sign-in and security The dashboard lives on the public internet, so a password is never enough on its own. ## Ways in - **Passkey**: Face ID, Touch ID, Windows Hello, Android or a security key. One tap, and it cannot be phished. - **Email and password, then a 6-digit code** from your authenticator app. A guessed or leaked password alone gets nobody in. - **Recovery code** instead of the 6-digit code, when your phone is gone. Each code works once and using one emails you. - **Forgot password** emails a link, and the new password still needs your authenticator or a recovery code. - **Break glass**: on the server, `farsightd enroll-link` prints a one-time link to add a passkey. ## Brakes - A browser check (Cloudflare Turnstile) before every sign-in attempt; the button stays disabled until it passes. - 5 failed password or code attempts from one address in 15 minutes block that address for an hour; 3 blocks in a day block it for a day (`farsightd unblock ` or Settings lifts it). A blocked address gets the same answer as a wrong password. Passkeys still work from a blocked address: they cannot be guessed, and many people share one address on mobile networks. - More than 30 failed password attempts in an hour, from anywhere, turn password sign-in off for an hour (passkeys still work) and email you. - Every new sign-in emails you: how, from where, which device. ## Sessions Sessions last 30 days of use (90 at most). Settings lists them with device and address; sign any out, or all others. Sensitive changes (passkeys, password, authenticator, recovery codes, API keys, alert channels, deleting monitors, exports) need a sign-in within the last 12 hours; otherwise Farsight asks you to confirm with a passkey tap or password and code, then carries on. ## Data Passwords are hashed with Argon2id. Sessions, API keys, links and recovery codes are stored only as SHA-256 hashes. Channel secrets, monitor credentials and the authenticator secret are encrypted (AES-256-GCM) with a key that lives only in the data folder (`master.key`). The data folder is readable by the service user alone. ## Network Farsight never probes cloud metadata addresses, and by default refuses private targets (loopback, private networks, CGNAT and Tailscale addresses) so an API key cannot reach services that were never meant to be public. A signed-in owner can allow private targets in Settings for a home network. The dashboard sends a strict Content Security Policy, HSTS and no-framing headers.