Two Factor Login on Awazon Market
TOTP from any authenticator
Login requires your passphrase plus a code from an authenticator app. You can use Google Authenticator, Authy, or similar apps. Scan the QR code shown during setup. The app generates a six-digit code every 30 seconds. Enter this code along with your password to access your account. The code changes constantly, adding a layer beyond static passwords. Install the app on your primary phone. Keep the device charged. If you lose phone access, you lose TOTP access. Sync your authenticator across devices if possible. Some apps allow cloud backup. Enable this feature if you use multiple phones. The code must match the current time window. Delays over 30 seconds cause rejection.
The PGP challenge backup
If you lose your phone, you can use a PGP challenge. The system sends a random string. You sign it with your private key and send the result back. This method requires your private key to be available. Keep a copy of your private key in a secure location. Test this backup method once a month. Generate a dummy challenge and sign it. Ensure your signing software works. This path is slower than TOTP but reliable. It does not depend on battery life or internet connectivity beyond sending the signed file. Use it only when TOTP is unavailable. Do not make it your default method due to the extra steps involved.
Fresh device logins
Logging in from a new browser or computer triggers an alert. You receive a notification on your existing sessions. Review these alerts regularly. Ignore unknown devices if you recognize the login. Otherwise, force logout remotely. Change your passphrase immediately if the login seems suspicious. The system tracks user agents and IP ranges. A jump from London to Moscow in five minutes flags the account. New device prompts ask for additional verification. Complete these promptly. Delayed responses may trigger temporary locks. Locks last up to 24 hours. During this time, you cannot trade or view balances.
Exporting tokens before moving devices
Before switching phones, export your TOTP tokens. Most apps allow a CSV backup. Encrypt this file with a strong password. Store it separately from your phone. Use a password manager or encrypted archive. Do not email it to yourself. Email accounts are common targets for phishing. Transfer the file to your new device before deleting the old one. Verify the new app generates correct codes. Log in once with the new setup. Confirm everything works. Then remove the app from the old device. Wipe the old device securely if you are selling it. Leftover cached data can leak session info.
When 2FA is not enough
Two factor authentication protects the login gate. It does not protect the wallet directly. If someone knows your passphrase and has your phone, they get in. Phishing sites mimic the login page. Enter credentials on a fake site, and they steal both factors temporarily. Always check the URL carefully. Look for the .onion address. Verify the PGP key of the site operator. Use bookmarks instead of typing. Clear browser caches after closing tabs. 2FA slows down attackers but does not stop them completely. Combine it with strong, unique passphrases. Avoid reusing passwords from other sites. Layered defense works best here.