Account Security
Everything on this page lives in one place: Security settings, from the gear in the navbar or the Security panel on your profile. Nothing here costs anything, nothing here is a plan tier, and the defaults are chosen so an account is safe before you open the page at all.
Your access keys are not on this page and are not affected by anything on it. Those authenticate S3 requests and are managed per bucket and per account in the dashboard. Signing out everywhere does not stop a running backup.
What a sign-in actually asks for
Up to three things, in this order:
-
Your password. Always.
-
Your authenticator app's code, if you set one up. Asked before the email code, so a wrong app code sends no mail.
-
A six-digit code emailed to your verified address. This is browser verification, and it is on for every account with a verified address. There is no switch for it.
On a browser you told Storm to remember, steps 2 and 3 are skipped until their cadence runs out.
Browser verification
A code goes to your verified address after your password. It is not optional and it has no off switch: an account with an unverified address cannot sign in at all.
Re-verify cadence is how long a remembered browser skips that code. Shorter means the code is asked more often.
The authenticator app
Off until you set it up. Once on, it is a second six-digit code from an app on your phone, asked after your password and before the email code.
Setting it up costs your password, and Storm shows the secret once, as a QR code and as text. It is never shown again and appears on no screen afterwards. Removing the app costs a live code from it, which is why a lost phone cannot be used to turn it off.
App cadence is how long a remembered browser skips the app's code, the same idea as the re-verify cadence.
Recovery codes
At your first sign-in after your address was verified, Storm showed you ten recovery codes once and asked you to confirm you had saved them. Each works one time, in place of either code: the email code, or the app's code if you set one up. At the app step a recovery code stands in for the app only, so a browser that still owes the email code is asked for it next.
They are issued once. Storm does not reissue them and does not show them again, because they are stored only as one-way hashes it cannot reverse. Completing an account recovery issues a fresh set.
If you have lost them and still have your inbox, you are not locked out: the email code is a way in. If you have lost both, Account Recovery covers proving control with an access key.
Remembered browsers
At sign-in, Remember this browser for longer sessions is checked by default. Uncheck it on a machine you do not control.
Checked, the browser is added to the list on your profile, and it can skip the codes for as long as your cadences allow. The list shows a name, the browser and operating system, when it was last used and from which IP address, and when its session expires. You can forget any browser at any time, which also signs it out and drops its IP and browser details immediately.
Unchecked, nothing is remembered: no name, no browser details, no IP address. The session ends when the browser closes, or after 24 hours at the latest, and the code is asked every time. Your profile shows only how many such sign-ins are open, with one control to end them all.
Forget browsers when their session ends is on unless you turn it off. On, logging out or an idle sign-out forgets the browser. Off, the browser stays on the list until a cadence runs out, its session expires, or you forget it, and it keeps only its name and dates.
Session length and idle logout
Two separate clocks, and both are enforced on every request rather than checked at sign-in.
-
Session length signs you out this long after you signed in, whatever you were doing.
-
Idle logout signs you out after this long without opening a page. Background polling does not count as you being there, so a dashboard left open on a second monitor still goes idle.
A browser you did not ask Storm to remember is capped at 24 hours regardless of what these say.
NIST AAL2
A line on the Security card that tells you whether your current settings meet the second authenticator assurance level in the United States NIST digital identity guidelines. It is a readout, not a setting. Storm shows it because some customers have to answer that question for someone else, and reading it off your own settings is easier than deriving it.
What Storm will not do
-
No self-serve email change. The address on file is the reset channel, so changing it from inside a session that might not be yours would repoint the way back in. It moves only through account recovery.
-
No support-desk override. Nobody at Storm can be talked into granting access. The only human gesture in the recovery path is a refusal.
-
No recovery code answers a Buckets control action. They are the way back into an account, not a substitute for a check you set on an action.
Defaults, in one place
If you never open Security settings, this is what you have:
| Setting | Default |
|---|---|
| Browser verification | On, and not switchable |
| Authenticator app | Off |
| Recovery codes | Ten, issued at your first verified sign-in |
| Remember this browser | Checked at sign-in |
| Forget browsers when their session ends | On |
| Unremembered sign-in | Ends with the browser, 24 hours at most |