KNOWLEDGEBASE
SECURITY

Best Practices

3 min read·Article 01 / 03

Practical account-security guidance for DigiFX Media Console users, plus what the Console enforces on your behalf so you know where the line between the two sits.

01Choose a password by length, not by punctuation

The Console sets its own password floor above the authentication provider's minimum, and the floor is length: at least ten characters. Composition rules — a capital, a digit, a symbol — feed the strength meter and the advice under it, but they never block a submission. That is deliberate. A rule demanding a symbol is the reason Password1! exists, whereas length is the only property that reliably buys entropy from real people. A long passphrase with no punctuation passes, and should.

A few things are refused outright rather than scored down: passwords on the short list of the most commonly used passwords in the world, a single character repeated to reach the length floor, and any password containing your own name or the local part of your email address. The last one catches the case a server-side policy is worst at — a password that looks strong in the abstract and is worthless for this specific account.

02Turn on two-factor authentication

The Console supports a time-based one-time password (TOTP) second factor from any standard authenticator app. It is opt-in, and you enroll from Settings → Security.

Four things are worth knowing before you enroll:

  • Your email address must be verified first, and you must have signed in recently. If your session is old, you will be asked to re-authenticate.
  • Once enrolled, the second factor applies to every sign-in method on the account, including Google sign-in.
  • Enrolling ends your other sessions. Other tabs and devices are signed out and must re-authenticate with a code.
  • Some clock drift on your phone is tolerated, so a code that is slightly stale still works. A badly wrong clock will not.

03Save your recovery codes at enrollment

Enrollment mints a set of ten single-use recovery codes and shows them once. Save them somewhere you can reach without the phone that holds your authenticator — that is the entire point of them.

Two facts people learn the hard way: codes can only be minted at enrollment, so there is no way to generate a set later for an account that is already enrolled; and a password reset does not clear a second factor. If you reset your password and still cannot get in, the password was never the problem.

04Use the Security page as a self-check

The Console's Security page reports real account state rather than a score. It shows whether your connection is a secure context, whether your email is verified, how many second factors are enrolled, and a live round-trip against the data layer with its true latency. It also lists genuine account alerts, the expiry of your current session token, and a merged log of sign-ins, setting changes, and billing events.

Sections without a real backing source say so rather than displaying a reassuring number.

Need custom diagnostic analysis?

Contact our support engineers directly to initiate bespoke technical resolution.

CONNECT SUPPORT