Finmind account security: two-factor sign-in and more
Редакция Finmind · · Обновлено · Время чтения: 7 мин.
Эта статья пока недоступна на русском языке, поэтому показан английский текст.
Protect your Finmind account with two-factor sign-in, several authenticator apps, recovery codes, Google or Telegram sign-in and security notices.
Your Finmind account can hold your portfolio, a connected brokerage account and your payment history, so it deserves more than a password. This guide walks through every protection Finmind offers, in the order you would set them up: a password and a verified email, two-factor sign-in, recovery codes, extra sign-in methods, and the checks that run in the background. Two-factor authentication is a core security feature, so it is free for every Finmind account, and you can turn it on as soon as you create a Finmind account.
Start with a password and a verified email
When you register, your password must have at least 8 characters and cannot be only digits. You can change it at any time in Settings, in the Security section, with Change password. If you created your Finmind account with Google or Telegram and have no password yet, the same section offers Set password so you can also sign in with your email.
Changing your password signs out every other session. If someone else had your old password and was signed in somewhere, that session ends.
Your email matters because sign-in codes and security notices go there. In Settings, the Email section shows whether your address is Confirmed. If it is not, choose Verify email: Finmind sends a 6-digit code that is valid for 10 minutes and stops working after too many wrong guesses.
If you forget your password
On the sign-in page, choose Forgot password? and enter your email. Finmind emails you a single-use link to choose a new password. The page gives the same answer whether or not a Finmind account exists for that address, so the form cannot be used to find out who uses Finmind. When you set the new password, every session of your Finmind account ends, including any that someone else might have opened.
Turn on two-factor authentication
Two-factor authentication means that after your password, Finmind asks for a second code that only you can produce. You find it in Settings, in the Two-factor authentication section. There are two methods, and one of them is active at a time:
- Authenticator app: codes from an app such as Google Authenticator, Microsoft Authenticator or 1Password. Codes are 6 digits, change every 30 seconds and work without a network connection.
- Telegram codes: a code is sent to your linked Telegram at every sign-in. You link Telegram first in the Telegram section of Settings. Finmind sends a test code before turning this on, so you are never locked behind codes that do not arrive.
To set up an authenticator app:
- Open Settings and find Two-factor authentication.
- Under Authenticator app, choose Set up the app and confirm your current password.
- Open your authenticator app and add an account for Finmind.
- Scan the QR code, or enter the Setup key by hand.
- Type the 6-digit code the app shows for Finmind and choose Confirm and turn on.
- Save the recovery codes that appear (see below).
Two-factor sign-in only turns on after the code from your app is accepted. You can later switch methods with Switch to Telegram codes or Switch to an authenticator app, or choose Turn off.
Several authenticator apps
You can add up to five authenticator apps, for example your main phone and a backup phone. Choose Add another authenticator app, give it a nickname such as "Backup phone", and confirm it with a code. At sign-in, a code from any of your apps works, and your recovery codes stay the same. Removing one app signs out every other session. Removing the last one turns two-factor authentication off and deletes your recovery codes.
Keep your recovery codes safe
When you turn on two-factor authentication, with either method, Finmind gives you ten recovery codes. Each code works once, in place of a code from your app or Telegram, and they are shown only at that moment. Use Copy codes or Download as text, store them somewhere safe away from your phone, then confirm with I have saved these codes.
If you lose your phone, choose Use a recovery code on the sign-in screen. When you are running low, Settings reminds you, and New recovery codes creates a fresh set. The old ones stop working at once.
Sign in with Google or Telegram
Besides email and password, you can sign in with Google or Telegram. The Sign-in methods section in Settings lists every Google and Telegram account that can open your Finmind account. You can link several of each, up to five per provider, for example a personal and a work Gmail, and give each a nickname so you can tell them apart. Any linked Telegram account can also sign in to the Finmind Mini App (see the Telegram bot and Mini App).
Finmind will not let you remove your only way to sign in. If a Google or Telegram account is all you have, set a password or link another method first.
Protections that work in the background
Several checks run without you having to set anything up:
- Re-authentication for sensitive changes. Linking or removing a sign-in method, changing your email, setting a password and every two-factor change ask for your current password, and also for a second-factor code when two-factor is on. A Finmind account with neither a password nor two-factor must prove itself again through Google or Telegram. A session left open on a shared computer therefore cannot quietly take over your Finmind account.
- Other sessions end after security changes. Turning two-factor on or off, switching methods, creating new recovery codes, changing your password and changing your email all sign out your other sessions.
- Security notices. When two-factor authentication is turned on or off, a recovery code is used to sign in, your sign-in email changes, or a sign-in method is linked or removed, Finmind tells you in the app, in Telegram if you have linked it, and by email. These notices are sent even if you have turned other notifications off, and a change of email is also reported to the old address.
- Limits on guessing. Wrong passwords and wrong codes are counted, and after too many attempts you have to wait before trying again.
- Secrets are not stored in plain text. Authenticator keys are encrypted, and Telegram codes and recovery codes are stored only in hashed form. How your brokerage login is protected is explained in connecting your brokerage account safely.
If you believe you have found a security vulnerability in Finmind, the security page explains how to report it. Market data pages such as UZSE stocks stay public and need no sign-in at all.
Frequently asked questions
Sign in with one of your saved recovery codes by choosing Use a recovery code, then remove the lost phone in Settings and set up your new one. If you had added a second authenticator app, a code from that app also works.
Yes. Finmind supports up to five authenticator apps on one Finmind account. Add each with Add another authenticator app, and a code from any of them is accepted at sign-in.
No. Two-factor authentication, recovery codes and extra sign-in methods are part of the core Finmind account and are available to every user without a purchase.
Yes. Changes such as turning two-factor off, linking a new sign-in method or changing your email trigger a notice in the app, by email and in Telegram if linked, regardless of your notification preferences.