Credential safety
Strong passwords, password managers, and credential isolation.
Walk through the four desk passes in order. They take about ten minutes the first time and five on subsequent visits.
Strong passwords, password managers, and credential isolation.
Authenticator apps versus SMS. Why authenticator wins.
Recovery codes, recovery email, and an offline backup.
What to do if the account is locked and self-service recovery fails.
The Come login credential is the gateway to every other safety feature on the platform. A weak credential exposes every other protection. Build it on solid footing before any other step.
A strong password is at least 16 characters, randomly generated by a password manager, and unique to the platform. No personal dates, no platform names, no dictionary words.


The day the password fails is not a day to improvise. Prepare the recovery path while the account is healthy, store the recovery codes offline, and rehearse the recovery flow once a year.
If the account is locked or two-factor is lost, the platform's self-service recovery flow is the first place to go. Walk through the steps in order and keep records of every request.

Two-factor is the second layer of protection on the account. The choice of second factor matters — the wrong choice can be defeated.
The strongest practical option. Codes are generated locally on the device. No network interception. Examples: Aegis, Authy, Google Authenticator, 1Password.
The strongest option overall. A physical key that the platform verifies via USB or NFC. Examples: YubiKey, Titan Key.
Better than SMS but weaker than an authenticator. Confirmations can be accidentally accepted.
The weakest option. Codes can be intercepted through SIM swap, SS7 attacks, or compromised telco accounts. Avoid where the platform offers anything stronger.
Once login is solid, the wallet and identity-verification walkthrough covers what to prepare and how to confirm the verification page is genuine.