Security and two-factor authentication
Everything about how you get into Teralo sits on one page: Settings, then Account, then Security & Access. Your password, the outside accounts you can sign in with, and two-factor authentication.
Nothing on this page is set by your organisation. An administrator can decide what you are allowed to do once you are in, but how you prove it is you is yours alone.
Change your password
The Login Methods card carries a Change password button. It asks for the new password twice, then emails a six-digit code to your current account address and makes the change when you enter it. The code lasts fifteen minutes, and a wrong one can be retyped straight away.
You are not asked for your old password. Control of the mailbox is the proof, which is the same standard as a reset, and it means a password you cannot remember is no harder to replace than one you can.
Password rules
A password must be at least eight characters and contain an uppercase letter, a lowercase letter, a number and a special character. The form says which rule you have missed as you type.
Changing your password here does not sign out your other devices. The old sessions carry on until they expire. If the reason you are changing it is that somebody else may have had it, use Forgot password on the sign-in screen instead: see the last section of this article.
Signing in with Google, Microsoft or Apple
All three are offered on the sign-in screen and all three can be linked to an existing Teralo account, from the same Login Methods card. A linked account is an extra way in rather than a replacement: your password keeps working unless you never set one.
Each row shows the address held by the provider once linked, so you can see at a glance which Google account is attached.
Teralo never links two accounts silently. If you sign in with a provider whose email matches an existing Teralo account, you land on a Confirm account link screen and have to enter your Teralo password first. Matching email addresses are not, on their own, proof of the same person.
Linking and unlinking
Link on any provider row sends you out to that provider and back. Unlink is the same button once linked, and it takes effect immediately.
Two things to know before you unlink.
Unlinking is not blocked, even when it is your only way in. Nothing checks that you have another sign-in method first, so if you signed up with Google and never set a password, unlinking Google leaves you with no way to authenticate. Use Change password to set one first: it works on an account that has never had one, because the verification code goes to your email rather than depending on the old password.
Your email is locked while Google or Microsoft is linked. Changing your address means unlinking first. See Your profile.
Two-factor authentication, or 2FA
Two-factor authentication, also written 2FA, adds a second step after your password: a six-digit code from an authenticator app on your phone. Teralo uses the standard TOTP scheme, so any of them work, including Google Authenticator, Microsoft Authenticator, 1Password, Bitwarden and Authy.
It is opt-in for everybody except system administrators, who are required to have it and cannot turn it off.
It is worth turning on. A Teralo account reaches contract sums, claim certificates, incident reports and the drawing set, and the password on it is the only thing between all of that and whoever guesses it.
Set up two-factor with an authenticator app (TOTP)
Set up two-factor on the Security & Access page opens the enrolment screen.
- Scan the QR code with your authenticator app. If you are on the phone that holds the app, or the camera will not focus, the secret is printed underneath with a copy button so you can type it in by hand.
- Enter the six-digit code the app now shows, and press Enable two-factor.
- Save your backup codes. Ten of them appear, with Copy and Download buttons, and you tick a box to confirm you have kept them before you can continue.
The codes are shown once and never again. Put them somewhere that is not the phone holding the authenticator app, because the case they exist for is losing that phone.
Backup codes
Each of the ten is single use. The Security & Access page shows how many are unused, as "N of 10 codes remaining".
Regenerate codes issues a fresh ten and asks for your password to do it. The old ten stop working the moment you do, including any you have written down elsewhere, so regenerate when you are low or when you think the list has been seen, and replace what you have saved at the same time.
Signing in with two-factor on
After your password, or after a Google, Microsoft or Apple sign-in, you get a Two-factor verification screen. Type the code from your app.
Use a backup code instead is on that screen if the app is not to hand. It takes one of your ten and consumes it.
Two details that catch people out. The verification screen expires after five minutes, so if you walk away mid sign-in you start again from your password. And wrong codes are rate limited, so guessing is not a strategy: if the code will not take, check that your phone's clock is set automatically, because a TOTP code is derived from the time.
Turning two-factor off
Disable two-factor asks for your password and a current six-digit code, together. Both, because turning the protection off should be no easier than using it.
Disabling also clears every backup code. Turning it back on later is a fresh enrolment: a new QR code, a new secret, ten new codes.
System administrators have no disable button. Their row reads "Required for system administrators" instead.
Account recovery: a lost phone or lost codes
There is a way back, and it goes through Teralo rather than through your own organisation. Nobody in your organisation can lift two-factor on your account, not your administrator and not the project host, by design.
The two-factor screen carries a link reading Contact support for account recovery. It opens a short form: your email, your name, and what happened. That reaches Teralo support, who will contact you at the address you gave. Sign out while you wait.
This is the reason the backup codes matter. Recovery is a conversation with a human, and it is measured in hours rather than seconds.
Sessions, and how to sign out everywhere
A signed-in session lasts thirty days. Using Teralo inside the last fifteen of them pushes it out to thirty again, so an account in regular use does not ask for a password on a schedule.
There is no list of your signed-in devices, and no per-device sign-out. Signing out ends the session on the device you are using. The one thing that ends them all at once is a password reset, which is why the section below sends you to Forgot password rather than to Change password. On a phone or tablet, signing out also wipes the offline copy Teralo keeps on that device, so the next person to sign in on it inherits nothing.
If you think your account is compromised
Use Forgot password on the sign-in screen, not Change password in settings. The two do not do the same thing, and the difference is the whole point here.
A password reset ends every session on your account, everywhere, including one an attacker has already opened. The in-app Change password does not, because it is the routine housekeeping tool and it runs inside the session you are already using. Since there is no device list to sign devices out from, the reset is Teralo's sign-out-everywhere.
So, in order:
- Sign out, then use Forgot password on the sign-in screen. Teralo emails you a reset link. Setting a new password through it closes every open session at the same time.
- Turn two-factor on if it is not already. It is what stops the same thing happening with the next password.
- Tell your administrator and tell Teralo support. See Contacting support.
Then look at what the account could reach while it was open: your sent mail, anything approved in your name, and the activity log on the records you work in. Actions in Teralo are attributable, so there is a trail.