Skip to content
All guides

Privacy

Two-factor authentication and account security on LiveNote

How sign-in security works on LiveNote: optional accounts, authenticator-app or emailed-code two-factor, what a password reset does to your sessions, and the limits of all of it.

Updated 6 min read

LiveNote works without an account — a fresh page is one click away, and anonymous notes are a first-class feature. But if you do keep an account, the security around it should be understandable rather than taken on faith. This guide walks through what is actually in place: two-factor authentication, how passwords and sessions are handled, and what each layer protects you from.

Two-factor, two ways

Two-factor authentication is optional, and both methods are enabled from Settings. You pick whichever suits you:

  • An authenticator app (TOTP). The standard time-based one-time password flow: pair Settings with Google Authenticator, Aegis, 1Password, or any TOTP app, and enter the six-digit code at sign-in. Your codes are generated on your device.
  • A code by email. If you would rather not manage an authenticator app, a sign-in code can be emailed to you instead. Same idea, different delivery.

Both exist because the weakest point of most accounts is a password that leaked from some other site. A second factor makes a leaked password alone not enough.

What a sign-in code can and cannot survive

The codes are deliberately unsentimental:

  • They expire in 10 minutes. A code that is still valid tomorrow would be a second password, not a second factor.
  • They burn after 5 wrong attempts. Five wrong entries and the code is deleted; a fresh one has to be issued. Guessing is not a strategy.
  • They are single-use. Entering a code correctly consumes it.

Passwords and resets

Account passwords are hashed with argon2id, a deliberately slow, memory-hard function, before they are stored. The server can verify a password you type; it cannot tell you a password you forgot. And sign-in attempts are rate-limited, so password guessing happens at the speed of nothing.

One consequence of the reset flow is worth knowing: resetting your password signs out every session, on every device. If you reset because a laptop was stolen, that stolen session dies with the reset. If you reset because you forgot the password, you will simply sign in again on your other devices.

How sessions work

When you are signed in, your browser holds an opaque cookie token — a random string that is not your password and carries no information in itself. The server stores only a hash of that token. A stolen database contains no usable session tokens, and there is nothing in the cookie to reverse.

Anonymous notes are a different system

Anonymous notes have no account to protect, so they use a different mechanism: a recovery key. The recovery key is the way to re-attach an anonymous note to a browser or hand it to a new one, and it lives wherever you put it. Lose the key and the note is unreachable — that is the trade for the note being tied to nothing else.

None of this is exotic; it is the standard toolkit, chosen deliberately and implemented the plain way. Turn on 2FA if you keep anything important in your account, and let links — not logins — be the only thing you ever hand to other people.