To keep your Host Media client area account as secure as possible, we have enabled Two-Factor Authentication (2FA) for all client area logins. This guide explains what 2FA is, why it matters, and how to get yourself set up in just a couple of minutes.
What is Two-Factor Authentication?
A standard login uses just your username and password. If that password is ever stolen or guessed, an attacker can walk straight into your account. Two-factor authentication adds a second, independent check before access is granted.
Even if someone has your password, they cannot log in without your second factor , such as a code from your phone or a physical security key. Think of it like a bank card: you need both the card itself and your PIN. One without the other is useless.
Why We Are Requiring 2FA
Your client area account is where your domain names, billing details, and hosting services are managed. Gaining access to it would allow an attacker to transfer domains, change payment details, or alter your services. It is worth noting that this 2FA requirement applies to the client area login only , your hosting control panel, webmail, and other services are not affected. Attackers typically gain access to client area accounts using the following methods:
- Phishing: Convincing fake login pages designed to capture your username and password without you realising.
- Credential stuffing: Taking leaked username and password combinations from other data breaches and trying them on hosting accounts. If you reuse passwords across different services, this is a genuine risk.
- Brute force attacks: Automated tools that cycle through large numbers of common and guessable passwords.
Enabling 2FA makes all three of these attacks effectively useless against your account. Even if an attacker has your correct password, they still cannot get in without access to your phone or hardware key. It is one of the most impactful security steps you can take.
Your Two Options
We support two 2FA methods. You only need to set up one. Choose whichever suits your workflow best.
Option 1: Time Based Tokens (TOTP)
An authenticator app on your smartphone or desktop/browser generates a fresh six-digit code every 30 seconds. At login, you enter the current code alongside your password. The app works completely offline , no internet connection is needed to generate codes once it is set up.
Good for: Most customers. It is free, quick to configure, and works on any iOS or Android smartphone.
Option 2: Yubico (YubiKey)
A YubiKey is a small, durable hardware key that plugs into your computer via USB or taps via NFC. At login, you simply touch the gold contact on the key to verify your identity. No codes to type, no phone needed, no battery to charge.
Good for: Those who prefer hardware-based security, or who would rather not rely on a smartphone for authentication. YubiKeys are available from yubico.com from around £25 and are a one-off purchase.
Recommended Apps for Time Based Tokens
If you choose the Time Based Tokens method, you will need an authenticator app on your phone or computer. Here are our recommendations:
- Google Authenticator , iOS | Android
Free and straightforward. The most popular choice for basic TOTP authentication with no extras needed. - Microsoft Authenticator , iOS | Android
Free, with cloud backup so your codes can be restored to a new phone. - Authy , iOS / Android / Desktop
Free, with multi-device support and encrypted cloud backup. A great option if you want access to your codes on both your phone and your computer. - 1Password , iOS / Android / Desktop / Browser
A paid password manager (from around £2.65/month) with built-in TOTP support. A convenient choice if you want to manage your passwords and 2FA codes together in one place. - Bitwarden , iOS / Android / Desktop / Browser
A free, open-source password manager. TOTP support is included in its Premium tier at around £8/year.
How to Enable Time Based Tokens (Step by Step)
- Download and install your chosen authenticator app using the links above.
- Log in to your Host Media client area.
- Click your name in the top-right corner and choose Security Settings.
- Under the Two-Factor Authentication section, click Click Here to Enable.
- Select Time Based Tokens from the list and click Get Started.
- A QR code will appear on screen. Open your authenticator app and look for the option to add a new account , usually a "+" button or a "Scan QR code" option.
- Point your phone's camera at the QR code through the app to scan it. If prompted for a name, we suggest entering Host Media.
- Your app will now display a six-digit code that refreshes every 30 seconds. Enter the current code into the Verification Code field on the page.
- Click Submit. Two-Factor Authentication is now active on your account.
How to Enable Yubico (Step by Step)
- Insert your YubiKey into a USB port on your computer.
- Log in to your Host Media client area.
- Click your name in the top-right corner and choose Security Settings.
- Under the Two-Factor Authentication section, click Click Here to Enable.
- Select Yubico from the list and click Get Started.
- Click inside the YubiKey OTP field on the page so the cursor is active inside it.
- Touch the gold contact on your YubiKey. It will automatically generate and fill in a one-time code.
- Click Save Changes. Two-Factor Authentication is now active on your account.
Frequently Asked Questions
- What if I lose access to my authenticator app?
- Please contact our team and we will verify your identity and temporarily disable 2FA on your account so you can log back in. We strongly recommend keeping your backup codes (issued during TOTP setup) stored somewhere safe to avoid this situation.
- What if I lose my YubiKey?
- Contact our support team to have 2FA disabled after identity verification. We recommend purchasing a second YubiKey as a spare and registering it ahead of time. You can switch between 2FA methods at any time from your Security Settings.
- I do not have a smartphone. Can I still use 2FA?
- Yes. Authy, 1Password etc have desktop applications for Windows and Mac that works without a smartphone. A YubiKey is also a fully phone-free option.
- Will I need to enter a code every single time I log in?
- Yes, your second factor will be required at each login. Most customers find it adds only a few seconds once they are used to the process.
- I manage sub-accounts or contact accounts under my main account. Will they need 2FA too?
- Yes. Any account that can log in to the client area will be required to have 2FA enabled.
- Is there any cost involved?
- The Time Based Tokens method is completely free. The Yubico method requires purchasing a YubiKey, which costs from around £25 and is a one-off purchase.
- Can I switch from one method to the other later?
- Yes. You can disable your current 2FA method and set up a different one at any time from your Security Settings in the client area.
- I am already locked out because 2FA was enforced and I am not set up. What do I do?
- Please contact our support team directly by email at [email protected] and we will get you back in after verifying your identity.
Need Help?
If you have any trouble setting up 2FA or have a question not answered above, our support team is happy to assist.