Is Two-factor Authentication (2FA) available?
Yes. You can set up Two-factor Authentication (2FA) on your S.T.A.R. Storage account - using SMS or Time-based One-time Passwords (TOTP) using an authenticator app.
To begin setting up 2FA on your account, go to your account's User Profile and click 'Enable' in the Two-factor Authentication section. With a verified S.T.A.R. Storage account and the correct mobile number registered with us, click the 'Verify' button next to your mobile number on the User Profile page to begin the SMS verification process.
1) 2FA by SMS
Click the 'By SMS' button at the Two-factor Authentication section of the User Profile.
2) 2FA by an authenticator app
This is a more secure 2FA option than SMS. It requires downloading a third-party authenticator app that generates a time-based one-time password (TOTP). This password is local to your mobile phone and does not communicate with the outside world. It is also refreshed after some seconds have passed to ensure that generated passwords are unique.
You can use any preferred authenticator app. If you are setting up TOTP 2FA for the first time, you can consider the following to begin with:
1) Google authenticator (commonly used)
2) Authy (if you want the TOTP codes to sync between devices)
3) andOTP (if you prefer open source)
With the authenticator app downloaded onto your mobile phone, click the 'Use Auth App' button on the Two-factor Authentication section in your account's User Profile. A QR code will be generated on the next page. Scanning this QR code with your authenticator app will result in a password generated by the app. Enter this code in the field at step 2 on the page with the QR code and click the 'Enable' button.
On the next page, please enter the codes sent to the phone number and email registered in your S.T.A.R. Storage account in the 2 respective fields. Then click 'Verify'.
TOTP 2FA is now set up on your account. You will be prompted to enter the code from your authenticator app whenever you login to your account or perform transactions that require this further verification step.