Your Fast Hive client area account is the master key to everything you own with us: hosting, domains, DNS, billing, and single sign-on into cPanel. Anyone who gets into it gets into all of that. Two-factor authentication makes a stolen password useless on its own, and it takes about three minutes to set up.

Why this matters more than it looks. With client area access, an attacker can change your DNS to redirect your website and intercept your email, transfer your domains away, or log straight into cPanel without ever knowing your cPanel password. Two-factor authentication closes all of that off.

Enabling two-factor authentication

  1. Sign in at my.fasthive.com.
  2. Go to Account Security, or find it under your name in the top-right menu.
  3. Find Two-Factor Authentication and click to enable it.
  4. Choose the authenticator app method.
  5. Scan the QR code with an authenticator app on your phone. Any TOTP app works - Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden and others.
  6. Enter the six-digit code the app shows to confirm the pairing.
  7. Save your backup code. This is the single most important step. See below.
The backup code is shown once and never again. Store it somewhere you can reach without your phone - a password manager, or printed and kept somewhere safe. Do not store it only on the phone that holds the authenticator app; losing that phone would then lock you out completely.

Signing in with 2FA enabled

  1. Enter your email address and password as usual.
  2. When prompted, open your authenticator app and type the current six-digit code.
  3. You are signed in. Codes rotate every 30 seconds, so if one is rejected, wait for the next.

If you lose access to your authenticator

  1. On the 2FA prompt, choose the option to use a backup code.
  2. Enter the code you saved when you enabled it.
  3. You are signed in, and that backup code is now spent.
  4. Immediately go to Account Security, disable and re-enable 2FA to pair your new device, and save the new backup code.

If you have lost both the authenticator and the backup code, open a ticket. Identity verification is required before we can remove 2FA from an account - that requirement is what makes the protection worth having, so expect it to take a little time.

The rest of your account security

Two-factor authentication is the biggest single improvement, but these matter too.

Control Where Why
A unique, generated password Account Security Reused passwords are the main way accounts are taken over, via breaches elsewhere.
A current email address Manage Your Account Password resets and security alerts go here. An old address is a real risk.
Security questions Account Security Used to verify you. Treat answers as passwords - they need not be truthful, only memorable.
Sub-users rather than shared logins User Management Each person gets their own access with their own 2FA, revocable individually.
Domain registrar lock My Domains Prevents an unauthorised transfer away. Leave it on except when you are deliberately transferring.

Recognising phishing

Hosting accounts are a common phishing target. Fast Hive will never:

  • Ask for your password, by email, chat or phone.
  • Ask for card details outside the secure client area.
  • Ask you to "verify your account immediately or it will be deleted".
  • Send you a login link for an urgent billing problem.

If a message makes you uneasy, do not click anything in it. Type my.fasthive.com into your browser yourself and check for the notice there. Genuine account issues are always visible when you log in normally. Forward suspicious messages to us via a ticket.

Troubleshooting

Symptom Cause and fix
Codes are always rejected The phone's clock has drifted. TOTP codes depend on accurate time. Turn on automatic date and time on the device, or use the app's time-sync option.
Lost the phone, still have the backup code Sign in with the backup code, then re-pair 2FA on the new device straight away.
Lost the phone and the backup code Open a ticket. Identity verification is required, so allow time.
New phone, app is empty Authenticator entries do not always migrate with a phone backup. Before replacing a phone, disable and re-enable 2FA on the new device.
Password reset email never arrives Check spam, and check whether the account email is one hosted on the very account you are locked out of. Keep a recovery address on a different provider.
You suspect the account was accessed Change the password, enable 2FA, review your DNS records and domain contacts, check for unfamiliar sub-users, and open a ticket immediately.

Frequently asked questions

Which authenticator app should I use?

Any standard TOTP app. If you already use a password manager with a built-in authenticator, that is convenient - just make sure the password manager itself is well protected.

Does 2FA on my account protect cPanel too?

It protects the single sign-on route into cPanel, which is the one most people use. cPanel has its own separate two-factor option you can enable as well.

Will I need a code every single time?

You are prompted when signing in. Ordinary browsing within a session is not interrupted.

Can I require 2FA for my team members?

Each sub-user configures their own two-factor authentication on their own login. Give everyone their own account rather than sharing one.

What if I do not have a smartphone?

Desktop authenticator applications and password managers with TOTP support work exactly the same way.

Locked out, or think your account has been compromised? Open a ticket at My Support Tickets straight away - use Technical Support for a suspected compromise. Never include your password or backup code in a ticket; we will never ask for either.
هل كانت المقالة مفيدة ؟ 0 أعضاء وجدوا هذه المقالة مفيدة (0 التصويتات)

Powered by WHMCompleteSolution