Security Settings
Essential security settings and management methods to keep your account safe
Current Security Level
🔐 Password Management
Change Password
- Profile → Security Settings → Change Password
- Enter current password
- Enter new password (8+ characters)
- Confirm new password
- Change complete → Re-login required
Secure Password Requirements
- Minimum 8 characters
- Mixed upper/lowercase
- Include numbers
- Special characters recommended (!@#$%^&*)
- No personal information
🛡️ Two-Factor Authentication (2FA)
2FA Benefits
- Significantly reduced hacking risk
- Safe even if password is leaked
- Additional verification for important actions
- Multi-device support
2FA Activation Process
- Install Google Authenticator app
- Security Settings → Set up 2FA
- Scan QR code or enter manually
- Enter 6-digit verification code
- Save backup codes securely
⚠️ Backup Code Management
Backup codes are the only recovery method if you lose your phone. Store them safely.
📱 Withdrawal Password
What is a Withdrawal Password?
A separate 6-digit numeric password required for withdrawals and fund transfers.
Setup Method
- Security Settings → Set Withdrawal Password
- Verify login password
- Enter 6 digits
- SMS verification code confirmation
- Setup complete
💡 Withdrawal Password Tips
- Don't use birthdate or phone number
- Avoid sequential numbers (123456)
- Avoid repeated numbers (111111)
- Change periodically
🌐 Login Security
Check Access History
You can check recent login history in Profile → Activity History.
Check Item | Description |
---|---|
Access Time | Date and time of login |
IP Address | IP of access location |
Device Info | Browser, OS information |
Access Status | Success/failure status |
If Suspicious Activity Found
- Change password immediately
- Activate 2FA (if not set)
- Report to customer support
- Change withdrawal password
🔔 Security Notification Settings
Real-time Notification Items
- Login Notification: When logging in from new device
- Password Change: When password change is complete
- Withdrawal Request: Immediate notification on withdrawal request
- Settings Change: When security settings change
Notification Methods
- Email notification (default)
- SMS notification (optional)
- App push notification (PWA)
🚨 Account Protection Features
Auto Logout
- Default: 30 minutes of inactivity
- Change settings: 10min, 30min, 1hr, 2hr
- Recommend immediate logout after sensitive operations
Login Restrictions
Login Failure Restrictions
- 5 consecutive failures: 10 minute restriction
- 10 consecutive failures: 1 hour restriction
- 20+ failures: Account locked (contact support)
🔑 Password Recovery
Password Reset
- Login page → "Find Password"
- Enter member ID or email
- Select verification method (Email/SMS)
- Enter verification code
- Set new password
Password reset link is valid for 1 hour only.
💻 Device Management
Trusted Devices
Register frequently used devices to skip additional verification.
Windows PC - Chrome
Last used: 2 hours ago
iPhone - Safari
Last used: 1 day ago
Device Management Methods
- Device Registration: Check "Remember this device" when logging in
- Check Devices: Security Settings → Registered Devices
- Remove Device: Remove devices no longer in use
⚠️ Public Computer Warning
Never check "Remember this device" on public computers like PC cafes or libraries.
🛡️ Security Checklist
Check Regularly
🚫 Phishing Prevention
How to Identify Phishing Sites
- Check URL: Verify official domain
- Check HTTPS: Secure connection status
- Email Sender: Verify official email address
- Grammar Errors: Awkward sentences or typos
⚠️ OpenInterest Never
- Asks for passwords via email
- Asks for withdrawal passwords via phone
- Requests account information via personal messenger
❓ Frequently Asked Questions
Q: I deleted the 2FA app
A: Use backup codes to log in and reset 2FA. If you don't have backup codes, contact customer support.
Q: I forgot my withdrawal password
A: You can reset your withdrawal password in Security Settings. SMS verification is required.
Q: I can't access from abroad
A: Some countries may have restricted access for security reasons. Request access permission from customer support.