Security

Protecting your account and your access

  • Updated Aug 18, 2026, 12:42 PM
  • Views 140

The vast majority of incidents come not from a technical flaw, but from a reused password or a fraudulent message someone replied to. Both can be prevented, and it takes no particular skill.

One password, one service

The rule fits in one line: never the same password in two places. When any service has its credential database stolen, the addresses and passwords are tried everywhere else, automatically. A reused password turns the leak of a forgotten site into a leak of all your accounts.

Length matters more than complexity. A phrase of four or five unrelated words resists better than a short word stuffed with symbols, and is remembered without effort.

A password manager solves the problem once and for all: it makes a different one for each service, and you remember only one — the one that opens the manager.

What makes a password weak

Practice Why it falls
The same one everywhere A single leak opens them all
A dictionary word, even distorted The usual substitutions are tested as a matter of course
A first name, a date, a company name Those are the first guesses
A short, very complex word Length weighs more than symbols
Written in a shared file or notebook The secret stops being one

Your email address is the master key

Every password reset passes through it. Whoever controls it controls the rest. Protect it first, enable two-factor authentication with your email provider if it exists, and keep it up to date in your client area: an abandoned address is a door left open.

Recognising a fraudulent message

Sign What it reveals
An urgency: imminent suspension, final warning Someone is trying to prevent reflection
A link whose real address does not match the expected domain The heart of the trick
An almost-right domain: an extra letter, an added hyphen, a different extension The most effective imitation
An unexpected attachment, especially an invoice The usual vehicle of malicious software
A request for a password, a code received by message, or bank details No serious provider does that
An impersonal greeting, or oddly phrased language A mass mailing

We will never ask you for your password. Not by email, not by phone, not in a ticket. Nor will any of our communications ask you to pay an invoice through an unusual channel or as an emergency.

The reflex that protects

Do not click; type the address yourself. If a message announces a problem with your account, open a new tab, type the client area's address from memory, and go look. If the problem is real, it will be there. If it is not there, the message was fake.

Hovering over a link before clicking shows its real destination at the bottom of the browser. On a phone, a long press does the same.

If you clicked, or typed something

  1. Change the password concerned, from a device you are sure of, typing the address yourself.
  2. Change it too everywhere it was reused. That is the moment when the cost of reuse is measured.
  3. Check what may have been altered: the account's email address, your mailbox's automatic forwarding rules, your site's administrator accounts.
  4. Open a ticket, even if you think you caught everything. We will look at what moved on the service.

Your site's own access

The hosting account is not the only one to protect. Your site's administration panel is another, often less well guarded.

  • Delete the accounts of former contractors or former colleagues.
  • One account per person, never a shared account: otherwise no one knows any more who did what.
  • Remove the extensions and themes you do not use, rather than deactivating them — see If your site has been compromised.
  • Keep the system and its extensions up to date: most intrusions come through an old, publicly documented version.