Archive > Operations and risk > NM-011
Passwords can be changed and keys can be rotated. A username that also exists on a forum you have posted to for years cannot be unlinked afterwards, because the association was created the moment both existed. This is the only requirement here with no repair path, which is why it appears first.
With PGP two factor enabled, signing in requires proving control of a key as well as knowing the password. A credential leak becomes an inconvenience rather than the loss of the account. The corresponding risk is losing the key, which is why the backup requirement is stated in the same document rather than separately.
The recovery phrase restores the account and is therefore the object every phishing page is built to collect. It belongs on paper. It does not belong in a synced note, a screenshot, or any web form, including one that presents itself as an account recovery tool.
This standard is met when a leaked password alone would not open the account, a lost device would not lose the account, and nothing about the username connects to any identity you hold elsewhere.
nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onionnexusma2iegzo7atzwbrwxhcdopyri3vare2twibldnlc3txqjdeb5yd.onionnexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onionRequired check. Open in Tor Browser only. Before entering anything, compare the onion printed on the login screen against your browser address bar. A mismatch means the page is a copy and the tab should be closed. See NM-004.