Security

Two-factor authentication, session review, and what happens after too many failed logins.

Two-factor authentication

Settings, then Security. Surf supports authenticator apps using standard time-based codes. Set it up once, keep the recovery information somewhere that is not the phone with the authenticator on it.

Sessions and devices

Active sessions are listed and can be ended individually. Ending a session on a device also removes that device's ability to read new encrypted messages.

Passwords

Passwords are 8 to 128 characters. After five failed attempts, logins are rate limited for fifteen minutes, which is a defence against someone else guessing rather than a punishment for you forgetting.

Changing your email

Changing your email address requires your password, and there is a 24-hour cooldown before it can be changed again.

Nobody at Surf will ever ask for your password, a two-factor code, or a chat backup passphrase. Report anyone who does.