95 lines
2.3 KiB
Markdown
95 lines
2.3 KiB
Markdown
# Security, Recovery, and Approvals
|
|
|
|
NuQloud includes normal cloud account security and decentralized account security.
|
|
|
|
Treat both seriously.
|
|
|
|
## Account Password
|
|
|
|
Your NuQloud password signs you in to the cloud.
|
|
|
|
Use a strong password and store it in a password manager.
|
|
|
|
## Decentralized Account Backup
|
|
|
|
If you create or attach a decentralized account, save the backup/auth file.
|
|
|
|
Best practice:
|
|
|
|
- Keep one copy in a password manager or secure vault.
|
|
- Keep one offline backup.
|
|
- Do not put it in a public shared folder.
|
|
- Do not send it through ordinary email or chat.
|
|
|
|
## Managed Recovery
|
|
|
|
If your provider offers managed recovery, you may be able to opt in.
|
|
|
|
Managed recovery can help if you lose access, but it does not mean your provider should know your passwords.
|
|
|
|
Follow your provider's recovery instructions exactly.
|
|
|
|
## App Approvals
|
|
|
|
NuQloud Apps may ask for approval before sensitive actions.
|
|
|
|
Common request types:
|
|
|
|
- Read account information.
|
|
- Publish data.
|
|
- Encrypt or decrypt data.
|
|
- Encrypt or decrypt data with a sharing key.
|
|
- Sign an action.
|
|
- Open another app or resource.
|
|
|
|
## When to Approve
|
|
|
|
Approve when:
|
|
|
|
- You trust the app.
|
|
- You understand the action.
|
|
- The request matches what you just clicked.
|
|
|
|
Cancel when:
|
|
|
|
- You did not initiate the action.
|
|
- The app asks for something unexpected.
|
|
- You are not sure what will happen.
|
|
|
|
## High-Risk Confirmations
|
|
|
|
NuQloud can require one extra confirmation for higher-risk actions after unlock.
|
|
|
|
This is used for requests such as sending credits/QORT, signing transactions, name operations, trade/asset actions, deploy/poll/vote actions, and large multi-publish requests.
|
|
|
|
Keep this enabled unless you are confident you want more automation and accept the risk.
|
|
|
|
## Wallet or Account Unlock Prompts
|
|
|
|
Some sensitive actions require unlocking your decentralized account.
|
|
|
|
If prompted:
|
|
|
|
1. Confirm the app and action.
|
|
2. Enter the password only if you trust the request.
|
|
3. Choose the shortest reasonable unlock time.
|
|
4. Lock or sign out when finished on shared computers.
|
|
|
|
## Public vs Private Data
|
|
|
|
Private cloud share:
|
|
|
|
- Access controlled inside NuQloud.
|
|
|
|
Public link:
|
|
|
|
- Anyone with the link may access it, depending on settings.
|
|
|
|
Private QDN publish:
|
|
|
|
- Content is encrypted before decentralized publishing.
|
|
|
|
Public QDN publish:
|
|
|
|
- Content is intended to be public.
|