Add a six-digit code from your phone, so a stolen password is not enough on its own.
A password can be guessed, reused or leaked in somebody else’s breach. A code that changes every thirty seconds cannot. This is the single biggest thing you can do to protect your account.
Two-step sign-in is not available on this installation yet. It needs an encryption key to be set up first, because your code’s secret is stored encrypted and never in plain text. Nothing about your account has changed.
When you set this up you will be given ten recovery codes. Save them somewhere that is not your phone — they are how you get back in if the phone is lost, and without them you would need an administrator to reset it for you.
Nobody at Qwota can read those codes back to you. They are stored so that we cannot.