LochStudios  /  Help Centre  /  Security  /  Create strong passwords and use a password manager

Create strong passwords and use a password manager

Pick a long unique password for every LochStudios login, store it in a password manager, and turn on portal two-factor authentication.

Updated

A short or reused password is the usual way someone else gets into a mailbox, a WordPress site, or the portal. You do not have one password with us. The portal, each mailbox, FTP, MariaDB, WordPress, and a VPS login are separate. Make each one long and unique, keep them in a password manager, and turn on two-factor for the portal.

We will never ask you to send a password by email. If you cannot sign in, start a portal password reset or open a support ticket. Do not reply to the message that looks like it came from us.

What makes a password strong?

A password worth keeping has:

  • Length. Aim for 16 characters or more. The portal will accept 12 as a minimum. Longer is better.
  • A mix of character types. Uppercase, lowercase, numbers, and symbols (!@#$%^&*). The portal needs at least three of those four classes.
  • No dictionary words and no obvious patterns such as password123 or Welcome2026.
  • No personal information. Not your name, birth date, company, or domain.
  • Uniqueness. Each login gets its own password. Never reuse the portal password on a mailbox, FTP account, database user, or website.

A generated string from a password manager beats a phrase you invented.

Weak vs strong

WeakStrong
password7mK#9Lx$2nQvWp@Rt!
myname2024Fj4@nBx9Kq!sYm2Lv$
admin123Gz8$Pw2@Yc!kTd5Rx9

Do not copy those strong examples. Generate your own.

Passwords you use with us

These are different secrets. Store each one under its own entry in the manager.

Portal

This is the account you use at the portal. It opens billing, tickets, Log in to cPanel, and Log in to WebMail. Change it under Account → password. The form asks for at least 12 characters and three of: lowercase, uppercase, digit, symbol. Use a generated 16+ character password anyway.

Forgot it? Use Forgot password. That reset is only for the portal, not for a mailbox.

Shared hosting (cPanel)

Open cPanel from the portal. Do not guess a hostname.

  1. Sign in at the portal.
  2. Open the hosting service.
  3. Click Log in to cPanel.

You do not type a cPanel owner password to get in. You still set separate passwords for:

In those cPanel screens, click Generate, copy the result into the password manager, then save. Do not reuse the portal password.

LochStudios Mail

Hosted business email is a different product from a cPanel mailbox. That mailbox password lives in WebMail. Change it there, then update every phone and desktop app. See Change your Axigen mailbox password.

Unsure which mail product you have? Open a support ticket and we will check with you.

WordPress

The WordPress administrator password is not the portal password, and it is not the MariaDB password in wp-config.php. All three should be different. See Secure your WordPress site.

VPS and dedicated

On a VPS, credentials and the console are on that server in the portal. Prefer SSH keys over a password you type every day.

On a dedicated server, open a support ticket and we will walk you through access.

Use a password manager

A password manager:

  • Generates long unique passwords so you stop inventing and reusing them
  • Stores them encrypted, so you only memorise one master password
  • Fills the real site, which helps you notice a fake login page
  • Warns you when a saved password has shown up in a public breach

Pick a reputable one (Bitwarden, 1Password, Dashlane, or KeePass are common). We do not sell or support a particular brand. Then:

  1. Install the app and the browser extension on the devices you actually use.
  2. Create a long master password. This unlocks everything else. Write it down once and keep that copy in a physical safe, not on a sticky note and not in email.
  3. Turn on two-factor on the manager itself.
  4. Generate a new password when you create or change a login.
  5. Save the username, password, and the real URL (for us that is the portal, mail.yourdomain.com, or the site's /wp-admin).
  6. Let the manager sync over its own encrypted channel if you use more than one device.

Turn on two-factor for the portal

A password alone is not enough for the account that opens hosting and mail.

  1. Sign in at the portal.
  2. Open Account → Two-factor authentication.
  3. Use an authenticator app (1Password, Authy, Google Authenticator, or the one your manager includes).
  4. Save the six recovery codes in the password manager as soon as they appear. Each code works once. They are how you get back in if you lose the phone.

Portal two-factor is an authenticator app. We do not send sign-in codes by SMS.

If you keep a WordPress administrator on a public URL, turn on a two-factor plugin there too.

Habits that keep this working

  • Never reuse a password. If one site is breached, attackers try that same string on the portal and on mailboxes.
  • Fix the important logins first: portal, the mailbox that receives our mail, then WordPress, FTP, and database users.
  • Change a password when you think it leaked, when a contractor finishes, or when you delete a user. A calendar rotation every 90 days is optional if the password is long and unique.
  • Do not send passwords in email, chat, or a ticket. We will never ask you to. If a message asks for one, treat it as phishing. See Recognise and avoid phishing emails.
  • Do not share the portal login. Create extra FTP or mailbox accounts for other people instead of handing over yours.

If you cannot sign in

  • Portal: Forgot password. After you are back in, set a new generated password and confirm two-factor is still on.
  • cPanel mailbox: sign in to the portal, open Log in to cPanel, then Email Accounts, and set a new mailbox password. Update Webmail and every mail app.
  • LochStudios Mail: open a support ticket and tell us the address. We can set a new mailbox password. We will never ask you to send the current one.
  • You think someone else has a password: change it from a device you trust, then open a support ticket. If a site looks compromised, also read What to do if your website is hacked.

Do not wait on an email thread.

Related


Was this article helpful?

← Back to Security