DrivenHost

Blog / security monday

Passkeys, 2FA and your hosting account

Your hosting account controls email, DNS and every file on your site, so here is how we lock ours down and who should still have access to yours.

Last month's Security Monday covered the five habits that stop most WordPress hacks. This month we want to talk about something people protect less carefully than their WordPress login, even though it matters more: the hosting account itself.

The master key problem

Think about what someone can do with access to your hosting control panel. They can read and change every file on your site. They can read your database. They can create and read email mailboxes, which means they can trigger password resets for almost every other service your business uses. And they can change DNS, pointing your domain anywhere they like.

Your hosting account is not one service among many. It is the master key to most of the others. Bank accounts, payment processors, social accounts: nearly all of them will happily send a reset link to an address that your hosting account controls.

That is why the password on it deserves more care than any other password you own, with one exception: the email account those reset links go to, which on many small-business setups is the same thing.

Turn on two-factor authentication today

Every serious hosting provider offers two-factor authentication on the control panel login, and cPanel has supported it for years. If you have not enabled it, that is your whole homework for this week. It takes five minutes with any authenticator app.

A one-time code from your phone means a leaked or guessed password is no longer enough on its own. Given how many credential dumps circulate at any moment, that is not a paranoid precaution. It is the baseline.

One practical note from our own experience: when you set up an authenticator app, record the recovery codes somewhere safe and offline. The lockouts we help people through are almost never caused by attackers. They are caused by a lost phone and no recovery codes.

Passkeys, in plain terms

Passkeys are the newer option you will increasingly see next to the password field. Instead of a secret you type, your device holds a private key and proves it has it, unlocked by your fingerprint, face or device PIN. Nothing reusable travels over the wire, and there is nothing for you to leak by typing it into a fake login page.

That last part is the quiet superpower. A convincing phishing page can capture a password and even a one-time code. It cannot capture a passkey, because the key simply will not work for the wrong website. As an engineering team, we like security measures that remove a whole class of mistake rather than asking humans to be careful forever.

Where a service offers passkeys, use them. Where it does not, a password manager plus 2FA remains a perfectly solid setup.

Who else still has a key?

Here is the question we ask every business owner who calls us about account security: who has access to this account right now?

The honest answer is often "my old developer", "an agency we stopped working with", or "a former employee, I think". Access granted years ago rarely gets removed, because removing it is nobody's job.

Make it a habit twice a year: list everyone who can log in to the hosting account, the domain registrar and the WordPress admin. Remove anyone who no longer needs it. If a contractor needs temporary access, create a separate user for them and delete it when the work ships, rather than sharing your own credentials. Shared credentials cannot be revoked for one person without changing them for everyone, which is exactly why they never get revoked at all.

And if someone who had the main password leaves on bad terms, change it the same day. We have seen how that story ends when people wait.

The short version

Two-factor authentication on the hosting account, passkeys where they are offered, and a twice-yearly audit of who can get in. None of it costs anything, and together they protect the account that protects everything else.

If you are hosting with us and want a second pair of eyes on your account access, contact us and we will walk through it with you.

security mondayaccounts2fa

← All posts

No sales team. No scripts.

Tell us what you're running.
We'll tell you what it needs.

Migrations are free, quotes are written, and the engineer who replies is on the team that will run your server.