DEWA89 home DEWA89 official siteOfficial site (opens in a new tab)
Support - Questions and answers

DEWA89 FAQ

Short answers to the questions readers send most often about account security and phishing: what to fix first, how to tell a fake login page from a real one, what to do in the minutes after you realise you typed a password into the wrong place, and what this site can and cannot do for you.

Every answer links to the full guide it comes from, so you can check the reasoning rather than taking our word for it.

Last reviewed 8 October 2026Free to read, no sign-up

Visit the official DEWA89 website (opens in a new tab)Opens the official DEWA89 website in a new tab.

Starting Out

These are the questions readers actually send. Each answer is short on purpose: if you want the reasoning, the linked guide has it.

What is the single most effective thing I can do for my account security?

Put a passkey, or a hardware security key, on your primary email account and add a backup factor on a second device. Your email can reset almost everything else, so it is the highest-value account you own, and a passkey is the only widely available method that survives a fake login page relaying your credentials in real time. Everything else on this site is a second-order improvement on that.

Which accounts should I fix first?

In order: primary email; the password manager and the platform account that syncs your passkeys; your mobile phone account plus a port-out PIN; banking and payment accounts; then social and messaging accounts, which are used to deceive the people who trust you. Cloud storage holding scans of identity documents also belongs near the top.

I am not a technical person. Is any of this realistic?

Yes, because the highest-value changes are settings changes rather than technical work. Adding a passkey is three taps in a security screen. Installing a password manager is an app install and one passphrase. Asking your mobile operator for a port-out PIN is a phone call. The genuinely technical parts - why origin binding works, what a key derivation function does - matter for understanding, not for doing.

Does any of this make my account safe?

No, and treat anyone who says otherwise as selling something. These measures raise the cost of an attack considerably: they defeat the techniques used at scale today. They do not remove risk, because the service can still be breached, your device can still be infected, and your recovery path can still be the weakest link. Security is a direction, not a state.

Phishing and Suspicious Messages

How do I tell whether an email is phishing?

Read the sender's domain from the right-hand end - only what follows the final @ means anything - then ask whether you were expecting the message, whether it pressures you with a deadline or secrecy, and whether it wants a secret, an approval or a payment. Those questions work better than judging how professional the message looks, because professional-looking phishing is now the norm.

What is the smartest thing to do with a message I am unsure about?

Do not act from inside it: no links, no attachments, no reply, no phone number it supplies. Navigate to the organisation yourself by typing its address or opening its app, and see whether the same notice is waiting there. If it is not, the message was not genuine.

What is an adversary-in-the-middle attack?

A phishing page that proxies the real site to you, so you see the genuine login page and the attacker forwards your password and your one-time code through to the real service in real time. They keep the resulting session cookie. One-time codes of any kind - SMS, email, authenticator app - do not stop this. Passkeys and security keys do, because the credential is bound to the real domain.

Why do I keep getting approval prompts I did not request?

Because someone already has your password and is trying to complete a sign-in. The flood - push bombing or MFA fatigue - is designed to make you tap Approve to stop the noise. Deny every prompt, change that password from a trusted device, and sign out all other sessions.

Passwords and Managers

Do I need a different password for every site, really?

Yes, and it is the single most useful password habit. Attackers replay credentials leaked from one service against hundreds of others automatically. A unique password makes each leak a dead end; a reused one turns any breach anywhere into a breach of everything. A password manager is what makes uniqueness free.

Are passphrases like "correct-horse-battery" actually strong?

Only if something random chose the words. A passphrase of unrelated words selected by dice from a published list of 7,776 words carries about 12.9 bits per word, so six words is roughly 77 bits. A phrase you invented yourself does not have that property, because your choices are not random and cracking tools model the way people choose.

What happens if I lose my master passphrase?

With honest zero-knowledge encryption, nothing can be done: the provider cannot reset it and neither can anyone else. This is the most common way people lose a vault, far more common than the vault being broken into. Print the recovery kit when you set it up, and choose a master passphrase you can reconstruct from memory.

Is it safe to let my browser save passwords?

It is much better than reuse, and it is already set up, which counts for a great deal in practice. Its weak points are that protection at rest often defaults to your computer login, so anyone at your unlocked machine can read them, and that a browser store is awkward for recovery codes or documents. A dedicated manager adds those, but a browser manager used properly beats a dedicated one you never install.

Multi-Factor Authentication

Are passkeys better than app-based codes?

Against a stolen password, both are good. Against real-time phishing, only the passkey works, because the app code is a short string that a proxy page can relay while the passkey refuses to produce anything for a domain it was not registered against.

Is SMS better than nothing?

Yes, and it stops casual attackers outright. It is simply the weakest option, because a SIM swap moves your number to someone else's handset without touching your phone, and because a text code can be relayed through a fake page. Use it where nothing better exists, and set a port-out PIN either way.

Do I need to buy a hardware security key?

For most people, a synced passkey is the right default: it is free, it works across your devices, and it is equally resistant to phishing. A physical key becomes worth buying when you are specifically targeted, when you hold an account whose compromise would be severe, or when you want your highest-value credential to have no online account behind it at all.

Can multi-factor authentication be bypassed?

Yes, by stealing the session a login creates rather than the login itself. Infostealer malware copies browser cookies, and a proxy page can keep the session it just completed for you. That is why revoking active sessions is part of every recovery procedure, and why signing out on shared machines matters. MFA also does nothing about consent phishing, where you grant an app access yourself.

When Something Has Gone Wrong

I clicked a link and typed my password. What do I do right now?

From a device you trust, open the real site by typing its address, change the password, and then sign out all other sessions - the sign-out is what invalidates any stolen cookie. Change the same password anywhere you reused it, starting with your email. Then check recovery email, recovery phone, connected apps, app passwords and mail forwarding rules. Full sequence in account recovery.

My account was hacked and I cannot get back in. Is there any point contacting you?

No, and we would rather say so plainly than let you wait for a reply. We cannot recover, unlock or investigate anyone's account, and we cannot contact a platform, bank or authority on your behalf. Use the provider's own recovery process, reached by typing its address, and contact your bank the same day if money or card details were involved.

Someone offered to recover my account for a fee. Is that legitimate?

No. Paid account-recovery offers are a documented follow-up scam aimed at people who have just lost access. They take payment, often then ask for your remaining credentials or a remote connection to your device, and they cannot do anything you cannot do through the provider's own recovery flow.

How do I know if my computer has malware?

Often you cannot, which is why recovery should be done from a different device. Warning signs include browser extensions you did not install, a changed search engine or homepage, security software disabling itself, and passwords failing again shortly after you reset them. Run a full scan, but treat a clean scan as inconclusive - and a confirmed infostealer as a reason to reinstall the operating system.

DEWA89: 15 questions readers ask

What is the single most effective thing I can do for my account security?

Put a passkey, or a hardware security key, on your primary email account and add a backup factor on a second device. Your email can reset almost every other account, so it is the highest-value target you own, and a passkey is the only widely available method that survives a fake login page relaying credentials in real time.

Which accounts should I protect first?

In order: your primary email; the password manager and platform account that sync your passkeys; your mobile phone account, with a port-out PIN; banking and payment accounts; then social and messaging accounts. Cloud storage holding scans of identity documents also belongs near the top of that list.

How can I tell whether an email is phishing?

Read the sender's domain from the right-hand end, because only what follows the final @ means anything. Then ask whether you were expecting the message, whether it pressures you with a deadline or secrecy, and whether it is asking for a secret, an approval or a payment. Those questions work better than judging how professional the message looks.

What is an adversary-in-the-middle phishing attack?

It is a phishing page that proxies the genuine site to you, so what you see is the real login page. The attacker forwards your password and your one-time code to the real service in real time and keeps the resulting session cookie. One-time codes of any kind do not stop it. Passkeys and hardware security keys do, because they are bound to the real domain.

Do I need a different password for every website?

Yes. Attackers replay credentials leaked from one service against hundreds of others automatically, so a reused password turns any breach anywhere into a breach of every account sharing it. A password manager is what makes unique passwords practical.

Are passphrases of several words actually strong?

Only when something random chose the words. A passphrase drawn by dice from a published list of 7,776 words carries about 12.9 bits per word, so six words is roughly 77 bits of unpredictability. A phrase you invented yourself does not have that property, because human word choices are predictable and cracking tools model them.

What happens if I forget my password manager's master passphrase?

With genuine zero-knowledge encryption nothing can be done: the provider cannot reset it. Lost master passphrases are a far more common problem than broken vaults, which is why the recovery kit should be printed and stored offline, and why the master passphrase should be one you can reconstruct from memory.

Are passkeys better than authenticator app codes?

Against a stolen password both are good. Against real-time phishing only the passkey helps, because an app code is a short string that a proxy page can relay, while a passkey will not produce anything for a domain it was not registered against.

Is SMS two-factor authentication worth using?

It is better than no second factor and stops casual attackers. It is nevertheless the weakest option, because a SIM swap moves your number to someone else's handset without touching your phone, and because a text code can be relayed through a fake login page. Use it only where nothing stronger is offered, and ask your carrier for a port-out PIN either way.

Can multi-factor authentication be bypassed?

Yes, by stealing the session a login creates rather than the login itself. Infostealer malware copies browser cookies, and a proxy page can keep the session it just completed for you. That is why revoking active sessions is part of every recovery procedure, and why consent phishing - granting an app access yourself - also bypasses MFA.

I typed my password into a suspicious page. What should I do first?

From a device you trust, open the real site by typing its address, change that password, then sign out all other sessions. The sign-out is what invalidates any stolen session cookie; a password change alone often leaves the attacker signed in. Then change the same password anywhere you reused it, starting with your email.

My account was hacked and I cannot get back in. Can DEWA89 help?

No. We cannot recover, unlock or investigate anyone's account, and we cannot contact a platform, bank or authority on your behalf. Use the provider's own account recovery process, reached by typing its address rather than following a link, and contact your bank the same day if money or card details were involved.

Someone offered to recover my account for a fee. Is that legitimate?

No. Paid account-recovery offers are a documented follow-up scam aimed at people who have just lost access to an account. They frequently take payment and then ask for remaining credentials or remote access to your device, and they cannot do anything you cannot do through the provider's own recovery flow.

Why do I receive approval prompts I never requested?

Because someone already knows your password and is trying to finish a sign-in. The flood of prompts - push bombing or MFA fatigue - is designed to make you tap Approve to stop the noise. Deny every prompt, change that password from a trusted device, and sign out all other sessions.

Does this site collect any personal data?

No. It is a static site with no cookies, no analytics, no trackers, no forms and no advertising. The only record of a visit is whatever request log the hosting provider keeps by default, under its own policy rather than ours.

Back to top ↑

Sources checked for this page

About DEWA89

DEWA89 is an independent educational project written by one person. It is not a company, an agency or a managed editorial team, and it does not pretend to be one. Rehan Aldiansyah writes these pages, checks them against the primary sources cited on each one, and answers corrections sent to the address on the support page.

DEWA89 is the name the site publishes under; the name above is the person accountable for what it says. Nothing here is generated and published unread: a claim either traces to a source you can open yourself, or it is marked as the author's own judgement.

How this site is funded

It is not. There is no advertising, no sponsorship, no affiliate link, no paid placement and no product for sale anywhere on this site. No company pays to be mentioned, and no page carries a commission-bearing link. Hosting is paid for out of the author's own pocket, which is the whole of the commercial relationship. If that ever changes, the change will be disclosed on this page before it appears anywhere else.

How to read this site

Editorial standards we hold ourselves to

Dates, and what they mean

The date below is the last time these pages were re-checked against the sources they cite. It is a record of what happened, not a schedule: no page here states a calendar interval for review, because a static site cannot enforce one. Pages are re-checked when something they describe actually changes — a vendor renames a setting, a standard is revised, a regulation is amended, a link breaks — and at least once a year regardless, so that nothing is left unexamined through neglect.

The date moves only when a person has re-opened the cited sources and confirmed the text still matches them. It is not the date a file was last saved. Where a passage has been left standing but is no longer certain, it is marked as uncertain rather than quietly carried forward.

If the date below looks old, that is information, not a fault. It means the pages are due for their next pass. Everything on them links its primary source precisely so you can check the current position yourself rather than relying on our copy of it.

Who is accountable for this page

Published byDEWA89, an independent educational project written and paid for by Rehan Aldiansyah
Written byRehan Aldiansyah — an independent writer, publishing under the DEWA89 name. No employer, qualification or years of experience is claimed here, because this site asserts only what can be checked.
Reviewed byRehan Aldiansyah. This site has no separate reviewer, and we do not name one to look better. Every page is self-reviewed against the sources it cites, and that is exactly what the review record below means.
CorrectionsSend a correction — specific reports are checked against a primary source and fixed or answered
First published2026-10-08
Last reviewed2026-10-08 — every page on this site carries the same review date, and each one links the sources it was checked against

Contact

Corrections, factual disputes, reports of a link that now leads somewhere harmful, and notices that a described setting has moved are all welcome at the address below. Rehan Aldiansyah reads them.

dewa89official@gmail.com

One person, checking messages between other work. Reports that name the passage and the source they disagree with are answered fastest — the support page sets out exactly what to include, and what we cannot help with.

We will never ask you for a password, a one-time code, a recovery code or remote access to your device, and we will never ask you to confirm account details by replying to a message. Any message claiming to come from this site and asking for any of that is not from us.

Scope and limitations

Read this before acting on anything here.

Back to top ↑