What We Can and Cannot Do
This page exists for one thing: corrections. If something on this site is wrong, out of date, or stated more confidently than the evidence supports, we want to know, and we will fix it or explain why we are not fixing it.
It is worth being equally clear about the rest, so that nobody loses a day waiting for a reply that will not help them.
| Request | Can we help? | Where to go instead |
|---|---|---|
| A factual error, dead link or outdated setting path on this site | Yes. This is what the contact address is for. | Email us with the section and the source. |
| "Is this message I received a scam?" | No. We cannot see the message, the headers or the sender's infrastructure. | Do not act from inside the message. Navigate to the organisation yourself and check there, then report it to your provider or national reporting service. |
| "Has my account been compromised?" | No. We have no access to any account and no way to examine one. | Review the security settings in the account itself: sign-in methods, sessions, recovery details. See account recovery. |
| "Help me recover or unlock my account." | No. Only the provider can do this, and only through its own recovery process. | The provider's official recovery flow, reached by typing its address. Your bank the same day if money was involved. An offer of paid recovery help is a scam. |
| "Contact the platform, bank or police for me." | No. We have no standing to act for anyone, in any jurisdiction. | The provider, your bank, or your national cybercrime and consumer reporting body, found on your government's own domain. |
| "Review my security setup and tell me what to fix." | No. We cannot audit an account, device or network we cannot see. | Work through the MFA guide and the passwords guide, in that order. |
| "Rewrite this article for my site" / "add my link" | No. We do not accept guest posts, sponsored placements or paid links. | Nothing to offer here, and that will not change. |
If someone contacts you claiming to be from this site, treat it as phishing. We will never ask for a password, a one-time code, a recovery code, a seed phrase, a payment, or remote access to your device. We will never ask you to confirm account details by replying to a message, and we do not run support over chat, SMS or direct message. Anything that claims otherwise is not from us.
Report a Correction
A specific report is fixed fastest. Vague reports - "some of this is wrong" - take longer, because we have to find the claim before we can check it.
What to include
- Which page and which passage. Quote the sentence or name the heading, so there is no ambiguity about what is being challenged.
- What you believe is wrong. "The menu path changed in version X", "the deadline in this jurisdiction is Y not Z", "this describes a control that has been deprecated".
- The source you are relying on. A link to the vendor documentation, the regulation, the standard or the authority's own page. If you are reporting from personal experience rather than a document, say so.
What happens next
- We read it and check the point against a primary source ourselves.
- If it is right, we correct the page and, where the substance changed, record what was wrong, what it now says, and the date of the change.
- If it is not right, we reply explaining why we are leaving it as it stands - usually with the source we checked.
- If we cannot verify it either way, we say so, and where it matters we mark the passage as uncertain rather than leaving it looking settled.
Two kinds of change are made without a note: typographical fixes, and repairs to wording that do not alter meaning. Everything substantive is recorded.
How This Site Is Researched and Written
Every factual claim on this site is meant to be traceable to a source a reader can open and check for themselves.
What counts as a source here
- Standards bodies - NIST, the W3C, the FIDO Alliance - for how authentication and the web actually work.
- National security agencies and regulators - CISA, the UK NCSC, the US FTC and their equivalents - for consumer guidance and reporting routes.
- Vendor documentation - the platform's own current help pages - for menu paths and settings, because only the vendor tracks its own changes.
- Independent organisations with published methodology, where a measurement or a category of attack needs a source.
Rules we hold ourselves to
- We do not quote a statistic without naming the report and its year.
- We do not state a settings path unless the vendor's own documentation shows it.
- We do not present a product as the answer. Where a category of tool helps, we describe the category and what to look for in it.
- We do not write in the voice of expertise we do not have. Where a question needs a lawyer, a bank or a regulator, the page says so and stops.
- We name the limits of every control we recommend, in the same section as the recommendation.
- We do not use fear as a sales tool, and we have nothing to sell.
Review cycle
Every page on this site carries the same last-reviewed date and links the sources it was checked against. That date means a person re-opened those sources and confirmed the guidance still matched them — not that a file was touched.
We deliberately do not state a fixed calendar interval, because a static site cannot enforce one and a claim like that quietly becomes false the moment it lapses. What we do state is the trigger: a page is re-checked when a source it cites actually changes — a vendor renames a setting, a standard is revised, a regulation is amended, a linked page moves — and in any case at least once a year, so that nothing is left unexamined through neglect.
If the date on a page looks old, treat that as useful information rather than as a defect: it tells you the page is due for its next pass, and every claim on it links the primary source so you can check the current position yourself.
Independence
There is no advertising, sponsorship, affiliate link, paid placement or product for sale anywhere on this site. Nobody pays to be mentioned. If that ever changes, the change will be disclosed here before it appears anywhere else. See the about section on the home page for the full statement of who is accountable for this site and what it does not do.
Reusing This Material
You are welcome to quote, summarise, translate or teach from these pages. Two conditions, both of them about accuracy rather than ownership:
- Do not attribute a claim to us that we did not make. If you shorten something, do not let the shortened version assert more certainty than the original. Where we hedged, keep the hedge; the hedge is usually the honest part.
- Link to the primary source, not only to us. The standards, regulator pages and vendor documentation linked on each page are the things that stay accurate. We are a summary, and summaries rot.
If you are translating a page, we would like to know, mainly so that we can tell you when the original changes. That is a courtesy rather than a permission requirement.
Contact
Corrections, factual disputes, reports of dead or hijacked links, and notices that a described setting has moved all go to the author of this site, Rehan Aldiansyah, who is also the person who wrote and self-reviewed every page here. There is no support desk, no team and no ticket queue behind this address — which is precisely why we would rather tell you what we cannot do than let you wait for an answer that is not coming.
What makes a report easy to act on
- The page and the passage. Quote the sentence or name the heading, so there is no ambiguity about what is being challenged.
- What you believe is wrong. "The menu path changed in version X", "the deadline in this jurisdiction is Y not Z", "this describes a control that has been deprecated".
- The source you are relying on. A link to the vendor documentation, the regulation, the standard or the authority's own page. If you are reporting from personal experience rather than a document, say so — that is still useful.
If you are reporting a security problem with this site itself — something that could mislead a reader, or a link that now leads somewhere harmful — please say so in the subject line so it is read first. Broken or hijacked outbound links are treated as urgent, because a security page that sends readers somewhere unsafe is worse than no page at all.
And to repeat the standing warning, because this is a site about phishing: we will never ask you for a password, a one-time code, a recovery code, a seed phrase or remote access to your device, and we will never ask you to confirm account details by replying to a message. Any message claiming to come from this site and asking for any of that is not from us. Do not reply to it; write to the address above instead.
Sources checked for this page
About DEWA89
DEWA89 is an independent educational project written by one person. It is not a company, an agency or a managed editorial team, and it does not pretend to be one. Rehan Aldiansyah writes these pages, checks them against the primary sources cited on each one, and answers corrections sent to the address on the support page.
DEWA89 is the name the site publishes under; the name above is the person accountable for what it says. Nothing here is generated and published unread: a claim either traces to a source you can open yourself, or it is marked as the author's own judgement.
How this site is funded
It is not. There is no advertising, no sponsorship, no affiliate link, no paid placement and no product for sale anywhere on this site. No company pays to be mentioned, and no page carries a commission-bearing link. Hosting is paid for out of the author's own pocket, which is the whole of the commercial relationship. If that ever changes, the change will be disclosed on this page before it appears anywhere else.
How to read this site
- Primary sources only. Where a claim can be checked, it links to the standards body, regulator or vendor documentation that supports it — not to another summary of it.
- Limits are stated. Where a control fails, or a setting only partly helps, the page says so in the same breath as the advice.
- Country-specific answers are labelled. Reporting routes, consumer protections and privacy law differ by country, so a passage that applies in only one is marked as such.
- No fear as a sales tool. Scaring a reader into a purchase is the behaviour this site exists to argue against.
Editorial standards we hold ourselves to
- We do not quote a statistic without naming the report and its year.
- We do not name a step-by-step settings path unless the vendor's own documentation still shows it.
- We do not present a product as the answer. Where a category of tool helps, we describe the category and what to look for in it.
- We do not write in the voice of expertise we do not have. When a question needs a lawyer, a doctor or a regulator, the page says so and stops.
- We do not silently rewrite a substantive claim. Material corrections are recorded with a dated note on the page, as described on the support page.
Dates, and what they mean
The date below is the last time these pages were re-checked against the sources they cite. It is a record of what happened, not a schedule: no page here states a calendar interval for review, because a static site cannot enforce one. Pages are re-checked when something they describe actually changes — a vendor renames a setting, a standard is revised, a regulation is amended, a link breaks — and at least once a year regardless, so that nothing is left unexamined through neglect.
The date moves only when a person has re-opened the cited sources and confirmed the text still matches them. It is not the date a file was last saved. Where a passage has been left standing but is no longer certain, it is marked as uncertain rather than quietly carried forward.
If the date below looks old, that is information, not a fault. It means the pages are due for their next pass. Everything on them links its primary source precisely so you can check the current position yourself rather than relying on our copy of it.
Who is accountable for this page
| Published by | DEWA89, an independent educational project written and paid for by Rehan Aldiansyah |
|---|---|
| Written by | Rehan Aldiansyah — an independent writer, publishing under the DEWA89 name. No employer, qualification or years of experience is claimed here, because this site asserts only what can be checked. |
| Reviewed by | Rehan Aldiansyah. This site has no separate reviewer, and we do not name one to look better. Every page is self-reviewed against the sources it cites, and that is exactly what the review record below means. |
| Corrections | Send a correction — specific reports are checked against a primary source and fixed or answered |
| First published | 2026-10-08 |
| Last reviewed | 2026-10-08 — every page on this site carries the same review date, and each one links the sources it was checked against |
Contact
Corrections, factual disputes, reports of a link that now leads somewhere harmful, and notices that a described setting has moved are all welcome at the address below. Rehan Aldiansyah reads them.
We will never ask you for a password, a one-time code, a recovery code or remote access to your device, and we will never ask you to confirm account details by replying to a message. Any message claiming to come from this site and asking for any of that is not from us.
Scope and limitations
Read this before acting on anything here.
- This is general education, not advice for your situation. It explains how account takeover and phishing generally work and what a reader can do about them. It is not legal advice, it creates no advisory relationship, and it should not be quoted in a dispute, a claim or a police report. If an account, your money or your identity is already affected, the people who can act are the provider's own recovery process, your bank, and the police or reporting body where you live.
- We cannot see your accounts or your devices. We cannot tell you whether a particular message you received is genuine, whether an account has been compromised, or what an organisation holds about you.
- We cannot act on your behalf. We cannot contact a platform, bank, regulator or data protection authority for you, and we cannot investigate anyone. Requests like that have to go to the provider directly.
- Menus move. Settings are renamed, moved and reset by updates. A click path that was accurate on the review date may look different in your version. Treat every step here as a description of what to look for rather than a guarantee of what you will see.
- We can be wrong. Errors get through. If you find one, the support page explains what happens next.
