See where you are logged in and recent activity
Check your active panel sessions, sign out a lost device or everywhere else at once, and read the activity log of logins and security changes.
The account page at my.vpsnine.com/account shows every browser that's logged in to your account, and links to a log of recent logins and security changes. Worth a glance now and then, and definitely after you've used a computer that isn't yours.
Who's logged in
The Sessions box has a row per logged-in browser: the device (something like "Firefox on Linux"), the ip it last came from, when it was last seen, and when it started. Yours is marked this session.
Sessions end on their own after 14 days without use, and after 30 days at most, however often you use them. Then you just log in again.
To sign out a device:
- revoke on its row signs out that one browser. It finds out the next time it loads a page.
- sign out everywhere else signs out every browser except the one you're using.
- log out on your own row, or logout at the top of any page, ends your current session.
Changing your password signs out every other session too, but leaves your API tokens working. Resetting a forgotten one signs out all of them and revokes every API token.
The activity log
Choose activity log to see the last 50 sign-in and security events, newest first, each with the time, address and device. That covers:
- logins, failed logins, and logins blocked after too many failures;
- wrong 2FA codes, and recovery codes used;
- password changes and reset requests;
- 2FA turned on or off, and sessions signed out;
- SSH keys added or deleted, API tokens created or revoked.
Something you don't recognise
A few Failed login lines from addresses you don't know are usually just bots trying common passwords. With a decent password and 2FA, they get nowhere, and you can ignore them.
A Logged in you didn't do, or a change you didn't make, is different. Then:
- Choose sign out everywhere else.
- Change your password.
- Turn on two-factor authentication if it's off.
- Revoke any API token you didn't create, and delete any SSH key you don't recognise.
- Open a support ticket and tell us what you saw, even if it turns out to be nothing.