Security Settings
About 590 wordsAbout 2 min
2026-08-14 10:00:00
Version Notice
This document corresponds to the v3 "Settings → General → Security" page. v3 is in Alpha stage; settings may change with versions, please refer to the actual interface.
Protect your configuration
Through flexible security configuration, protect your system from unauthorized access. All settings are saved in real-time and take effect automatically.
Security settings protect sensitive operations (settings modification, drawing, window control, etc.). They support three verification methods — password, TOTP and USB drive binding — which can be combined.
Security Switch
Enable Security Protection: When enabled, selected operations require verification before execution
- On: All selected security operations require verification
- Off: Security operations do not require verification
Tips
Security verification always runs through the unified security service and cannot be bypassed.
Verification Methods
Enable Password Verification
Description: Protect sensitive operations with a local password
How to use:
- Enable "Password Verification"
- Click "Set Password", enter a password (at least 6 characters)
- Takes effect after saving
Notes:
- Minimum 6 characters; no additional character class restrictions
- Can "Change Password" or "Remove Password" anytime
Enable TOTP Verification
Description: Protect sensitive operations with one-time codes (i.e., 2FA)
How to use:
- Enable "TOTP Verification"
- Click "Set TOTP", scan the QR code or enter the key with an authenticator app (e.g., Google Authenticator, Microsoft Authenticator)
- Enter the 6-digit code generated by the authenticator to complete binding
Notes:
- Can "Reset TOTP" anytime
- The code is a 6-digit dynamic passcode
Bind USB Drive
Description: Only allow verification when the bound device is present
How to use:
- Enable "USB Binding"
- Insert the USB drive to bind
- Click "Bind USB Drive" to complete
Notes:
- A dedicated security token (
.SecRandom.safety.key) is stored on the bound drive - Multiple devices can be bound; view them in the "Bound Devices" list (drive letter, disk name, device identifier, connection status)
- Can "Unbind" or "Unbind Selected" devices
- Binding records only keep stable device IDs and token hashes, not volatile info like drive letters
Protection Scope
Verify Before Sensitive Operations
Description: Require verification before modifying key settings (security, linkage, lists, etc.)
Verify Before Linkage Operations
Description: Require verification before external linkage triggers drawing or page switching
Window & App Operations
Protect the following (optional):
- Open Settings: Verification required when opening the settings window
- Allow Read-only Settings Preview: When entering settings verification, allow previewing settings content (read-only before verification, modifiable after)
- Show/Hide Main Window: Verification required to show/hide the main window
- Show/Hide Floating Window: Verification required to show/hide the floating window
- Restart App: Verification required to restart the software
- Exit App: Verification required to exit the software
Draw Operations
Protect the start and reset of each draw type separately:
- Roll Call Start / Roll Call Reset
- Quick Draw Start / Quick Draw Clear
- Lottery Start / Lottery Reset
Verification Method Combination
Verification Methods
Choose the combination of methods to use (password, TOTP, USB drive)
All Selected Methods Required
- On: Must complete all selected methods to pass
- Off: Passing any selected method is enough to continue
Tips
The password always protects the credentials themselves; other methods must be configured before they can be selected.
Security Recommendations
- Enable the security switch to strengthen system security
- Set a strong password and change it regularly
- Enable USB/TOTP verification as a second factor when needed
- Enable verification for important operations (exit, open settings, draws)
Related Pages
- Verifiable drawing (proof & notarization): see Verifiable Drawing
- Backup & restore: see Backup Settings
- Privacy options: see Privacy Settings
Contributors
Changelog
4088d-Update navbar links and remove Advanced Settingson
Copyright
Copyright Ownership:SECTL
License under:CC BY-NC-SA 4.0
