Anti-Phishing Protection

Your personal security identity - a unique phrase, avatar, and optional audio signature that prove you're logging in to the real WIGGWIGG, not a fake phishing site.

What is Anti-Phishing Protection?

Most authentication is one-way: you prove your identity to the website. But how does the website prove its identity to you?

Our anti-phishing protection works both ways. Before you enter your full password, we show you a security identity (visual phrase and avatar, plus optional audio signature) that only the real WIGGWIGG can display.

Here's How It Protects You

1

We ask for only the first 3 characters of your password

2

We use those to retrieve your unique security phrase and avatar

3

We display them to you before you enter your full password

If you don't see your exact phrase and avatar, you know you're on a fake site - and you haven't given away your full password.

Aperçu Visuel

What It Looks Like

Here's exactly what you'll see when you log in - your personal security identity

Your Security Identity
🤖

Crystal Fox Sacred Cobra

This phrase is unique to you and proves you're on the real WIGGWIGG site

(Audio playback available in the web app)

⚠️ If this doesn't match what you remember

You may be on a phishing site. Do not enter your full password.

Note: This is a visual example. When you register, you'll receive your own unique phrase, avatar, and colors that will be completely different.

How It Works

The Login Process

A five-step verification that protects you from phishing attacks

1

Enter Account ID

Start by entering your Account ID. This is your public identifier, so no risk yet.

2

First 3 Characters

Enter only the first 3 characters of your password. We use these to verify partial authentication and retrieve your security identity.

3

Verify Identity

We show your unique security phrase and avatar, and play your personal audio signature (if enabled). Recognize them? You're on the real site. Don't recognize them? Close the page immediately.

4

Complete Login

After confirming your security identity, enter your full password to complete authentication. Safe and verified.

5

Access Granted

Once authenticated, you gain full access to your account knowing you're on the legitimate WIGGWIGG platform.

Why This Matters

Phishing sites can look identical to the real site. They can copy our design, colors, and logo perfectly. But they typically cannot display your unique security identity because they don't have access to our servers. However, advanced real-time proxy attacks can relay your credentials and show your real identity - always verify the exact domain in your address bar. This verification step stops most phishing attacks before you expose your full credentials.

Security Features

Multiple Protection Mechanisms

Visual & Audio Identity Verification

Your unique phrase and avatar are generated server-side from your personal security seed using cryptographic processes. Additionally, you can enable an optional audio signature - a unique musical pattern that plays during login. Some people remember sounds better than visual elements, making this a valuable multi-sensory verification option.

Domain Awareness

Always verify you're on an official WIGGWIGG domain (wiggwigg.ca, app.wiggwigg.ca) before entering any credentials. Your security identity helps confirm you're on the real site, but always check the address bar as your primary verification.

Partial Authentication

We only ask for the first 3 characters initially, stored as a cryptographic hash (HMAC-SHA256). Even if intercepted, these 3 characters can't complete login - they only unlock your security identity display. Your full password stays protected.

Connection Security

We require HTTPS connections for all authentication. Always verify you see the padlock icon and the correct domain in your browser's address bar before entering credentials.

Stay Protected

How to Protect Yourself

DO

  • Memorize your security phrase and avatar during registration

  • Verify you see them before entering your full password

  • Type wiggwigg.ca directly into your address bar

  • Check for HTTPS and valid SSL certificate

  • Use bookmarks instead of clicking email links

DON'T

  • Enter your full password if security identity is wrong

  • Click login links in unsolicited emails

  • Ignore security warnings or certificate errors

  • Log in from embedded frames or pop-ups

  • Trust similar-looking domains without checking

If You Suspect a Phishing Attempt

1. Close the browser tab immediately - don't click anything

2. Open a new browser window and type wiggwigg.ca directly

3. Change your password immediately if you entered it

4. Report the phishing site to our support team

5. Check your account activity for any suspicious logins

Technical Implementation

How It Works Under the Hood

Our anti-phishing system combines multiple cryptographic and security techniques to verify both you and us.

Security Identity Generation

  • Generated server-side from your unique security seed using cryptographic hash functions

  • Unique phrase created from word list (3-4 words, high entropy)

  • Avatar generated using deterministic algorithms (consistent per user)

  • Optional audio signature: unique 6-note musical pattern using a sound synthesizer

  • Audio uses pentatonic scales, varied rhythms, and waveforms for pleasant, recognizable sounds

  • Stored securely in database, never exposed until partial auth succeeds

Partial Password Verification

  • First 3 characters hashed using HMAC-SHA256

  • Hash compared against stored partial password hash

  • Success triggers security identity retrieval

  • Full password never transmitted until identity confirmed

  • Important: Treat all password characters as sensitive - use a strong, unique password

Connection Security

  • HTTPS-only enforcement (TLS 1.2+)

  • Always verify the padlock icon in your browser

  • Check the domain matches wiggwigg.ca or app.wiggwigg.ca exactly

  • Content Security Policy (CSP) headers prevent XSS

  • Your security identity provides a second layer of verification

Important Limitations

What Anti-Phishing Cannot Protect Against

While our anti-phishing protection is strong, it's important to understand its limitations:

Real-Time Phishing Proxies

The most sophisticated phishing attacks act as a live proxy between you and WIGGWIGG. These attacks can show your real security identity (visual and audio) while stealing your full password in real-time. This is why you must always verify the exact domain in your address bar: wiggwigg.ca or app.wiggwigg.ca. No exceptions.

Man-in-the-Middle Attacks

If an attacker intercepts your connection using compromised certificates or network-level attacks, they could relay your credentials in real-time. Always verify SSL certificates and avoid untrusted networks.

Social Engineering

If an attacker convinces you to share your full password directly (phone call, in person, fake support), anti-phishing can't protect you. Never share your password with anyone - not even WIGGWIGG support staff.

Malware & Keyloggers

If your device is infected with malware that captures keystrokes or screenshots, anti-phishing cannot prevent credential theft. Keep your devices secure and updated.

Browser Extensions & Compromised Software

Malicious browser extensions or compromised software on your device could manipulate what you see, including your security identity display. Only install extensions from trusted sources and keep your software updated.

Recommendation

Anti-phishing protection is one layer of defense. Combine it with strong passwords, two-factor authentication, and careful verification of domains for maximum security.

Frequently Asked Questions

What is a security identity?

Your security identity is a unique combination of a personalized phrase and avatar that we show you during login. See it as a secret handshake between you and WIGGWIGG: if you don't see your exact phrase and avatar, you know something is wrong.

How does partial authentication work?

When you log in, we first ask for only the first 3 characters of your password. This limited verification allows us to retrieve and show you your security identity without exposing your full password. We verify these 3 characters using cryptographic hashing - they never travel unencrypted.

What should I do if I don't see my security identity?

STOP immediately. Do not enter your full password. Close the browser tab and navigate directly to wiggwigg.ca by typing it in your address bar. If your security identity is missing or different, you may be on a phishing site designed to steal your credentials.

Can a phishing site fake my security identity?

Typically no, but advanced attacks exist. Your security identity is generated server-side using your unique security seed. A phishing site would need to breach our servers to get this information. However, sophisticated real-time proxy attacks can act as a middleman, relaying your partial password to us and showing you the real security identity while capturing your full password. This is why you must always verify the exact domain (wiggwigg.ca or app.wiggwigg.ca) in your address bar, not just your security identity.

Do I need to memorize my security phrase?

Yes. During registration, you'll acknowledge your security phrase and avatar. You should memorize them so you can instantly recognize when you're logging in to the legitimate site. If you ever see a different phrase or avatar, it's a red flag that you're on a fake site.

What is the audio signature feature?

The audio signature is an optional feature that plays a unique 6-note musical pattern during login. It's generated from your security seed just like your visual identity, making it unique to you. Some people find auditory recognition easier than visual - it's a matter of personal preference. You can enable or disable it, adjust volume, and manually replay it anytime during login. Note: Audio signatures provide an additional verification layer but are not cryptographically unbreakable on their own - always combine with visual verification and domain checking.

How do I verify I'm on the real site?

Always check two things: First, verify the domain in your address bar is exactly wiggwigg.ca or app.wiggwigg.ca (look for the padlock icon too). Second, after entering the first 3 characters of your password, verify your security identity matches what you remember. If either check fails, close the browser immediately and navigate directly to wiggwigg.ca.

Ready for Two-Way Security?

Experience the confidence of knowing you're always on the real site.