Anti-Phishing Protection

Your personal security marker: a unique phrase, color pair, avatar, and optional audio signature that prove you're logging in to the real WIGGWIGG, not a fake phishing site (if you turned it on at sign-up or in Settings).

What is Anti-Phishing Protection?

Most authentication is one-way: you prove your identity to the website. But how does the website prove its identity to you?

Our anti-phishing protection works both ways. Before you enter your full password, we show you a security marker (a unique phrase, color pair, and avatar, plus an optional audio signature) that only the real WIGGWIGG can display, if you turned it on at sign-up or in Settings.

Here's How It Protects You

1

We ask for only the first 3 characters of your password

2

We use those to retrieve your unique security phrase, colors, and avatar (and play your audio signature if you've enabled it)

3

We display them to you before you enter your full password

If your security marker doesn't match what you remember, you know you're on a fake site, and you haven't given away your full password.

Visual preview

What It Looks Like

Here's exactly what you'll see when you log in (if you turned it on at sign-up or in Settings): your personal security marker

Your Security Marker
🤖

Crystal Fox Sacred Cobra

This phrase is unique to you and proves you're on the real WIGGWIGG site

(Audio playback available in the web app)

⚠️ If this doesn't match what you remember

You may be on a phishing site. Do not enter your full password.

Note: This is a visual example. When you turn it on (at sign-up or in Settings), you'll receive your own unique phrase, color pair, avatar, and audio signature that will be completely different.

The login that fights phishing

Before you ever type your password, your sign-in greets you with a personal marker: a phrase, color pair, and avatar derived from a secret seed only your account holds. A copycat site can't display it.

Real sign-inYour marker, you'd know it
Phishing copyCan't match your seed

Memorize your phrase and colors. If a login ever shows different ones, it's fake. Close the tab.

Audio signature

Recognizing the real site by ear

Beyond the phrase, the colours and the avatar, your security marker can also be heard: six notes drawn from a pentatonic scale, generated from your security seed. They are yours alone, and always the same.

How It Works

The Login Process

A five-step verification that protects you from phishing attacks

1

Enter Account ID

Start by entering your Account ID. This is your public identifier, so no risk yet.

2

First 3 Characters

Enter only the first 3 characters of your password. We use these to verify partial authentication and retrieve your security marker.

3

Verify Your Marker

We show your unique security phrase, colors, and avatar (if you turned it on at sign-up or in Settings), and play your personal audio signature (if enabled). Recognize them? You're on the real site. Don't recognize them? Close the page immediately.

4

Complete Login

After confirming your security marker, enter your full password to complete authentication. Safe and verified.

5

Access Granted

Once authenticated, you gain full access to your account knowing you're on the legitimate WIGGWIGG platform.

Why This Matters

Phishing sites can look identical to the real site. They can copy our design, our colors, and our logo perfectly. But they typically cannot display your unique security marker (your personal phrase, color pair, avatar, and audio signature) because they don't have access to our servers. Advanced real-time proxy attacks can relay your credentials and show your real marker, so always verify the exact domain in your address bar too. This verification step stops most phishing attacks before you expose your full credentials.

Security Features

Multiple Protection Mechanisms

Visual & Audio Marker Verification

Your unique phrase, color pair, and avatar are derived on your device from your personal security seed. The seed is sealed under a key derived from the first characters of your password, which bounds the protection: a stolen database can't mass-render markers. You can also enable an optional audio signature, a unique musical pattern that plays during login. Some people remember sounds better than visual elements, making this a valuable multi-sensory verification option.

Domain Awareness

Always verify you're on an official WIGGWIGG domain (wiggwigg.ca, app.wiggwigg.ca) before entering any credentials. Your security marker helps confirm you're on the real site, but always check the address bar as your primary verification.

Partial Authentication

We only ask for the first 3 characters initially, stored as a cryptographic hash (HMAC-SHA256). Even if intercepted, these 3 characters can't complete login - they only unlock your security marker display. Your full password stays protected.

Connection Security

We require HTTPS connections for all authentication. Always verify you see the padlock icon and the correct domain in your browser's address bar before entering credentials.

Stay Protected

How to Protect Yourself

DO

  • Memorize your security phrase, colors, and avatar during registration (and your audio signature if enabled)

  • Verify you see them before entering your full password

  • Type wiggwigg.ca directly into your address bar

  • Check for HTTPS and valid SSL certificate

  • Use bookmarks instead of clicking email links

DON'T

  • Enter your full password if security marker is wrong

  • Click login links in unsolicited emails

  • Ignore security warnings or certificate errors

  • Log in from embedded frames or pop-ups

  • Trust similar-looking domains without checking

If You Suspect a Phishing Attempt

1. Close the browser tab immediately - don't click anything

2. Open a new browser window and type wiggwigg.ca directly

3. Change your password immediately if you entered it

4. Report the phishing site to us

5. Check your account activity for any suspicious logins

Technical Implementation

How It Works Under the Hood

Our anti-phishing system combines multiple cryptographic and security techniques to verify both you and us.

Security Marker Generation

  • Derived on your device from your unique per-account security seed, sealed under a key derived from the first characters of your password (which bounds the protection: a stolen database can't mass-render markers)

  • Unique phrase created from word list (3-4 words)

  • Color pair generated deterministically from the seed (used as a visual cue alongside the avatar)

  • Avatar generated using deterministic algorithms (consistent per user)

  • Optional audio signature: unique 6-note musical pattern using a sound synthesizer

  • Audio uses pentatonic scales, varied rhythms, and waveforms for pleasant, recognizable sounds

  • Stored securely in database, never exposed until partial auth succeeds

Partial Password Verification

  • First 3 characters hashed using HMAC-SHA256

  • Hash compared against stored partial password hash

  • Success triggers security marker retrieval

  • Your full password is never transmitted at all; you only type it after the marker check

  • Important: Treat all password characters as sensitive - use a strong, unique password

Connection Security

  • HTTPS-only enforcement (TLS 1.2+)

  • Always verify the padlock icon in your browser

  • Check the domain matches wiggwigg.ca or app.wiggwigg.ca exactly

  • Content Security Policy (CSP) headers prevent XSS

  • Your security marker provides a second layer of verification

Important Limitations

What Anti-Phishing Cannot Protect Against

While our anti-phishing protection is strong, it's important to understand its limitations:

Real-Time Phishing Proxies

The most sophisticated phishing attacks act as a live proxy between you and WIGGWIGG. These attacks can show your real security marker (visual and audio) while stealing your full password in real-time. This is why you must always verify the exact domain in your address bar: wiggwigg.ca or app.wiggwigg.ca. No exceptions.

Man-in-the-Middle Attacks

If an attacker intercepts your connection using compromised certificates or network-level attacks, they could relay your credentials in real-time. Always verify SSL certificates and avoid untrusted networks.

Social Engineering

If an attacker convinces you to share your full password directly (phone call, in person, fake support), anti-phishing can't protect you. Never share your password with anyone - not even WIGGWIGG support staff.

Malware & Keyloggers

If your device is infected with malware that captures keystrokes or screenshots, anti-phishing cannot prevent credential theft. Keep your devices secure and updated.

Browser Extensions & Compromised Software

Malicious browser extensions or compromised software on your device could manipulate what you see, including your security marker display. Only install extensions from trusted sources and keep your software updated.

Recommendation

Anti-phishing protection is one layer of defense. Combine it with strong passwords, two-factor authentication, and careful verification of domains for maximum security.

Frequently Asked Questions

What is a security marker?

Your security marker is a unique combination of a personalized phrase, color pair, and avatar (with an optional audio signature) that we show you during login (if you turned it on at sign-up or in Settings). See it as a secret handshake between you and WIGGWIGG: if your security marker doesn't match what you remember, you know something is wrong.

How does partial authentication work?

When you log in, we first ask for only the first 3 characters of your password. This limited verification allows us to retrieve and show you your security marker without exposing your full password. We verify these 3 characters using cryptographic hashing - they never travel unencrypted.

What should I do if I don't see my security marker?

STOP immediately. Do not enter your full password. Close the browser tab and navigate directly to wiggwigg.ca by typing it in your address bar. If your security marker (phrase, colors, avatar, or audio) is missing or different, you may be on a phishing site designed to steal your credentials.

Can a phishing site fake my security marker?

Typically no, but advanced attacks exist. Your security marker is derived on your device from your security seed, which is sealed under a key derived from the first characters of your password. That bounds the protection: a stolen database can't mass-render markers, and a static phishing site has nothing to show. However, sophisticated real-time proxy attacks can act as a middleman, relaying your partial password to us and showing you the real security marker while capturing your full password. This is why you must always verify the exact domain (wiggwigg.ca or app.wiggwigg.ca) in your address bar, not just your security marker.

Do I need to memorize my security phrase?

Yes. If you turn it on at sign-up (or later in Settings), you'll acknowledge your security phrase, colors, avatar, and audio signature. You should memorize them so you can instantly recognize when you're logging in to the legitimate site. If anything looks or sounds different, it's a red flag that you're on a fake site.

What is the audio signature feature?

The audio signature is an optional feature that plays a unique 6-note musical pattern during login. It's generated from your security seed just like the visual part of your marker, making it unique to you. Some people find auditory recognition easier than visual - it's a matter of personal preference. You can enable or disable it, adjust volume, and manually replay it anytime during login. Note: Audio signatures provide an additional verification layer but are not cryptographically unbreakable on their own - always combine with visual verification and domain checking.

How do I verify I'm on the real site?

Always check two things: First, verify the domain in your address bar is exactly wiggwigg.ca or app.wiggwigg.ca (look for the padlock icon too). Second, after entering the first 3 characters of your password, verify your security marker matches what you remember. If either check fails, close the browser immediately and navigate directly to wiggwigg.ca.

Ready for Two-Way Security?

Experience the confidence of knowing you're always on the real site.