Your personal security marker: a unique phrase, color pair, avatar, and optional audio signature that prove you're logging in to the real WIGGWIGG, not a fake phishing site (if you turned it on at sign-up or in Settings).
Most authentication is one-way: you prove your identity to the website. But how does the website prove its identity to you?
Our anti-phishing protection works both ways. Before you enter your full password, we show you a security marker (a unique phrase, color pair, and avatar, plus an optional audio signature) that only the real WIGGWIGG can display, if you turned it on at sign-up or in Settings.
We ask for only the first 3 characters of your password
We use those to retrieve your unique security phrase, colors, and avatar (and play your audio signature if you've enabled it)
We display them to you before you enter your full password
If your security marker doesn't match what you remember, you know you're on a fake site, and you haven't given away your full password.
Here's exactly what you'll see when you log in (if you turned it on at sign-up or in Settings): your personal security marker
This phrase is unique to you and proves you're on the real WIGGWIGG site
(Audio playback available in the web app)
⚠️ If this doesn't match what you remember
You may be on a phishing site. Do not enter your full password.
Note: This is a visual example. When you turn it on (at sign-up or in Settings), you'll receive your own unique phrase, color pair, avatar, and audio signature that will be completely different.
Before you ever type your password, your sign-in greets you with a personal marker: a phrase, color pair, and avatar derived from a secret seed only your account holds. A copycat site can't display it.
Memorize your phrase and colors. If a login ever shows different ones, it's fake. Close the tab.
Beyond the phrase, the colours and the avatar, your security marker can also be heard: six notes drawn from a pentatonic scale, generated from your security seed. They are yours alone, and always the same.
They play at the same moment as the rest of your security marker: after the first three characters of your password, before you type the full one.
The audio signature is off by default, even when your security marker is on. It is a separate setting, alongside the phrase, the colours and the avatar.
It is there to be recognized, not to prove. A live relay site can replay what it just received: the limitations further down apply to the sound exactly as they do to the picture.
A five-step verification that protects you from phishing attacks
Start by entering your Account ID. This is your public identifier, so no risk yet.
Enter only the first 3 characters of your password. We use these to verify partial authentication and retrieve your security marker.
We show your unique security phrase, colors, and avatar (if you turned it on at sign-up or in Settings), and play your personal audio signature (if enabled). Recognize them? You're on the real site. Don't recognize them? Close the page immediately.
After confirming your security marker, enter your full password to complete authentication. Safe and verified.
Once authenticated, you gain full access to your account knowing you're on the legitimate WIGGWIGG platform.
Phishing sites can look identical to the real site. They can copy our design, our colors, and our logo perfectly. But they typically cannot display your unique security marker (your personal phrase, color pair, avatar, and audio signature) because they don't have access to our servers. Advanced real-time proxy attacks can relay your credentials and show your real marker, so always verify the exact domain in your address bar too. This verification step stops most phishing attacks before you expose your full credentials.
Your unique phrase, color pair, and avatar are derived on your device from your personal security seed. The seed is sealed under a key derived from the first characters of your password, which bounds the protection: a stolen database can't mass-render markers. You can also enable an optional audio signature, a unique musical pattern that plays during login. Some people remember sounds better than visual elements, making this a valuable multi-sensory verification option.
Always verify you're on an official WIGGWIGG domain (wiggwigg.ca, app.wiggwigg.ca) before entering any credentials. Your security marker helps confirm you're on the real site, but always check the address bar as your primary verification.
We only ask for the first 3 characters initially, stored as a cryptographic hash (HMAC-SHA256). Even if intercepted, these 3 characters can't complete login - they only unlock your security marker display. Your full password stays protected.
We require HTTPS connections for all authentication. Always verify you see the padlock icon and the correct domain in your browser's address bar before entering credentials.
Memorize your security phrase, colors, and avatar during registration (and your audio signature if enabled)
Verify you see them before entering your full password
Type wiggwigg.ca directly into your address bar
Check for HTTPS and valid SSL certificate
Use bookmarks instead of clicking email links
Enter your full password if security marker is wrong
Click login links in unsolicited emails
Ignore security warnings or certificate errors
Log in from embedded frames or pop-ups
Trust similar-looking domains without checking
1. Close the browser tab immediately - don't click anything
2. Open a new browser window and type wiggwigg.ca directly
3. Change your password immediately if you entered it
4. Report the phishing site to us
5. Check your account activity for any suspicious logins
Our anti-phishing system combines multiple cryptographic and security techniques to verify both you and us.
Derived on your device from your unique per-account security seed, sealed under a key derived from the first characters of your password (which bounds the protection: a stolen database can't mass-render markers)
Unique phrase created from word list (3-4 words)
Color pair generated deterministically from the seed (used as a visual cue alongside the avatar)
Avatar generated using deterministic algorithms (consistent per user)
Optional audio signature: unique 6-note musical pattern using a sound synthesizer
Audio uses pentatonic scales, varied rhythms, and waveforms for pleasant, recognizable sounds
Stored securely in database, never exposed until partial auth succeeds
First 3 characters hashed using HMAC-SHA256
Hash compared against stored partial password hash
Success triggers security marker retrieval
Your full password is never transmitted at all; you only type it after the marker check
Important: Treat all password characters as sensitive - use a strong, unique password
HTTPS-only enforcement (TLS 1.2+)
Always verify the padlock icon in your browser
Check the domain matches wiggwigg.ca or app.wiggwigg.ca exactly
Content Security Policy (CSP) headers prevent XSS
Your security marker provides a second layer of verification
While our anti-phishing protection is strong, it's important to understand its limitations:
The most sophisticated phishing attacks act as a live proxy between you and WIGGWIGG. These attacks can show your real security marker (visual and audio) while stealing your full password in real-time. This is why you must always verify the exact domain in your address bar: wiggwigg.ca or app.wiggwigg.ca. No exceptions.
If an attacker intercepts your connection using compromised certificates or network-level attacks, they could relay your credentials in real-time. Always verify SSL certificates and avoid untrusted networks.
If an attacker convinces you to share your full password directly (phone call, in person, fake support), anti-phishing can't protect you. Never share your password with anyone - not even WIGGWIGG support staff.
If your device is infected with malware that captures keystrokes or screenshots, anti-phishing cannot prevent credential theft. Keep your devices secure and updated.
Malicious browser extensions or compromised software on your device could manipulate what you see, including your security marker display. Only install extensions from trusted sources and keep your software updated.
Anti-phishing protection is one layer of defense. Combine it with strong passwords, two-factor authentication, and careful verification of domains for maximum security.
Experience the confidence of knowing you're always on the real site.