# How to use Meshnet securely

## Introduction <a href="#introduction" id="introduction"></a>

When using Meshnet, it's essential to keep in mind the nuances of network security — even if you haven't encountered any issues yet. The purpose of this article is to offer actionable steps to fortify your Meshnet infrastructure against various types of cyber threats.

## You find an unknown device on your Meshnet <a href="#you-find-an-unknown-device-on-your-meshnet" id="you-find-an-unknown-device-on-your-meshnet"></a>

If you discover an unknown device in your list of Meshnet devices, follow these steps:

<details>

<summary>1. Unlink the unknown device</summary>

Having an unknown device linked to your Meshnet network is a serious security risk. To remove the device you don’t recognize, you can use either the **NordVPN** app or the [Nord Account](https://my.nordaccount.com/) website.

**In the NordVPN app**

1. Navigate to **Meshnet** <img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FyNPGbeTmyQ5agRdyJD19%2Ficon_meshnet_blue.svg?alt=media&#x26;token=478d08e6-81b2-4acc-af45-46579f95599e" alt="" data-size="line">.
2. Find the device list and unlink the suspicious device.

**On the Nord Account website**

1. Log in to your NordVPN account.
2. Select the **Meshnet (by NordVPN)** card.
3. Find the device list and unlink the suspicious device.

For detailed steps, consult the guidelines appropriate for your operating system:

* [Unlink devices on Windows](https://meshnet.nordvpn.com/how-to-start-using-meshnet/using-meshnet-on-windows#unlink-devices)
* [Unlink devices on Android](https://meshnet.nordvpn.com/how-to-start-using-meshnet/using-meshnet-on-android#unlink-devices)
* [Unlink devices on iPhone/iPad](https://meshnet.nordvpn.com/how-to-start-using-meshnet/using-meshnet-on-ios#unlink-devices)
* [Unlink devices on macOS](https://meshnet.nordvpn.com/how-to-start-using-meshnet/using-meshnet-on-macos#unlink-devices)
* [Unlink devices on Linux](https://meshnet.nordvpn.com/how-to-start-using-meshnet/using-meshnet-on-linux#remove-your-device-from-meshnet)
* [Unlink devices on Android TV](https://meshnet.nordvpn.com/how-to-start-using-meshnet/using-meshnet-on-android-tv#unlink-devices)

</details>

<details>

<summary>2. Change your account password</summary>

Your account may have been compromised. Change your password as a preventive measure.

**If you are using a desktop device**

1. Log in to [Nord Account](https://my.nordaccount.com/) using your current password.

2. In the upper-right corner, click your account name and choose **Account settings**.

   <div align="left"><figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FTzkLgtYfMUnP4gKrGjQ5%2Fucp_account_settings.png?alt=media&#x26;token=f3c3c81f-4c38-41d1-bb17-3c952b9040dd" alt="Showing the Account settings option selected" width="375"><figcaption></figcaption></figure></div>

3. Under **Account details**, Select **Change password**.

   <figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FF1b0SvLKsDwASMyGfrqA%2Fucp_change_password.png?alt=media&#x26;token=56879a87-d2a4-490d-8ff6-fc802282dc0f" alt=""><figcaption></figcaption></figure>

   &#x20;

**If you are using a mobile device**

1. Log in to [Nord Account](https://my.nordaccount.com/) using your current password.
2. Tap the three-bar menu in the upper-right corner of the screen.

   <div align="left"><figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FvyjPUrrxBrozjO1prA6Q%2Fucp_mobile_hamburger.png?alt=media&#x26;token=b4bffc50-52ff-43ad-838f-519aa97cdfd9" alt="Three-bar menu highlighted." width="375"><figcaption></figcaption></figure></div>

   &#x20;
3. Select **Account settings**.

   <div align="left"><figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FgykTozqLO0vrmJFrVQrv%2Fucp_mobile_acc_settings.png?alt=media&#x26;token=f2fcac77-2220-41bc-84c2-7bb3e2ecab7a" alt="&#x22;Account settings&#x22; button highlighted." width="375"><figcaption></figcaption></figure></div>

   &#x20;
4. Under **Account details**, tap **Change password**.

   <div align="left"><figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FS7xw98PsfvEo3rGvZ5pA%2Fucp_mobile_change_password.png?alt=media&#x26;token=7170de88-4f96-4f94-83d0-eba899e4b104" alt="&#x22;Change password&#x22; button highlighted." width="375"><figcaption></figcaption></figure></div>

</details>

<details>

<summary>3. Enable MFA for your Nord account</summary>

Multi-factor authentication (MFA) is a security mechanism that verifies user identity by requiring two or more forms of authentication. This could be a combination of a password, PIN, token, USB security key, fingerprint, or facial recognition.

**If you are using a desktop device**

1. Log in to [Nord Account](https://nordaccount.com/?_gl=1*k01z0l*_ga*M2EzODgyYWQtN2M1Yy00MGExLWExYmQtZTczNmZiNGZlNWQ4*_ga_LEXMJ1N516*MTY5NzQ2MTQ5Mi45NC4xLjE2OTc0NjM5NzAuNjAuMC4w&_ga=2.86431960.1332578323.1697452471-3a3882ad-7c5c-40a1-a1bd-e736fb4fe5d8&_gac=1.95285614.1696426553.Cj0KCQjwmvSoBhDOARIsAK6aV7gig_lui9ZOimdsGqDM7b84lfs4ODITgJrFi2LqieIMxqAiCl12-vgaAkjOEALw_wcB).
2. In the upper-right corner, click your account name and choose **Account settings**.

   <div align="left"><figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FTzkLgtYfMUnP4gKrGjQ5%2Fucp_account_settings.png?alt=media&#x26;token=f3c3c81f-4c38-41d1-bb17-3c952b9040dd" alt="Showing the Account settings option selected" width="375"><figcaption></figcaption></figure></div>

   &#x20;
3. Under **Multi-factor authentication (MFA)**, click the **Manage MFA** button.

   <figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FmhKCKSvntN1HOyGcb2vT%2Fucp_manage_mfa.png?alt=media&#x26;token=2af26dea-05ff-47b6-8272-144a448e51ea" alt="&#x22;Multi-factor authentication (MFA)&#x22; tab selected and the &#x22;Manage MFA&#x22; button highlighted."><figcaption></figcaption></figure>

   &#x20;
4. An email with a verification code will be sent to you. Enter this code in the designated field.
5. Click **Set up** next to your preferred MFA method. Follow the on-screen instructions to complete the setup.

   <div align="left"><figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FngmdLMAQYONoFNdWEcEu%2Fucp_mfa_options.png?alt=media&#x26;token=56a9b0ae-3988-44e7-8cef-ee0b4ca68be8" alt="&#x22;Set up&#x22;  buttons highlighted next to both MFA options."><figcaption></figcaption></figure></div>

   &#x20;

**If you are using a mobile device**

1. Log in to [Nord Account](https://nordaccount.com/?_gl=1*k01z0l*_ga*M2EzODgyYWQtN2M1Yy00MGExLWExYmQtZTczNmZiNGZlNWQ4*_ga_LEXMJ1N516*MTY5NzQ2MTQ5Mi45NC4xLjE2OTc0NjM5NzAuNjAuMC4w&_ga=2.86431960.1332578323.1697452471-3a3882ad-7c5c-40a1-a1bd-e736fb4fe5d8&_gac=1.95285614.1696426553.Cj0KCQjwmvSoBhDOARIsAK6aV7gig_lui9ZOimdsGqDM7b84lfs4ODITgJrFi2LqieIMxqAiCl12-vgaAkjOEALw_wcB).
2. Tap the three-bar menu in the upper-right corner of the screen.

   <div align="left"><figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FvyjPUrrxBrozjO1prA6Q%2Fucp_mobile_hamburger.png?alt=media&#x26;token=b4bffc50-52ff-43ad-838f-519aa97cdfd9" alt="Three-bar menu highlighted." width="375"><figcaption></figcaption></figure></div>

   &#x20;
3. Select **Account settings**.<br>

   <div align="left"><figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FgykTozqLO0vrmJFrVQrv%2Fucp_mobile_acc_settings.png?alt=media&#x26;token=f2fcac77-2220-41bc-84c2-7bb3e2ecab7a" alt="&#x22;Account settings&#x22; button highlighted." width="375"><figcaption></figcaption></figure></div>

   &#x20;
4. Navigate to **Multi-factor authentication (MFA)** and select **Manage MFA**.

   <div align="left"><figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2Fbf7oiqabjgViYJqyj2Lx%2Fucp_mobile_manage_mfa.png?alt=media&#x26;token=cffe5dd2-0222-4af4-959d-e40733193f79" alt="&#x22;Multi-factor authentication (MFA)&#x22; tab selected and the &#x22;Manage MFA&#x22; button highlighted." width="375"><figcaption></figcaption></figure></div>

   &#x20;
5. An email with a verification code will be sent to you. Enter this code in the designated field.
6. Tap **Set up** under your preferred MFA method. Follow the on-screen instructions to complete the setup.

   <div align="left"><figure><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FGb05nwLUVMTe6uRuI4cM%2Fucp_mobile_mfa_options.png?alt=media&#x26;token=ebbedc5b-3380-4082-a175-7b4b6d89982f" alt="&#x22;Set up&#x22; buttons highlighted under both MFA options." width="375"><figcaption></figcaption></figure></div>

   &#x20;

You have two options for enabling MFA for your Nord account:

* **Authenticator app**\
  If you choose this method, use apps like [Google Authenticator](https://nordvpn.com/blog/what-is-google-authenticator/), Microsoft Authenticator, or Authy. These apps generate a code that changes every 30 seconds, which you'll need to enter when accessing your Nord Account.
* **Security key**\
  If you prefer this method, use a Bluetooth, NFC, or USB security key that holds a unique PIN. Nord Account is compatible with FIDO2-certified USB keys, including various series like Security Key, Yubikey 5, and others.

</details>

## An unknown device sends an invitation <a href="#an-unknown-device-sends-an-invitation" id="an-unknown-device-sends-an-invitation"></a>

If you do not recognize the email account of the sender, do not accept or reject the invitation.

## You're unsure about the invitation sender <a href="#youre-unsure-about-the-invitation-sender" id="youre-unsure-about-the-invitation-sender"></a>

If you're unsure whether an invitation is from someone you know, directly ask the supposed sender to confirm if they sent the invitation.

## Review access permissions for linked devices <a href="#review-access-permissions-for-linked-devices" id="review-access-permissions-for-linked-devices"></a>

Linked devices can access your device resources based on specific permissions you've set.

1. Check your device's permission settings to see what each linked device can access.\
   For more details, consult these pages:
   * [Remote access permissions](https://meshnet.nordvpn.com/features/explaining-permissions/remote-access-permissions)
   * [File sharing permissions](https://meshnet.nordvpn.com/features/explaining-permissions/file-sharing-permissions)
   * [Traffic routing permissions](https://meshnet.nordvpn.com/features/explaining-permissions/traffic-routing-permissions)
   * [Local network permissions](https://meshnet.nordvpn.com/features/explaining-permissions/local-network-permissions)
2. Change permissions if you want to restrict access to certain resources.\
   &#x20;\
   **Example**\
   You can block a device from accessing your local network when it routes traffic through your device, as shown:

   <div align="left"><figure><picture><source srcset="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2FEdU3STLm1A037yoRDTgJ%2Fsecure_disable_lan_dark.png?alt=media&#x26;token=426faa61-7812-4e30-ad28-63f89f31c223" media="(prefers-color-scheme: dark)"><img src="https://3559400189-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0cTezbT2vN0lurEio8Z5%2Fuploads%2Fc0AHCZlM9eGxzTcDcDxr%2Fsecure_disable_lan.png?alt=media&#x26;token=cb5e76cb-52a6-4cb9-b412-212a6d4974b2" alt="&#x22;Access to your local network&#x22; toggled turned off in Permissions menu"></picture><figcaption></figcaption></figure></div>

## Consider traffic routing risks <a href="#consider-traffic-routing-risks" id="consider-traffic-routing-risks"></a>

Traffic routing offers great opportunities but comes with its own set of risks.

* **Public IP exposure**\
  If someone routes their traffic through your device, your [public IP address](https://nordvpn.com/what-is-my-ip/) could be associated with their online activities.
* **Local network access**\
  A threat actor who gains [Local network permissions](https://meshnet.nordvpn.com/features/explaining-permissions/local-network-permissions) could potentially access other devices on your local area network (LAN) and make unauthorized changes.
* **Network monitoring**\
  A device that you are routing traffic through could maliciously monitor your network activity, including [DNS queries](https://nordvpn.com/cybersecurity/glossary/dns-query/), thereby gaining insights into your online behavior.

Remember that the privacy of your Meshnet network depends on the reliability of its members. By following the security measures outlined above, you can enjoy a safer Meshnet experience.
