• Lodion 🇦🇺M
    link
    fedilink
    English
    11
    edit-2
    1 year ago

    I encourage everyone, but especially mods to enable 2FA on their account. I’ll do up a post tonight with screenshots on exactly how to do this, I realise the lemmy process isn’t as smooth as it could be. Ideally it would present a QR code to scan with with your phone as most other sites do.

    • Zagorath
      link
      fedilink
      English
      61 year ago

      Some points from the admin of ttrpg.network in our Discord chat:

      • the html injection seems not to apply to 18.1 (the version we’re on) [us too!], but if it does, it applies to the sidebar, posts, and comments (so a huge deal)
      • apparently there’s some concerns around the implementation (of 2fa) at the moment…maybe i’ll just shut it off for now and wait then…

      This thread explains the very serious risk of Lemmy’s current 2FA implementation.

      Real risk of locking yourself out of your account.

      • @[email protected]
        link
        fedilink
        English
        51 year ago

        Yeah, 2fa didn’t work for me when I tried to set it up. Was just lucky I was logged in on more than one browser, so I could go and disable it.

      • Lodion 🇦🇺M
        link
        fedilink
        English
        41 year ago

        Real risk of locking yourself out of your account.

        yes, the initial setup is not intuitive at all. Once setup it functions normally.

            • @[email protected]
              link
              fedilink
              English
              31 year ago

              Thanks. This worked. I got a little confused with points 3, 4 and 5 but now that I’ve re-read your instructions I see that they are clear and I have no suggestions for improving them at this time.

            • Gorgritch_Umie_Killa
              link
              fedilink
              English
              21 year ago

              Hey, so i followed the guide. I think i hit all the steps, but when i try to log in on the browser to test whether its worked. The 2fa box does come up. But when i enter the code and hit login theres no progression on from that screen. Not sure where i’ve gone wrong? Using Aegis btw.

              • Lodion 🇦🇺M
                link
                fedilink
                English
                21 year ago

                Hmm you may need to disable 2FA again. I’m not sure why it wouldn’t work, perhaps Aegis hasn’t imported it correctly?

          • Lodion 🇦🇺M
            link
            fedilink
            English
            31 year ago

            In the short term, use a 60 character password and never use that account interactively. ie only use it with your scripts/bot. And obviously keep the password securely stored.

    • Rusty Raven
      link
      fedilink
      English
      31 year ago

      Mine just won’t enable it at all. I have it set up on my other account, but this one when I hit save nothing happens.

      • Lodion 🇦🇺M
        link
        fedilink
        English
        3
        edit-2
        1 year ago

        That is one of the issues… if you tick the box to enable 2FA and hit save, you then need to hit F5/refresh for the ‘2FA Installation link’ to appear.

        Actually making use of the 2FA installation link is also not intuitive… as I said I’ll try and post a sequence of screenshots tonight with a fresh test account to show the process.

        • Rusty Raven
          link
          fedilink
          English
          41 year ago

          That didn’t work, but I have solved it. I had to take the emoji out of my display name. No idea why that has any impact, but it did.

            • Rusty Raven
              link
              fedilink
              English
              31 year ago

              I’ve been playing around and it’s only some emojis it has a problem with. Your bagels are safe.

              • Rusty Raven
                link
                fedilink
                English
                31 year ago

                The 2FA system might just be prejudiced against birds. I tried putting it back in after it was set up and it won’t save my settings if the emoji is there. It’s very weird.

                  • Rusty Raven
                    link
                    fedilink
                    English
                    21 year ago

                    It won’t let me put it anywhere in the field. A bagel or a smiley face are find, but I can’t do the bird, or a black cat. It might be something to do with the specific emoji - both the black bird and cat are a standard bird/cat paired with a black square which display as a single emoji on some systems.

              • Gloomy Bagel 🥯
                link
                fedilink
                English
                21 year ago

                thank you, and the 2FA set up was actually the easiest i’ve ever set up on iOS. a little too easy …

    • @Aesecakes
      link
      English
      21 year ago

      I tried doing this but have lost access to my aussie.zone account (same user name). I checked the 2FA box but I couldn’t see the extra setup steps (I think I refreshed the page), so I unchecked the box and saved. I then changed my pw. Now it seems to accept new pw but am getting incorrect 2FA token error. What do I do?