this post was submitted on 07 Jul 2023
2 points (100.0% liked)

Lemmy.world Support

3302 readers
1 users here now

Lemmy.world Support

Welcome to the official Lemmy.world Support community! Post your issues or questions about Lemmy.world here.

This community is for issues related to the Lemmy World instance only. For Lemmy software requests or bug reports, please go to the Lemmy github page.

This community is subject to the rules defined here for lemmy.world.

To open a support ticket Static Badge


You can also DM https://lemmy.world/u/lwreport or email report@lemmy.world (PGP Supported) if you need to reach our directly to the admin team.


Follow us for server news ๐Ÿ˜

Outages ๐Ÿ”ฅ

https://status.lemmy.world/



founded 2 years ago
MODERATORS
 

Right now, 2FA is half-baked. You can enable it and it gives you a link to sync it to an authenticator app, which only works on mobile. But there's no confirmation required to enable it, so you may think it's working with your code but it doesn't take. This will lock people out of accounts.

It really should be disabled until it's fully fleshed out. In the meantime, give us the option to send 2FA codes to the verified email on file.

UPDATE: Read this post here: https://lemmy.sdf.org/post/405431

It's clear that the Lemmy implementation of 2FA is flawed as it a) doesn't work with all authenticator apps, and b) doesn't verify the code is working before it enables 2FA on the account.

It needs to be disabled until this is fixed.

you are viewing a single comment's thread
view the rest of the comments
[โ€“] mxwarp@lemmy.ca 0 points 2 years ago (2 children)

No complaints here, Seemless integration of both password & 2FA with iCloud keychain!

[โ€“] darrsil@lemmy.world 0 points 2 years ago (1 children)

Except you didn't confirm your 2FA codes to enable 2FA. You also don't have backup codes you can download.

It may have worked for you, but that doesn't mean it's working properly.

[โ€“] mxwarp@lemmy.ca -1 points 2 years ago

In iOS, the activation of 2FA is an automated process, eliminating the need for a separate 2FA code to confirm its enablement.

I agree with your observation regarding the unavailability of backup codes for download.