• 5 Posts
  • 30 Comments
Joined 1 year ago
cake
Cake day: June 14th, 2023

help-circle


















  • Just be careful with it. It doesn’t confirm that your code is correct before enabling it, and the way it gets set up doesn’t work on a number of different authenticators (such as Authy).

    Best way to do it is to enable it in settings add it to your app, and then while the settings screen is still open, open an incognito tab and try to log in.






  • That doesn’t address the issue. Yeah, that makes setting up a code easy on your device - but the code still should be verified and confirmed as working by the website before 2FA is enabled on the account.

    Case in point: I used your revered “automated 2FA key implementation” for Lemmy in Authy. It set up the account in my Authy list, and 2FA was supposed to be working. I opened an icognito tab, went to log in, put in my 2FA code and… it didn’t work.

    Luckily, I still had my settings open in my other window and was able to deactivate 2FA.

    The code should be tested and confirmed by the site before it’s enabled. Otherwise you can easily get locked out of your account. This is standard practice when implementing 2FA on websites.