Given the recent attack, I think this is a good opportunity to remind of the importance of using 2FA.
(although it doesn’t appear to make any difference in this case as session cookies were being exploited so login credentials were not needed)
But for me at least, this event has made me go back and take another shot at setting up 2FA.
I am happy to report I finally got it working on all my Lemmy accounts/instances, so I thought I’d share some tips:
otpauth://
link which on a mobile device should be handled by a 2FA app if you have one installed.otpauth://
links it may be possible to do on desktop as well.secret=
value from the link to manually add it to an authenticator on/from desktop.After several failed attempts previously, I finally figured out Authy was the problem and I have now secured all my Lemmy accounts with 2FA. Annoying that I have to use GA, but that appears to be an Authy issue not a Lemmy one.
2FA might not have made any difference today but it very well might in the future.
Stay safe everyone! 🔐
A community to talk about the Fediverse and all it’s related services using ActivityPub (Mastodon, Lemmy, KBin, etc).
If you wanted to get help with moderating your own community then head over to [email protected]!
Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy
2FA feels very half-baked atm.
Tried to set it up and got locked out, but apparently you can get around 2FA by simply requesting a password reset…
That seems like a massive security flaw, and essentially makes 2FA non-existent atm.