Heads up that we’ve bumped the UI up to 0.18.2-rc.1, which should resolve the current exploit that was seen on lemmy.world.

We’ve also logged out all currently logged in users as part of it, so you’ll need to login again.

You are viewing a single thread.
View all comments
3 points

I went looking to re-attempt 2FA setup. After enabling it in the options, the link that for 0.18.0 would trigger an event to add it to AndOTP (instead of just providing the secret) isn’t showing up at all. (If that makes any sense in my current decaffeinated state)

permalink
report
reply
4 points

FYI, andOTP is no longer maintained, so I’d recommend switching to an alternative and there are many options. My transition to Aegis was very smooth.

permalink
report
parent
reply
2 points

Yeah, it’s not my primary, I just happen to still have it installed.

permalink
report
parent
reply
3 points
*

I’ll take a look in a bit but might be a new bug.

Edit: I can see the link just fine, even without deactivating it first. Can you try clearing your browser cache?

permalink
report
parent
reply
2 points

Weird, opening in my browser now, it’s there. (And I’ve finally figured out how to make bitwarden handle sha256.) In any case, I’m all good and properly using 2FA.

permalink
report
parent
reply
3 points

It’s currently a little awkward, after you enable + save the first time you need to refresh the page in order to see the button which contains the otpauth:// link.

permalink
report
parent
reply
2 points

Same. Click the link button and nothing happens.

permalink
report
parent
reply
6 points
*

The link starts with otpauth://, which will likely do nothing on desktop. Either click on it from a mobile device, or on desktop you can use an addon like Offline QR Code Generator (Firefox), then right-click the link and select QR code from link. This will show a QR code you’ll be able to enroll in any TOTP app. Hopefully they’ll add an option to display a QR code when using the desktop interface in newer versions of Lemmy.

permalink
report
parent
reply
2 points

Can I copy the link it generates and put it directly into my app that handles 2FA? (1password). Thought about trying it, but I didn’t see any recovery codes and am not keen on getting locked out.

permalink
report
parent
reply

Lemmy.ca's Main Community

!main@lemmy.ca

Create post

Welcome to lemmy.ca’s c/main!

Since everyone on lemmy.ca gets subscribed here, this is the place to chat about the goings on at lemmy.ca, support-type items, suggestions, etc.

Announcements can be found at https://lemmy.ca/c/meta

For support related to this instance, use https://lemmy.ca/c/lemmy_ca_support

Community stats

  • 87

    Monthly active users

  • 230

    Posts

  • 2.8K

    Comments