Heads up that we’ve bumped the UI up to 0.18.2-rc.1, which should resolve the current exploit that was seen on lemmy.world.

We’ve also logged out all currently logged in users as part of it, so you’ll need to login again.

    • m-p{3}@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      1 year ago

      The link starts with otpauth://, which will likely do nothing on desktop. Either click on it from a mobile device, or on desktop you can use an addon like Offline QR Code Generator (Firefox), then right-click the link and select QR code from link. This will show a QR code you’ll be able to enroll in any TOTP app. Hopefully they’ll add an option to display a QR code when using the desktop interface in newer versions of Lemmy.

      • TheMadIrishman@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 year ago

        Can I copy the link it generates and put it directly into my app that handles 2FA? (1password). Thought about trying it, but I didn’t see any recovery codes and am not keen on getting locked out.

        • durablenapkin@lemmy.ca
          link
          fedilink
          English
          arrow-up
          3
          ·
          edit-2
          1 year ago

          This worked for me in Bitwarden: note since Lemmy 2FA uses SHA256 you have to copy/paste the entire link and not just the secret token. If you copy/paste just the secret token most password managers with TOTP generation have it defaulted to SHA1.