Heads up that we’ve bumped the UI up to 0.18.2-rc.1, which should resolve the current exploit that was seen on lemmy.world.

We’ve also logged out all currently logged in users as part of it, so you’ll need to login again.

  • m-p{3}@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    1 year ago

    The link starts with otpauth://, which will likely do nothing on desktop. Either click on it from a mobile device, or on desktop you can use an addon like Offline QR Code Generator (Firefox), then right-click the link and select QR code from link. This will show a QR code you’ll be able to enroll in any TOTP app. Hopefully they’ll add an option to display a QR code when using the desktop interface in newer versions of Lemmy.

    • TheMadIrishman@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 year ago

      Can I copy the link it generates and put it directly into my app that handles 2FA? (1password). Thought about trying it, but I didn’t see any recovery codes and am not keen on getting locked out.

      • durablenapkin@lemmy.ca
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        1 year ago

        This worked for me in Bitwarden: note since Lemmy 2FA uses SHA256 you have to copy/paste the entire link and not just the secret token. If you copy/paste just the secret token most password managers with TOTP generation have it defaulted to SHA1.