this post was submitted on 17 Jul 2023
135 points (100.0% liked)

Blahaj Lemmy Meta

2230 readers
2 users here now

Blåhaj Lemmy is a Lemmy instance attached to blahaj.zone. This is a group for questions or discussions relevant to either instance.

founded 2 years ago
MODERATORS
 

We've had several people reach out to us who have accidentally locked themselves out of their account whilst trying to setup 2 factor authentication.

Whilst it is possible for us to disable 2fa for an account directly from the database, for privacy and security reasons, we won't do this at the request of an external/second account.

However, all is not lost! Enabling 2fa will not log you out of existing sessions, so if you make sure you are logged in to a second browser before enabling 2fa, you will be able to disable it again if you run in to any issues.

all 19 comments
sorted by: hot top controversial new old
[–] [email protected] 30 points 1 year ago

I was surprised they didn't have backup codes or anything when I set it up so I got nervous hopefully they'll get added soon too.

[–] [email protected] 19 points 1 year ago (1 children)
[–] [email protected] 13 points 1 year ago (1 children)

At least you had access to an app and could message us from your account.

[–] [email protected] 9 points 1 year ago

Very true and also thank you!

[–] [email protected] 17 points 1 year ago

Hopefully they add recovery keys to the 2FA setup sometime soon.

[–] [email protected] 8 points 1 year ago (1 children)

oh yeah there's no confirmation for setting up 2fa right now, so make sure you got codes going before logging out

[–] load_nikon 2 points 1 year ago

That is bonkers!

[–] [email protected] 5 points 1 year ago* (last edited 1 year ago)

The 2FA is so secure even the user can't access their account. 😛

[–] load_nikon 3 points 1 year ago (1 children)

I'm getting prompted for 2fa and I never set it up! The 2fa apps I use would have this site added to their list if I had. @Ada, any suggestions?

[–] [email protected] 3 points 1 year ago (1 children)

Someone else said that you can do a password reset to login without 2fa. I haven't tested it, but it's worth trying

[–] load_nikon 1 points 1 year ago (1 children)

Yeah, that didn't work for me. Do you have any recommendations, as the administrator of this instance, on how a user can remediate a 2fa implementation that is failing so wildly that it requires this thread to exist? Do you have a "whoops, do over" button?

[–] [email protected] 4 points 1 year ago

The brutal truth is that Lemmy as a platform isn't mature and probably wasn't ready for the scale of growth.

I'm trying to put out fires for an app I didn't develop and have no input in to. I wish there was an oops button!

What I'll get you to do is DM me the email address of the account that's locked. I'll confirm the email address and then send you an email at that address

[–] [email protected] 3 points 1 year ago

I feel bad for you on this one, clearly some 2FA is better than no 2FA, but the implementation of this from the Lemmy devs leaves a lot to be desired. Ah well, they are clearly trying, and I am sure it will get better