Make sure you are logged in to multiple browsers before enabling 2 factor - eviltoast

We’ve had several people reach out to us who have accidentally locked themselves out of their account whilst trying to setup 2 factor authentication.

Whilst it is possible for us to disable 2fa for an account directly from the database, for privacy and security reasons, we won’t do this at the request of an external/second account.

However, all is not lost! Enabling 2fa will not log you out of existing sessions, so if you make sure you are logged in to a second browser before enabling 2fa, you will be able to disable it again if you run in to any issues.

  • load_nikon@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 year ago

    I’m getting prompted for 2fa and I never set it up! The 2fa apps I use would have this site added to their list if I had. @Ada, any suggestions?

    • Ada@lemmy.blahaj.zoneOPM
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 year ago

      Someone else said that you can do a password reset to login without 2fa. I haven’t tested it, but it’s worth trying

      • load_nikon@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Yeah, that didn’t work for me. Do you have any recommendations, as the administrator of this instance, on how a user can remediate a 2fa implementation that is failing so wildly that it requires this thread to exist? Do you have a “whoops, do over” button?

        • Ada@lemmy.blahaj.zoneOPM
          link
          fedilink
          English
          arrow-up
          4
          ·
          1 year ago

          The brutal truth is that Lemmy as a platform isn’t mature and probably wasn’t ready for the scale of growth.

          I’m trying to put out fires for an app I didn’t develop and have no input in to. I wish there was an oops button!

          What I’ll get you to do is DM me the email address of the account that’s locked. I’ll confirm the email address and then send you an email at that address