this post was submitted on 10 Jul 2023
23 points (100.0% liked)

Meta

707 readers
1 users here now

Discussion about the aussie.zone instance itself

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 11 points 2 years ago* (last edited 2 years ago) (29 children)

I encourage everyone, but especially mods to enable 2FA on their account. I'll do up a post tonight with screenshots on exactly how to do this, I realise the lemmy process isn't as smooth as it could be. Ideally it would present a QR code to scan with with your phone as most other sites do.

[–] [email protected] 6 points 2 years ago (9 children)

Some points from the admin of ttrpg.network in our Discord chat:

  • the html injection seems not to apply to 18.1 (the version we're on) [us too!], but if it does, it applies to the sidebar, posts, and comments (so a huge deal)
  • apparently there's some concerns around the implementation (of 2fa) at the moment....maybe i'll just shut it off for now and wait then....

This thread explains the very serious risk of Lemmy's current 2FA implementation.

Real risk of locking yourself out of your account.

[–] [email protected] 4 points 2 years ago (1 children)

Real risk of locking yourself out of your account.

yes, the initial setup is not intuitive at all. Once setup it functions normally.

[–] [email protected] 3 points 2 years ago (2 children)

Thanks. I'm going to wait for your guide. What do you advise we do with bot accounts?

[–] [email protected] 4 points 2 years ago (2 children)
[–] [email protected] 3 points 2 years ago

Thanks. This worked. I got a little confused with points 3, 4 and 5 but now that I've re-read your instructions I see that they are clear and I have no suggestions for improving them at this time.

[–] [email protected] 2 points 2 years ago (1 children)

Hey, so i followed the guide. I think i hit all the steps, but when i try to log in on the browser to test whether its worked. The 2fa box does come up. But when i enter the code and hit login theres no progression on from that screen. Not sure where i've gone wrong? Using Aegis btw.

[–] [email protected] 2 points 2 years ago (1 children)

Hmm you may need to disable 2FA again. I'm not sure why it wouldn't work, perhaps Aegis hasn't imported it correctly?

[–] [email protected] 2 points 2 years ago

Okay cool, it just worked. No idea what difference waiting overnight made though.

[–] [email protected] 3 points 2 years ago

In the short term, use a 60 character password and never use that account interactively. ie only use it with your scripts/bot. And obviously keep the password securely stored.

load more comments (7 replies)
load more comments (26 replies)