I encourage everyone, but especially mods to enable 2FA on their account. I'll do up a post tonight with screenshots on exactly how to do this, I realise the lemmy process isn't as smooth as it could be. Ideally it would present a QR code to scan with with your phone as most other sites do.
Some points from the admin of ttrpg.network in our Discord chat:
the html injection seems not to apply to 18.1 (the version we're on) [us too!], but if it does, it applies to the sidebar, posts, and comments (so a huge deal)
apparently there's some concerns around the implementation (of 2fa) at the moment....maybe i'll just shut it off for now and wait then....
This thread explains the very serious risk of Lemmy's current 2FA implementation.
Real risk of locking yourself out of your account.
Thanks. This worked. I got a little confused with points 3, 4 and 5 but now that I've re-read your instructions I see that they are clear and I have no suggestions for improving them at this time.
Hey, so i followed the guide. I think i hit all the steps, but when i try to log in on the browser to test whether its worked. The 2fa box does come up. But when i enter the code and hit login theres no progression on from that screen. Not sure where i've gone wrong? Using Aegis btw.
In the short term, use a 60 character password and never use that account interactively. ie only use it with your scripts/bot. And obviously keep the password securely stored.
That is one of the issues... if you tick the box to enable 2FA and hit save, you then need to hit F5/refresh for the '2FA Installation link' to appear.
Actually making use of the 2FA installation link is also not intuitive... as I said I'll try and post a sequence of screenshots tonight with a fresh test account to show the process.
I tried doing this but have lost access to my aussie.zone account (same user name). I checked the 2FA box but I couldn't see the extra setup steps (I think I refreshed the page), so I unchecked the box and saved. I then changed my pw. Now it seems to accept new pw but am getting incorrect 2FA token error. What do I do?
Oh bugger. Sorry, I'll need to find out how to manually toggle 2FA on your account in the database. I won't be able to do this until I get home this evening.
You are one of the best admins I've met in my coupla decades of internet usage. I love ya work mate and if you ever want a hand from a fellow sysadmin hit me up.