Hi. I was trying to set up 2FA in my settings, where there is a button named “2FA installation link.” I right clicked on the button, copied the link, and put it into a QR code generator. I scanned it with Twilio Authy on my phone to add it. To my surprise, when I tried using it to log in, the generated codes simply do not work. I have 20ish entries on Authy and they all work, with the Lemmy accounts being the outliers. I have also tested the 2FA on my other account at feddit.nl, and it doesn’t work with Authy either.

So, I tried using Google Authenticator instead. I used it to scan the very same QR code, and it spits out different codes from those generated by Authy. The ones generated by GAuthenticator work, whereas the Authy ones don’t work. I wonder what the issue is?

Edit: grammar

  • Blaze
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    11 months ago

    2FA does not completely work at the moment

    • randint@lemm.eeOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      11 months ago

      Ah, ok. Thanks!

      Edit: I just read the comment by @gnzl@nc.gnzl.cl, and apparently the root cause is that Authy uses SHA1 despite the link clearly specifying SHA256. Now I wonder what you mean by 2FA doesn’t completely work yet?

      • Blaze
        link
        fedilink
        English
        arrow-up
        3
        ·
        11 months ago

        There has been issues on the GitHub about that, AFAIK it’s still a bit buggy

        • KᑌᔕᕼIᗩ@lemmy.ml
          link
          fedilink
          English
          arrow-up
          1
          ·
          11 months ago

          I tried setting it up and almost completely lost access to my account. Sadly I’m going to wait until its properly sorted.

          • Blaze
            link
            fedilink
            English
            arrow-up
            1
            ·
            11 months ago

            Sorry to hear that. Maybe you can try contacting your instance admins?