-8

How could 2FA be disabled if you need 2FA in order to login to disable it and my free OTP+ is biometric protected?

top 12 comments
sorted by: hot top controversial new old
[-] vk6flab@lemmy.radio 12 points 3 months ago

Ask your instance administrator.

[-] MrKaplan@lemmy.world 9 points 3 months ago

This was unfortunately an error on our end.

Please bear with us while we work on resolving this situation.

[-] MrKaplan@lemmy.world 3 points 3 months ago* (last edited 3 months ago)

2FA has been restored for all LW users that had it enabled before and didn't reactivate it on their own since.

There will be an announcement posted later on explaining what happened.

edit: announcement is out: https://lemmy.world/post/18503967

[-] scrubbles@poptalk.scrubbles.tech 4 points 3 months ago

ITT OP learns that 2FA is just a token stored on a server, and that server is in control by other people

[-] lightscription@lemmy.world 1 points 3 months ago

This is what I thought. I keep telling people they don't exclusively own their passwords / security tokens once they give it to a site. Salted hashes to obscure the pw don't even matter since the admin could also bypass that. Tanks for the validation.

[-] undefined@links.hackliberty.org 3 points 3 months ago

And you better pray the website owner (websites in general, not Lemmy specifically) at least hashes your password.

[-] lightscription@lemmy.world 2 points 3 months ago

yes, the more layers of security, the better, even if it is just a futile matter of time to consume the time of an ATP.

[-] conciselyverbose@sh.itjust.works 2 points 3 months ago

The server owner has complete control of your account.

They could very easily take control completely if they want.

[-] lightscription@lemmy.world 2 points 3 months ago

This is what I thought. I keep telling people they don't exclusively own their passwords / security tokens once they give it to a site.

If I shared encrypted info that I kept encrypted, I guess it would still be mine but no one could then read it.

[-] Dark_Arc@social.packetloss.gg 2 points 3 months ago* (last edited 3 months ago)

Going to need a lot more context than that.

I'm sure site admins could just clear the 2FA field if they wanted. Would they? IDK, probably not unless they had good reason.

Could someone steal your session information and disable your 2FA with that? Yeah, but I doubt they did, you'd have to have your system compromised or some kind of cross site scripting.

Did you use any shady lemmy clients?

etc

[-] lightscription@lemmy.world 1 points 3 months ago

No, nothing shady. Just was notified there was a mistake on the server end. Perhaps tmi to elaborate...

[-] Asudox@lemmy.world 1 points 3 months ago

Locking as this question violates rule 5.

this post was submitted on 09 Aug 2024
-8 points (33.3% liked)

Ask Lemmy

27043 readers
304 users here now

A Fediverse community for open-ended, thought provoking questions

Please don't post about US Politics. If you need to do this, try !politicaldiscussion@lemmy.world


Rules: (interactive)


1) Be nice and; have funDoxxing, trolling, sealioning, racism, and toxicity are not welcomed in AskLemmy. Remember what your mother said: if you can't say something nice, don't say anything at all. In addition, the site-wide Lemmy.world terms of service also apply here. Please familiarize yourself with them


2) All posts must end with a '?'This is sort of like Jeopardy. Please phrase all post titles in the form of a proper question ending with ?


3) No spamPlease do not flood the community with nonsense. Actual suspected spammers will be banned on site. No astroturfing.


4) NSFW is okay, within reasonJust remember to tag posts with either a content warning or a [NSFW] tag. Overtly sexual posts are not allowed, please direct them to either !asklemmyafterdark@lemmy.world or !asklemmynsfw@lemmynsfw.com. NSFW comments should be restricted to posts tagged [NSFW].


5) This is not a support community.
It is not a place for 'how do I?', type questions. If you have any questions regarding the site itself or would like to report a community, please direct them to Lemmy.world Support or email info@lemmy.world. For other questions check our partnered communities list, or use the search function.


Reminder: The terms of service apply here too.

Partnered Communities:

Tech Support

No Stupid Questions

You Should Know

Reddit

Jokes

Ask Ouija


Logo design credit goes to: tubbadu


founded 1 year ago
MODERATORS