User Details
- User Since
- Jul 9 2019, 5:53 PM (297 w, 4 d)
- Availability
- Available
- LDAP User
- Unknown
- MediaWiki User
- ElHef [ Global Accounts ]
Dec 25 2020
Sep 19 2020
Sep 18 2020
As another issue I see with this, the shared secret stays openly viewable in my preferences after being set. It's right below the password change fields, which ask for a 2FA token (presumably as a security check). Rather defeats the purpose of asking for that if you can just grab the secret and generate a code...
Sep 17 2020
I was able to set it up in Google Authenticator without issue and it seems to be behaving. (Wouldn't let me log in with a blank or wrong code, and did let me log in with the right one.) It is somewhat confusing and fairly easy to mess up though. Agree with previous comment about documenting and communicating about the blank 2FA field when logging in. Manual entry of the shared secret seems like it would be fairly easy to accidentally brick your account, especially since I'm not seeing anywhere that it generates scratch codes.
Sep 16 2020
As would I, just say the word