Email or username:

Password:

Forgot your password?
Aaron Weiss

Just a friendly reminder to enable 2-factor authentication on your Mastodon account. It's under Preferences > Account > Two-factor Auth.

49 comments
Jeztastic

@aweiss errr... Where's preferences? 😳

Aaron Weiss

@jeztastic Depending on whether you're using the Advanced view or not, it's the gear up top or the gear over to the right.

taija

@aweiss thanks! Mostly using the iOS app, and it’s kind of hidden!

minicircle

@aweiss Thanks for the reminder! I set up my account yesterday and now have set up two-factor authentication.

Mia

@aweiss Does not seem to be a thing on Tusky at the moment. Is your picture from web?

Candice

@aweiss thank you!
There's gonna be quite a learning curve, I think!

Gray Rabbit

@aweiss I use the site on a web browser on my phone, and I don’t see an option to set up 2FA.

KevinCarson1

@aweiss I'd do it, if two-factor authentication didn't so frequently require text or QR code verification on the assumption that I have a smart phone.

Aaron Weiss

@KevinCarson1 Authy has a wonderful desktop interface too, FWIW

Max

@KevinCarson1 @aweiss KeePassXC supports generating TOTP codes. It's not the safest way to do it but it still improves security over not using MFA.

Josh Soref

@KevinCarson1 @aweiss for Desktop works too. There are a handful of desktop clients.

Andrew Starr :donor:

@aweiss thanks for the heads up, whilst my yubikey rego didn't work I noticed device unlock (assume using webauthn?) and it worked great!

Laura Kosloff

@aweiss thank you for the reminder, feel like I should have remembered to do that!

Matt Stine

@aweiss good reminder! Just took care of that. Thanks.

Tony Serrata 🇺🇦:verified:

@aweiss Recommend for the less technically inclined to use Authy app.

Kaetrin

@aweiss I tried to do this using 2 separate authenticator apps but both times I got an error message asking if the device time and server time are correct?
New Mastodon user here. Can you suggest any help please? 🙏

Aaron Weiss

@Kaetrin I'd check the time on your phone, but I haven't run into that one before.

Dan 🏳️‍🌈

@aweiss Are there any strong reasons to prefer one of the TOTP apps for this?

Aaron Weiss

@dan I happen to prefer Authy, but anything that syncs to the cloud should do the job. BitWarden is my password manager, and at some point I might migrate my OTPs over, but I haven't done it yet.

Simon Lucy

@aweiss isn't that an instance feature and not globally available?

JamesOliverJr

@aweiss don't see it under account preferences. Using android app.

Aaron Weiss

@adamhill Sadly not, but it works fine even without an icon

Debra Adams

@aweiss Question: What's the need to use 2-factor auth?

Aaron Weiss

@teco22222 If someone gets a hold of your password, they still can't take over your account, because you also need an ever-changing code that your phone generates.

Acey

@aweiss Always a must, for all apps! 👏

Swolfe

@aweiss can’t find this anywhere on my phone

Demetrios

@Swolfe @aweiss I can’t either. I’m too lazy rn to get my computer lol.

Aaron Weiss

@AwkwardChewbaca @Swolfe You may have to be signed in on a desktop computer to turn it on.

BwdsdwB

@Swolfe @aweiss You will have to do it via the website.

Glenn Shaw

@aweiss Took me a bit to look for the setting, but now it's done. I even saved the backup codes as a comment for my Mastodon login in LastPass.

Tracey Eva

@aweiss My mistake! Just found out that this is for people who have websites! Sorry!

Jason G. Murray

@aweiss Now if only I could use my Yubikey...

Chris Hubick

@aweiss When you get home from the lake to discover you must've left your phone on the roof of the car, once you get it replaced you'll wish your MFA was just using SMS.

Mike Little

@hubick @aweiss that's what cloud-replicating TOTP apps like Authy are for. I use it everywhere now. Two phone changes since I started using it. No issues. Recommended.

emma

@aweiss immediately did it, didn't know it was an option! Thanks for spreading awareness!

AvisHG

@aweiss sorry to be dim… but how do I get to preferences?

(Newbie, be gentle)

LZVolk

@aweiss I’m not sure the apps offer access to that function. Mastodon app does not.

Molly Cantrell-Kraig ✅

@aweiss I keep getting error codes, even though I’m literally cutting and pasting the plain text (using the QR code sends me to my iPhone account settings, but the Mastodon app isn’t linked). Since I’m a verified Twitter user, I really appreciate the 2FA feature (I’ve literally had stalkers show up at my house and my acct hacked). Not sure what I’m doing wrong, but am open to learning. Thanks!

Go Up