this post was submitted on 13 Jan 2022
5 points (85.7% liked)
Lemmy Support
4713 readers
35 users here now
Support / questions about Lemmy.
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
yes please!
Only problem is admins have to have a way of "resetting" 2FA when users inevitably loose their phone =/
Why would it be the responsibility of the admins if users don't have proper backups? Wouldn't the ability to reset 2FA completely negate the advantages of it if the admins can be subject to a phishing attack that removes 2FA from someones account?
most people are stupid, so most people will lose 2fa, so most people on your instance will be locked out.
You can not like this, but its what will happen if you allow 2fa without having any recovery methodology =/
that's not how it works. It's not the admin's job to fix your password stupid.