2FA "change device" does not work | Bugs & Issues | …
2FA "change device" does not work
  • |X| SuicideTree [2131931]SuicideTree [2131931]
    • SuicideTree [2131931]
    • Role: Civilian
    • Level: 90
    • Posts: 112
    • Karma: 24
    • Last Action: 2 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Thread created on 07:51:15 - 30/08/21 (1 month ago)
    |
    Last replied 08:07:18 - 30/09/21 (15 days ago)
    2FA login is not working after switching device with "change device" option.

    I've recently changed my device and the option to "change device" for 2FA is not really working. Three times I burned two of my login attempts on wrong codes, that's a total of 6 wrong codes. Every time I had to login with the code provided via email.

    The point is that to make it *take*, I had to remove 2FA altogether and then add my new device.

    So once again, the "change device" does nothing at all. You are seemingly left with 2FA on, because the code generated by the new authenticator is accepted in torn settings. However it is not registered/paired correctly and I am not able to log in with it right after. I cannot say if the old authenticator would still work in this case as that has been removed already before the switch.

    This happened around 08/25. On the day or before it.

    What's going on an whose fault is it?
  • NS CloudJumper [1636201]CloudJumper [1636201]
    • CloudJumper [1636201]
    • Role: Officer
    • Level: 100
    • Posts: 14329
    • Karma: 13216
    • Last Action: 7 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 08:32:30 - 30/08/21 (1 month ago)
    Post link copied to clipboard Copy post link
    I am unsure who the correct developer for this would be. Passing along to Joe for re-assignment.

    Thanks!

  • Ðé Chedburn [1]Chedburn [1]
    • Chedburn [1]
    • Role: Admin
    • Level: 15
    • Posts: 24862
    • Karma: 42259
    • Last Action: 9 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 08:58:12 - 30/08/21 (1 month ago)
    Post link copied to clipboard Copy post link
    By the sounds of it, all sounds fine here?

    You're right that we don't have a confirmation process once a 2FA device has been added, we just assume all's fine. If a mistake was made, can't you login with the email code and change it again?
  • |X| SuicideTree [2131931]SuicideTree [2131931]
    • SuicideTree [2131931]
    • Role: Civilian
    • Level: 90
    • Posts: 112
    • Karma: 24
    • Last Action: 2 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 09:15:06 - 30/08/21 (1 month ago)
    Post link copied to clipboard Copy post link
    I can, but presumably a feature that is broken or does not work all the time or in a predictable manner, most likely should not be present at all?

    Leaving it as is, crossing your fingers and hoping for the best does not seem like a good practice.

    If the correct or 100% foolproof way to change your 2FA is to remove it completely and add it from scratch, I would suggest removing the option to "change" it altogether.

    I am no genius, but someone less savvy, who is unable to login, might not return to the game at all, especially if they locked themselves out of their account and the procedure to get back in (emails, verification or whatnot; I do not know what are the steps after 3 failed 2FA codes have been used) is too annoying or long.

    That is a risk, as tiny as it may be.

    Current state is imo not acceptable and confusing/misleading.
  • Ðé Chedburn [1]Chedburn [1]
    • Chedburn [1]
    • Role: Admin
    • Level: 15
    • Posts: 24862
    • Karma: 42259
    • Last Action: 9 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 09:20:52 - 30/08/21 (1 month ago)
    Post link copied to clipboard Copy post link
    I've just tested the system and it all appears to be working fine, I wonder if you missed the "NEXT" button below the QR code? Please try again, or maybe I'm misunderstanding something.
  • |X| SuicideTree [2131931]SuicideTree [2131931]
    • SuicideTree [2131931]
    • Role: Civilian
    • Level: 90
    • Posts: 112
    • Karma: 24
    • Last Action: 2 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 10:13:07 - 30/08/21 (1 month ago)
    Post link copied to clipboard Copy post link
    I missed the next button...? Okay. Lets assume I did.

    The steps:

    Change
    Scan the QR
    Next button
    Enter code
    Verify button

    Then I log out and try to login with the new authenticator, all codes fail when I do it this way.

    I have to remove 2FA completely and add it back in as if I had no 2FA to begin with if I want it to work properly.

    I do not know if I can make it any clearer. Which Next button did I miss again?
    Last edited by SuicideTree on 10:15:31 - 30/08/21
  • Ðé Chedburn [1]Chedburn [1]
    • Chedburn [1]
    • Role: Admin
    • Level: 15
    • Posts: 24862
    • Karma: 42259
    • Last Action: 9 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 16:27:07 - 30/08/21 (1 month ago)
    Post link copied to clipboard Copy post link

    SuicideTree [2131931]

    I missed the next button...? Okay. Lets assume I did.

    The steps:

    Change
    Scan the QR
    Next button
    Enter code
    Verify button

    Then I log out and try to login with the new authenticator, all codes fail when I do it this way.

    I have to remove 2FA completely and add it back in as if I had no 2FA to begin with if I want it to work properly.

    I do not know if I can make it any clearer. Which Next button did I miss again?
    Have you tried it again? I followed the exact process but it worked fine for me. I had no failures.
  • |X| SuicideTree [2131931]SuicideTree [2131931]
    • SuicideTree [2131931]
    • Role: Civilian
    • Level: 90
    • Posts: 112
    • Karma: 24
    • Last Action: 2 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 18:30:19 - 30/08/21 (1 month ago)
    Post link copied to clipboard Copy post link
    Just changed the authenticator twice successfully. So at the moment I cannot reproduce it either. However there should clearly be six failed attempts in the logs around 08/25. I am not doing anything differently now, if you cant see anything wrong on your end - close this.
    Last edited by SuicideTree on 10:39:34 - 31/08/21
  • Ðé Chedburn [1]Chedburn [1]
    • Chedburn [1]
    • Role: Admin
    • Level: 15
    • Posts: 24862
    • Karma: 42259
    • Last Action: 9 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 10:38:14 - 31/08/21 (1 month ago)
    Post link copied to clipboard Copy post link
    If you notice it again, please create a new report. I know there's just under 8,000 people using the authenticator 2FA currently, and this is the first I've heard of this problem. Let's see if anyone else mentions it in the future.
  • PT Crudak [2224763]Crudak [2224763]
    • Crudak [2224763]
    • Role: Civilian
    • Level: 75
    • Posts: 377
    • Karma: 240
    • Last Action: Now
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 23:17:37 - 14/09/21 (1 month ago)
    Post link copied to clipboard Copy post link
    Hi @chedburn

    I have noticed this issue. Android 10 , switched from Google Authenticator to Authy. I have paired through the settings with Authy and when I try to login in a new browser using the code from Authy, I get an incorrect message.

    I have reseted to Authy twice and still same issue.

                

  • NS CloudJumper [1636201]CloudJumper [1636201]
    • CloudJumper [1636201]
    • Role: Officer
    • Level: 100
    • Posts: 14329
    • Karma: 13216
    • Last Action: 7 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 05:00:26 - 15/09/21 (1 month ago)
    Post link copied to clipboard Copy post link
    Re-confirming.

  • Ðé Chedburn [1]Chedburn [1]
    • Chedburn [1]
    • Role: Admin
    • Level: 15
    • Posts: 24862
    • Karma: 42259
    • Last Action: 9 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 11:39:17 - 16/09/21 (29 days ago)
    Post link copied to clipboard Copy post link

    Crudak [2224763]

    Hi @chedburn

    I have noticed this issue. Android 10 , switched from Google Authenticator to Authy. I have paired through the settings with Authy and when I try to login in a new browser using the code from Authy, I get an incorrect message.

    I have reseted to Authy twice and still same issue.
    So you fully setup the 2FA on authy, but now when you login, the code supplied is not being accepted?

    Can you completely remove it and set it up again please, to ensure it was not a mistake on your end?
  • Ðé Chedburn [1]Chedburn [1]
    • Chedburn [1]
    • Role: Admin
    • Level: 15
    • Posts: 24862
    • Karma: 42259
    • Last Action: 9 hours
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 10:16:33 - 17/09/21 (28 days ago)
    Post link copied to clipboard Copy post link
    I'll pass this to Nikita, maybe he might be able to find some kind of issue here. Then we can ask Serhii for his advice perhaps.
  • nikitad [2147691]nikitad [2147691]
    • nikitad [2147691]
    • Role: Tester
    • Level: 77
    • Posts: 2249
    • Karma: 658
    • Last Action: 1 day
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 15:38:26 - 17/09/21 (28 days ago)
    Post link copied to clipboard Copy post link
    Hello
    Seems to be, I've replicated the issue
    I just removed all authenticator devices and re-create a new one
    Passing up to Serhii
    Thanks
  • PT Crudak [2224763]Crudak [2224763]
    • Crudak [2224763]
    • Role: Civilian
    • Level: 75
    • Posts: 377
    • Karma: 240
    • Last Action: Now
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 10:55:37 - 20/09/21 (25 days ago)
    Post link copied to clipboard Copy post link
    Hi, I have, for the 3rd time, rechanged the authenticator. This time it works. (I did the change 2-3 days ago tho)

                

  • PT Crudak [2224763]Crudak [2224763]
    • Crudak [2224763]
    • Role: Civilian
    • Level: 75
    • Posts: 377
    • Karma: 240
    • Last Action: Now
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 10:56:54 - 20/09/21 (25 days ago)
    Post link copied to clipboard Copy post link

    Crudak [2224763]

    Hi @chedburn

    I have noticed this issue. Android 10 , switched from Google Authenticator to Authy. I have paired through the settings with Authy and when I try to login in a new browser using the code from Authy, I get an incorrect message.

    I have reseted to Authy twice and still same issue.

    Chedburn [1]

    So you fully setup the 2FA on authy, but now when you login, the code supplied is not being accepted?

    Can you completely remove it and set it up again please, to ensure it was not a mistake on your end?
    Could not be a mistake on my end since I only have to take a picture of the QR code using Authy, theres no way to mess that up.

                

  • PT Crudak [2224763]Crudak [2224763]
    • Crudak [2224763]
    • Role: Civilian
    • Level: 75
    • Posts: 377
    • Karma: 240
    • Last Action: Now
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 15:56:38 - 28/09/21 (17 days ago)
    Post link copied to clipboard Copy post link
    Hi, this is happening again. The code provided by my authenticator is not valid, after 3 tries.

                

  • serhiid [2307949]serhiid [2307949]
    • serhiid [2307949]
    • Role: Admin
    • Level: 17
    • Posts: 62
    • Karma: 16
    • Last Action: 2 days
    • Quote
    • Report
      • 0
    • Reason:
      Are you sure you want to report this post to staff?
      Cancel
    Posted on 08:07:18 - 30/09/21 (15 days ago)
    Post link copied to clipboard Copy post link
    Hello
    It seems the issue is related to unsynchronized time in the authentification app. Please follow the instructions in the error message (https://i.imgur.com/kSNlF8n.png). After that, the issue should go.
    Thanks!

    1

Reply
Thread Title: