I previously asked on AskMbin@thebrainbin.org on how to migrate my account to a different instance as I got a error saying “email not verified” after completing my email verification (original post here: https://kbin.earth/m/AskMbin@thebrainbin.org/t/1532246). This made question the security of kbin.earth. And now, I can’t enable 2FA! It says “Error enabling 2FA for account”! Seriously what the hell is going on in kbin.earth? To the developer of Interstellar- You shouldn’t have made kbin.earth the default instance when signing up from the Interstellar app if your instance has some serious security issues! I need answers NOW!

  • jwr1@kbin.earthM
    link
    fedilink
    arrow-up
    3
    ·
    8 hours ago

    Hello @BubblyRomeo! It is true, like @green_copper said, I have a life outside of Mbin, but I have now seen your comments (please try to keep a nicer tone though). I’ll try to help you where I can.

    Interstellar uses kbin.earth as the default instance, mainly because they were both created by me. But you are most certainly not forced to use kbin.earth with Interstellar, you can add/switch to any Mbin, Lemmy, or PieFed account by going to the settings. And once you have added a different account (and switched to it), you can even remove the default guest kbin.earth account from the app.

    As for your kbin.earth issues, are you saying anytime you try to log in, you get an “email not verified” message? I’m actually surprised that’s happening just because usually if an account on Mbin is not email verified yet, then it wouldn’t even let you make comments or posts yet. And for the 2FA problem, I’m not really sure what the issue is there, I tested it just now and was able to enable 2FA on my own account just fine; is it possible your phone’s (or whatever device you have the 2FA app on) clock is slightly off? Which could definitely cause issues for TOTP based 2FA.

    You shouldn’t have made kbin.earth the default instance when signing up from the Interstellar app if your instance has some serious security issues!

    kbin.earth is just an Mbin instance. The only thing I’ve really customized is the kbin.earth branding. If you think kbin.earth has security issues, then you probably shouldn’t use Mbin at all. That said, if you’d like to migrate to a different Mbin instance, Mbin doesn’t really have a good way to do that. If you have tons of magazine or user subscriptions, then you could try using Interstellar’s account transfer feature, but otherwise, you’ll just have to manually copy over your settings to your new account.

    • green_copper@kbin.earth
      link
      fedilink
      arrow-up
      1
      ·
      47 minutes ago

      Regarding 2FA maybe it was a hiccup. What would interest me: is there a statistic about how many (active) users have 2FA enabled?

    • BubblyRomeo@kbin.earthOP
      link
      fedilink
      arrow-up
      1
      ·
      7 hours ago

      As for your kbin.earth issues, are you saying anytime you try to log in, you get an “email not verified” message?

      I got “email not verified” error right after I completed my email verification when I signed up on kbin.earth. Not every time I login. I’ve described it in detail in my original post here-https://kbin.earth/index.php/m/AskMbin@thebrainbin.org/t/1532246 . And yes, you are correct I wouldn’t be able to reply or post if my account was really not email verified. But I am able to, so this might be due to some technical error in the code which is executed when the user signs up.

      @jwr1

      • jwr1@kbin.earthM
        link
        fedilink
        arrow-up
        1
        ·
        7 hours ago

        Honestly, I wouldn’t worry about it. It’s likely just a technical issue, like bentigorlich mentioned in your other thread. I’d say as long as you’re able to access your account, then you’re good to go on that aspect. My only guess as to why the message popped up is due to some sort of delay in the system after you actually verified your account through your email.

      • BubblyRomeo@kbin.earthOP
        link
        fedilink
        arrow-up
        1
        ·
        7 hours ago

        is it possible your phone’s (or whatever device you have the 2FA app on) clock is slightly off? Which could definitely cause issues for TOTP based 2FA.

        I used Ente auth on Android phone running Android 13. And I checked my clock is synced correctly.

        If you think kbin.earth has security issues, then you probably shouldn’t use Mbin at all. That said, if you’d like to migrate to a different Mbin instance, Mbin doesn’t really have a good way to do that. If you have tons of magazine or user subscriptions, then you could try using Interstellar’s account transfer feature

        Not just this sentence but your whole reply is slightly passive aggressive and you’re asking ME to keep a nicer tone? Haha! I pointed 2 crucial errors both of which are related to account security - one error when the user onboards on the server and the other one when the user tries to secure their account through 2FA. And the reply you gave to both of these are “I’m actually surprised that’s happening” and “I’m not really sure what the issue is there”. You can’t seem to pinpoint on how a specific error pops up and have the audacity to ask other users to “keep a nicer tone” when the user was just pinpointing errors in your instance! And, when did I even have a harsher tone? Is it from the “Seriously what the hell is going on in kbin.earth” from my title? If so, you’re very prudish and shouldn’t be browsing the internet. And you have no right to tell me not to use Mbin at all! I’ll try the account transfer feature in your app or better yet, create my own instance and Android app for Mbin! Try being less of a snowflake and try to accept criticisms for your creations next time. And, if you have time, think about going back to college because you lack CS basics if you can’t pinpoint 2 errors.

        @jwr1

        • jwr1@kbin.earthM
          link
          fedilink
          arrow-up
          3
          ·
          6 hours ago

          Not just this sentence but your whole reply is slightly passive aggressive and you’re asking ME to keep a nicer tone?

          I am very sorry that I came across that way, I was certainly not trying to sound passive aggressive.

          And the reply you gave to both of these are “I’m actually surprised that’s happening” and “I’m not really sure what the issue is there”.

          I only mentioned I was surprised about it just because I’ve never had any other users report the error to me, that’s all. I also haven’t encountered either of the two issues myself.

          You can’t seem to pinpoint on how a specific error pops up

          That is true. I run this Mbin instance, but I’m not necessarily an Mbin dev, so I wouldn’t say I know the ins and outs of everything.

          And you have no right to tell me not to use Mbin

          That wasn’t what I was trying to say. I was just suggesting that maybe it’s not for you, but of course, you can use whatever you want.

  • BubblyRomeo@kbin.earthOP
    link
    fedilink
    arrow-up
    1
    ·
    13 hours ago

    No comment from the admin of kbin.earth even after 13 hours of posting! This doesn’t inspire much confidence in you or your instance or your app @jwr1 !

    • green_copper@kbin.earth
      link
      fedilink
      arrow-up
      3
      ·
      11 hours ago

      They are a single person who also have a life outside of Mbin. 13 hours is not much (customer support of some paid products take longer).
      I know that broken 2FA is not nice but also not the end of the world. So maybe try calm down and also start be a tick more polite with your requests.