I was getting invalid codes all of a sudden. I had to use a backup code to log in. And then I tried disabling 2-factor and re-enabling it. But I could not re-enable it, because the 2-factor code would not work for the string of characters it provided me (I do not scan QR codes).
Is this issue just on my end?
1 Like
Whats your VM/OS that you have your TOTP on? Whonix or KS based?
1 Like
KeePassXC in ZorinOS 18.1 host
1 Like
Very likely related:
Whonix workstation-based app qubes are now showing a consistent ~2-minute time difference compared to other qubes (including the offline Vault). This breaks 2FA (TOTP) on accounts accessed through Whonix.
The clock qube is set to sys-net, which is based on the Kicksecure template.
The offline Vault/KeepassXC is used for 2FA and is set to UTC.
This has been my setup for a long time, but it has only recently started causing problems.
Any solution?
This thread might be merged with the thread linked above if it is determined that the same root cause is behind both issues.
Edit: Looks like I was wrong, see discussion below.
1 Like
Can you check now, i got locked out as well, but now i was able to login.
I find it unlikely that the issue arraybolt listed is the same issue. My host and the whonix guest are never more than 0-2 seconds apart in time.
Today I tried logging into other accounts with 2FA in whonix. They worked.
Today I also tried adding 2FA again to whonix forums. This was successful today. So the issue is apparently resolved, for now?
I have backup codes saved, in case it happens again.
2 Likes