No, no, make it ultra secure and display none it, every website will be a database of important information, you just have to put everything into a hidden table!!
No point sending the code to your phone when it's displayed right there. The idea of doing this is making sure nobody has stolen your password, because they still need access to your phone before they can access your account.
I'll be homest with you, some people really struggle with email 2fa. The amount of working Americans I have spoken with who don't understand how to have two tabs open at once is genuinely frightening.
Even with autofilling it on iOS, macOS you still have developers that need to fuck with form fields using JavaScript because they think they’re smarter than you.
App based 2FA is better. Either the app generates a time based code that you enter into the site or the site sends a push notification to the app asking you to verify the login attempt.
Passkeys are good too as they replace the password completely and leave the 2FA part to the device.
If it's alright with your threat model, you can put the time-based OTPs into your password manager of choice, like Bitwarden. Upon filling your username and password, it places your OTP in your clipboard, so that you can simply paste it in. This does of course reduce the security of the system slightly, since you centralize your passwords and your OTPs. When opting for this method, it is therefore imperative to protect your password manager even more, like via setting up 2FA for the password manager itself or making sure your account gets locked after something like 10 minutes of inactivity. The usability aspect is improved by using a yubikey or another similar physical key technology.
Well, they're not a bad thing per se, it's just important to remember that by doing that you are essentially delegating the access security (including any means of MFA) from the target website to the password manager. I.e., instead of inputting password and 2FA code for example.com, you have to input your password and 2FA code for the password manager itself. This has the same security guarantees, so long as you don't set your vault to—for example—never lock automatically.
For the case of passkeys, using Bitwarden, even with 2FA does reduce the security level in my eyes somewhat, since I'd argue passkeys to be a more secure measure than password + OTP. Unless, of course, you use a different passkey to authenticate yourself to Bitwarden.
TLDR; be careful about putting everything inside Bitwarden. You'll be fine if you make sure to protect your password manager adequately, but if you put OTP secrets (or passkeys) for other website inside Bitwarden AND only use password authentication for Bitwarden without any MFA, then you are effectively reducing your MFA back to a single factor (the Bitwarden password).
I'm afraid user authentication on the internet is broken beyond salvation. It's already complex enough to grasp fully for tech-savvy people, meanwhile we've taught the general population to use password123 for all their accounts and write it on a post-it for a good measure.
I wonder if there are any TOTP apps for Linux phones (though I think I'll have to keep an Android or Apple device around for my workplace's 2FA which doesn't have anything for anything other than apple and Android phones, and only with full security)
Yes. The original post that coined the term was using "vibe coding" to indicate how problematic it is to build software by generating code based on vague prompts.
But a lot of people didn't read the entire post and just thought the term sounded cool and used it as if it was positive thing.
Now we're seeing the negative impacts of vibe coding, just as the original post predicted. So it started as derogatory, somehow became something positive, but it's going back to being derogatory again.
Nah, it's still a thing unfortunately. There will have to be a bunch of business go bankrupt because of it before managers start to think it's a bad idea.
Agreed, they're getting off light. I've worked with people who felt the code, but werent always able to communicate their ideas. I'd say theyd fit the idea of vibe coding without ai.
The concept is taken, and doesn't describe the intent well. How about "pseudocoders".
O saved the ass of the company I worked for at software QA multiple times 🤭
Most of the time, it was just miscommunication between decision makers and devs and I had to explain to both why it is not working how it is now and that none of them is clearly to blame for the situation.
I still work for that company, but manage IT infrastructure now, but I am confident that my successor will still do good job, than unlike me, he has a proper education in programming, 😂 I was literally in vibe code state
I feel like I saw this or the same thing on a different screenshot before AI, I'm not sure whether it's deliberately crafted bad security thing or legit bad from the wild
What QA? They were all fired over the pandemic and "replaced" with "ai".
The zero to three people doing all the qa tasks for the 10 to Infinity developers before that never really got a chance to test anything beyond the basic "if this breaks were fucked" stuff anyway though, so it's not like quality was ever a priority for the people in charge sucking up all the money.
79 Comments
scrubbles@poptalk.scrubbles.tech · 220 pts · 324d
You're absolutely right! It doesn't make sense to show the user the 2fa code! removes 2fa completely
Uli@sopuli.xyz · 150 pts · 324d
Oh, I get it! You still want 2fa, you just don't want the code to be shown! colors the text white
ThePancakeExperiment@feddit.org · 38 pts · 324d
No, no, make it ultra secure and display none it, every website will be a database of important information, you just have to put everything into a hidden table!!
PattyMcB@lemmy.world · 20 pts · 324d
Font size 0
Schmoo@slrpnk.net · 5 pts · 324d
*Includes it in the URL
Redjard@lemmy.dbzer0.com · 17 pts · 324d
Oh you want the code not rendered into html!
Drops the code in javascript when it is received from the backend.
kamen@lemmy.world · 1 pts · 324d
Imagine breaking someone's scraper with that change.
pure_bliss@discuss.tchncs.de · 13 pts · 324d
aberrate_junior_beatnik@midwest.social · 112 pts · 324d
It took me way too long to figure out what was wrong with this screenshot
Ilovethebomb@sh.itjust.works · 56 pts · 324d
Yeah, same here. I was counting the boxes thinking they'd got the wrong amount of numbers.
shalafi@lemmy.world · 13 pts · 324d
I counted the boxes 3 times. :(
Darkmuch@lemmy.world · 9 pts · 324d
I need help. I don’t get it…
teegus@sh.itjust.works · 27 pts · 324d
The "secret" code sent to your phone is spelled out in the text
moriquende@lemmy.world · 5 pts · 324d
No point sending the code to your phone when it's displayed right there. The idea of doing this is making sure nobody has stolen your password, because they still need access to your phone before they can access your account.
8000gnat@reddthat.com · 82 pts · 324d
no factor authentication
undefined@lemmy.hogru.ch · 80 pts · 324d
SMS/email-based 2FA should die.
ColdSideOfYourPillow@anarchist.nexus · 54 pts · 324d
Luckily, you don't even need to check SMS or input a valid number with the “verification” in the screenshot!
bamboo@lemmy.blahaj.zone · 31 pts · 324d
mission failed successfully
nogooduser@lemmy.world · 14 pts · 324d
It’s better than nothing and some people would really struggle to do other types of 2FA.
djsoren19@lemmy.blahaj.zone · 8 pts · 324d
I'll be homest with you, some people really struggle with email 2fa. The amount of working Americans I have spoken with who don't understand how to have two tabs open at once is genuinely frightening.
Natanael@infosec.pub · 6 pts · 324d
As a reset method it's worse than having nothing
null@lemmy.nullspace.lol · 5 pts · 324d
It's wild how standard SMS is given how (relatively) trivial it is to exploit.
undefined@lemmy.hogru.ch · 1 pts · 324d
Even with autofilling it on iOS, macOS you still have developers that need to fuck with form fields using JavaScript because they think they’re smarter than you.
dharmacurious@slrpnk.net · 3 pts · 324d
What's the best alternative?
nogooduser@lemmy.world · 13 pts · 324d
App based 2FA is better. Either the app generates a time based code that you enter into the site or the site sends a push notification to the app asking you to verify the login attempt.
Passkeys are good too as they replace the password completely and leave the 2FA part to the device.
victorz@lemmy.world · 6 pts · 324d
Passkey or notification please. So sick of entering these codes on a daily basis.
Opisek@piefed.blahaj.zone · 4 pts · 324d
If it's alright with your threat model, you can put the time-based OTPs into your password manager of choice, like Bitwarden. Upon filling your username and password, it places your OTP in your clipboard, so that you can simply paste it in. This does of course reduce the security of the system slightly, since you centralize your passwords and your OTPs. When opting for this method, it is therefore imperative to protect your password manager even more, like via setting up 2FA for the password manager itself or making sure your account gets locked after something like 10 minutes of inactivity. The usability aspect is improved by using a yubikey or another similar physical key technology.
victorz@lemmy.world · 2 pts · 324d
Very good point. I have Bitwarden set up as a passkey for at least one account. I should remove that. 👍
Opisek@piefed.blahaj.zone · 2 pts · 324d
Well, they're not a bad thing per se, it's just important to remember that by doing that you are essentially delegating the access security (including any means of MFA) from the target website to the password manager. I.e., instead of inputting password and 2FA code for example.com, you have to input your password and 2FA code for the password manager itself. This has the same security guarantees, so long as you don't set your vault to—for example—never lock automatically.
For the case of passkeys, using Bitwarden, even with 2FA does reduce the security level in my eyes somewhat, since I'd argue passkeys to be a more secure measure than password + OTP. Unless, of course, you use a different passkey to authenticate yourself to Bitwarden.
TLDR; be careful about putting everything inside Bitwarden. You'll be fine if you make sure to protect your password manager adequately, but if you put OTP secrets (or passkeys) for other website inside Bitwarden AND only use password authentication for Bitwarden without any MFA, then you are effectively reducing your MFA back to a single factor (the Bitwarden password).
I'm afraid user authentication on the internet is broken beyond salvation. It's already complex enough to grasp fully for tech-savvy people, meanwhile we've taught the general population to use password123 for all their accounts and write it on a post-it for a good measure.
RaivoKulli@sopuli.xyz · 1 pts · 324d
I just save the cookies tbh
victorz@lemmy.world · 1 pts · 323d
Aren't cookies invalidated after a while anyway? Doesn't seem viable to me.
RaivoKulli@sopuli.xyz · 1 pts · 323d
After some time, yeah. Depends on the site.
victorz@lemmy.world · 1 pts · 323d
And the browser saves those cookies for you, right? Throws them out when they expire.
psud@aussie.zone · 2 pts · 322d
I wonder if there are any TOTP apps for Linux phones (though I think I'll have to keep an Android or Apple device around for my workplace's 2FA which doesn't have anything for anything other than apple and Android phones, and only with full security)
djsoren19@lemmy.blahaj.zone · 0 pts · 324d
Okay, but then you have to develop an app
nogooduser@lemmy.world · 4 pts · 324d
You don’t for the one time codes because there is a standard that is supported by many authenticator apps.
PlexSheep@infosec.pub · 1 pts · 324d
TOTP, FIDO2 or not worrying about logins and just using {GitHub,Google,Microsoft,selfhosted.lan} as identity provider with OIDC
aarRJaay@lemmy.world · 54 pts · 324d
That's up there with: "You cannot use this password, it's already in use by ... "
SethTaylor@lemmy.world · 11 pts · 324d
But that's so practical. Maybe I can contact them and ask them if we can swap. Haha
Sam_Bass@lemmy.world · 44 pts · 324d
They were called scriptkiddies back in the day
_stranger_@lemmy.world · 20 pts · 324d
Has the general discourse settled on a proper epithet for this new version?
"vibe coders" doesn't feel derogatory enough.
glitchdx@lemmy.world · 6 pts · 324d
"vibe coding" was supposed to be derogatory?
SpaceCowboy@lemmy.ca · 4 pts · 323d
Yes. The original post that coined the term was using "vibe coding" to indicate how problematic it is to build software by generating code based on vague prompts.
But a lot of people didn't read the entire post and just thought the term sounded cool and used it as if it was positive thing.
Now we're seeing the negative impacts of vibe coding, just as the original post predicted. So it started as derogatory, somehow became something positive, but it's going back to being derogatory again.
glitchdx@lemmy.world · 1 pts · 322d
I thought vibe coding just didn't work, and that was the end of it?
SpaceCowboy@lemmy.ca · 1 pts · 322d
Nah, it's still a thing unfortunately. There will have to be a bunch of business go bankrupt because of it before managers start to think it's a bad idea.
_stranger_@lemmy.world · 3 pts · 324d
My point entirely. It'll probably stick though. Ah well, I'm sure script kiddies were called far more derogatory things that didn't stick either.
2deck@lemmy.world · 6 pts · 323d
Agreed, they're getting off light. I've worked with people who felt the code, but werent always able to communicate their ideas. I'd say theyd fit the idea of vibe coding without ai.
The concept is taken, and doesn't describe the intent well. How about "pseudocoders".
REDACTED@infosec.pub · 9 pts · 323d
At least they had real intelligence, doing stuff like this is basically so stupid you'd be clinically braindead
elvith@feddit.org · 35 pts · 324d
IIRC the screenshot in the tweet is from a shitpost in reddits r/badUIbattles
lord_ryvan@ttrpg.network · 2 pts · 305d
Yeah and it's quite old, this one has nothing to do with vibe coding.
pineapplelover@lemmy.dbzer0.com · 27 pts · 324d
I will be honest, it took me a good while to figure out what's wrong
frostysauce@lemmy.world · 2 pts · 324d
Same. And I came here to comment exactly that.
MystikIncarnate@lemmy.ca · 1 pts · 323d
Me too, but I woke up.... Checks watch .... 25 minutes ago, and I'm still pretty out of it.
Treczoks@lemmy.world · 26 pts · 324d
This could be vibe coding, or just an intern "doing the web site".
Neither should have write access to production code.
cupcakezealot@piefed.blahaj.zone · 6 pts · 324d
i mean either one of those fucked up but it's also on the qa/testing team and the deployment team that they let it GET to production.
melfie@lemy.lol · 4 pts · 324d
RagingRobot@lemmy.world · 3 pts · 324d
Yeah we are shifting left! Engineers are now responsible for testing and QA can go fuck off I guess :(
Treczoks@lemmy.world · 2 pts · 324d
If they have one.
Petter1@discuss.tchncs.de · 1 pts · 323d
O saved the ass of the company I worked for at software QA multiple times 🤭
Most of the time, it was just miscommunication between decision makers and devs and I had to explain to both why it is not working how it is now and that none of them is clearly to blame for the situation.
I still work for that company, but manage IT infrastructure now, but I am confident that my successor will still do good job, than unlike me, he has a proper education in programming, 😂 I was literally in vibe code state
(Thank you AI)
psud@aussie.zone · 2 pts · 322d
I feel like I saw this or the same thing on a different screenshot before AI, I'm not sure whether it's deliberately crafted bad security thing or legit bad from the wild
I don't think it's the result of vibe coding
Evil_Shrubbery@thelemmy.club · 24 pts · 324d
Feels like testing feature, hopefully the screenshot isn't from production.
AmbiguousProps@lemmy.today · 34 pts · 324d
We test in production, silly.
Evil_Shrubbery@thelemmy.club · 14 pts · 324d
vs
ICastFist@programming.dev · 2 pts · 324d
It's not like QA would've caught these problems before it went to production anyway
_stranger_@lemmy.world · 3 pts · 324d
What QA? They were all fired over the pandemic and "replaced" with "ai".
The zero to three people doing all the qa tasks for the 10 to Infinity developers before that never really got a chance to test anything beyond the basic "if this breaks were fucked" stuff anyway though, so it's not like quality was ever a priority for the people in charge sucking up all the money.
VonReposti@feddit.dk · 12 pts · 324d
Everyone has a test environment. Some are just lucky enough to have a separate production environment.
OppaGundamStyle@discuss.tchncs.de · 2 pts · 324d
It's the only way to fly.
cows_are_underrated@feddit.org · 21 pts · 324d
Assuming this is real, how the fuck do you fuck up so badly?
mcv@lemmy.zip · 17 pts · 324d
What!? It's more user friendly this way. No need to make the user switch to a totally different device when you can tell them right here!
/s
(I hate pointing out sarcasm, but it's better not to risk it these days.)
Cevilia@lemmy.blahaj.zone · 5 pts · 324d
rumba@lemmy.zip · 5 pts · 324d
When I first added 2fa to page, I had a bug and made it do that to compare the values.
production or test, it's likely debug code.
Lukemaster69@lemmy.ca · 2 pts · 324d
New intern
cupcakezealot@piefed.blahaj.zone · 20 pts · 324d
i'm ashamed to say that took me a while to figure out what was wrong mostly because i didn't think someone would be that dumb.
prettybunnys@sh.itjust.works · 16 pts · 324d
This could also be a funny translation issue.
My bank sends a text message to me with the first code and a second code I enter.
They tell me the first code in a similar way so I can verify they sent it to me, then I enter the other code in the text.
idunnololz@lemmy.world · 15 pts · 324d
Sike! That's the wrong number! /s
Psythik@lemmy.world · 22 pts · 324d
It's spelled "psych", as in you're psyching them out.
idunnololz@lemmy.world · 7 pts · 324d
It's ok I'm oot of academia.
guy@piefed.social · 3 pts · 324d
Nitpicking words like this makes me psich
exu@feditown.com · 14 pts · 324d
Just delay accepting the numbers for 10 seconds to simulate the time needed to check SMS and type them.
MonkderVierte@lemmy.zip · 0 pts · 324d
Repost.
SkunkWorkz@lemmy.world · 2 pts · 323d
Request granted: