Blåhaj Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@sh.itjust.works to Programmer Humor@programming.dev · 6 months ago

Vibecoding is the future

lemmy.ml

message-square
50
link
fedilink
  • cross-posted to:
  • fuck_ai@lemmy.world
  • programmerhumor@lemmy.ml
1.11K

Vibecoding is the future

lemmy.ml

cm0002@sh.itjust.works to Programmer Humor@programming.dev · 6 months ago
message-square
50
link
fedilink
  • cross-posted to:
  • fuck_ai@lemmy.world
  • programmerhumor@lemmy.ml
alert-triangle
You must log in or # to comment.
  • Scrubbles@poptalk.scrubbles.tech
    link
    fedilink
    English
    arrow-up
    196
    ·
    6 months ago

    You’re absolutely right! It doesn’t make sense to show the user the 2fa code! removes 2fa completely

    • Uli@sopuli.xyz
      link
      fedilink
      arrow-up
      138
      ·
      6 months ago

      Oh, I get it! You still want 2fa, you just don’t want the code to be shown! colors the text white

      • ThePancakeExperiment@feddit.org
        link
        fedilink
        arrow-up
        35
        ·
        6 months ago

        No, no, make it ultra secure and display none it, every website will be a database of important information, you just have to put everything into a hidden table!!

        • PattyMcB@lemmy.world
          link
          fedilink
          arrow-up
          20
          ·
          6 months ago

          Font size 0

        • Schmoo@slrpnk.net
          link
          fedilink
          arrow-up
          6
          ·
          6 months ago

          *Includes it in the URL

      • Redjard@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        16
        ·
        6 months ago

        Oh you want the code not rendered into html!
        Drops the code in javascript when it is received from the backend.

    • pure_bliss@discuss.tchncs.de
      link
      fedilink
      arrow-up
      11
      ·
      6 months ago

  • aberrate_junior_beatnik (he/him)@midwest.social
    link
    fedilink
    English
    arrow-up
    103
    ·
    6 months ago

    It took me way too long to figure out what was wrong with this screenshot

    • Ilovethebomb@sh.itjust.works
      link
      fedilink
      arrow-up
      53
      ·
      6 months ago

      Yeah, same here. I was counting the boxes thinking they’d got the wrong amount of numbers.

    • Darkmuch@lemmy.world
      link
      fedilink
      arrow-up
      9
      ·
      6 months ago

      I need help. I don’t get it…

      • teegus@sh.itjust.works
        link
        fedilink
        arrow-up
        23
        ·
        6 months ago

        The “secret” code sent to your phone is spelled out in the text

  • Cousin Mose@lemmy.hogru.ch
    link
    fedilink
    arrow-up
    81
    ·
    6 months ago

    SMS/email-based 2FA should die.

    • coopi@anarchist.nexus
      link
      fedilink
      English
      arrow-up
      51
      ·
      6 months ago

      Luckily, you don’t even need to check SMS or input a valid number with the “verification” in the screenshot!

      • bamboo
        link
        fedilink
        English
        arrow-up
        30
        ·
        6 months ago

        mission failed successfully

    • nogooduser@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      ·
      6 months ago

      It’s better than nothing and some people would really struggle to do other types of 2FA.

      • djsoren19
        link
        fedilink
        English
        arrow-up
        7
        ·
        6 months ago

        I’ll be homest with you, some people really struggle with email 2fa. The amount of working Americans I have spoken with who don’t understand how to have two tabs open at once is genuinely frightening.

      • Natanael@infosec.pub
        link
        fedilink
        arrow-up
        6
        ·
        6 months ago

        As a reset method it’s worse than having nothing

    • null@lemmy.nullspace.lol
      link
      fedilink
      English
      arrow-up
      4
      ·
      6 months ago

      It’s wild how standard SMS is given how (relatively) trivial it is to exploit.

      • Cousin Mose@lemmy.hogru.ch
        link
        fedilink
        arrow-up
        1
        ·
        6 months ago

        Even with autofilling it on iOS, macOS you still have developers that need to fuck with form fields using JavaScript because they think they’re smarter than you.

    • Dharma Curious (he/him)@slrpnk.net
      link
      fedilink
      arrow-up
      2
      ·
      6 months ago

      What’s the best alternative?

      • nogooduser@lemmy.world
        link
        fedilink
        English
        arrow-up
        14
        ·
        6 months ago

        App based 2FA is better. Either the app generates a time based code that you enter into the site or the site sends a push notification to the app asking you to verify the login attempt.

        Passkeys are good too as they replace the password completely and leave the 2FA part to the device.

        • Victor@lemmy.world
          link
          fedilink
          arrow-up
          4
          ·
          6 months ago

          Passkey or notification please. So sick of entering these codes on a daily basis.

          • Opisek@piefed.blahaj.zone
            link
            fedilink
            English
            arrow-up
            4
            ·
            6 months ago

            If it’s alright with your threat model, you can put the time-based OTPs into your password manager of choice, like Bitwarden. Upon filling your username and password, it places your OTP in your clipboard, so that you can simply paste it in. This does of course reduce the security of the system slightly, since you centralize your passwords and your OTPs. When opting for this method, it is therefore imperative to protect your password manager even more, like via setting up 2FA for the password manager itself or making sure your account gets locked after something like 10 minutes of inactivity. The usability aspect is improved by using a yubikey or another similar physical key technology.

          • RaivoKulli@sopuli.xyz
            link
            fedilink
            arrow-up
            1
            ·
            6 months ago

            I just save the cookies tbh

        • psud@aussie.zone
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 months ago

          I wonder if there are any TOTP apps for Linux phones (though I think I’ll have to keep an Android or Apple device around for my workplace’s 2FA which doesn’t have anything for anything other than apple and Android phones, and only with full security)

        • djsoren19
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 months ago

          Okay, but then you have to develop an app

      • PlexSheep@infosec.pub
        link
        fedilink
        arrow-up
        1
        ·
        6 months ago

        TOTP, FIDO2 or not worrying about logins and just using {GitHub,Google,Microsoft,selfhosted.lan} as identity provider with OIDC

  • 8000gnat@reddthat.com
    link
    fedilink
    arrow-up
    59
    ·
    6 months ago

    no factor authentication

  • -RJ-@lemmy.world
    link
    fedilink
    English
    arrow-up
    46
    ·
    6 months ago

    That’s up there with: "You cannot use this password, it’s already in use by … "

    • Seth Taylor@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      6 months ago

      But that’s so practical. Maybe I can contact them and ask them if we can swap. Haha

  • Elvith Ma'for@feddit.org
    link
    fedilink
    arrow-up
    34
    ·
    6 months ago

    IIRC the screenshot in the tweet is from a shitpost in reddits r/badUIbattles

    • The Ramen Dutchman@ttrpg.network
      link
      fedilink
      English
      arrow-up
      2
      ·
      5 months ago

      Yeah and it’s quite old, this one has nothing to do with vibe coding.

  • Evil_Shrubbery@thelemmy.club
    link
    fedilink
    arrow-up
    23
    ·
    6 months ago

    Feels like testing feature, hopefully the screenshot isn’t from production.

    • AmbiguousProps@lemmy.today
      link
      fedilink
      English
      arrow-up
      31
      ·
      6 months ago

      We test in production, silly.

      • Evil_Shrubbery@thelemmy.club
        link
        fedilink
        arrow-up
        13
        ·
        6 months ago

        vs

        • I Cast Fist@programming.dev
          link
          fedilink
          arrow-up
          2
          ·
          6 months ago

          It’s not like QA would’ve caught these problems before it went to production anyway

      • VonReposti@feddit.dk
        link
        fedilink
        arrow-up
        10
        ·
        6 months ago

        Everyone has a test environment. Some are just lucky enough to have a separate production environment.

      • OppaGundamStyle@discuss.tchncs.de
        link
        fedilink
        arrow-up
        2
        ·
        6 months ago

        It’s the only way to fly.

  • /home/pineapplelover@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    20
    ·
    6 months ago

    I will be honest, it took me a good while to figure out what’s wrong

    • MystikIncarnate@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 months ago

      Me too, but I woke up… Checks watch … 25 minutes ago, and I’m still pretty out of it.

    • frostysauce@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      Same. And I came here to comment exactly that.

  • da_cow (she/her)@feddit.org
    link
    fedilink
    arrow-up
    18
    ·
    6 months ago

    Assuming this is real, how the fuck do you fuck up so badly?

    • mcv@lemmy.zip
      link
      fedilink
      arrow-up
      13
      ·
      edit-2
      6 months ago

      What!? It’s more user friendly this way. No need to make the user switch to a totally different device when you can tell them right here!

      /s

      (I hate pointing out sarcasm, but it’s better not to risk it these days.)

      • Cevilia (they/she/…)
        link
        fedilink
        English
        arrow-up
        4
        ·
        6 months ago

        (you don’t need to apologise for using tone tags, they’re a useful accessibility tool and hurt nobody)

    • rumba@lemmy.zip
      link
      fedilink
      English
      arrow-up
      5
      ·
      6 months ago

      When I first added 2fa to page, I had a bug and made it do that to compare the values.

      production or test, it’s likely debug code.

    • Lukemaster69@lemmy.caB
      link
      fedilink
      arrow-up
      2
      ·
      6 months ago

      New intern

  • katy ✨@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    14
    ·
    6 months ago

    i’m ashamed to say that took me a while to figure out what was wrong mostly because i didn’t think someone would be that dumb.

  • exu@feditown.com
    link
    fedilink
    English
    arrow-up
    12
    ·
    6 months ago

    Just delay accepting the numbers for 10 seconds to simulate the time needed to check SMS and type them.

  • MonkderVierte@lemmy.zip
    link
    fedilink
    arrow-up
    2
    ·
    6 months ago

    Repost.

  • Treczoks@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    6 months ago

    This could be vibe coding, or just an intern “doing the web site”.

    Neither should have write access to production code.

Programmer Humor@programming.dev

programmer_humor@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !programmer_humor@programming.dev

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

  • Keep content in english
  • No advertisements
  • Posts must be related to programming or programmer topics
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 227 users / day
  • 3.18K users / week
  • 9.06K users / month
  • 16.8K users / 6 months
  • 556 local subscribers
  • 30.7K subscribers
  • 2.13K Posts
  • 73K Comments
  • Modlog
  • mods:
  • Feyter@programming.dev
  • adr1an@programming.dev
  • BurningTurtle@programming.dev
  • Pierre-Yves Lapersonne@programming.dev
  • BE: 0.19.16
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org