Derock's Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
MHLoppy@fedia.io
cake
to Programmer Humor@programming.dev · 1 day ago

Vibe coding your MFA

fedia.io

message-square
64
fedilink
  • cross-posted to:
  • [email protected]
1

Vibe coding your MFA

fedia.io

MHLoppy@fedia.io
cake
to Programmer Humor@programming.dev · 1 day ago
message-square
64
fedilink
  • cross-posted to:
  • [email protected]

Original post: infosec.exchange (glitch-soc (Mastodon fork))

alert-triangle
You must log in or register to comment.
  • CanadaPlus@lemmy.sdf.org
    link
    fedilink
    arrow-up
    0
    ·
    2 hours ago

    It took me a while to notice the problem. Am I an AI?

  • Agent641@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    3 hours ago

    No amount of vibe coding will ever be able to match the absolute atrocities produced by a first year engineer

  • hakunawazo@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    5 hours ago

  • MystikIncarnate@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 hours ago

    Honestly, probably not much less secure than SMS.

    • Balthazar@sopuli.xyz
      link
      fedilink
      arrow-up
      0
      ·
      2 hours ago

      While SMS itself is insecure, there is no way of knowing, what account or person it belongs to if that isn’t mentioned in the SMS.

      Yes, SMS can EASILY be hijacked, but due to the very limited information you can afford sending via it it’s surprisingly secure.

      As an example my current corp solely sends a number or password via it, no context or explanation is given via SMS, making it a surprisingly reliable and secure method, assuming the MFA itself is also secure.

  • elrik@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 hours ago

    Even if it didn’t outright display the code you need to enter, my guess is this and similar implementations hide further vulnerabilities like: the numbers aren’t generated with a secure random number generator, or the validation call isn’t resistant to simple brute force quickly guessing every possible number, or the number is known client side for validation, etc.

    • no_username@lemm.ee
      link
      fedilink
      arrow-up
      0
      ·
      6 hours ago

      what if 435841 is the most secure 6 digit numerical code?

      why use another?

      • Valmond@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        6 hours ago

        I use the random number 4, I even rolled a dice to get a real random number instead of those “pseudo” random numbers. (XKCD?)

        • MHLoppy@fedia.io
          cake
          OP
          link
          fedilink
          arrow-up
          0
          ·
          5 hours ago

          https://xkcd.com/221/

    • ouRKaoS@lemmy.today
      link
      fedilink
      arrow-up
      0
      ·
      7 hours ago

      It probably just always displays the one code.

    • DragonTypeWyvern@midwest.social
      link
      fedilink
      arrow-up
      0
      ·
      7 hours ago

      Yep. There’s going to be some absolutely massive breach at some point that hurts a lot of people.

  • FundMECFS@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    0
    ·
    9 hours ago

    I’m embarrassed by how long it took me to see an issue.

    • buttnugget@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      8 hours ago

      We’re so used to seeing this kind of setup that it just seems normal lol

      • decended_being@midwest.social
        link
        fedilink
        arrow-up
        0
        ·
        4 hours ago

        I counted the boxes and compared to the number of digits.

  • TheEighthDoctor@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 hours ago

    I’ve seen very similar in the wild, the webapp would sendo a requet to the API with the numbers so that the captcha imagem was generated

  • MyNameIsIgglePiggle@sh.itjust.works
    link
    fedilink
    arrow-up
    0
    ·
    14 hours ago

    I’m a fan of AI, I know that’s unpopular here but I think it’s a cool tool.

    But you need to know what you are doing and how to program. I’ve said before we are going to see sooo much of this

    The reality is we will always need engineers. Certainly not ready yet, but we probably won’t always need “programmers” - which is a shame because I do get a kick out of solving a really complex problem in a super elegant way

    • Randelung@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      4 hours ago

      AI is a tool like any other. I wouldn’t turn on a power tool, set it down in a construction site, and expect everything to be done the next day.

      Copilot saves a lot of time and mental load. I’d never let it vibe code, though. Suggesting is all it gets to do.

  • lemmyingly@lemm.ee
    link
    fedilink
    arrow-up
    0
    ·
    18 hours ago

    We just sent the code, provide the phone number we sent it to

    • MHLoppy@fedia.io
      cake
      OP
      link
      fedilink
      arrow-up
      0
      ·
      10 hours ago

      We just sent the code

      Somehow this phrase triggered a memory of this short comedy sketch: https://youtu.be/LButXcZ57pc

  • Venator@lemmy.nz
    link
    fedilink
    arrow-up
    0
    ·
    21 hours ago

    That’s so convenient: don’t even need to get out your phone.

  • irelephant [he/him]@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    0
    ·
    21 hours ago

    Glitch-Soc is still around?

    • MHLoppy@fedia.io
      cake
      OP
      link
      fedilink
      arrow-up
      0
      ·
      21 hours ago

      Yes! It still maintains some features not in mainline Mastodon, which I guess is why infosec.exchange runs it

  • JackbyDev@programming.dev
    link
    fedilink
    English
    arrow-up
    0
    ·
    21 hours ago

    It’d be funny if you enter 435841 and it’s like “SIKE!”

    • Psythik@lemm.ee
      link
      fedilink
      arrow-up
      0
      ·
      18 hours ago

      Psych*

      • scbasteve7@lemm.ee
        link
        fedilink
        arrow-up
        0
        ·
        12 hours ago

        It’s both

      • JackbyDev@programming.dev
        link
        fedilink
        English
        arrow-up
        0
        ·
        18 hours ago

        NERD!

        • MyNameIsIgglePiggle@sh.itjust.works
          link
          fedilink
          arrow-up
          0
          ·
          14 hours ago

          Sucked in!

        • Psythik@lemm.ee
          link
          fedilink
          arrow-up
          0
          ·
          18 hours ago

          We’re in a nerdy community; the fuck did you expect?

          • JackbyDev@programming.dev
            link
            fedilink
            English
            arrow-up
            0
            ·
            17 hours ago

            The joke being it’s still a 4 letter word in all caps. Relax.

            • Psythik@lemm.ee
              link
              fedilink
              arrow-up
              0
              ·
              17 hours ago

              no u

    • Glitterbomb@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      19 hours ago

      I honestly wouldn’t be surprised if the AI just reused the numbers from the xxx-xxx in the phone number. Looks like 435-841 is a valid npa-nxx for Utah.

  • HugeNerd@lemmy.ca
    link
    fedilink
    arrow-up
    0
    ·
    21 hours ago

    I was curious to see how to get a Masters of Fine Arts with vibe coding but this is much funnier!

    • baguettefish@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      0
      ·
      21 hours ago

      In case you’re legitimately wondering about the acronym, it’s multi-factor authentication

      • HugeNerd@lemmy.ca
        link
        fedilink
        arrow-up
        0
        ·
        14 hours ago

        Oh I know, I was expecting some sort of slam on vibe coding and AI about how to use it in the most outlandish way possible.

  • chicken@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    0
    ·
    22 hours ago

    I love it, hate having to check my phone for these, brilliant choice to put the code onscreen

  • /home/pineapplelover@lemm.ee
    link
    fedilink
    arrow-up
    0
    ·
    23 hours ago

    Because this person is on infosec.exchange, I think this is supposed to be some kind of joke…right?

Programmer Humor@programming.dev

programmer_humor@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

  • Keep content in english
  • No advertisements
  • Posts must be related to programming or programmer topics
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 80 users / day
  • 470 users / week
  • 1.59K users / month
  • 3.97K users / 6 months
  • 0 local subscribers
  • 24.2K subscribers
  • 1.03K Posts
  • 20.3K Comments
  • Modlog
  • mods:
  • Feyter@programming.dev
  • adr1an@programming.dev
  • BurningTurtle@programming.dev
  • Pierre-Yves Lapersonne@programming.dev
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org