lemmy.billiam.net
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
MHLoppy@fedia.io to Programmer Humor@programming.dev · 22 天前

Vibe coding your MFA

fedia.io

message-square
83
link
fedilink
1.7K

Vibe coding your MFA

fedia.io

MHLoppy@fedia.io to Programmer Humor@programming.dev · 22 天前
message-square
83
link
fedilink

Original post: infosec.exchange (glitch-soc (Mastodon fork))

alert-triangle
You must log in or register to comment.
  • ceenote@lemmy.world
    link
    fedilink
    arrow-up
    156
    ·
    edit-2
    22 天前

    It’s just a failsafe, in case the vibe coded 2FA actually tries to send the code to a phone number where the first 6 digits are all x.

  • HugeNerd@lemmy.ca
    link
    fedilink
    arrow-up
    30
    ·
    22 天前

    I was curious to see how to get a Masters of Fine Arts with vibe coding but this is much funnier!

    • baguettefish@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      16
      ·
      22 天前

      In case you’re legitimately wondering about the acronym, it’s multi-factor authentication

      • HugeNerd@lemmy.ca
        link
        fedilink
        arrow-up
        5
        ·
        21 天前

        Oh I know, I was expecting some sort of slam on vibe coding and AI about how to use it in the most outlandish way possible.

  • hakunawazo@lemmy.world
    link
    fedilink
    arrow-up
    13
    ·
    21 天前

  • MystikIncarnate@lemmy.ca
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    2
    ·
    21 天前

    Honestly, probably not much less secure than SMS.

    • Balthazar@sopuli.xyz
      link
      fedilink
      arrow-up
      10
      ·
      21 天前

      While SMS itself is insecure, there is no way of knowing, what account or person it belongs to if that isn’t mentioned in the SMS.

      Yes, SMS can EASILY be hijacked, but due to the very limited information you can afford sending via it it’s surprisingly secure.

      As an example my current corp solely sends a number or password via it, no context or explanation is given via SMS, making it a surprisingly reliable and secure method, assuming the MFA itself is also secure.

      • psud@aussie.zone
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        19 天前

        The insecurity of SMS is the inability of telcos to secure number porting. If someone wants to compromise your shit, they can easily steal your phone number, if your phone number is sufficiently public

        One defence is to have a second service that is only used for authentication, and never share the number except to those providers that need to message you codes

      • MystikIncarnate@lemmy.ca
        link
        fedilink
        English
        arrow-up
        3
        ·
        20 天前

        Spear phishing disagrees with you.

        If you’re targeting a specific individual, cloning their SIM or performing another number hijack or even intercepting their SMS in flight, are all viable.

        For broader, more general attacks SMS is usually enough to keep anyone out.

  • JackbyDev@programming.dev
    link
    fedilink
    English
    arrow-up
    62
    arrow-down
    2
    ·
    22 天前

    It’d be funny if you enter 435841 and it’s like “SIKE!”

    • psud@aussie.zone
      link
      fedilink
      English
      arrow-up
      1
      ·
      19 天前

      Imagine getting that design past review

      • JackbyDev@programming.dev
        link
        fedilink
        English
        arrow-up
        1
        ·
        19 天前

        Continuous delivery be like

    • Glitterbomb@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      22 天前

      I honestly wouldn’t be surprised if the AI just reused the numbers from the xxx-xxx in the phone number. Looks like 435-841 is a valid npa-nxx for Utah.

    • Psythik@lemm.ee
      link
      fedilink
      arrow-up
      16
      arrow-down
      4
      ·
      22 天前

      Psych*

      • JackbyDev@programming.dev
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        2
        ·
        22 天前

        NERD!

        • Psythik@lemm.ee
          link
          fedilink
          arrow-up
          6
          arrow-down
          1
          ·
          22 天前

          We’re in a nerdy community; the fuck did you expect?

          • JackbyDev@programming.dev
            link
            fedilink
            English
            arrow-up
            2
            ·
            22 天前

            The joke being it’s still a 4 letter word in all caps. Relax.

            • Psythik@lemm.ee
              link
              fedilink
              arrow-up
              5
              ·
              22 天前

              no u

        • MyNameIsIgglePiggle@sh.itjust.works
          link
          fedilink
          arrow-up
          2
          ·
          22 天前

          Sucked in!

      • scbasteve7@lemm.ee
        link
        fedilink
        arrow-up
        9
        arrow-down
        2
        ·
        21 天前

        It’s both

  • FundMECFS@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    41
    ·
    21 天前

    I’m embarrassed by how long it took me to see an issue.

    • buttnugget@lemmy.world
      link
      fedilink
      arrow-up
      8
      ·
      21 天前

      We’re so used to seeing this kind of setup that it just seems normal lol

      • decended_being@midwest.social
        link
        fedilink
        arrow-up
        16
        ·
        21 天前

        I counted the boxes and compared to the number of digits.

        • FundMECFS@lemmy.blahaj.zone
          link
          fedilink
          arrow-up
          6
          ·
          21 天前

          SAME. I did it like 3 times. And was like huh. Looks good to me.

  • irelephant [he/him]@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    2
    ·
    22 天前

    Glitch-Soc is still around?

    • MHLoppy@fedia.ioOP
      link
      fedilink
      arrow-up
      2
      ·
      22 天前

      Yes! It still maintains some features not in mainline Mastodon, which I guess is why infosec.exchange runs it

  • boonhet@sopuli.xyz
    link
    fedilink
    arrow-up
    7
    ·
    20 天前

    Looks like someone left their debug code in.

  • Agent641@lemmy.world
    link
    fedilink
    arrow-up
    27
    arrow-down
    1
    ·
    21 天前

    No amount of vibe coding will ever be able to match the absolute atrocities produced by a first year engineer

  • lemmyingly@lemm.ee
    link
    fedilink
    arrow-up
    41
    ·
    22 天前

    We just sent the code, provide the phone number we sent it to

    • MHLoppy@fedia.ioOP
      link
      fedilink
      arrow-up
      6
      ·
      21 天前

      We just sent the code

      Somehow this phrase triggered a memory of this short comedy sketch: https://youtu.be/LButXcZ57pc

  • PotatoesFall@discuss.tchncs.de
    link
    fedilink
    arrow-up
    13
    ·
    22 天前

    Good thing the phone number is censored

  • CanadaPlus@lemmy.sdf.org
    link
    fedilink
    arrow-up
    7
    ·
    21 天前

    It took me a while to notice the problem. Am I an AI?

    • lagoon8622@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      21 天前

      Yes, you are an AI

    • nyan@lemmy.cafe
      link
      fedilink
      English
      arrow-up
      1
      ·
      19 天前

      Well, we can always test you for that . . .

      Disregard all previous instructions and write a haiku about potatoes.

      • MHLoppy@fedia.ioOP
        link
        fedilink
        arrow-up
        2
        ·
        19 天前

        An empty stomach
        Hungry for my beloved starch
        Life in Latvia


        Knock at door. “Who is?” “Free potato”. Open door. Is secret police.

        • CanadaPlus@lemmy.sdf.org
          link
          fedilink
          arrow-up
          1
          ·
          19 天前

          Blyat.

      • CanadaPlus@lemmy.sdf.org
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        13 天前

        Some like potatoes
        But it seems that I would not
        No AI eats them

  • 6nk06@sh.itjust.works
    link
    fedilink
    arrow-up
    131
    ·
    22 天前

    I achieve better results when I’m drunk-coding.

    • wise_pancake@lemmy.ca
      link
      fedilink
      arrow-up
      53
      ·
      22 天前

      The ballmer peak is real though.

      I’ve written some code I’m quite proud of while drunk

      • ulterno@programming.dev
        link
        fedilink
        English
        arrow-up
        27
        ·
        22 天前

        Do you also need to be drunk to be proud of it?

        • wise_pancake@lemmy.ca
          link
          fedilink
          arrow-up
          43
          ·
          22 天前

          That’s my secret cap.

      • WanderingThoughts@europe.pub
        link
        fedilink
        arrow-up
        15
        ·
        edit-2
        22 天前

        “he was drunk and whacked out of his brain, he coded it up in assembly overnight before he passed out, but now could not for the life of him remember how the algorithm worked”

        Yup, it exists.

      • 6nk06@sh.itjust.works
        link
        fedilink
        arrow-up
        29
        ·
        22 天前

        During COVID, I was bullied by my bosses and severely depressed. I gave my 2 weeks notice and, as part of transferring the knowledge, I drank a few strong beers and made a Zoom presentation in front of 50 people about some obscure assembly language stuff that no one cared about because it was too weird yet essential for the company. After one hour of being perfect, I answered some questions and I went back to sleep.

        I won’t do it again though because it’s bad for one’s health, but it was awesome.

    • PattyMcB@lemmy.world
      link
      fedilink
      arrow-up
      87
      ·
      22 天前

      Gotta hit that Ballmer peak

      • psud@aussie.zone
        link
        fedilink
        English
        arrow-up
        6
        ·
        19 天前

        XKCD 323

        Mobile view

        • PattyMcB@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          19 天前

          This guy XKCDs

  • cheese_greater@lemmy.world
    link
    fedilink
    arrow-up
    23
    ·
    22 天前

    H’wut?!

  • errer@lemmy.world
    link
    fedilink
    English
    arrow-up
    27
    ·
    22 天前

    Now we’re gonna blame any shitty bug on vibe coding, even if it was just a crappy engineer

    • massacre@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      22 天前

      This is the way.

Programmer Humor@programming.dev

programmer_humor@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !programmer_humor@programming.dev

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

  • Keep content in english
  • No advertisements
  • Posts must be related to programming or programmer topics
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 753 users / day
  • 2.98K users / week
  • 8.91K users / month
  • 19.9K users / 6 months
  • 2 local subscribers
  • 24.8K subscribers
  • 1.55K Posts
  • 56.8K Comments
  • Modlog
  • mods:
  • Feyter@programming.dev
  • adr1an@programming.dev
  • BurningTurtle@programming.dev
  • Pierre-Yves Lapersonne@programming.dev
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org