That's what Google use. I lost access to a Google account even though I had the right password because they randomly decided they didn't think I was the account owner, and I didn't have a phone number attached so the account recovery wasn't available
Microblog Memes
A place to share screenshots of Microblog posts, whether from Mastodon, tumblr, ~~Twitter~~ X, KBin, Threads or elsewhere.
Created as an evolution of White People Twitter and other tweet-capture subreddits.
RULES:
- Your post must be a screen capture of a microblog-type post that includes the UI of the site it came from, preferably also including the avatar and username of the original poster. Including relevant comments made to the original post is encouraged.
- Your post, included comments, or your title/comment should include some kind of commentary or remark on the subject of the screen capture. Your title must include at least one word relevant to your post.
- You are encouraged to provide a link back to the source of your screen capture in the body of your post.
- Current politics and news are allowed, but discouraged. There MUST be some kind of human commentary/reaction included (either by the original poster or you). Just news articles or headlines will be deleted.
- Doctored posts/images and AI are allowed, but discouraged. You MUST indicate this in your post (even if you didn't originally know). If an image is found to be fabricated or edited in any way and it is not properly labeled, it will be deleted.
- Absolutely no NSFL content.
- Be nice. Don't take anything personally. Take political debates to the appropriate communities. Take personal disagreements & arguments to private messages.
- No advertising, brand promotion, or guerrilla marketing.
RELATED COMMUNITIES:
I kept seeing a popup about adding a phone number because I might lose access to my account. I removed the phone number a decade ago. You mean my recovery email, OTP code, and backup codes can't be used for recovery motherfucker!?!
Anyway I exported everything and closed my account because the fascists can eat a dick.
They may work, this was years ago before OTP was so widespread, and I don't remember if it had a recovery email associated or not. I just remember I had the right password and it wouldn't let me in anyway
Same thing happened to me. Recovery email means nothing to them, even with the correct username and password and recovery email code, I'm still locked out that account
Same thing happened with my Binance account. Then when I finally started to get some traction with customer service, my state banned Binance. And now it's effectively gone forever
Same here. Any time I try to recover it they're like "Nope, fuck you. Next time give us your phone number."
Me after setting up SSH on a server and unable to log in remotely:

You cannot call yourself an admin if this didn't happen to you.
Damn you apf / csf. *Shakes fists at sky
That feeling when you disabled password authentication before copying over your public key.
my favorite is when you type in a password then it makes you do an email code anyways, OR you press the "forgot password" button and.... you just do an email code. It's just 1 factor authentication with extra steps
types in the password that didn't work
"You cannot reuse an old password."
🤔
meanwhile there are LLM call centers with no authentication
I called one, and the only authentication they asked was my birthday. instead of asking me my name or other details it just said "please confirm, are you [full name]?"
that's all the security to access my private data!
then after going nowhere I managed to be transferred to a human and it took them a few minutes to authetify me.
Sites keep pushing Passkeys on me. I tried them. Did not work cross device. Did not integrate with every app. For now, I gave up on them.
It’s only a secure technology when it works and the key turns in the lock.
works cross-device with third party password managers (or smart keys like yubikeys)
Got I wanted a Yubikey for so long hearing about them. And earlier this year, Work got everyone Yubikeys for work, and they are essentially mandatory to use, and good fucking God so I hate Yubikeys.
Now I have this thing I have to carry around and dig out and plug in and my phone is going to eventually require it too and what the fuck happens when I inevitably lose it or it gets broken because it's very flimsy feeling and already looks a little bent.
usually you have two of them with the same keys so you have a backup (at a safe place), but I do admit it feels really unsafe
Now you have to maintain two pieces of electronic to keep up-to-date.
Very grear.
I actually keep commenting that "I wish I could order more of these" especially because, as far as I can tell from what numbers I have seen, we paid almost nothing for these. I wanted to bulk order a dozen at the price they paid (if it's accurate) and it would cost me less than one from Amazon.
This effort was using a third-party cross-platform password manager.
The specific case was a mobile game that needed to open a web browser that logged into a secondary account system, which I had set up to use passkeys. The in-app browser didn't seem aware of my phone's password manager plugin, and so it allowed no way to get in. Other times, logging in on a web browser with the password manager fully working simply gave an error - which could be blamed on the individual account provider, but then if I'm taking a chance on each passkey account, it's again pointless.
Yeah I don't like those things. If your password is two or three words, with a special character and 3 numbers anywhere before between or after, it would take millions of years to brute force, and then you're still covered with auth codes 2 factor. Theres no point in having a password so complex that you yourself can't remember it.
The only exception is when a common password is found in a data breach, but you should have unique passwords for work and financial accounts and theres no guarantee that the password managers won't be hacked at some point.
I was stopped by a bouncer in a bar and was asked to show ID. I had forgotten my wallet with my ID, but luckily, I have the national app for the driver's license. But to get that, I need to log in with my bank's secure login. That login is behind 2FA so I needed to approve with a separate app and type in my password. My password is safely stored within a password manager. But that password manager's access on my phone requires login through the microsoft single-sign-on. The microsoft login is buggy and requires me to manually log in through a separate URL.
I was arriving at the last step of my login before the bouncer announced that he saw that I was over the age limit of 18, so I didn't have to continue. I was 33 at the time.
I don't have much to add, just "lol"
I can't stand how many websites are making me check my email or text messages for 2fa shit. Just let me use a TOTP, or even better, a passkey to get into my account!
Yes, it's so slow and cumbersome. Fine as a backup but it also makes security worse if everyone uses email as then access to email gets everything.
Not good as a backup either because once they get in to your sms or email, they now have access to everything
Next is meta-factor authentication where part of the authentication process is making sure you perform each authentication method in the correct order as when you setup your account.
Then need to reset it when someone accidentally leaks the password to the unsecured database where everything was left in plain text.
Every time I come up against that, I decide whatever I was trying to login for isn't worth my time. It's been happening a lot lately.
It's like a monkey's paw. I felt like I was spending too much time online a few years ago and slowly the internet has been giving me more reasons to not use it.
Same. Perhaps it's by design. The internet used to be a lot more fun than it is now. Perhaps the people in charge of everything have been intentionally enshittifying the internet to break everyone's addiction. But I thought they like it when we have addictions. The masses are easier to control when they're hypnotized by things.
Thats just called getting a microsoft live account
That's why I hate banking apps. It's 5-factor authentication for me and it's seriously annoying.
The factors for logging into the internet banking are:
- Having a password manager - Something I have
- Remembering a master password - Something I know
- Having a banking app on the phone (🤮) - Something I have
- Using a password to log in to a user that has the app installed (I have a GrapheneOS and the banking app requires Gurgle services, so the services and apps must be separated) - Something I know
- Using a PIN inside the banking app to confirm the login - Something I know
Time to go back to communication via letter and telephone and read encyclopedias.
Medical company sends me a bill after insurance for $5.34.
They first send me 7 e-mails telling me to pay it online. Every single day for a week.
In order to pay it online, the first screen is to log in make an account that fails to load in firefox.
So I try the webpage in chromium, an account setup requires 2Fa and submitting an ID to pay a bill.
I say fuck that block their e-mails and wait until they send me a paper bill.
Paper bill arrives and I dust off the old checkbook. The last check was written in 2017 for some school pictures for my kid who just graduated college.
Takes me 10 seconds to write the check and $0.82 for the stamp. It got mailed the next time I took the dog for a walk and checked the mail.
I just looked up the cost of ordering new duplex checks that I prefer. Looks like around $0.25 each.
Now if I want too I can get laser printer checks for around $0.15 each. I might just go that route. I bet I can find a Linux program that will print them easily.
The Internet was nice while it lasted but it looks like I am back to writing checks for everything.
JavaScript should be illegal for banks, paying bills, etc.
Just straight up illegal. You only need JavaScript for three valid reasons:
- Games
- CSS can't do it
- Storing secrets in the browser in a webapp
most sites when you use a vpn
Twitch is the one that I don't get. Their opaque password requirements feel like something you'd use to secure bioweapons.
I've been there, deleted my Gmail a while back and then two weeks later realized it was attached to a login I didn't want to lose.
Personally, im thrilled
Sounds pretty good actually
CMMC Level 2 has entered the chat.