this post was submitted on 02 Oct 2026
335 points (98.0% liked)

196

6932 readers
2219 users here now

Community Rules

You must post before you leave

Be nice. Assume others have good intent (within reason).

Block or ignore posts, comments, and users that irritate you in some way rather than engaging. Report if they are actually breaking community rules.

Use content warnings and/or mark as NSFW when appropriate. Most posts with content warnings likely need to be marked NSFW.

Most 196 posts are memes, shitposts, cute images, or even just recent things that happened, etc. There is no real theme, but try to avoid posts that are very inflammatory, offensive, very low quality, or very "off topic".

Bigotry is not allowed, this includes (but is not limited to): Homophobia, Transphobia, Racism, Sexism, Abelism, Classism, or discrimination based on things like Ethnicity, Nationality, Language, or Religion.

Avoid shilling for corporations, posting advertisements, or promoting exploitation of workers.

Proselytization, support, or defense of authoritarianism is not welcome. This includes but is not limited to: imperialism, nationalism, genocide denial, ethnic or racial supremacy, fascism, Nazism, Marxism-Leninism, Maoism, etc.

Avoid AI generated content.

Avoid misinformation.

Avoid incomprehensible posts.

No threats or personal attacks.

No spam.

Moderator Guidelines

Moderator Guidelines

  • Don’t be mean to users. Be gentle or neutral.
  • Most moderator actions which have a modlog message should include your username.
  • When in doubt about whether or not a user is problematic, send them a DM.
  • Don’t waste time debating/arguing with problematic users.
  • Assume the best, but don’t tolerate sealioning/just asking questions/concern trolling.
  • Ask another mod to take over cases you struggle with, if you get tired, or when things get personal.
  • Ask the other mods for advice when things get complicated.
  • Share everything you do in the mod matrix, both so several mods aren't unknowingly handling the same issues, but also so you can receive feedback on what you intend to do.
  • Don't rush mod actions. If a case doesn't need to be handled right away, consider taking a short break before getting to it. This is to say, cool down and make room for feedback.
  • Don’t perform too much moderation in the comments, except if you want a verdict to be public or to ask people to dial a convo down/stop. Single comment warnings are okay.
  • Send users concise DMs about verdicts about them, such as bans etc, except in cases where it is clear we don’t want them at all, such as obvious transphobes. No need to notify someone they haven’t been banned of course.
  • Explain to a user why their behavior is problematic and how it is distressing others rather than engage with whatever they are saying. Ask them to avoid this in the future and send them packing if they do not comply.
  • First warn users, then temp ban them, then finally perma ban them when they break the rules or act inappropriately. Skip steps if necessary.
  • Use neutral statements like “this statement can be considered transphobic” rather than “you are being transphobic”.
  • No large decisions or actions without community input (polls or meta posts f.ex.).
  • Large internal decisions (such as ousting a mod) might require a vote, needing more than 50% of the votes to pass. Also consider asking the community for feedback.
  • Remember you are a voluntary moderator. You don’t get paid. Take a break when you need one. Perhaps ask another moderator to step in if necessary.

founded 2 years ago
MODERATORS
 

Or even an account for that matter

top 41 comments
sorted by: hot top controversial new old
[–] thethunderwolf@lemmy.dbzer0.com 7 points 21 hours ago* (last edited 21 hours ago)

also not everything needs email

just username + password is enough usually

[–] Passerby6497@lemmy.world 13 points 1 day ago (1 children)

I would rather have 2fa than the magic link email bullshit. I am so fucking tired of sites assuming I don't want to use a simple username and password, and I clearly want to have to wait on email delivery to be able to access my account instead of JUST ENTERING MY GODS DAMNED CREDENTIALS.

[–] toynbee@lemmy.world 5 points 23 hours ago (1 children)

There is an app on my phone that, after every update (and sometimes just because it's bored) logs me out. When I log back in, it opens a browser to request a username, a password, and a random number that it emails me. The number is not in the subject line of the email, so I have to switch to my inbox to get the number.

Unfortunately, half the time when I open the email, when I switch back to the web browser number form has forgotten that it's a text field and so won't open my keyboard. I haven't yet figured out a way to fix this, other than waiting a few hours then trying again. If I force close and try again immediately, the same issue occurs.

[–] psilotop@lemmy.world 3 points 23 hours ago

Ugh that's frustrating. I've had similar experiences. Bluetooth keyboard was my savior which is really only available if I'm at home

[–] SailorMoss@sh.itjust.works 5 points 22 hours ago (1 children)

Just use Keepass, it lets you store your passwords and totp in an encrypted database file you can move around just like any other file. Just make sure you make a backup when ever you add new credentials.

[–] pressanykeynow@lemmy.world 3 points 22 hours ago* (last edited 22 hours ago) (1 children)

If I store your password and totp in one app it's not 2fa, there's literally no reason to setup both then

[–] SailorMoss@sh.itjust.works 1 points 22 hours ago (1 children)

Sounds like it solves OPs problem then.

[–] pressanykeynow@lemmy.world 1 points 22 hours ago (1 children)

Well yeah, if their problem is the security of their accounts, that solves it

[–] SailorMoss@sh.itjust.works 2 points 22 hours ago

Keepass is pretty well respected by security experts. Often more than other password managers such as bitwarden. Though of course bitwarden is recommended as well.

It’s a file that is not stored online so hackers cannot access it unless they’ve already compromised your personal system, even then it’s encrypted so they would also need to capture your keepass password as well.

[–] germanatlas@lemmy.blahaj.zone 89 points 1 day ago (3 children)

Things that I have 2FA for for some reason:

  • my abandoned Ubisoft account which holds two free games and doesn’t have any personal details about me

Things I don’t have 2FA for, although I’d probably prefer if I could have:

  • my bank account
[–] sigezayaq@startrek.website 6 points 1 day ago

My bank makes me do 2fa for every transaction

[–] Malgas@beehaw.org 48 points 1 day ago (3 children)

No, you see banks don't need 2fa because they've got ironclad password requirements like "max of 8 characters, alphanumeric only".

[–] igmelonh@lemmy.blahaj.zone 19 points 1 day ago

But some of them don't tell you that when you first set it, so you have to call tech support and, after sending you a temporary password to log in and set a new password which then also doesn't work, they're like "wait, you can't have & or ! in the password — try it without," and it works because it accepted the password but removed all special characters without telling you 🙃

[–] Darkassassin07@lemmy.ca 10 points 1 day ago

My bank doesn't allow copy+paste into the new password fields, and clears anything you've typed if you switch apps.

To set a new password (which is mandatory every 6mo) I have to physically write down the new password that my password manager generates...

[–] NominatedNemesis@reddthat.com 9 points 1 day ago (1 children)

Your bank lets you use letters? Mine just numbers. The registration allowed 10 numbers but the login does not allowed more than 8... At least they block the account after 3 incorrect guess and make you ask for a reset in person. So I had to go twice in a day... and the teller lady asked why I don't use 4 digits like a normal person... Sill beter than the other bank which sends the password back in plain text email after registration in 2019

My bank allows alphanumeric passwords, but only 5 characters

I sometimes wonder how their opsec specialists cope…

[–] carotte@lemmy.blahaj.zone 11 points 1 day ago

2fa for a ubisoft account is actually very important. what if somebody hacks into ur account and buys more ubisoft games???

[–] Bieren@lemmy.today 3 points 21 hours ago

I had one the other day. Enter passcode from Auth app. Ok done. Great. We just emailed you another code enter that now.

[–] AzuraTheSpellkissed@lemmy.blahaj.zone 41 points 1 day ago* (last edited 1 day ago) (5 children)

This, but specifically because of Microsoft Authenticator. I hate this app so damn much. [I'm forced to use it] not with TOTP tokens, but push-notification based ones which arrive only sometimes and are slow. And then it's mocking me saying "pull to refresh if you don't see a notification", but there is no pull to refresh feature. Oh and Microsoft Azure Portal? It asks you to authenticate twice in a row, just to be sure. Burn burn burn

[–] NekoKoneko@lemmy.world 14 points 1 day ago

I tried MS Authenticator after creating a business account with me as the admin, and it let me enroll and then immediately gave me a device untrusted error (I'm rooted, sue me, but there's no warning or way to tell that's not allowed) which then login-looped every recovery option to try to re-enroll or remove the 2FA, requiring me to file a ticket and manually prove who I am which took 48-hours.

Just the fact that they let me sign up before pulling the rug and revoking access with a hidden, time-bomb fail condition, really impressed me. It takes work to be that evil.

Some companies let you use TOTP instead of the app, look in the dashboard and select the verification mode that gives you the qr code

[–] arudesalad@piefed.ca 4 points 1 day ago

That sounds horrible. I hate that steam requires me to use their app instead of the authenticator app I use for everything else but at least it works every time

[–] Dojan@pawb.social 3 points 1 day ago

I feel this. And the endless fucking prompt to log in. Several times a day. Everywhere. We should bill Microsoft for the time lost.

[–] HexaBack@lemmy.blahaj.zone 3 points 1 day ago

Only for its "cloud saves" to suddenly forget everything after switching devices 🤦‍♀️️ I'd upvote 3 times if i could

[–] celeste@feddit.org 3 points 1 day ago
[–] heartSagan5@lemmy.zip 10 points 1 day ago* (last edited 1 day ago)

My favorite is now needing two email accounts to access one.

[–] saltnotsugar@lemmy.world 15 points 1 day ago (2 children)

For some reason I read it as “I lost the love of my life to two factor authentication” and really wanted to hear how that was possible.

[–] Jilanico@lemmy.world 15 points 1 day ago

Long distance relationship, locked out of email, can't remember their email address 🥀

[–] 0ops@piefed.zip 8 points 1 day ago

heyy cutie, can I get your number? can you give me the code i sent to your phone number, hot stuff? you're adorbs, is this still a good email to reach you with?

[–] bluespin@lemmy.world 14 points 1 day ago

IMO anything hooked up to your financial info should have 2FA

I store 2FA in the same place I store my password, I just need to copy one, then the other. I may have lost hours or even days to 2FA, the same amount I lose by having to authenticate with a password

[–] thenextguy@sh.itjust.works 10 points 1 day ago (2 children)

SoCal Edison just enabled 2fa? To protect what, exactly? Someone hack my account and pay my bill!

My utility account shows power use by 15 minute intervals. Technically someone could use that as a way of figuring out when people are home or away if you have a regular life schedule. Seems like a farfetched concern though.

[–] shads@leminal.space 0 points 1 day ago

Always had the same reaction to requiring a PIN to refund a transaction on an EFTPOS machine. Someone wants to steal my card and put money on it that's cool, just stop them from taking it out and they can hold onto that card as long as they want.

[–] kibiz0r@midwest.social 6 points 1 day ago (1 children)
[–] thenextguy@sh.itjust.works 3 points 1 day ago

No thanks. I'm fine with passwords for most things, and MFA of my choosing for important things.

[–] PeteWheeler@lemmy.world 5 points 1 day ago (1 children)

What really grinds my gears is when they require a password as well.

Why did you require a password when your going to bug me about 2fa anyways? Why did you require me to change said password every 3 months if you bug me about 2fa anyways? Why are you asking me to switch my password with your dumb restrictions (no special characters, really BofA?) when it has been recommended for years to not require users to do that since it just makes the passwords less unique in the long term?

2fa is fine, just remove passwords if your going to do it.

[–] EmoPolarbear@lemmy.ca 16 points 1 day ago (1 children)

It’s not a second factor if you remove passwords, the password is the first factor.

otherwise yes absolutely, password recycling should be dropped as soon as 2fa is implemented.

[–] Randelung@lemmy.world 3 points 1 day ago (1 children)

That's what bugs me about passwordless. It's just 1fa again, except that the password is still there to sign in from other devices if you don't have a passkey set up yet, so now you have more than one attack vector.

[–] EmoPolarbear@lemmy.ca 0 points 1 day ago

Passkeys and Totp codes in my password manager make no fucking sense to me. And whoever is pushing passkeys as the new default needs to get a hard slap in the face, they’ve clearly never dealt with end users or my mom.

[–] Thatuserguy@lemmy.world 6 points 1 day ago

I had a really fun one with my Google account the other day. It was the one where you had to select the number it was showing on "the other screen". However it was trying to show it on my same phone I was trying to log in on, only to immediately overwrite it with the prompt to select the correct number. Cue me sitting there having to guess the right number like 6 times before finally getting access, getting logged back out every time I failed to guess right