• 1 Post
  • 10 Comments
Joined 2Y ago
cake
Cake day: Jul 03, 2023

help-circle
rss

Yeah, that’s absolutely what I am saying. Its nowhere even near the coast where a hurricane is ever a serious concern besides some gusts and a few inches of rain from one and even then, you’re thinking of that much closer to the coast.



How does Okta not have systems like support systems like what was breached with the credentials behind a VPN as well? A system like that really ought to be on a secured network. We have so many systems at work that are VPN required and it’s mostly those where sensitive data lives.


The fields where you can’t paste a password or any other types of data like credit card info absolutely kill me. It’s doing the exact opposite of adding any level of security and it’s just infuriating.

My favorite recently is my company has TOTP 2FA but you can’t paste the 6 digits. You have to type in one digit at a time, each being its own box. Paste fails in every browser I’ve tried. It’s just a shitty user interface.


If a service you use does not offer TOTP but implements their own 2FA through another method, you have no choice to use it though.


I also used to run into this when flying for work I would have paid for wifi on a plane flight but my mobile device isn’t able to get their text or push notification because I only paid for my laptop to have wifi. Used to drive me crazy and then I just stopped working while on flights because of dumb policies.


Why Do Companies Not Use Existing 2FA Standards?
This is something I am seeing more and more of. As companies start to either offer or require 2FA for accounts, they don't follow the common standards or even offer any sort of options. One thing that drives me nuts is when they don't offer TOTP as an option. It seems like many companies either use text messages to send a code or use some built in method of authorizing a sign in from a mobile device app. What are your thoughts on why they want to take the time to maintain this extra feature in an app when you could have just implemented a TOTP method that probably can be imported as an existing library with much less effort? Are they assuming that people are too dumb to understand TOTP? Are they wanting phone numbers from people? Is it to force people to install their apps? *edit: I also really want to know what not at least give people the option to choose something like TOTP. They can still offer mobile app verification, SMS, email, carrier pigeon, etc for other options but at least give the user a choice of something besides an insecure method like SMS.
fedilink

Containers are such a game changer for how I manage my apps and their dependencies. Love how I can try things out in a container, nuke it and start over, knowing I have a clean environment. I hate installing anything on my native host OS install these days if I can help it.


Minor nit here - “docker containers” or just “containers” because “dockers” are pants.


Older: Command and Conquer Generals. I’ve started playing it with my kid which is fun. Newer: Rocket League. It’s been fun especially when I stop caring about ranking up. It’s just a game and I can play for 10 minutes and walk away.


Sounds like the perfect recipe to become like the next Google+ though