this post was submitted on 16 Oct 2025
1384 points (99.5% liked)

Microblog Memes

9797 readers
760 users here now

A place to share screenshots of Microblog posts, whether from Mastodon, tumblr, ~~Twitter~~ X, KBin, Threads or elsewhere.

Created as an evolution of White People Twitter and other tweet-capture subreddits.

Rules:

  1. Please put at least one word relevant to the post in the post title.
  2. Be nice.
  3. No advertising, brand promotion or guerilla marketing.
  4. Posters are encouraged to link to the toot or tweet etc in the description of posts.

Related communities:

founded 2 years ago
MODERATORS
 
top 50 comments
sorted by: hot top controversial new old
[–] warpotato@lemmy.world 50 points 1 month ago (7 children)

Okay so I get this is a meme BUT I started using a yubikey instead of the auth app and it has done a world of good for my sanity.

[–] halcyoncmdr@lemmy.world 32 points 1 month ago* (last edited 1 month ago) (4 children)

I transitioned everything to Bitwarden. Password manager, passkeys, and MFA code generation all in one app that works on all of my devices.

And then I started to self-host it via Vaultwarden and transferred all the data.

[–] alsaaas@lemmy.dbzer0.com 42 points 1 month ago (3 children)

A friendly FYI: having your passwords and MFA in one place partially defeats the purpose

[–] halcyoncmdr@lemmy.world 23 points 1 month ago* (last edited 1 month ago) (1 children)

True, but the alternatives generally are either a pain in the ass or require yet another syncing service to have sensitive info just so I can access things reliably anywhere.

It is still more secure than SMS and email based options.

Besides, my vaultwarden still needs an MFA code to access in the first place, and that's handled by a separate generator.

[–] alsaaas@lemmy.dbzer0.com 9 points 1 month ago (1 children)

I get that not everyone wants to set up something like Aegis in combination with e.g. Syncthing.

Of course it is still better than SMS and email, but I would recommend you check out Ente Auth and/or Proton Auth.

Both are end to end encrypted and you would at least have it in separate apps

[–] halcyoncmdr@lemmy.world 15 points 1 month ago (1 children)

I'm willing to accept the slight security difference in exchange for the convenience of having access on a single app 99.9% of the time.

To get into my Vaultwarden in the first place to get my info they'd first have to know my self-hosted server exists to target. And they'd need to compromise that MFA which is handled by a separate unrelated app.

That's more than enough security for nearly everyone on the planet.

[–] alsaaas@lemmy.dbzer0.com 6 points 1 month ago

Perfectly valid, everyone has their own threat model and their own standards.

[–] Passerby6497@lemmy.world 4 points 1 month ago (1 children)

Sure. But if your bitwarden is protected by a 50char password AND a yubikey, it's not that big of a tradeoff imo. That's what I do, but I have hundreds of MFA tokens and it was PAINFUL to auth a lot of the time when I was using an authenticator app.

load more comments (1 replies)
load more comments (1 replies)
[–] artiman@piefed.social 7 points 1 month ago

Bitwarden is just so awesome

load more comments (2 replies)
[–] jaybone@lemmy.zip 9 points 1 month ago (1 children)

Depends on your org. I have a yubikey, a phone app Authenticator, a pin and my regular SSO login/password. All of which I have to use constantly, because some dumbass did something dumb like two fucking years ago. So I can hardly get shit done. Plus the same dumbasses who probably fucked all this up are writing production code for an actual product. Please kill me.

load more comments (1 replies)
load more comments (5 replies)
[–] Korhaka@sopuli.xyz 29 points 1 month ago (3 children)

Our password manager requires logging in and using the authenticator every time the session times out, so we all started using a browser plug-in to keep the session alive all day.

[–] Passerby6497@lemmy.world 9 points 1 month ago (1 children)

Seconding the ask on the extension, I hate having to log into my secret store every 15 minutes while working on stuff

[–] Korhaka@sopuli.xyz 10 points 1 month ago

Session alive

[–] falseWhite@lemmy.world 6 points 1 month ago (1 children)

Same issue. What's the extension called?

[–] Korhaka@sopuli.xyz 5 points 1 month ago

I use session alive

[–] krooklochurm@lemmy.ca 5 points 1 month ago (1 children)
[–] Korhaka@sopuli.xyz 11 points 1 month ago (1 children)

Complain to the guys that set stupid policies that encourage people to do this. We gave up trying and don't care any more.

[–] krooklochurm@lemmy.ca 6 points 1 month ago (2 children)

That may have come off as judgmental. It wasn't meant to be. When you make security so onerous that no one will do it then it's little surprise that people.... won't.

Especially when it's a business.

load more comments (2 replies)
[–] Jankatarch@lemmy.world 27 points 1 month ago

And get 15 emails from microsoft regarding how you just logged in.

[–] echodot@feddit.uk 25 points 1 month ago (6 children)

No matter how bad you have it someone else has it worse.

In order to do my job I have to log into the VPN, and then remote desktop onto a server, then from that server remote desktop onto another server. Then I have to go back to the first remote desktop and remote desktop onto a different server which from there I can remote desktop onto two other servers, on one of those servers there are two different log ons which I can use to do different tasks.

Then back on the main desktop I can remotely connect via web browser to a virtual machine that I can then remote desktop onto a server. If I want to change the password on that server I have to remote desktop from that remote desktop from that virtual machine, into a remote desktop.

Oh and then there is the web app that I have to use that only works in Internet Explorer, but for security reasons IE has been removed from the main system, so I have an entire remote desktop literally just to use Internet Explorer.

It takes about 25 minutes to log into everything everyday and about 10 minutes to log out at the end of the day.

[–] Muffi@programming.dev 15 points 1 month ago

Thanks for the aneurysm. I feel for you.

[–] LadyButterfly@piefed.blahaj.zone 13 points 1 month ago (1 children)

Oh ffs I got annoyed just reading the comment I can't imagine the hell of having to do that

load more comments (1 replies)
[–] lightnegative@lemmy.world 7 points 1 month ago

I bet the security "experts" who designed this are busy jerking each other off about how "secure" they've made everything

load more comments (3 replies)
[–] MuskyMelon@lemmy.world 19 points 1 month ago (1 children)

Oh did you change your phone? Suffer bitch!!!

/s

[–] MystikIncarnate@lemmy.ca 7 points 1 month ago (2 children)

As someone on the other side, in IT support, you can fix this yourself and I wish more people would.

Before your old phone gets wiped and sent to the graveyard, log in using authenticator, and go to "view account" from any of the online pages for Microsoft (if you're unsure, try login.microsoft.com ). Go to your security options, and you should see all the info you need to remove the old authenticator and add a new one.

From here you can also add backups, which I encourage everyone to do.

It saves you from having to call IT all the time to fix it, and since you don't have to go through the usual back and forth of verifying who you are, or whatever, and getting them to do a thing, you can take care of it for yourself, by yourself, without those unnecessary delays.

Your IT people will appreciate it, and you'll have to talk to them a bit less as a result.

load more comments (2 replies)
[–] The_v@lemmy.world 17 points 1 month ago (1 children)

The largest issue I have is the randomness of all the different security setups. One requires MFA by e-mail, one requires an authenticator, most require sms, some push to require using their app, and this random page requires a code by phone call. Now they are pushing passkeys and that is a complete cluster.

What's ironic is that most of the webpages that push these things don't reach the "Do I give a fuck?" threshold. The security is usually there to protect against unauthorized use of user stored credit cards. Since I am not liable for any fraudulent charges to the credit card, I really don't give a fuck about securing the account. Yeah I am reusing passwords, keeping them in plain text in a word doc etc..

When I worked for other companies, I moderately gave fuck about there security. Not enough to inconvenience me. If they made me change the password constantly, they got the number changing series at the end of the password - $tupidPass#01 Seriously that was my actual work password for over a decade.

Now my bank account and financial logins. You'd better believe those have every security feature they offer setup. I do not fuck around with those. I give a fuck about those.

[–] SaraTonin@lemmy.world 20 points 1 month ago (4 children)

I remember reading an article once which referred to research which suggested that making people change passwords every month made their accounts less secure, because they have to go extra steps to remember them - which usually translates to making them really obvious and/or storing them where they’re easily accessed. In one of my previous jobs where we had to change passwords every month, basically everybody would have their password written on a post-it on their computer monitor.

[–] The_v@lemmy.world 14 points 1 month ago (2 children)

In my first job I had like 7 different passwords to access different systems. Each one had different schedule of password reset. They each ended up being on a different reset schedule. I had to reset a password once or twice a week.

Yeah, everyone had their passwords on a sticky note on their monitor. I once got praise for being the one person without it. I of course had an abreviation for the system with what number series the password was on posted on my monitor.

[–] MirthfulAlembic@lemmy.world 4 points 1 month ago

This is my current job. I've got monthly, every three months, every quarter, once per year... Thank goodness the last service they added has SSO.

load more comments (1 replies)
[–] vortexsurfer@lemmy.world 9 points 1 month ago

Yeah, that's actually also why it's no longer considered best practice to force regular password changes. But many places / websites /apps still do, obviously.

[–] its_kim_love@lemmy.blahaj.zone 4 points 1 month ago

I worked in top secret military stuff and the worst I had was every 4 months on some systems. Monthly seems extremely ineffective.

load more comments (1 replies)
[–] sirico@feddit.uk 13 points 1 month ago (3 children)

Get a yubi key then you have to find your keys

[–] fedev@lemmy.world 9 points 1 month ago (1 children)

I have a Yubi key that crashes Authenticator when I select the option to it l use it. It goes into a loop asking to touch the button and type the PIN. But it does not wait for input, it just keeps creating windows until it crashes.

load more comments (1 replies)
[–] zalgotext@sh.itjust.works 5 points 1 month ago

I have multiple accounts configured on the same yubikey, but it seems like any of the Microsoft login portals expect you to always use the account you most recently signed in with. So any time I need to switch accounts (which is often, I have different accounts for each different testing environment and access level), I have to type in my pin and touch my key twice - once to allow Microsoft to try logging in with the wrong account and fail, and then another time where it asks which account I want to use. 🙃

load more comments (1 replies)
[–] Reygle@lemmy.world 12 points 1 month ago

Have the day you/your company paid to have.

[–] Tja@programming.dev 11 points 1 month ago (2 children)

You should try Okta instead! It's... blue.

[–] chellomere@lemmy.world 6 points 1 month ago

Da ba dee da ba da

[–] couch1potato@lemmy.dbzer0.com 5 points 1 month ago

My company... runs both, for some reason.

[–] dan69@lemmy.world 10 points 1 month ago (1 children)

On a scale of 1-10 how likely are you having conversations with your friends about

[–] martinb@lemmy.sdf.org 5 points 1 month ago

Hmmm. Conversation, yes.

[–] altphoto@lemmy.today 9 points 1 month ago

One day Ms will make the power point you're sharing on teams even smaller than today.....but I'm here to tell you how to do it now. Take a look at the slide below!

                                   .    

Lemmy is now better than teams! Yey!

[–] pseudo@jlai.lu 9 points 1 month ago (2 children)

Is there a community around here dedicated to the hatred of Microsoft?

[–] echodot@feddit.uk 9 points 1 month ago

You mean system administrators?

[–] shneancy@lemmy.world 7 points 1 month ago

i think that's just all of lemmy at this point

[–] hardcoreufo@lemmy.world 5 points 1 month ago (1 children)

We use duo as 2fA for our Microsoft accounts at work. Every Thursday its log into teams on phone log into teams on desktop, log into outlook on phone, log into outlook on desktop. Why can't your apps cross authenticate on the same device? How does one drive manage to stay authenticated throughout the whole process?

Any actual work I need togets done is done on a 15 year old think pad running Debian. The beefy 12th gen i9 just whirrs its fan around and occasionally gets used for emails, team chats and logging up tickets.

load more comments (1 replies)
[–] fin@sh.itjust.works 5 points 1 month ago (13 children)

I hate MS Auth so badly. Why don't they just implement the "normal" 2FA instead? MS doesn't work with Ente Auth

[–] quoll@lemmy.sdf.org 7 points 1 month ago (3 children)

microsoft has sucked arse for eons. the real q is why the fuck IT keeps buying their shit.

load more comments (3 replies)
load more comments (12 replies)
[–] Matriks404@lemmy.world 4 points 1 month ago* (last edited 1 month ago) (5 children)

I like when you want to make a Microsoft account, it asks you to enter your exisiting e-mail first (you can enter one ending with @outlook.com or @hotmail.com though, it will create new mail account). It's like they don't believe in their own products, lol.

[–] AnUnusualRelic@lemmy.world 4 points 1 month ago* (last edited 1 month ago) (2 children)

I once created a Microsoft account (for a Windows 7 machine I think) and entered a Google address. It didn't seem to mind. It's my Microsoft account to this day, not that I have much use for it. Maybe it's gotten more weird nowadays.

load more comments (2 replies)
load more comments (4 replies)
load more comments
view more: next ›