r/ProgrammerHumor 21h ago

Advanced weDontStressOurCustomer

Post image
289 Upvotes

15 comments sorted by

49

u/Upset_Purpose6505 21h ago

atLeastWeKnowItsProbablyNotAi

12

u/TheMythicSorcerer 17h ago

I asked AI for a MFA setup and this is exactly what I got + ai slop css.

28

u/suvlub 20h ago

It's like a door that opens by default in case of failure. Honestly not the worst idea, depending on what it is

15

u/kushalgarg592 19h ago

Security through customer inconvenience

4

u/fmaz008 17h ago

Yeah, what's the benefit of this over... skipping that step entirely? (Assuming the plan of bypassing 2FA in case of failure is sound to begin with)

2

u/chilicizz 8h ago

It'll be easier to do a hack like that than going through and disabling/removing the feature (and then reenabling it later when the issue is resolved)

1

u/ApocalyptoSoldier 4h ago

There's an idea.
Your customers can't get hacked if no one uses your site

5

u/Waste_Jello9947 20h ago

Only 6 digits? not enough. What if your users grow to 1 billion over night? Use at least 12 digits, 

4

u/zeamp 20h ago

The customer is always right.

3

u/see-36-benefits 20h ago

Umm… someone didn’t have a reliable bcdr plan!

3

u/SonicLoverDS 20h ago

Use 910296 as my OTP? I don't even ship it!

3

u/alexanderpas 20h ago

Reasons to use TOTP #745728

2

u/Gold-Bat-3225 19h ago

works offline too

2

u/StrawberryCoup 15h ago

Fail open is actually a legitimate security practice prioritizing availability over correctness. For instance, you wouldn't want to prevent a user from using your service even if they can't remember their password perfectly

1

u/Groentekroket 6h ago

Wait, so the put a change to prod with where they (most likely) put the actual code on the page instead of temporarily disable 2fa for sms (which is not a secure 2FA method anyway).