813
Sign up for our newsletter (media.piefed.social)
all 31 comments
sorted by: hot top controversial new old
[-] undefined@lemmy.hogru.ch 79 points 1 month ago

“Magic email” login is the most stupid method to me. Yeah, just make it impossible to log in with my password manager. The average person probably has the weakest password for their email anyway so if a hacker has access to their account you just made it 100% easier for them to log in.

[-] kambusha@sh.itjust.works 30 points 1 month ago

It's to outsource the security risk/liability to a third-party

[-] undefined@lemmy.hogru.ch 7 points 1 month ago

Even though I can’t stand “log in with…”-style logins I’d still take that over the stupid link.

[-] brygphilomena@lemmy.dbzer0.com 6 points 1 month ago

Oh yea. 100%. You can't have your vibe coded insecure supabase user database stolen with plaintext creds if you don't store user creds in the first place.

[-] ShrimpCurler@lemmy.dbzer0.com 1 points 1 month ago

Well that's definitely the lesser of two evils

[-] JensSpahnpasta@feddit.org 10 points 1 month ago

It's one of those dark patterns that prevents account sharing. So if you use a magic email login, nobody can share their account with their family & friends and everybody has to pay. Profit!

[-] undefined@lemmy.hogru.ch 1 points 1 month ago

laughs in Sieve filter

[-] Amir@lemmy.ml 1 points 1 month ago

You can just automate forwarding those login emails, no?

[-] Zorcron@lemmy.zip 9 points 1 month ago

I mean if your email is compromised, most of your accounts can have their passwords reset, no? So it’s basically the same as resetting your password every time you log in. Dumb, I agree, but surely not worse from a security standpoint, right?

[-] Pyro@pawb.social 8 points 1 month ago

Fully agree, it's almost security theater.

They need to offer a way for use with a password manager, maybe a slightly hidden option or detecting a really long password to stop all the extra bits.

I forgot what the service was but it will have my user and pass, prompt the email verify, and then it will ask for the token generated in an Auth app.

At a certain point the proper user probably can't get in

[-] Clent@lemmy.dbzer0.com 3 points 1 month ago
[-] Pyro@pawb.social 2 points 1 month ago

Yes, for the last Auth they had me use TOTP.

Thanks, still having my morning drink and forgot the name, When I replied.

[-] Fiery@lemmy.dbzer0.com 6 points 1 month ago

To be fair basically all services allow resetting passwords via email so even without the magic email link they'd be fucked anyways if their email got hacked.

[-] snek_boi@lemmy.ml 26 points 1 month ago

This, exactly, stopped me from subscribing to a service last night

[-] HollowNaught@lemmy.world 25 points 1 month ago

My biggest annoyance with these processes is when they ask for your user name (loading...) then takes you to a different page to ask for your password (loading...)

Like, just stick them on the same page, it's an annoyance for the sake of trying to get us to use auto sign in

[-] Jako302@feddit.org 13 points 1 month ago

it's an annoyance for the sake of trying to get us to use auto sign in

Not really, that's more in the realm of incompetence than malice. Its basically the cheapest and fastest way to implement multiple different log in methods within one login page.

Let's say you have Google login, Facebook login, SSO (corporate single sign-on), Email/SMS codes and good old password and username. The easiest option would be to just put a different login button for each of these and be done with it. That works as long as your users know what type they should use.

But once you have a user that doesn't know what he should use you need a backup login that always works. Thats what the standard login button is used for nowadays. When you put in your username/Email it checks the associated login method for that account and redirects you to the correct login page. That way multiple login methods can be accessed with the same starting page.

Sure, its mildly annoying for people that use a normal passwords, but considering that the overwhelming majority of people either uses Google sign in or just stays logged in, its a very easy decision to make for the developers.

[-] TheEighthDoctor@lemmy.zip 24 points 1 month ago

It's especially good when you already have an account but accidentally press the Google button and then it creates a duplicate account with the same email and breaks the login for your regular email.

[-] tiramichu@sh.itjust.works 11 points 1 month ago

Who needs 'vibe coding' when people have been building half-broken shit the old-fashioned way for years?

[-] Arigion@feddit.org 3 points 1 month ago

Guess on which code the vide coding models were mostly trained....

[-] ICastFist@programming.dev 2 points 1 month ago

Vice coding exists so you can break more shit faster

[-] LogicalDrivel@sopuli.xyz 16 points 1 month ago* (last edited 1 month ago)


I got this yesterday after signing back in to my google account. Like fuck off, google, i know you already know my address. Its just for those "ads purposes" they try to sneak in the bottom there.

[-] Remember_the_tooth@lemmy.world 11 points 1 month ago
[-] ChaoticNeutralCzech@feddit.org 9 points 1 month ago

My sister told me she had problems recovering her password. The page said "email address not registered" when she tried that but "email address in use" when she tried to create a new account. She eventually tried "Sign in with Google" (it was a Gmail address), which led to a permission page, making it seem like she was setting up a new connected service to the account. She went through with it and saw her profile page with all her details, history and credits. By the time she navigated to another page, her account had been reset to a new one with nothing but an email address... The service admins did have a backup though and restored the account.

And I remember a site that would show you your password in account details, and did not even support https... in 2011 up to fucking 2015. Gaining control of all 300,000+ accounts (not hard if the backend's security was as strong as it seems to have been) would not have been valuable itself (users could not interact, the site was basically a quiz game with a leaderboard akin to freerice.com) but it was for children 6-18, most of whom would reuse passwords. And it was designed by CDI.cz, a major web design agency with high-profile Czech clients including the post office, a top 3 telecom, a major heath insurance provider and the national railway company...

[-] RedGreenBlue@lemmy.zip 6 points 1 month ago* (last edited 1 month ago)

After the age check laws take effect; you won't need to log in. They will know who you are.

You only have to type the url in your browsers adress bar and you will recieve your obligatory bone sampling kit in your mail box the next day.

[-] maplesaga@lemmy.world 2 points 1 month ago* (last edited 1 month ago)

Buy the Google stock, average people dont give a flying shark about privacy.

[-] davidagain@lemmy.world 5 points 1 month ago

This kind of thing really thoroughly gets on my nerves.

[-] TypFaffke@feddit.org 4 points 1 month ago

Why won't you give it your bones???

[-] ExLisper@lemmy.curiana.net 2 points 1 month ago

I wonder if it's because some usage statistics tell those sites that 99% of users visiting the site are already logged in and the only case someone is not logged in when they don't have an account yet or if they are just stupid.

[-] Epzillon@lemmy.world 2 points 1 month ago

As a web developer I simply have to tell you that this clearly superior web design is the only thing I ever implement. You have to understand the maximized convenience this workflow gives the user and the UX implementation for this makes the login experience flawlessly seamless without any hickups. /s

Jokes aside. How the fuck did we even get here? 

[-] Imgonnatrythis@sh.itjust.works 1 points 1 month ago

Deviant art?? This is not July of 2025 for sure

this post was submitted on 15 Mar 2026
813 points (100.0% liked)

Microblog Memes

11309 readers
1321 users here now

A place to share screenshots of Microblog posts, whether from Mastodon, tumblr, ~~Twitter~~ X, KBin, Threads or elsewhere.

Created as an evolution of White People Twitter and other tweet-capture subreddits.

RULES:

  1. Your post must be a screen capture of a microblog-type post that includes the UI of the site it came from, preferably also including the avatar and username of the original poster. Including relevant comments made to the original post is encouraged.
  2. Your post, included comments, or your title/comment should include some kind of commentary or remark on the subject of the screen capture. Your title must include at least one word relevant to your post.
  3. You are encouraged to provide a link back to the source of your screen capture in the body of your post.
  4. Current politics and news are allowed, but discouraged. There MUST be some kind of human commentary/reaction included (either by the original poster or you). Just news articles or headlines will be deleted.
  5. Doctored posts/images and AI are allowed, but discouraged. You MUST indicate this in your post (even if you didn't originally know). If an image is found to be fabricated or edited in any way and it is not properly labeled, it will be deleted.
  6. Absolutely no NSFL content.
  7. Be nice. Don't take anything personally. Take political debates to the appropriate communities. Take personal disagreements & arguments to private messages.
  8. No advertising, brand promotion, or guerrilla marketing.

RELATED COMMUNITIES:

founded 2 years ago
MODERATORS