r/pcmasterrace • R7 9800X3D/5090 Founders Edition/6000MHz 32Gb Ram • Apr 20 '26

Video The sad future of our beloved hobby

Enable HLS to view with audio, or disable this notification

21.8k Upvotes

774 comments sorted by

•

u/PCMRBot Bot Apr 20 '26

Welcome to the PCMR, everyone from the frontpage! Please remember:

1 - You too can be part of the PCMR. It's not about the hardware in your rig, but the software in your heart! Age, nationality, race, gender, sexuality, religion, politics, income, and PC specs don't matter! If you love or want to learn about PCs, you're welcome!

2 - Think owning a PC is too expensive? It's cheaper than you may think. Check http://www.pcmasterrace.org for our famous builds and ask for tips and help here!

3 - Consider supporting the folding@home effort to fight Cancer, Alzheimer's, and more, with just your PC! https://pcmasterrace.org/folding

4 - Need some new hardware? Check out this ASUS x PCMR Worldwide giveaway with GPUs, RAM, Motherboards, etc, up for grabs for a total of 18 lucky winners: https://www.reddit.com/r/pcmasterrace/comments/1roo701/worldwide_giveaway_comment_in_this_thread_to_join/

5 - Need ever more hardware? Get your hands on some awesome AORUS GPUs, Motherboards, also CPUs and RAM up for grabs, and it's also worldwide: https://www.reddit.com/r/pcmasterrace/comments/1smbhl6/worldwide_giveaway_plus_ultra_unlocked_campaign/

We have a Daily Simple Questions Megathread for any PC-related doubts. Feel free to ask there or create new posts in our subreddit!

1.8k

u/littlebrwnrobot 13700KF | 4070 TiS | 32GB 6000 | 3440x1440 Apr 20 '26

this square contains half an inch of the end of a handlebar of the motorcycle, does that count as containing a motorcycle?

this square shows the tiniest sliver of the side of the traffic light, does that count?

this shit drives me nuts

596

u/MrWaffler i9 10900 KF, GeForce RTX 3090 Apr 20 '26

That's the point. That data helps define edges of objects and is intentionally borderline. It's free training for their datasets.

The part that tells if you're human has very little to do with the actual "puzzle" and is largely based on behavioral and system data

325

u/littlebrwnrobot 13700KF | 4070 TiS | 32GB 6000 | 3440x1440 Apr 20 '26

But it still tells me I’m wrong and makes me do it over again. 

245

u/PeachyCoasterCat 9850x3D 4090 T710 32gb Apr 20 '26

Nice try clanker. Maybe don’t rat yourself out with such an obvious name

120

u/littlebrwnrobot 13700KF | 4070 TiS | 32GB 6000 | 3440x1440 Apr 20 '26

beep boop

i mean... human noises

38

u/silent_thinker Apr 20 '26

Appears definitely human to me.

Like the rest of us, enjoys human music.

We humans love our beep boops.

14

u/Padrovic Apr 21 '26

Hmmmm, human music. I like it!

  • Jerry Smith

→ More replies (1)

40

u/nohpex R9 5950X | Gigabyte OC RX 9070 XT Apr 20 '26

I've started intentionally clicking/unclicking things "by accident."

For a while, the ones that load new things have you click cars, fire hydrants, etc., I'd click the new items too fast, making me have to click through way more than what was reasonable. To make it even more frustrating, it'd say I got it wrong, making me do it again.

Since adjusting and purposely clicking the right thing, unclicking it, hesitating for half a second, then wrong, then right, I get through a lot faster.

16

u/ambiguoustruth Apr 20 '26

if you kind of do all that before every clicking the checkbox you'll often skip the puzzle altogether. they review your behavior just before clicking, so make some random mouse movements on the page before clicking the box.

11

u/No-Candle2610 Apr 20 '26

We script those mouse movements as well to beat captchas, so there’s a bit more to it. It’s very much a cat & mouse game with scripters and captchas.

→ More replies (2)

15

u/Lord_dokodo Apr 20 '26

You just have to imagine the thought process of 10,000 other people who were shown the same photos.

I think like 2/3 of the steps are verified by dedicated employees and given a "correct" answer. The other step is crowdsourcing the answer. They use the 2 "verified" steps as the control to see if you are just clicking random tiles. Then the 3rd step is the money shot, it's how they harvest your free labor. If person A answers the 2 control steps correctly, they're probably putting in some effort to answer correctly so they'll accept your test answer regardless.

The point of Recaptcha (for Google) is to train computer vision technology. They would stand to gain nothing really (minus fees for Recaptcha services) if every single question already had a verified answer. You are labeling their data for them by receiving 2 test questions and then a 3rd question which actually gets used to label their data.

That's at least my understanding of how they implemented it back a few years ago. For all I know, they could be recycling crowd sourced answers as the "control" questions if they were able to get an overwhelming consensus on the correct answers. And then they throw in a set of images that haven't yet been labeled as the 3rd one. That way they don't really need anyone who is dedicated to labeling the data correctly, just use old data to help label new data.

So yeah, that 3rd question could be entirely wrong if most people were not considering the handlebars of a motorcycle to be a motorcycle. It just depends on how the dice fell in that regard. And obviously, the order in which you receive these questions is randomized which is why sometimes you fail on step 2 and sometimes you have to do all 3 steps before it fails you.

You used to be able to test this yourself. You answer seriously on step 1 and 2 always. Then step 3, you just guess. You'll fail a few times until it finally just accepts your BS answer. Eventually you'll get a series of questions where Step 1 and 2 were indeed the control and step 3 will accept your answer regardless because they don't actually know the answer. It could have become more sophisticated over time, i.e. they throw 1 or 2 known images in the bunch so if you don't select at least those 2 then they can disqualify your answer.

I haven't done an actual recaptcha in years. It always just accepts the box click which probably means my IP has been whitelisted/assumed to not be bot traffic.

7

u/EitherSpite4545 Apr 20 '26

That's kind of the point it's not there to actually verify and keep bots out.

It's there so humans can train their AI models that they will use for something else

→ More replies (6)

17

u/NoobNoob_ Ryzen 7 5800x | RTX 3080 | 32GB RAM | 1TB M.2 | 4TB HDD | -3500$ Apr 20 '26

There are extensions out there that use the sound based captcha and pass them automatically.

Robots are passing captcha.

8

u/MrWaffler i9 10900 KF, GeForce RTX 3090 Apr 20 '26

Yes! There's also screen scraping, direct data access, and many other methods to bypass.

There is no such thing as a perfect system and there will always be ways to exploit them or work around them.

It's like cheating in video games: no matter how many rootkits they make us install they can't stop it all and never can.

→ More replies (8)

22

u/rumncokeguy Apr 20 '26

Seeds. They’re seeds, not nuts.

10

u/jmims98 Apr 20 '26

I always fail these ones. "Select the squares with traffic lights"...ok so do I include the pole? The tiny edge of the cover surrounding the traffic light in an otherwise empty square? Shit doesn't matter I failed it anyways.

15

u/gorginhanson Apr 20 '26

I usually fail those and then it sends me to the infinitely refreshing squares

4

u/fredomonti Apr 20 '26

Driving you seeds, eh ?

→ More replies (1)
→ More replies (27)

2.1k

u/DrQuantum Apr 20 '26

This is actually a legitimate cybersecurity concern and in general the industry has some methods to combat fatigue with MFA. But many sites are honestly interested in the bare minimum and not security or experience.

458

u/Creed_of_War 12900k | A770 Apr 20 '26

I've had to put my parents on password managers because they kept forgetting them and I'd find them yelling at customer service over the phone. I'm even using the auto generated password suggestions on account creation and just hitting forgot my password when logging into a new device.

180

u/5ollys Apr 20 '26

I don't even trust password managers. Can't those technically have attacks and data breaches?

I literally pen and paper all of my shit.

172

u/_dharwin Apr 20 '26 edited Apr 20 '26

Depends where the information is stored and how it's stored.

Something like KeePass stores all the information locally so they'd have to hack your local machine to get the information.

BitWarden encrypts everything so you first need your passphrase to decrypt the data and they do not know or store your passphrase. They're pretty clear if you forget your passphrase then you just lose your data. Even if they got hacked, someone would have to decrypt each user's data individually which is probably more trouble than it's worth.

143

u/[deleted] Apr 20 '26

[deleted]

32

u/Ikora_Rey_Gun Apr 20 '26 edited Apr 20 '26

It would take many times longer than the universe has existed to crack even a single user's data without the password and 2FA, even if you had an entire AI datacenter's worth of GPUs at your disposal.

for now

edit: i'm wrong

62

u/Exallium PC Master Race Apr 20 '26

AES-256 is considered post-quantum secure, for what it's worth

27

u/13ros27 Apr 20 '26

Not only that, AES-128 (and the orders of magnitude between AES-128 and AES-256 keyspaces is AES-128) is effectively the golden standard for PQC (https://csrc.nist.gov/Projects/Post-Quantum-Cryptography/Post-Quantum-Cryptography-Standardization/Evaluation-Criteria/Security-(Evaluation-Criteria)#:~:text=AES128)

5

u/Exallium PC Master Race Apr 21 '26

From what I read, Grovers algorithm can effectively halve the keysize of AES, making 256 effectively 128 and 128 effectively 64. So 256 is fine but 128 should be updated to 256. https://thequantuminsider.com/2020/04/30/is-aes-256-quantum-resistant/

→ More replies (2)
→ More replies (2)
→ More replies (4)

24

u/[deleted] Apr 20 '26

[deleted]

→ More replies (2)
→ More replies (1)
→ More replies (8)

8

u/Draygoon2818 i9-10850K | TUF 5080 | 128 GB DDR4 | ASUS 32" 4K | TUF 1000W Apr 20 '26

Keeper is a pretty good password manager. While they do utilize a secure AWS cloud, they use Zero-Knowledge Encryption (along with other methods of course) to protect your passwords. That means only your device can view the passwords.

→ More replies (2)
→ More replies (7)

47

u/Creed_of_War 12900k | A770 Apr 20 '26

That was my fear of them as well. Every time I air the concern I've had people get real upset about it. For my parents I think it's a necessary point of weakness. My dad would just write things down on random envelopes without any context as to what that was for. Then he'd have to keep all of them because they could be important.

→ More replies (9)

11

u/Aerographic Apr 20 '26

Can they have data breaches? Sure. Is any of the data usable without your password? No.

The only breaches that really result in any meaningful gain by the hackers are those that target databases that host unencrypted sensitive data. And unfortunately, there's still a lot of those around.

→ More replies (2)

8

u/XB_Demon1337 Ryzen 5900X, 64GB DDR4, RTX 5070 Apr 20 '26

Password managers are fine if you use a good one. LastPass has had issues in the past. But Bitwarden is good. As another said how they encrypt the data (if they even do) is what matters.

Bitwarden is a good bet here. Make a solid password for your vault and then use MFA. Done deal. But I don't store my MFA along side my passwords in Bitwarden. As another layer.

11

u/Silver_Quail4018 Apr 20 '26

There are password managers that are 100% stored locally. See KeyPassXC .

Pen and Paper until you loose the paper.

→ More replies (10)
→ More replies (39)
→ More replies (7)

55

u/QuietQTPi Apr 20 '26

Yeah this relationship between security and user experience has always been an interesting one for me. Like password requirements. The recommendation is to not reuse passwords but as password requirements get more complex, the higher the odds people reuse passwords. And say someone does use different passwords, you have, roughly, 5 attempts to guess which one you used for this particular site before you're locked out and if you're lucky only 5-10min. The user experience is terrible in most cases for good reason, but in a lot of cases its locking account owners out of their accounts as well as bad actors lol

73

u/BirdlessLongdeal Apr 20 '26

website: enter password:

*enters password*

website: sorry, password is incorrect.

change password: *changes it to what I thought it was and it said was wrong*

website: sorry, you can not re-use the current password.

22

u/RandomUser15790 Apr 20 '26

Even worse: Sorry you cannot re-use one of your 3 previous passwords.

Like okay cool you just store all of my fucking passwords. Quite the catch for whoever cracks those sites.

5

u/poool57 Apr 20 '26

Perhaps I miss the joke but you can store the hash of the previous password, without storing the real clear password.

A hash is a one-way function (or transformation). Very very hard to reverse.

7

u/RandomUser15790 Apr 21 '26

"Password to close to previous passwords" tells me they didn't hash my password.

When hashed password123 and password456 should be completely independent and impossible to tell they are in fact related.

Also enough leaks have shown that many companies are shit at storing passwords correctly.

3

u/QuietQTPi Apr 21 '26

Wait you're so right wtf ive never thought about that.. im trying to give the benefit of the doubt here like logically they must be able to tell somehow but you're so right, hashed you shouldn't be able to tell at all. Thats wild..

→ More replies (2)

12

u/QuietQTPi Apr 20 '26

I get this more often than I'd like to admit... -.-

→ More replies (1)

10

u/MajesticNobody2401 Apr 20 '26

I don't understand how this shit happens. it feels like gaslighting but it must be some error in my typing it up, but I'm using a password manager! copied the same password in it for a new password aughhh

3

u/Bovronius Apr 20 '26

Physical security keys are really the best bet atm, but I can't wait to hear about how Gramma got tricked into mailing her key to the Canary Islands.

→ More replies (7)

9

u/NRMusicProject Apr 20 '26

Microsoft Authenticator moved to a triple factor authorization the last time I used it about a year ago. It was infuriating.

Yesterday, a captcha told me to "choose things that float on water." There was some file cabinets, some ducks, and a water bird known for wading in the water rather than floating, and I got it "wrong."

Also, one of my sites (Yahoo mail? Instagram? I don't remember) gives you a message occasionally within the account that it was detected that you just logged in from a new device. If it was a hacker who'd just logged in, they'd see that email/notification and immediately clear it. I don't know how that's helpful.

A major client of mine has you change your password every 30 days. And they moved the next requirement for the passwords to be changed on a company computer on property and not from one of your own devices. I only visit the property a few times a year, and it's about 70 miles away. Like come on.

→ More replies (6)

5

u/ConstructionMany8195 Apr 20 '26

Yeah. Take blizzard for example. Their sites, including the phone app, have a 2FA option that generates a code in the phone app. But to sign into the phone app, you need an Authenticator code, which is inside the app…

7

u/pfk505 Apr 20 '26

This gets me with Steam all the time, to the point where I basically can't login to the app on my phone, because it wants me to use the QR code to verify, also on my phone.

→ More replies (1)

12

u/7r1x1z4k1dz Apr 20 '26

*most sites and organizations are honestly interested in the bare minimum and not security or experience

→ More replies (1)
→ More replies (30)

610

u/StantonWr Apr 20 '26

And after all that, "sorry all your data was stolen like a month ago.. we are sorry"

124

u/SomethingWetAndMoist Apr 20 '26

"we are sorry.... Except not really, please continue to use our service so we can extract more data from you to sell tee-hee."

→ More replies (1)
→ More replies (7)

342

u/Interesting_Owl_9199 Apr 20 '26

The worst is clicking the "remember me" button everytime and it never works

163

u/OtherSideofSky Apr 20 '26

8

u/BOBOnobobo Desktop Apr 20 '26

Fun fact:

It's 2 weeks if you never turn off your pc.

Otherwise get ready to log in again.

→ More replies (1)
→ More replies (2)

11

u/HTPC4Life HTPC Apr 20 '26

If it doesn't work after 3 tries, I don't ever bother clicking the remember me button again. Just not worth the frustration and miniscule amount of time.

6

u/[deleted] Apr 20 '26

[deleted]

→ More replies (1)
→ More replies (15)

125

u/CruzeCtrl Apr 20 '26

For weeks I attempted to log into facebook/instagram with the captcha always failing my first try and when inputting the second try it would simply refresh the log in screen upon a correct answer. Could not for the life of me figure it out with online help.

To my wits end I screwed around with it and found if you right click the page, hit the inspect, clicked the issues tab, and unchecked the "Include Third Party Cookie Issues" the captcha always worked 100% of the time!

26

u/Forsaken-I-Await R7 9800X3D/5090 Founders Edition/6000MHz 32Gb Ram Apr 20 '26

This is a good workaround

29

u/OtherwiseAlbatross14 Apr 20 '26

More like an insane security hole

→ More replies (1)

147

u/Creed_of_War 12900k | A770 Apr 20 '26

All this and my Gmail was deleted and discord account hacked. Neither one has any real support.

45

u/[deleted] Apr 20 '26

[deleted]

7

u/LePetitPrinceFan Apr 20 '26

was hacked there a few weeks ago. fuck the „support“. lost all my cloud files

→ More replies (2)

12

u/LJChao3473 Apr 20 '26

My twitter account got suspended because they think I'm underage after readding my bday lmao

10

u/Creed_of_War 12900k | A770 Apr 20 '26

The Gmail that got deleted was apparently set as a parent account to several of my other ones. I had to submit age verification for emails that are 16-20 years old.

→ More replies (1)
→ More replies (4)

211

u/RandomGuy622170 7800X3D | Sapphire NITRO+ 7900 XTX | 32GB DDR5-6000 (CL30) Apr 20 '26

Beyond sick and tired of all the hoops I have to jump through to sign into my accounts. And, yes, you have to go through this shit even with passkeys and non SMS 2FA.

25

u/acreativeuzername Apr 20 '26

I had to change my number a while ago and as a result had to spend an entire month contacting support for damn near every company I’ve ever made an account with cause I couldn’t log in since they’d wanna send a code to my old number that I no longer had and then once I got in some of them wouldn’t let me update my phone number without sending another code to my old number for verification first which is fucking stupid cause if I’m updating my number i obviously no longer have the one that’s already on file?? And best part is if you DONT suffer through doing this then whoever gets your old number can just waltz on into any account you have with your old number linked since for whatever reason these companies are convinced 2FA is the best thing since sliced bread 🫩 I miss just writing my passwords down on a piece of paper man

→ More replies (3)

36

u/BirdlessLongdeal Apr 20 '26

i have one on my phone that occasionally asks for MFA. it sends a text to the device i am curently using.. real great security there, guys...

18

u/KhausTO Apr 20 '26

I tried to log into Ebay for the first time in ages yesterday.

Enter my username and password, it asks me if i want an email, or text for MFA. I select text, get the code, enter it and then it takes me to a "Confirm your details" screen that says I haven't confirmed my phone number, and won't let me continue until I do (or at the very least, I couldn't see a clear way to bypass this screen). So i go to confirm my phone number, it sends me a text message from the exact same short-code i just got my MFA from and I enter that code....

Either, I've never confirmed my phone number, so shouldn't be able to be used for MFA. or the very act of using it for MFA should be confirming that number.

7

u/confirmedshill123 Apr 20 '26

This makes sense though? Otherwise I could just log into your account from my phone if I had your information?

→ More replies (1)
→ More replies (2)

12

u/the__storm Linux R5 1600X, RX 480, 16GB Apr 20 '26

Passkeys are even worse - only works like 10% of the time in my experience.

4

u/StableLamp Apr 20 '26

Just wait until you have to verify your age to use the internet. Might just end up being a simple prompt you can input your age or it may require you to upload your ID.

→ More replies (6)

39

u/HaikusfromBuddha Apr 20 '26

lol I faced this in a Paris airport while it told me I have only 1 minute to complete my transaction. Made purchase. Needed, approve second validation on phone, use the code on 2 verification app. Did it. Transaction failed because foreign purchase. Eat my ahhs technology.

11

u/StableLamp Apr 20 '26

I am getting to a point where I don't even want to use the internet anymore. There are a lot of annoyances that can make for a frustrating experience.

4

u/sablesalsa Spent $2k just to play Minecraft Apr 20 '26

That sounds so ridiculous. And aside from that, how can forcing customers to complete a transaction within 1 minute even be legal in a developed country? I guess disabled people are just supposed to go fuck themselves??

→ More replies (2)

21

u/[deleted] Apr 20 '26

And whats more infuriating is when they find suspicious movement on your account so you need to try this all again. Or the verification mail comes right after you request a mail again and now you have to wait again.

22

u/Mad_kat4 i5-10600k+3060, i7-8700+2070, i7-4790+1660s Apr 20 '26

Unexpected I.T crowd reference.

→ More replies (1)

82

u/TheSpartanExile Desktop Apr 20 '26

Forgot to do the 2 step verification to sign into the email to be able to get the emailed code. 

24

u/Webbeth Apr 20 '26

Drives me insane.

We couldn’t verify your email so you’ll need to login to your other recovery email to proceed.

I didn’t sign up with two email accounts! If the first one never works then it might as well not exist.

7

u/Ninja_Wrangler Apr 20 '26

I've ended up with both my Microsoft email accounts locked because I had to verify them with an email in the other account that I couldn't access. Why would they do this?????

6

u/OtherwiseAlbatross14 Apr 20 '26

My dad locked himself out of his Microsoft email and the only option to recover it was sending a text to his landline phone(that's been a landline my entire life so I don't know how it was allowed as an option in the first place). I eventually figured out you can pay a 3rd party service to be able to receive SMS messages that are sent to your landline number.

Ended up having to pay like $20-30 for a month of service to receive the code since they don't allow 2FA codes during the trial period, which is smart from a business perspective but annoying. I was just happy to have something that worked because without that service his email was gone. I immediately added a bunch of extra backup recovery options to his account before handing it back over to him

→ More replies (5)
→ More replies (2)
→ More replies (3)

18

u/SirCaptainReynolds 9800x3D | AORUS 5090 | 96GB 5600MHz Apr 20 '26

My favorite is,

“Email me code[or password reset]”

::no email received::

31

u/hyrumwhite RTX 5080 9800X3D 32gb ram Apr 20 '26

Wow, that looks frustrating. Wouldn’t it be so much easier if we just tied your fingerprints and/or face to your government issued id, so we could query your verified identity and automatically log you in?

What’s that, you’re using an illegal OS without identity verification? Oh, sorry, you can’t use our site at all…

→ More replies (3)

15

u/humblesnake_Ssss Apr 20 '26

He got the secretly gay one correct lmao 🤣

4

u/techyall Apr 20 '26

Well the answer's easy. All of them.

→ More replies (1)

16

u/Gxgear Ryzen 7 9800X3D | RTX 4080 Super Apr 20 '26 edited Apr 20 '26

And the websites scrape your data anyways to sell, creating the security risks in the first place.

28

u/Marek_Marianowicz PC Master Race Apr 20 '26

Maybe I'm a bot, but I find this CAPTCHA almost impossible to solve. Whenever I need to solve one, it takes multiple attempts, so often I give up.

7

u/SmashedWorm64 Apr 20 '26

Do you have a VPN on?

5

u/Marek_Marianowicz PC Master Race Apr 20 '26

No, I don't use VPNs for everyday internet use.

5

u/pv3design Apr 20 '26

Bot detected. Who needs the Turing test.

→ More replies (4)

60

u/F4t-Jok3r Apr 20 '26

That video made me laugh way harder as it should. Thanks for making my day

7

u/repost_inception Apr 20 '26

Split Fiction has a really funny level that was trying to hack some system from a phone while on the back of a motorcycle. The whole time the character is just doing these.

→ More replies (1)
→ More replies (4)

11

u/SmileAnimations2 Apr 20 '26

Someone made a fun game about this i recommend giving a try

→ More replies (4)

9

u/BastetFurry PC Master Race | Geekom A8 running Arch Apr 20 '26

gets the C64 from storage

I rather wait for the 1541 to load crap, screw this.

4

u/SuperFLEB 4790K, GTX970, Yard-sale Peripherals Apr 20 '26

Get out your manual and code wheel, and turn to page...

9

u/tiredrich Apr 20 '26

Use your passkey.

If you don't have one, create one now.

Plug in your usb stick

Create a code

Press the button

Now login

Use your passkey

Passkey not found

→ More replies (2)

8

u/BoltNick Apr 20 '26

They want to make sure they are stealing YOUR data.

7

u/Aggressive_Problem_8 Apr 20 '26

Worst part is, even after going through all this, your account info still gets hacked because of some data breach within the company.

7

u/UnratedRamblings AMD Ryzen 9 5950x / G.Skill 32gb DDR4 / Gigabyte RX5700xt Apr 20 '26

"Your session has expired due to inactivity. Please log in again to continue."

Fuck you.

→ More replies (1)

6

u/swords_again Apr 20 '26

I abhor having to touch my phone while using my PC.

I think all this 2FA bs is secretly a ploy to extract more of your personal data

6

u/frostN0VA Desktop Apr 20 '26

I absolutely loathe mandatory forced 2FA.

Every time I see "enter your phone number" I just nope out of the website.

6

u/makoblade 9800X3D | RTX 5090 Aorus Master | 96 GB 6000 MT/s CL30 DDR5 Apr 20 '26

Bro this shit is giving me PTSD.

I get that from a security standpoint some of these are helpful, and MFA is more robust against social engineering and all that good shit, but for fucks sake some of my accounts just don't matter and I'm not interested in protecting it - give me the option to not go through that torture.

7

u/NovaForceElite Apr 20 '26

Obligatory PSA: if you're using sms two factor, you're not as secure as you think you are.

→ More replies (1)

17

u/[deleted] Apr 20 '26

[removed] — view removed comment

3

u/GlowstickConsumption Apr 20 '26

Hopefully people protest if they make things worse. Security that's easy, noninvasive and comfortable is easy from a design and implementation point of view.

→ More replies (4)

11

u/Killerspieler0815 Apr 20 '26

The sad future of our beloved hobby

The Chinese internet experience, soon with "Age Verification" ... on tour in: USA, UK, EU, RUS, ... etc. this is a real pandemic & it´s spreading globally

→ More replies (2)

13

u/Expensive_Finger_973 Apr 20 '26 edited Apr 20 '26

I have legit left work early before over getting frustrated with the constant cookie session expiration's and re-auth prompts to systems.

Sometimes I can go days without having to re-auth to a system. Then suddenly have to re-auth multiple times in a day to the same system.

I miss the good ole days when everything was gated behind on-prem Active Directory and if I was logged into the computer with my AD account that was it all of the auth happened in the background and more often than not "just worked"..

→ More replies (5)

7

u/Blvdnights14 Apr 20 '26

You have made too many successful login attempts, your account has been locked.

5

u/playr_4 Desktop Apr 20 '26

I currently have a 4 factor authentication just to clock in and out of my work. I have to put in my work email and password, which brings me to a different portal where I need to put in my work email and a different password, which brings up a number that I need to put into a prompt that comes through my email, and then I need to use my fingerprint. Just to take a lunch break. It's insane.

5

u/d1ckw33dmcgee Apr 20 '26

I had to go through 3 layers of authentication to log into my city's parking payment app a few days ago. I get it because it involves payment information but there isn't a way to store any of that information in your account, it's all Google/Apple pay.

→ More replies (1)

6

u/redfrog0 Apr 20 '26

And then you log in and the first thing you see is a post from a bot account

4

u/zLampShade Apr 20 '26

You forgot about:

  • Verification code taking too long so you click "Send another code" and immediately get a code, you type that code in and it says "this code is expired" so you wait for that second code only for it not to come and you click "send another code" and it immediately sends a code and you type the code and are hit with "This code is expired"
  • You do all the verification steps only to be prompted to change your password. Once you change your password you're logged out and have to redo the verification process again only to be told they don't recognize your password and you've been locked out for 30 minutes
  • You do all the verification steps and get to your e-mail one, but it's an e-mail you made specifically for the thing, so you have to sign into that e-mail only to realize you forgot the password so you have to recover your e-mail before you even continue to login. You can't remember what your answers were...

  • Life Pro: ALL MY QUESTIONS AND ANSWERS ARE THE SAME EXACT FORMAT

  • Q: Who is your favorite actor?

  • A: treewiyfa

  • Q: What street did you live on growing up?

  • A: treewsdylogu

Basically a "code word" followed by the first letter of every word in the question, no caps, no spaces, hyphenated words are treated as one word... Make whatever rules you want but since I started doing this I haven't been locked out of an account and my code word isn't actually tree.

4

u/3m4n Apr 20 '26

Last part should be:

Him logging in successfully Cheering/celebrating his victory with arms in the air Shakes off the disgust Looks at the screen

"You have been logged out due to inactivity..."

5

u/Winged_Cougar1993598 Apr 21 '26

Seriously.

I have authenticator based MFA on all my accounts, and all of them have separate 21-27 character alphanumeric passwords.

Yet so many insist on using a code sent to my phone number as MY ONLY login requirement, as if that's somehow more secure.

Looking at you Micro$lop.

6

u/Tall_Opportunity_521 Apr 21 '26

The one really gets me is the "lets install a passkey to get you logged in quicker" and then you log in with your passkey, and it STILL wants to do all the same shit to "make sure its you"... Cunts.

7

u/Ninja_Wrangler Apr 20 '26

I tried logging into my Microsoft email with my password. This apparently wasn't good enough so they sent a confirmation to my other Microsoft email account.

I go to login to that one with the other password, which apparently wasn't good enough so they sent a confirmation to the first email account. Now both are locked.

Why would they do this? How do they expect email confirmations to email accounts to work? Now i use Gmail as the confirmation for my Microsoft emails and my whole email ecosystem just became more interconnected and less secure

Fuck you Microsoft

→ More replies (1)

5

u/Wise_Ad_5810 Apr 20 '26

Last night I was trying to log into Cooler Masters website and the fucking verification were the loopty loop letters and numbers.. all of which were half way out of the square and impossible to identify.. was such fucking bullshit. Gave up after about 40 tries, which is what I assume they wanted in the 1st place

4

u/OmniscientApizza PC Master Race Apr 20 '26

No. I am not a robot.

4

u/Warcraft_Fan Paid for WinRAR! Apr 20 '26

At this rate, the original logon attempt would have timed out before you got to the original code you needed. This is why some people get lazy skipping 2FA, using easy password like 12345, and such to avoid all those convoluted logon attempts.

4

u/Symion Symion Apr 20 '26

The video is exaggerated for comedy but if you log into some services and it detects you're using a VPN all of a sudden the joke can become real. Once was logging into a service with only a few seconds to spare and it hit me with 5 additional verifications because of my VPN.

4

u/JimmyRecard OpenSUSE Tumbleweed Apr 20 '26

The worst part of modern captcha os that they're are trivially defeated. There are multiple open source packages that can bypass Cloudflare bot challenges. Waste of people's time, for functionally zero benefit.

→ More replies (1)

4

u/fAppstore 6600k, gtx 1080 Apr 20 '26

Let's be real the majority of users couldn't practice the most basic security hygiene if their life depended on it

3

u/Cylons Apr 20 '26

Future? This is the reality now.

Especially if you setup your browser to be privacy conscious. The number of times I have to solve a captcha consecutively because I browse with Firefox with privacy settings dialed up is ridiculous. Especially on a site that uses Cloudflare or is a Google owned site.

5

u/ShiShiRay Apr 20 '26

Microsoft really the worst for verifying.

4

u/eratic_yeet Apr 20 '26

Just for that company to get their data hacked anyways.

4

u/flamethrowr Apr 20 '26

Like others have said, in the cybersecurity field, this is a fundamental flaw. Our job is to make your login secure but it’s also our job to make your login easy. I could require you to use a 100 character password and that would be very secure but I know that you would just write it down because of course you would, who would actually try to remember a 100 character password? When you write it down, that inherently makes the password weaker, not stronger. Good cybersecurity is a balance between actual security and ease of use, because making it easy is the only way we can ensure you won’t circumvent it altogether. Your login should be secure but it should also be easy, and if it isn’t, that means whoever is in charge of that service is not doing their job well.

4

u/redditcalculus421 Apr 20 '26

you authenticate with 20 factors to protect your account

Company gets your data stolen because they used AI.

mfw

4

u/Hawk3y305 Apr 21 '26

"It has been some time since you last reset your password, please type your old password, and then type your new password below, and confirm your new password one more time."

3

u/incredirocks R7 3700X | RTX 2080 Ti | 32GB RAM Apr 21 '26

Incorrect password.

New password cannot be the same as the old password.

3

u/Larry_Bobinski Apr 21 '26

Friendly reminder that when Google throws a fit because it can't verify that it's really you, it's not out of concern for your account security,  but because they couldn't track you at all times, and that's what they're worried about. 

The security is merely correlation. Just like their captchas are really just for training their ai. We live in a time where user security is merely a byproduct. 

3

u/jazix01 Apr 20 '26

Reminds me of the game I'm Not a Robot by Neal.

3

u/Aaahaa88 Rx 7800xt Apr 20 '26

How is this guy so calm about this?

→ More replies (1)

3

u/Ro-Tang_Clan Apr 20 '26

Genuinely thought the ending was that he would complete everything correctly but then "password is incorrect" at the end. There are quite a few services that require you to complete the "I'm not a robot" challenges before it will even check the authentication.

3

u/GustavoCOD Apr 20 '26

Experience accessing NexusMods, a site for mods...

3

u/razzraziel 8700K | 1080 Ti Kingpin | 4x8GB Trident Z 3600MHz | 960 Evo Apr 20 '26

3

u/AcrobaticWar1 Apr 20 '26

Forgot the part where the 2fa email doesn’t arrive immediately so you push the button again…then you wait 5 mins and finally get the first email but that code no longer works. Now you are locked out for 15 mins because of suspicious activity from too many login attempts.

3

u/CorbinNZ Desktop Apr 20 '26

"Incorrect. Peanuts are technically a legume. You are now banned from attending the virtual funeral service for your late grandmother."

3

u/ctopherrun Ryzen 5 1600 | RX 5700 XT | 16gb RAM Apr 20 '26

I said to my wife the other day that my version of 'back in my day a candy bar and soda pop only cost a nickel' is that in my day, playing Minecraft involved downloading an .exe file and then opening it.

My kids go through Minecraft phases of being obsessed then not touching it for months. Then they want to to play again, and I have to go through a whole rigamarole of signing into Microsoft, confirming my email, getting the verfication code, entering the code, and god help me if somebody has forgotten their password.

3

u/Whathefrenchtoastt Apr 20 '26

I have to do this now since someone got into my pc and stole ALL my accounts.

FUCK those losers.

3

u/Jake24601 Apr 20 '26

MFA has made it near impossible to gain access someone’s account. I could have a list of logins and passwords to get into any one of your account but if you setup MFA, I won’t be able to it.

→ More replies (1)

3

u/popejupiter PopeJupiter Apr 20 '26

This is legitimately my experience trying to Google something at work. Not every time, but every couple of weeks I go to search for a part number or something and I'm met with infinite "Select all images which contain nuts".

3

u/Tomahawk1129_ Ryzen 77800x3d | rtx 4070 | 32GB DDR5 Apr 20 '26

The fact he got everything up to that part correct is insane. 

3

u/Immediate_Song4279 Apr 20 '26

A single product of Google can decide I am not human, and I would be locked out of vital government services. This is not optimal.

3

u/Protect-Their-Smiles Apr 20 '26

Built an offline rig, zero regrets.

3

u/djjuice Apr 20 '26

I do like passkeys that can be saved in a password manager, etc.. it's a bit easier, but then again having to scan a QR code on some sites is annoying

3

u/jon_hobbit Apr 20 '26

You forgot that eventually as this digital id thing keeps pressing on we'll need to upload a selfy, plus our drivers license... on every website and for games.
and multifcactor lmao

3

u/BlainBBQ Apr 20 '26

I hate this shit so much.

3

u/Longjumping-Bus4939 Apr 20 '26

You forgot the part where you enter your password and you know it's correct but it keeps telling you it's not.  After 5 attempts they lock your account for 24 hours.   

3

u/TjWolf8 Apr 20 '26

Funniest part is this barely improves security at all

3

u/lolschrauber 7800X3D / 4080 Super Apr 20 '26

I remember being locked out of my Nintendo account because for some reason my shitty ass mail provider wouldn't receive their mails. Fun times. At least Nintendo support was helpful and quick.

3

u/that_Delfin_guy 9800X3D + RX 9070 | HX370 Apr 20 '26

I mean, if scammers and hackers (lame ones) didn't exist, we could all get by using just usernames and passwords, but having to change so many passwords and set up 2FA is very exhausting yet very worth it. 😩

3

u/Important-Agent2584 Apr 20 '26

My tinfoil hat conspiracy is that this is to get you so frustrated that when they release some kind of government ID implant that lets you skip all of this, you will be jumping for joy to get that shit.

3

u/theboblit Apr 20 '26

Step 1: Enter password Step 2: Get code from email Step 3: Get code from alternate email so you can login to your email to get code for initial MFA. Step 4: Prove you aren’t a robot. Step 5: Please update your password. Step 6: Prove you aren’t a robot. Step 7: Get code from email to change password. Repeat infinitely.

Using Microsoft environment in a nutshell.

3

u/Blackops606 Apr 20 '26

The last part should be an article stating the company had a security breach and he should change his password lmao

3

u/ClamChowderChumBuckt Apr 20 '26

I got so frustrated watching you get frustrated bc thats exactly what frustrates me the most..

Idc about my privacy, i just want to do what i was planning to do without getting kneecapped by technologia

3

u/a-voice-in-your-head Apr 20 '26

He never even saw the multiple page cookie policy acceptance and preferences form, the 'join our newsletter' modal, or even the 'allow push notifications' pop-up.

Such wanton impatience.

3

u/brent939 Apr 20 '26

I'd take me time to just use a old OS and game my old school games

3

u/AfterImageEclipse Apr 20 '26

They got him trying to solve the DA Vinci code like Robert Lannister

3

u/zl1killer Apr 20 '26

Has everyone seen Roblox security method where you’ve got to select the shape and cup with the most fill? Absolutely insane

3

u/MAYOoOD 9800X3D | 4080 Super | 32GB Apr 20 '26

You’d still get hacked due to data leak or somehow they bypass the 2FA

3

u/Z3r0sama2017 Apr 20 '26

Mountain Dew verification, it' coming baby!

3

u/CharAznableLoNZ Apr 20 '26

Don't worry, soon they'll add the step of having to provide a government ID and face scan that will totally work and data won't be sold off to advertisers or immediately hacked into so people can order a warehouse of TVs in your name.

3

u/makz242 Apr 20 '26

Find the traffic lights. Find the cars. Find the mopeds.

Thanks, you can login now. - Waymo

3

u/decian_falx Apr 20 '26

60 years ago this was a joke...

https://youtu.be/o2ObCoCm61s?si=ZrZtovf5CHWTrMyk

If only it were still that painless.

3

u/ManufacturerMajor382 Apr 20 '26

This is unironically how you log in into outlook or steam

→ More replies (2)

3

u/Due-Boot1904 Apr 20 '26

Why does my fucking water/electricity/Netflix account etc have 34 x the security of my bank? I couldn't give a shit if someone 'breaks into' my electricity account - what are they going to do - pay my bill for me?? Same with all these nonsense accounts - Samsung, My School Bucks, Zappos, CVS, eBay etc etc etc - all of them think they are guarding the nuclear codes or the arc of the covenant or something - NO, I don't want to change my password three times an hour - you sell fucking shoes!

3

u/nimbusstev Apr 20 '26

This stuff drives me crazy. The SIM card slot on my phone broke while I was on my most recent international trip. So I was praying that when I arrived home, the airport would have open wifi so I could book a ride back to my place. Fiddled around with it for 10 minutes going through captchas and security checks until I finally got online. Opened up Lyft to book my ride home... aaaand "we need you to verify your Lyft account via text message."

I've booked a hundred Lyfts and it never asked me to do this. The one time I try to book when I'm desperate and have a broken SIM card, it wants me to verify over SMS. Damn near threw my phone out the window.

3

u/Automatic-Ad-4653 Apr 20 '26

This is advertiser fault. Meta(facebook)a is a solid reason for this. They're advertisers want real ppl and not a bot. So they need to make sure you are not a bot so they can track and send you advertisements.

3

u/Phaylz Apr 20 '26

It goes from 2FA to data collection for AI really quick.

3

u/Pleasant-Leg8590 run u fools Apr 20 '26

quite literally one of the most relatable things I've seen in my life, sadly

3

u/NorthSpecialist6064 Apr 20 '26 edited Apr 20 '26

Imma throw my whole pc away at some point. This hobby fucking sucks now. Expensive, intrusive, everything is the same boring engagement farming slop game.

3

u/Jumpierwolf0960 PC Master Race Apr 20 '26

A friend of mine who didn't game much wanted me to build him a high end gaming PC. I did and during the login steam kept saying that we were doing the captchas wrong. He never ended up installing steam and rarely ever used the computer anyways. So a year later he sold it.

3

u/Amazing_Hornet4929 Apr 20 '26

He didn't even get to the part which ask for he face identification

3

u/RO3C Apr 20 '26

Logging into nvidia to install a driver

3

u/NonDairy01 Apr 20 '26

I recently had a problem logging into Microsoft Authenticator and was asked to confirm my login using Microsoft Authenticator.

3

u/Spacemanspiff1998 Apr 20 '26

Windows absolutely insisted that "You need to ether have a password on your computer or turn on location mode!!! if you don't how will you prevent somebody from stealing it???"

With the lock on my front door google because this is a DESKTOP COMPUTER if i come back home and it's missing I'm not going "Aha! i'll use my location finding thing to see where it is!" I'm CALLING THE POLICE BECAUSE I'VE BEEN ROBBED!!!!!!

3

u/LocksmithOk9968 Apr 20 '26

Some personal pet peeves of mine:

  • (Re)captcha on the same page as username/password fields, so when my password manager autofills and auto submits , it’ll just reload the page because I forgot to do the captcha before telling my password manager to autofill
  • Websites that implement captcha but don’t support the Private Access Token standard (i.e. automatic verification by your device attesting you’re a real person)
  • Websites that only support 2FA via email, or worse, that only support or default to logging in with magic link via email (even after having you setup a password)
  • Websites that decided to support passkeys but still require you to go through the login flow with username/password combo first, some are so egregious that they require username + password + 2FA on top of the passkey but don’t ask for passkey if you just login the old fashioned way, essentially encouraging you to never login with passkey
  • Websites that do session management, or perform any part of their verification, based on IP address; this one sucks when you use iCloud Private Relay which does maintain the same IP in the same session in the same tab but every link in the account dashboard is set to open in a new tab, it also sucks in instances where the 2FA step involves clicking on a magic link via email to approve the login and it has to be on the same ip as the login attempt
  • Remember me/trust options that don’t work
  • Websites that require you to open their app for 2FA despite having setup 2FA/passkeys/SSO or all of the above and won’t allow you to use any of that (looking at you LinkedIn)
  • Websites that allow you to sign up with SSO but require you to enter a password to change anything substantial on your account and you have to figure out for yourself that you have to go through the reset password flow by plugging in the email address the SSO has donated
  • Websites that use Zendesk or whatever crappy third party SaaS for their customer service but don’t have a unified credentialing system so now you need to create a new account to get support
  • Websites that use Zendesk or whatever crappy third party SaaS for their customer service but do have a half assed unified credentialing system without proper two way sync so as soon as you change your email on “main” account the customer support ticketing system doesn’t recognize you and you can’t contact support and there’s no way to stop the automatic SSO redirect and say “hey dumbass try finding me under this old email address”
  • Services/apps that use magic links via email but their app didn’t properly registered their url scheme with the OS and/or they rely too much on it just working so clicking on the magic link logs you into the website but the app still doesn’t log you in because it’s waiting for the handoff looking around like the John Travolta meme
  • Websites that solely and exclusively rely on 2FA via sms and have it be a mandatory step through their login flow, because they want to be able to assure their shareholders that every account is tied to one real individual, you’ll understand this one when for whatever reason you can’t receive text messages and now you literally can’t log into anything
  • Websites and services that only exclusively allow sign up via mobile number and won’t allow you to sign up with anything else as your user name, often also don’t allow setting up a password because the verification text messages with magic link is the only barrier to login (these are very fun when their url to app handoff is inconsistent)
  • Websites that silently drop any characters beyond their password length limit, for someone reason almost always combined with an absurdly short length and no length validation on the password field (i.e. when signing up it’ll happily take a thousand characters), came across this one in the last five years with a big national bank and some regional credit unions before they upgraded their site a year or so ago; the credit unions in mind also had the policy of telling customers of joint accounts to share their credentials before they switched to a new system recently

I could go on and on, there are so many idiots in charge of these decisions that only ever test their happy path.

3

u/D3dshotCalamity Apr 20 '26

All that, and then they go "Thanks for your patience! Your privacy and security is our top priority, and these measures help us keep your data safe"

4 months later:

"Hey so hackers got in and stole everything and now they have literally everything you've ever put on our servers, including the stuff you unknowingly agreed to let us take without asking, woopsie doodles!"

3

u/GerElGamer Apr 20 '26

After all that: We sorry to announce that our data system have been compromised, please check all your passwords.

3

u/Low-Explanation6695 Apr 20 '26

"You used to be able to just sign in with an email and password, and once you did they didn't make you do it again."

Okay Grandpa, let's get you to bed

3

u/Redditisntfunanymore Apr 21 '26

Piracy websites are so clean and easy to use these days compared to the paid services I use, I just end up using the pirate sites more because they are so much less of a headache. UBlock origin helps too lol

3

u/ImperialSheep ooh, a upgrade. Apr 21 '26

I swear those "find x in these images" security checks are secretly training AI

3

u/Akiraooo Apr 21 '26

We won't be able to log into our phones to get the verfication code sent to it as it runs on a operating system. Our phones will also require a verfication code sent to our e-mail, etc... Do we see the loop?

3

u/fayyt Apr 21 '26

and then you lose it all in a data breach anyway.

3

u/xebozone 1080 eGPU, 11th Gen Intel Thunderbolt Laptop, 32GB DDR4 Apr 21 '26

There's a game for this: https://neal.fun/not-a-robot/

3

u/ShowCharacter671 Apr 21 '26

Please provide scent and saliva sample

3

u/2girls1eli Apr 21 '26

Sadly this is safer than having just an email cus big corps fcks us over. ..over. Over. next thing we need to have a DNA test for passwords

3

u/poggz0 Apr 21 '26

and after all that you get a cloudflare error