All 2FA is security theater. All 2FA in use today is normally just 1FA pretending to be 2FA. If I have your phone, then I have everything I need to login. That's 1 factor. 2FA is only 2FA if the physical device ownership requirement does not have access to use the thing being accessed. Why? Because you store passwords on that device. That device has your password. If I have the device, I have your password. You would have to use no auto-fill and memorize your passwords so that the physical device does not have your password in it. The point is, if I get one factor, I don't have the other. But in reality, our physical devices can access the thing we want, and therefore you likely store your credentials on that device.
Good you shouldn't be using them. You shouldn't be using foreign keys either. It just makes working with data harder and doesn't help with constraining it if your data modifications are inside transactions and properly written statements.
It's because you're getting passed the point of having simple questions. Once you get to a certain point of understanding, there is less available online for shared problem solving. This just happens.
My app has been removed from youtube oauth multiple times because we keep getting different verifiers. We've even had permission revoked after being approved. All we do is use a oauth to get their userid and read their livechat for a chatbot. They just can't get their shit together.
Yes there is. A computer counter is worse than a computer ballot printer. You have to have it as distributed as possible to make it as expensive as possible. A single counting or handful of counting machines makes it one machine to take over to do anything you want.
This happened to me directly on Logitech's website. It's why I'll never buy their products again. I received a wireless headset that didn't keep a full day charge longer than 30 minutes. I had to use it plugged in (powering) 24/7. I submitted a 1 star review stating my problem and they removed my feedback without even telling me. It was just gone a few weeks later when I checked it, hoping they hadn't removed it.
It doesn't have built-in websocket support so it can F off. Build better dev tools and feel bad. Even the plugin that used to be usable isn't supported on the new FF.
Why does this guy think that JWT tokens secure against CSRF? They're unrelated. This scares me. I want to know what projects he works on so I can avoid them. Not knowing something is insecure is one thing, but knowing that it's insecure scares me.
This is correct behavior in lots of places. It's safer for when turning right to have a biker wait for you to turn. They have no right to "go first" unless they are already in the lane beside you or in front.
You know what's worse? Full-stack architects. It doesn't seem very plausible that someone has all the knowledge in both the now very complicated front-end and back-end stacks to be a proper architect.