leyrer @leyrer.bsky.social · 30/06/2026Developers and UI/UX designers that split username and password prompts into separate steps should be forced to log in every 5 minutes. #rant 461073111
Mr. Surly @nuancesystems.com · 30/06/2026"Oh, you haven't logged in for a week. Now you have to go check your email for a code we just sent!" Fuck ALL the way off. 010
Lothrazar @lothrazar.bsky.social · 30/06/2026really i kind of like it. especially when it remembers my username. also it supports different OTP layers and user strategies 010
Snapple Caps @kristianne411.bsky.social · 30/06/2026noooo no I think just add a captcha before every page load 110
sister_sam @privacy-nut.bsky.social · 30/06/2026Among other things it breaks password manager extension bring up the correct credentials. 000
FemBotsUnite @fembotsunite.bsky.social · 30/06/2026And also maybe they can explain why every single site or app needs a hidden password field at login (and in-app), as if every user in the world always has a would-be hacker looking over the shoulder. (PSA: this is not how hacking has ever worked.) 3152
Matt @notdanish.bsky.social · 01/07/2026Let's not forget the absurd requests to type only the 1st, 4th and 9th digits (e.g.) of my PIN, thus forcing me to write it down and count. 000
No Sheds @nosheds.bsky.social · 30/06/2026Especially if the dialog box looks exactly the same. If, due to typos on unfamiliar keyboards for example, you try to log in multiple times, and get confused as to if you're typing username or password, you can put the password as the username & vice versa. ... 120
TankFu (Gamer) @tankfu.bsky.social · 30/06/2026static.klipy.comThank You Michael ScottALT: Thank You Michael Scott 000
Tim Wiederhake @twiederh.bsky.social · 30/06/2026And Sourceware still makes you email their admin to ask for an account. I wish we had an SSO option that is not (indirectly) owned by some government or big advertisement networks. 000
Cranky Northerner 🇨🇦🇨🇦🇨🇦 @thunderbuck.bsky.social · 30/06/2026And WHY do developers not use the email mask on email entry fields? It’s such a tiny, easy-to-implement setting that it irks me when it’s set as a straight text field. 000
Whoa Sopaipillas! @whoaaaasopaipillas.bsky.social · 30/06/2026static.klipy.comThe Good Place AnnoyedALT: The Good Place Annoyed 030
armyguy8382.bsky.social @armyguy8382.bsky.social · 30/06/2026Yes. And same with the ones that put the cursor in the password box instead of the username. Pisses me off so much when I log into my PC at work. It isn't a big deal but just unnecessarily annoying. 000
Michael Geutebrück @michaelgeutebrueck.bsky.social · 30/06/2026Or when you hit enter to login, but have to push the login-button. Or first hit tab, then enter. It's equally annoying. 010
JPWKeeper @jpwkeeper.bsky.social · 30/06/2026So should the website designers and security "experts" who insist on having a password that has at least one each of a lowercase, uppercase, number, symbol, emoji, and Klingon character. NIST hasn't recommended that for password security for over a decade. Secure passwords are just long. 011
Doris @dorisfornow.bsky.social · 30/06/2026Hi. This question is off-topic. Was this self-made: "𝘛𝘩𝘪𝘴 𝘶𝘴𝘦𝘳 𝘪𝘴 𝘴𝘶𝘴𝘱𝘦𝘤𝘵𝘦𝘥 𝘰𝘧 𝘣𝘦𝘪𝘯𝘨 𝘱𝘢𝘳𝘵 𝘰𝘧 𝘢 𝘵𝘦𝘳𝘳𝘰𝘳𝘪𝘴𝘵 𝘰𝘳𝘨𝘢𝘯𝘪𝘻𝘢𝘵𝘪𝘰𝘯 𝘤𝘢𝘭𝘭𝘦𝘥 𝘈𝘯𝘵𝘪𝘧𝘢. 𝘗𝘭𝘦𝘢𝘴𝘦 𝘳𝘦𝘱𝘰𝘳𝘵 𝘢𝘯𝘺 𝘴𝘶𝘴𝘱𝘪𝘤𝘪𝘰𝘶𝘴 𝘣𝘦𝘩𝘢𝘷𝘪𝘰𝘳."? 100
Stephane "Rainlife" Vanraes 🦄 @arzidava.com · 30/06/2026The actual worst is when after entering the username it tells you the username does not exist or redirects to a sign-up page. That is actual a massive privacy/security issue. 1361
buildaditya.bsky.social @buildaditya.bsky.social · 30/06/2026i'd also add the PM who approved it 😭 there's no reason entering an email needs to feel like progressing to the next level in a video game 110
Antilles @wedgeantilles.bsky.social · 30/06/2026Just had to change my password on some site for whatever reason, google’s suggested strong password was one character short of the required 16 characters, so that was fun 000
Mace Moneta @macemoneta.bsky.social · 30/06/2026With Timed One-Time Passwords where each digit is in a separate input box, that doesn't handle a paste properly, so the whole TOTP pastes into the first box, forcing manual entry. Of course by the time you realize it, the timer has expired, so you have to switch back to the TOTP app and try again. 0602
Tait van Strien @handle.invalid · 01/07/2026It's a 2 step because organisations want to use their single sign on portal. As such we read the user on first input and either redirect to SSO or password Auth. 190
thisisfranciswu @thisisfranciswu.bsky.social · 30/06/2026Usually it’s for Single Sign-On. The system needs to know who you are in order to route you to the appropriate sign-in method. This is often true in enterprise settings where your credentials are shared across multiple systems. 110
jenc @jenchan.biz · 30/06/2026Let's not forget those ones who custom design datepickers or form validations 020
Brian Stork @rhetoricalanswer.bsky.social · 30/06/2026I'm convinced passkeys are the way to go. I don't want another password. 030
Kevin @atomic-startup.bsky.social · 30/06/2026Just implemented this last night with a popular service provider (Clerk), and discovered that this is default behavior that is not easily changed without risking a fragile implementation. 100
haltroy @haltroy.bsky.social · 30/06/2026my uni does this all the time and theres not a single password manager that can autofill correctly, even the ones that are built ın to browser itself and it pisses me off i just set it to a single simple and kinda safe password and type it by hand nowadays 020
BENgalTiger 🐯 @bengaltig3r.bsky.social · 30/06/2026static.klipy.comRight to Jail, Right AwayAlt: Right to Jail, Right Away 010
muesliman.bsky.social @muesliman.bsky.social · 30/06/2026exactly! There is no valid reason, and the browser's autofill feature gets confused 100
Jim Murphy @jimmurmac.bsky.social · 30/06/2026As someone that made a living working on security software, it really is time for us to move to something along the lines of a Yubico security key. They cost about $60 and allow for logging in without a password. Very secure and much less hassle. Just my 2 cents. 770
Pfiffiges IT-Frettchen @it-frettchen.de · 30/06/2026You nailed it!static.klipy.comWoman Points to 'THIS'Alt: Woman Points to 'THIS' 020
Brian Plester @brianplester.bsky.social · 01/07/2026Likewise with log-on pages which don't put the cursor on the username field. 000
Bill B @ldroadie.bsky.social · 30/06/2026Using a browser to keep track of your logins and passwords makes life easier. Especially one that differentiates UID and PW prompts. 000
adarkfable @adarkfable.com · 30/06/2026I should be able to bash my head against my monitor in frustration, and that count as my passkey. maybe they can count my forehead wrinkles or something. 000
rynther @rynther.bsky.social · 30/06/2026With a new password every hour, and you can't use any of the last 30 passwords. 000
Ryan Germann @ryangermann.bsky.social · 30/06/2026It'a probably thought to "enhance security" but very easily circumvented by malicious actors with intent. Like the foegot password "enter your email and IF your email exists we will send a link". Just say "no such email exists". 110
Scenario @scenario-studios.bsky.social · 30/06/2026Yes. Or those who turn FaceID/TouchID into a multi-step process. Apple has done a shitty job enforcing that. 000
Ian Spencer 🐧 @ian.spennys.world · 30/06/2026I'm using a SAP* system that: Prompts for user name (at least it remembers that). Next asks for sort of confirmation to be used. Select Password (or OKTA or email link). Third screen: Enter password. Fourth screen: enter OTP *Say no more. 010