Yeah, I have never understood the over reliance on AI. Writing the code is not the challenge. The time it takes to push a new feature and test it out is often trivial, maybe a few hours.
The real challenge is forming the new ideas in the first place and most of those new ideas coming either from using the code as a product or time spent maintaining and refactoring large code.
Anyways, if you want to continue on the path towards regaining control and take it to the next level I wrote something similar here: <a href="https://blog.sharefile.systems/be-brave-go-low/" rel="nofollow">https://blog.sharefile.systems/be-brave-go-low/
Wriring the code is not the challenge, but it's what was taking up most of the time. Not the typing itself, but also because I had to think of how to implement it.
Now I can just say "add 2FA" and in 5 minutes, while I test something else, it is done.
It also made iterations a lot faster, you can try something out, see how it feels, if it doesn't work, you can just trash all the code and start again.
I don't know what it built for you in 5 minutes, probably something that "works".
I have spent two weeks using opus just to write a plan/design for 2FA and iron it out until review (about 7 of them) doesn't flag it with 20+ problems (with security holes of various sizes), for which I had to guide it through to not turn it into a mess and whac-a-mole.
It's just a secret key that an autheticator uses to generate a time-based code, which the app can validate before completing a normal log-in flow.
What model did you use?
Astra xhigh on fast mode can probably indeed one-shot that in 5 minutes.
Plus optionally QR image generator to easily add that key to the authenticator app.
There are already many libraries doing 2FA, but implementing it in any language is quite trivial, right
Aside from the fact that the implementation must be secure, you want for example to:
- handle accounts that have lost their second factor in an way appropriate for your business
- decide what to do with accounts who don't configure it. If e.g. you want to send them authentication codes via email or SMS that's another can of worms.
Let alone the simple things such as making sure that your implementation works with the various TOTP apps
austin-cheney · · focus · HN ↗
The real challenge is forming the new ideas in the first place and most of those new ideas coming either from using the code as a product or time spent maintaining and refactoring large code.
Anyways, if you want to continue on the path towards regaining control and take it to the next level I wrote something similar here: <a href="https://blog.sharefile.systems/be-brave-go-low/" rel="nofollow">https://blog.sharefile.systems/be-brave-go-low/
XCSme · · focus · HN ↗
Now I can just say "add 2FA" and in 5 minutes, while I test something else, it is done.
It also made iterations a lot faster, you can try something out, see how it feels, if it doesn't work, you can just trash all the code and start again.
aytigra · · focus · HN ↗
I have spent two weeks using opus just to write a plan/design for 2FA and iron it out until review (about 7 of them) doesn't flag it with 20+ problems (with security holes of various sizes), for which I had to guide it through to not turn it into a mess and whac-a-mole.
XCSme · · focus · HN ↗
It's just a secret key that an autheticator uses to generate a time-based code, which the app can validate before completing a normal log-in flow.
What model did you use?
Astra xhigh on fast mode can probably indeed one-shot that in 5 minutes.
Plus optionally QR image generator to easily add that key to the authenticator app.
There are already many libraries doing 2FA, but implementing it in any language is quite trivial, right
n_e · · focus · HN ↗
No?
Aside from the fact that the implementation must be secure, you want for example to:
- handle accounts that have lost their second factor in an way appropriate for your business - decide what to do with accounts who don't configure it. If e.g. you want to send them authentication codes via email or SMS that's another can of worms.
Let alone the simple things such as making sure that your implementation works with the various TOTP apps
XCSme · · focus · HN ↗
One-time displayed recovery codes are a standard practice, and most good LLMs will add it by default without even asking for it.
And yeah, I am talking about TOTP apps, I think sms/email is not as secure.