Live data from Hacker News

Short session expiration does not help security

sjoerdlangkemper.nl

261–270 of 434 posts

Re: Short session expiration does not help security

#261
post #163
post #149

Earlier quoted context omitted.

>There is a cost every time a user has to re-authenticate. There is a cost in resources to handle the extra authentications. There is a cost in complexity to maintain and extend the system doing authentication. I think this is definitely where the security trends in modern IT have gone very awry, as it _is_ extremely annoying to be an end user having to work with modern IT security practices. Off the top of my head:…

> if you have any issues with your alternative authentication devices, you are completely locked out of your work You have printed the rescue codes when prompted, and have put that physical piece of paper into your wallet, haven't you?

I have ~1000 accounts, ~200 of which are used for work occasionally. Their 2FA recovery methods vary, and some have no recovery method. I'd like to say my wallet is not large enough for the printed codes, but only about 5 accounts even offer backup codes, considerably fewer than the number of 2FA accounts.

Besides, my last Gmail account for work appeared to be locked to my phone and didn't accept backup codes, and was OAuth master to a number of other accounts.

(For real: I lost access to that Google account permanently when my phone screen stopped working due to an internal fault. It wasn't really a problem and I didn't pursue it fully because I left the job soon after anyway, but the fact I couldn't regain access during that time despite copying the broken phone's content to a new device which successfully transferred the 2FA codes for all other accounts, was striking. It's why I don't use Google for id when there's another option. I tend to use GitHub for id at the moment.)

Re: Short session expiration does not help security

#263

Earlier quoted context omitted.

I will posit this proposition: Short sessions are thinking like physical security. Someone can pick any lock, the question is will it take long enough for a human to interrupt the attack? It doesn’t matter how long a computer has access to the key. How fast it can cause damage is limited by the speed of light, not human fingers. If you ever leave the credentials where they are accessible, they can be used even if the…

> Machines hack differently than humans. An awful lot of hacking is done manually, by humans. For many scenarios, considering human timeframes is completely reasonable.

We live in a world where real time advertising auctions happen. If you think there’s something about that which can’t apply to organized crime you’re gonna be in for a rude awakening when your systems start to fail en masse.

I’ve had to replace a credit card twice for suspicious activity (once cost me my favorite domain name, which is still parked). There were no major charges in either case. One charge at a business I’ve never been to.

Some people get a card and use it. Some immediately sell it after proving it works. That means a clearing house. A food chain. That will get more automated, not less.

Re: Short session expiration does not help security

#264
post #8

> Also, it would be better to protect against this by securing the logs or using hard drive encryption. This one line is emblematic of the flaws in the article. My take on the article is, “Imagine that everything else in a system is done correctly, and the system, overall, is perfectly secure. In this imaginary world, short sessions don’t help.” One fact about security which you cannot avoid is that any one particula…

Fully agreed. Just because 1 security measure doesn't prevent all malicious attacks, doesn't mean that it "does not help security". It's just fundamentally false because some malicious attacks rely on long expirations, therefore for those attacks, this method does help security. Not all malicious attempts are refined or perfectly executed and sometimes a user can simply rely on a token that lasts too long.

It's a clickbait title and it worked. A title like this would be much more accurate: "Short session expirations provide less security than you might think"

Re: Short session expiration does not help security

#265

The main place I see short session expirations is on banking and financial apps, which seems defensible to me for a couple of reasons: 1) They're used by a wide variety of people, including people who may not own a computer or mobile device, or who may not have a backup device to use when their personal device breaks. This group is probably shrinking—more and more people have smartphones and the remaining people who…

> major corporations like Google don't use short sessions

Ask a Google employee. When I worked there sessions were limited to 20 hours. Beyond that full re-authentication with password + security key would be needed.

Re: Short session expiration does not help security

#266
post #262

This is total bullshit. Stolen sessions are being actively sold on Darknet in bulk. If nothing else the best thing that can happen is that they have expired before someone have the time to exploit them.

Totally agreed. OP has no idea the scale of account takeover attacks by stealing tokens for any large online service (Google accounts, iCloud accounts, Microsoft accounts, etc).

Re: Short session expiration does not help security

#267
post #226

Earlier quoted context omitted.

That's a nightmare process for any normal user. There's no way the vast majority of people are savvy enough to do this correctly.

Which part of the "click print, cut or rip out a corner, put it in your wallet" a nightmare for a normal user? (I'm not one, can't judge.)

I used to do something like this with my passwords. A folded, printed sheet with tiny font holding my accounts and passwords that I carried in my wallet. Eventually I found there wasn't enough space even on both sides of an A4 sheet with the tiniest legible text, and a full sheet was hard to fold small enough. The text got mangled in places due to crushing.

I think normal users don't have a printer or a nearby print shop in 2023. (For those with an inkjet printer, the ink has dried and the head seized up since they printed something last year.)

Many people, who I assume to be normal, don't have a wallet separate from their phone these days. They use virtual payment cards on their phone and store paper notes and if necessary cash and a payment card inside their phone case. Not useful for "lost my phone" recovery codes, terrible for "my phone was stolen" as it reveals too much, but maybe good for "my phone broke".

Re: Short session expiration does not help security

#268
post #19

Earlier quoted context omitted.

The author also puts lot’s of faith on the user not doing stupid things: “Is this a thing? Are shared computers without user separation a thing? If so, these shouldn’t be used to access web applications with sensitive information at all, no matter how short the session expiry time is.” Yeah, users might just leave their bank logged in a open and logged computer library. That’s why short sessions exist for those as th…

It's better to let users do stupid things so they learn from their mistakes and not do them ever again. And probably tell their story to their friends and family so they, too, don't do this. Putting all these excessive guards in place kinda encourages ignorance and tech illiteracy.

You have far too much faith in stupid people.

Re: Short session expiration does not help security

#269
post #8

> Also, it would be better to protect against this by securing the logs or using hard drive encryption. This one line is emblematic of the flaws in the article. My take on the article is, “Imagine that everything else in a system is done correctly, and the system, overall, is perfectly secure. In this imaginary world, short sessions don’t help.” One fact about security which you cannot avoid is that any one particula…

[deleted]

Re: Short session expiration does not help security

#270

Earlier quoted context omitted.

> You're really angry with that straw man you've stood up. The OP isn't saying systems have to be locked down to the extent that they're useless. Who would ever argue for such a thing? You are - you're literally arguing for it right now. Short sessions just don't help all that much, and they have an outsized impact on users. Why are you dying on this hill? Likely because your mindset is "security above all else" and…

[flagged]

FWIW, it seems pretty clear to me that you are the person who is being insulting here. I mean, I can't even figure out how to reply to this comment without making it all about you and how you are involved in this thread and the words and strategy you are using, as that's what you are doing to horsawlarway... who, notably, was addressing an idea and an attitude, not a person and their behavior.

Like, if I put myself in the shoes of the people each of you are replying to, I can see how to reply to horsawlarway: if I disagree with their interpretation of what I said, I can argue back; if I realize that I said something poorly and didn't mean it, I can apologize and correct it; if I disagree with their analysis, I can push back with my own arguments...

...but your comment? You are just pointing at someone and calling them rude. You are then not only refusing to engage with their comment or their points, you are just telling them they shouldn't even be discussed or listened to because they used a word which, to be quite frank, is not insulting; and, in doing so, you have dragged this discussion from one between people who were passionate about an interesting topic that affects everyone on this website--one where I was excited to read both sides--to a bunch of people--sadly, now including me!--squabbling about how words are chosen and how arguments are formed while pointing fingers at each other about who is being insulting, which is a waste of everyone's time so bad I frankly feel bad about how I now feel like I also have to take part.

(BTW, I actually did at first choose to not send this comment: I wrote it, and then decided it was just further feeding you and further wasting other peoples' time, so I put it in a text file and moved on; but, then I noticed one of horsawlarway's responses had been flagged--even though you are clearly the instigator here--so I would need to post a defense of why I vouched for it: you are the person who not only took this thread in a personal direction, but you are the person who decided to start throwing around playground-style bullying: saying an idea is cancer is an opinion and analysis, not an insult... but all of your comments on this thread are patronizing and are the kind of taunting people use to start fist fights.)

Post reply on HN