user clicks a phishing link and is asked to login to M365 again, they do it without hesitation because they are used to doing this 5 times a day logging into phishing links would make more people pause if they didnt have to login constantly to get work done
Frequent reauth doesn't make you more secure
141–150 of 539 posts
Re: Frequent reauth doesn't make you more secure
#142Earlier quoted context omitted.
I'm not surprised that it occasionally prompts for a password (about once or twice a week for me), because otherwise people will forget their passwords and bug them about it. The problem I have is that it doesn't explain who wants the password or why, and the prompts aren't associated with any particular action on my part. Instead, Apple is conditioning people to mindlessly type in their password on demand. Why in th…
People are supposed to have extremely complicated passwords, which are impossible to remember. The security is in your biometric ID. There is no reason for a person to ever have to remember any password except their login password, as long as they are using a device with biometric ID. And as far as I know, almost all Apple devices currently for sale have biometric ID. iCloud is the only login that regularly breaks bi…
Yet they'll still make you type it out in so many situations, including on account creation confirmation where some service will even block copy/paste to push you to type it.
Services will accept losing an user over password grating issues ("no compromise on security"), so it just gets worse and worse.
Re: Frequent reauth doesn't make you more secure
#143Re: Frequent reauth doesn't make you more secure
#144OMG I wish that someone would tell this to Apple. Apple's developer services, such as App Store Connect, actually use session cookies. It's infuriating.
Uh, session cookies being one of the most fundamental pieces of authentication tech, there's nothing wrong with them. This is like saying, "example.com actually uses HTTPS. It's infuriating." Do you mean that you have to reauth across domains? Those still use session cookies. Edit: I'm dating myself here, but as far as I can tell apparently sometime between 2010 and 2011, developers started referring to session cooki…
Re: Frequent reauth doesn't make you more secure
#145I hate Apple products for this. I see this pattern across all apple products - not one. On my mac, I setup my touch ID, and log in to my Apple account on the App Store. Time and again, when I try to install apps, it keeps repeatedly prompting for my password, instead of letting me just use my touchID. This applies to free apps as well, which is again silly beyond what is already enough silliness. I briefly see this o…
And it's even worse if you are accessing Apple services on a non-Apple device. No matter how many times I click "trust device" when logging in to icloud.com it will still make me do the password + one-time code song and dance the next day. Another pointless annoyance - if Face ID fails when making a payment or installing an app (like it frequently does for reasons like sleeping in bed or wearing sunglasses) it won't…
Re: Frequent reauth doesn't make you more secure
#146Pretty rich coming from a company that only let's you create an account via SSO from the largest offenders of this.
Re: Frequent reauth doesn't make you more secure
#147Earlier quoted context omitted.
Remembering things reliably must be the most unsolvable problem in computer science. Unless it's related to advertising. Then it works flawlessly and sometimes survives device transfers and factory resets.
I hate how in macOS, I can double click a window's title bar to maximize it, and five minutes later the original window size will be forgotten so you can't restore it. Windows 95 had this shit figured out on systems running a 486 and 6MB of RAM.
Oh, you double clicked to make it bigger? How about making it postage stamp sized in the bottom left of a different monitor...
Re: Frequent reauth doesn't make you more secure
#148Only if you make a bunch of assumptions that may not apply. My employer allows BYO and has a default Outlook Web session timeout. Is it ok that my son stopped at my desk at home and saw customer PII that was left open? I enforce these kinds of policies at my company even though I find them personally stupid. I do so because I’m the custodian of my customers property and have a duty to minimize risk of employees or co…
>Is it ok that my son stopped at my desk at home and saw customer PII that was left open? In practice/reality, probably. Most employers will disagree. Consider your son could just as easily over hear a phone call, see a piece of paper, etc. If your son was actively malicious, there's all kinds of things from cameras to video splitters to key loggers he could do. If he's not actively malicious, who cares if he sees so…
Re: Frequent reauth doesn't make you more secure
#149Corporate IT still makes you change your password every N months. Tell them to extend the max session length beyond a day and some VP will have an aneurysm.
No modern IT organization mandates periodical password changes since, I dunno, mid-2000's. edit : please note the "modern" qualifier, tons of IT orgs continue to mandate this anachronistic policy, sure, but those orgs aren't modern, the policy isn't a requirement for e.g. SOC2 or whatever, it's purely historical inertia.
It is a PCI requirement and probably from other sources.
Of course it is brain dead and we even have authoritative documentation from NIST explaining why it is stupid, but nobody at PCI has any technical skills to understand that so the madness lives on.
Re: Frequent reauth doesn't make you more secure
#150Earlier quoted context omitted.
If it helps there's no security advantage of a 50+ character password over a suitable 16 character one.
Yeah, but passphrases don’t require switching keyboards as often in mobile. And if you’re using a 16 character P@s5w0R6, a 50 character passphrase can be just as secure. What I can’t stand if when I’m prompted to type a password on my Apple TV and can’t use my phone for some reason. Scrolling across the alphabet for a passphrase is torture.
Now its 21 minimum but requires upper, lower and numeric. I guess at least I don't have to stick an exclamation on the end.