Live data from Hacker News

Frequent reauth doesn't make you more secure

tailscale.com

151–160 of 539 posts

Re: Frequent reauth doesn't make you more secure

#151

Earlier quoted context omitted.

People are supposed to have extremely complicated passwords, which are impossible to remember. The security is in your biometric ID. There is no reason for a person to ever have to remember any password except their login password, as long as they are using a device with biometric ID. And as far as I know, almost all Apple devices currently for sale have biometric ID. iCloud is the only login that regularly breaks bi…

People are _required_ to have complicated passwords in most services. Yet they'll still make you type it out in so many situations, including on account creation confirmation where some service will even block copy/paste to push you to type it. Services will accept losing an user over password grating issues ("no compromise on security"), so it just gets worse and worse.

It's much more practical for me as a user to use biometric identification to fill in passwords. That means I can have different auto generated passwords for each service, that are impossible to crack. And if one gets leaked, then that's the only password that gets cracked. The security benefits are enormous, and the ease-of-use benefits are enormous.

I haven't seen any service block paste when filling in or making a password for at least the past 8 years. Any such service would instantly lose all their customers with iPhones or other Apple devices. Not good business.

Re: Frequent reauth doesn't make you more secure

#152
post #81

I don't get why asking for a password multiple times is perceived as more secure. It's the same password. If an attacker was able to find it and input it once, surely they can do it multiple times too...

It's not about asking for the password, it's about expiring sessions frequently. Nobody is going to steal sessions, of course, but the cargo cult security remains.

Re: Frequent reauth doesn't make you more secure

#153

Earlier quoted context omitted.

I agree with you, but it's the same reason why Microsoft asks you to type a numeric code generated by their Outlook app in order to login. It's to prevent people from dismissing the alert by clicking "OK" without even reading (especially if they're in the middle of something else, e.g. during a scam phone call).

Right, the numeric code is proof of intent. In theory, tapping "ok" or "yes, this is me" should be proof of intent. In reality, it's common for those who have compromised someone's password to flood people with these notifications and auth prompts to get them to eventually say "ok," even if by accident.

Duo Mobile at least make it two clicks (on Android at least). So a distracted user would likely to swipe off the notification, instead of tapping through and clicking "Yes, it is me" on the next screen.

Re: Frequent reauth doesn't make you more secure

#154
post #41

Earlier quoted context omitted.

And it's even worse if you are accessing Apple services on a non-Apple device. No matter how many times I click "trust device" when logging in to icloud.com it will still make me do the password + one-time code song and dance the next day. Another pointless annoyance - if Face ID fails when making a payment or installing an app (like it frequently does for reasons like sleeping in bed or wearing sunglasses) it won't…

Microsoft crap is similarly broken. After each and every login there is the question whether it should remember me and whether it should ask that question again. It doesn't matter at all what you answewr there, it changes absolutely nothing.

Disable anti-tracking features and ad blocks, it turns out cookies and temp storage for ad tracking are how IDPs track your choice to trust the device too.

Re: Frequent reauth doesn't make you more secure

#155
post #122

Earlier quoted context omitted.

I set my browser to clear cookies on exit so that my cookies cannot be stolen by malware.

Why do you think malware can't steal your cookies when the browser is open (and I assume it is open for most of the day)?

Because (at least less sophisticated) malware just steals your browser files which contain cookies. I am assuming of course the browser is smart enough not to write cookies to disk if I set it to clear cookies on exit.

Re: Frequent reauth doesn't make you more secure

#156
post #77

Only if you make a bunch of assumptions that may not apply. My employer allows BYO and has a default Outlook Web session timeout. Is it ok that my son stopped at my desk at home and saw customer PII that was left open? I enforce these kinds of policies at my company even though I find them personally stupid. I do so because I’m the custodian of my customers property and have a duty to minimize risk of employees or co…

>Is it ok that my son stopped at my desk at home and saw customer PII that was left open? In practice/reality, probably. Most employers will disagree. Consider your son could just as easily over hear a phone call, see a piece of paper, etc. If your son was actively malicious, there's all kinds of things from cameras to video splitters to key loggers he could do. If he's not actively malicious, who cares if he sees so…

Also, there are shields for screens which basically hide it from anywhere not directly in front

Very useful for people who work in trains and stuff: their neighbors can't see things

Re: Frequent reauth doesn't make you more secure

#157

I hate Apple products for this. I see this pattern across all apple products - not one. On my mac, I setup my touch ID, and log in to my Apple account on the App Store. Time and again, when I try to install apps, it keeps repeatedly prompting for my password, instead of letting me just use my touchID. This applies to free apps as well, which is again silly beyond what is already enough silliness. I briefly see this o…

I have to change my apple password every single time I need to download an app.

It seems like insane friction for something that is making them a lot of money

Re: Frequent reauth doesn't make you more secure

#158
post #57

Earlier quoted context omitted.

Also, every time I plug my iPhone into my Mac for syncing it asks "Trust this Device" both the Mac and the iPhone. I click "yes" and yet it asks again next time.

Remembering things reliably must be the most unsolvable problem in computer science. Unless it's related to advertising. Then it works flawlessly and sometimes survives device transfers and factory resets.

I feel like advertising relies on getting it right "enough" not for everyone and ... they don't care.

Auth and settings people will tell you when it is wrong and that is generally thought of as a problem. Yet advertising doesn't care.

For years Amazon kept showing me women's products. I never once bought any or looked them up but man they were sure I wanted to buy some.

Google thought I was a Nebraska Cornhuskers fan but really I'm a fan of a rival, that's why I had to google a few things about them, but my old google news feed was sure I was a fan... even when they gave me a chance to say "no news about this team" they kept doing it ...

Re: Frequent reauth doesn't make you more secure

#159

Earlier quoted context omitted.

Came here to say this, upvoted. Both Apple and Microsoft have "corporate IT" settings that can be used to turn off "trust my device", "remember me", etc. Auditors and CISO offices tend to lean in on checklist security - in other words it doesn't matter if it's actually more secure, it only matters that it passes the checklist audit. Many of the settings are user hostile and incentivize users to work around them. Maki…

I’m not sure how one changes the mind of auditors who are just there for a job and who aren’t actually interested in the field? IME, the only auditors who are knowledgeable are those overseeing the folks with checklists — and they rarely seem to have the time to correct the folks they’re overseeing.

Stop paying them, I guess, and find a different audit firm that's more knowledgeable. Just like anything else—you get the level of competence you pay for. (Although I guess there's probably a "sweet spot" at which you can pay less AND get better first-level auditors if you're not looking at the biggest firms that are going to charge the most money and also have the most churn)

Re: Frequent reauth doesn't make you more secure

#160

I hate Apple products for this. I see this pattern across all apple products - not one. On my mac, I setup my touch ID, and log in to my Apple account on the App Store. Time and again, when I try to install apps, it keeps repeatedly prompting for my password, instead of letting me just use my touchID. This applies to free apps as well, which is again silly beyond what is already enough silliness. I briefly see this o…

I wonder if what you're seeing is geographic. I'm in Scandinavia and authentication lasts a decent while for me, with strict settings. I tried a few things with my SO's iPhone and iPad and they behaved the same.
Post reply on HN