Live data from Hacker News

Frequent reauth doesn't make you more secure

tailscale.com

201–210 of 539 posts

Re: Frequent reauth doesn't make you more secure

#201
post #179
post #61

Earlier quoted context omitted.

It's a good point on password usability. Signal app periodically prompts you for the encryption PIN to make sure you don't forget it. I think this should be handled out of band of the login process. Similar to "is xxx still your phone number?" -- companies could do periodic password hygiene and freshness checks. Context matters. Companies forget that people are trying to get something important done, and blocking the…

> Signal app periodically prompts you for the encryption PIN to make sure you don't forget it. At least Signal does not block the app until you enter the PIN. WhatsApp forces you to enter it before you can reach your messages, which not only is annoying when you're in a hurry, but also forces you to type the PIN even when you're in a place where it might be seen by someone else. On the other hand, on Signal it's poss…

Apps need to treat these experiences more critically. I had a similar forced re-auth with Gaia when i was offline, losing my maps.

So here I am, lost, trying to find my way using a downloaded map, and the app won't let me in.

These are no longer casual entertainment experiences we are dealing with. Many of these apps are central to carrying on with life. And they are introducing new and unanticipated failure modes.

Re: Frequent reauth doesn't make you more secure

#202
post #180

Earlier quoted context omitted.

I’ve kind of become a fan of the sites that don’t even have passwords but just email you a “magic” link. If my account security is tied to my email why make me do extra song and dance if I’m gonna have to fish out an email for every login anyway?

I despise this. With username and password my password manager just fills it in and it is one click to click "login". With email magic link I need to enter my email (it seems to rarely auto-fill for some reason), then wait (often it takes 10s for the email to be sent for some reason), then if I was logging in on something that isn't my default browser I need to copy+paste the link (often just clicking the link author…

And on top of that, the session is probably gonna expire in less than day. I hate logging in to Anthropic because of this signin-email dance

Re: Frequent reauth doesn't make you more secure

#203

Forced password rotation and expiry seems the bigger problem; given that it causes people to get locked out so often, (e.g. if pw expires when on holiday), — often then requiring travelling to IT, or at least a few hours trying to get IT on the phone to reset, or chasing up colleagues who aren't locked out to get in touch with IT. Many (most?) companies still do it, despite it now not being recommended by NIST: > Ver…

1234abcd@ it is then for all my accounts.

Re: Frequent reauth doesn't make you more secure

#204

This depends on your "world model", that is, what situations do you anticipate the people using your web site / application are in? The assumption that basically, device = same person (browser session really) over a long period of time is the right one, 99% of the time. Sometimes it's appropriate to make much more conservative assumptions. People might be in bad family situations (where not everyone with access to a…

> People might be in bad family situations (where not everyone with access to a shared device

Then they should configure their browser to log them out. Not hope that every site has good settings for their niche scenario.

Re: Frequent reauth doesn't make you more secure

#205
I hate the corporate office 365. How many times on the same corporate laptop on which I log in from home do I need to reenter outlook password and 2FA.

I seriously think ms365 login chain is straight broken Click here to sign in - enters userID and pass - thanks for logging out :o

Re: Frequent reauth doesn't make you more secure

#206
post #16

Corporate IT still makes you change your password every N months. Tell them to extend the max session length beyond a day and some VP will have an aneurysm.

There is very little incentive to actually do information security correctly - because hardly anyone can tell if you have - consequently there are very few people who try. It is all just theater to cover their asses, and they'll admit it under the right circumstances. They don't want to change idiotic policies like this because it means they'd have to admit they've been dogmatically enforcing counter-productive polic…

Hardly anyone can tell, until everyone can tell, because you have a breach.

It's similar to the idea that if you aren't doing restore drills you aren't really taking backups. But people rarely test their auth rules.

Re: Frequent reauth doesn't make you more secure

#207
post #88

Earlier quoted context omitted.

Had that on the WiFi system at a facility I used to work from for a while. When you connect to their WiFi, you go to a guest portal to connect to the internet. The guest portal grants your MAC address 24 hours of access. Meaning one day you get to work at 9, the next day you get in at 8:55, you’ll have 5 minutes more of WiFi before things just stop working and your system takes a minute to realize you need to reauth…

And successfully opening a wifi captive portal is the most difficult thing to achieve in all of tech for some reason.

It's even harder than moving a file from a desktop into a telephone on the same LAN with an USB cable plugging both.

Computer security has a problem.

Re: Frequent reauth doesn't make you more secure

#208
post #154

Earlier quoted context omitted.

Microsoft crap is similarly broken. After each and every login there is the question whether it should remember me and whether it should ask that question again. It doesn't matter at all what you answewr there, it changes absolutely nothing.

Disable anti-tracking features and ad blocks, it turns out cookies and temp storage for ad tracking are how IDPs track your choice to trust the device too.

Adblocking and anti-tracking are mandatory on my company laptop, cannot switch those off. And I wouldn't want to.

Re: Frequent reauth doesn't make you more secure

#209
post #41

I hate Apple products for this. I see this pattern across all apple products - not one. On my mac, I setup my touch ID, and log in to my Apple account on the App Store. Time and again, when I try to install apps, it keeps repeatedly prompting for my password, instead of letting me just use my touchID. This applies to free apps as well, which is again silly beyond what is already enough silliness. I briefly see this o…

And it's even worse if you are accessing Apple services on a non-Apple device. No matter how many times I click "trust device" when logging in to icloud.com it will still make me do the password + one-time code song and dance the next day. Another pointless annoyance - if Face ID fails when making a payment or installing an app (like it frequently does for reasons like sleeping in bed or wearing sunglasses) it won't…

related pet peeve: faceid is often (but unpredictably) really slow - like, I'm looking at the phone and in a hurry and would prefer to enter my pin but touching the screen goes back to the lockscreen, and swiping up starts faceid again.

Re: Frequent reauth doesn't make you more secure

#210

I hate Apple products for this. I see this pattern across all apple products - not one. On my mac, I setup my touch ID, and log in to my Apple account on the App Store. Time and again, when I try to install apps, it keeps repeatedly prompting for my password, instead of letting me just use my touchID. This applies to free apps as well, which is again silly beyond what is already enough silliness. I briefly see this o…

I think free apps are still scrutinized because they don’t want attackers to install known-compromised apps or trackers. Like a controlling spouse sneakily face IDing a sketchier Life360 while “making a phone call”.

Could be wrong, but that’s the only thing I can think of.

Post reply on HN