Live data from Hacker News

Short session expiration does not help security

sjoerdlangkemper.nl

431–434 of 434 posts

Re: Short session expiration does not help security

#431

Earlier quoted context omitted.

It’s funny you think there’s a difference

It's funny you think there isn't a difference between the humanity of your parents and some faceless governamental bureaucracy.

It’s funny you think there is a separation between the two in any practical way.

Re: Short session expiration does not help security

#432
post #429

Earlier quoted context omitted.

My parents giving me a name is one thing. The state giving me a number and arresting me if I fail to produce that number to police on demand is another.

Which one of those is problematic to you? The state giving you a number or arresting you if you refuse to identify yourself? Because you've given yourself a nice straw man to fight by conflating them.

Oh he knows that, but that’s all their type has: faux-bravado against imagined threats.

Not least: they’re ignoring that simply having an identity is a traceable & trackable thing… because that would derail their paranoid fantasies where they’re a hero, fighting against a dystopian world.

Re: Short session expiration does not help security

#433
post #347

Earlier quoted context omitted.

> We just don’t the government enough to let them track us everywhere. That statement is both true and emblematic of the problem. Everyone is so cynical that a clean public-key, offline, certificate-based solution, with an absolute zero visibility to the government of who is doing what, would always be assumed to be part of some nefarious Illuminati/Democrat/Republican plot. Proving it to people with technical tests…

Because there has never been a proposal for a "clean public-key / offline / certificate-based solution". It's always a central database that also does x and y and will be available for w and z departments to do as they will with it.

It doesn’t matter though, because the percentage of Americans who can understand public key crypto even in a vague way sufficient to critically read a technical analysis and judge it to be true, you could count on one hand. Nobody has proposed it because if any politicians have seen such a proposal on their desks, even if they themselves grasp it (unlikely), they know most Americans would freak out on principle.

Re: Short session expiration does not help security

#434
post #8

> Also, it would be better to protect against this by securing the logs or using hard drive encryption. This one line is emblematic of the flaws in the article. My take on the article is, “Imagine that everything else in a system is done correctly, and the system, overall, is perfectly secure. In this imaginary world, short sessions don’t help.” One fact about security which you cannot avoid is that any one particula…

Short sessions are there because, for all practical purposes, SLO doesn't work and we are using short sessions to simulate high-latency SLO. In a previous life we supported SLO properly, and it had no value at all.

It's one of the many sad realities of the modern world that basic functions don't work and no one will fix them.

Post reply on HN