I hate Apple products for this. I see this pattern across all apple products - not one. On my mac, I setup my touch ID, and log in to my Apple account on the App Store. Time and again, when I try to install apps, it keeps repeatedly prompting for my password, instead of letting me just use my touchID. This applies to free apps as well, which is again silly beyond what is already enough silliness. I briefly see this o…
Also, every time I plug my iPhone into my Mac for syncing it asks "Trust this Device" both the Mac and the iPhone. I click "yes" and yet it asks again next time.
Frequent reauth doesn't make you more secure
91–100 of 539 posts
Re: Frequent reauth doesn't make you more secure
#92I hate Apple products for this. I see this pattern across all apple products - not one. On my mac, I setup my touch ID, and log in to my Apple account on the App Store. Time and again, when I try to install apps, it keeps repeatedly prompting for my password, instead of letting me just use my touchID. This applies to free apps as well, which is again silly beyond what is already enough silliness. I briefly see this o…
I'm not surprised that it occasionally prompts for a password (about once or twice a week for me), because otherwise people will forget their passwords and bug them about it. The problem I have is that it doesn't explain who wants the password or why, and the prompts aren't associated with any particular action on my part. Instead, Apple is conditioning people to mindlessly type in their password on demand. Why in th…
Re: Frequent reauth doesn't make you more secure
#93Earlier quoted context omitted.
Session cookies are cookies that identify a session. They last however long you specify. A bank forces quick session expiry. Amazon doesn't. Compare https://docs.djangoproject.com/en/5.2/topics/http/sessions/ . > To use cookies-based sessions, set the SESSION_ENGINE setting to "django.contrib.sessions.backends.signed_cookies". > When using the cookies backend the session data can be read by the client. > A MAC (Messa…
No, they're not. This terminology is well-established. https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Coo...
Re: Frequent reauth doesn't make you more secure
#94My employer just started doing daily reauth for all microsoft logins (teams, ...). The worst thing is that it's just 24h not start of day, so it may just be five seconds before you want to join a meeting. They haven't found the setting for mobile yet, so I might just stop using desktop teams.
Had that on the WiFi system at a facility I used to work from for a while. When you connect to their WiFi, you go to a guest portal to connect to the internet. The guest portal grants your MAC address 24 hours of access. Meaning one day you get to work at 9, the next day you get in at 8:55, you’ll have 5 minutes more of WiFi before things just stop working and your system takes a minute to realize you need to reauth…
Re: Frequent reauth doesn't make you more secure
#95Earlier quoted context omitted.
Really? I never have to re-auth unless I get a new device.
Same behavior here. I use TouchID to log in several times per day, and am required to enter a password "to enable TouchID" about once per week. iOS and macOS both. This feels reasonable to me.
Re: Frequent reauth doesn't make you more secure
#96Industry-wide IT security is driven by the "nobody got fired for buying IBM" phenomenon. It doesn't matter if things are broken. It matters that you did everything by the book. And the book in this case was written 30 years ago and is woefully inadequate. But try convincing your VP of information security that employees shouldn't have to change their password every 3 months...
Re: Frequent reauth doesn't make you more secure
#97Earlier quoted context omitted.
No, they're not. This terminology is well-established. https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Coo...
You can believe what you like, but that won't change what people mean by the term "session cookie". If you try to communicate with other people using that definition of "session cookie", your communication will fail.
Re: Frequent reauth doesn't make you more secure
#98Earlier quoted context omitted.
I'm not surprised that it occasionally prompts for a password (about once or twice a week for me), because otherwise people will forget their passwords and bug them about it. The problem I have is that it doesn't explain who wants the password or why, and the prompts aren't associated with any particular action on my part. Instead, Apple is conditioning people to mindlessly type in their password on demand. Why in th…
Yes, it’s really bad for security. I just deny it if I don’t know what it’s for. I’m sure I’m missing out on some very important functionality.
I just have to trust their security model to not allow random apps to pop up and issue those prompts.
Re: Frequent reauth doesn't make you more secure
#99I hate Apple products for this. I see this pattern across all apple products - not one. On my mac, I setup my touch ID, and log in to my Apple account on the App Store. Time and again, when I try to install apps, it keeps repeatedly prompting for my password, instead of letting me just use my touchID. This applies to free apps as well, which is again silly beyond what is already enough silliness. I briefly see this o…
I have a very old iPad that my kid uses. It’s stuck to iOS 10.3. Also, it can’t use my password manager. The browser is so old that the website won’t load (32-bit app). And the PW manager app isn’t made for this old a device. So Apple wants me to type in my 50+ character password every time I use the App Store app. It’s such a pain.
- As you said, it's a multi-platform account, so probably multiple devices in multiple locations will need the password. Meaning you won't have easy access to your password manager. - Popular account, so you'll likely be using it often, probably re-typing or pasting it.
Common sense says that manually typing out a password was a likely scenario.
Switch to a phrase-based password. It'll still be really secure, and you'll be freed from your self-inflicted woes.
Re: Frequent reauth doesn't make you more secure
#100Earlier quoted context omitted.
I have a very old iPad that my kid uses. It’s stuck to iOS 10.3. Also, it can’t use my password manager. The browser is so old that the website won’t load (32-bit app). And the PW manager app isn’t made for this old a device. So Apple wants me to type in my 50+ character password every time I use the App Store app. It’s such a pain.
If it helps there's no security advantage of a 50+ character password over a suitable 16 character one.
It would be nifty if your phone could just connect to other devices as a BT keyboard and type in passwords there too. Probably not worth the actual fuss of pairing a BT device, but if that part were not so painful it could be quite a nice solution.