> Because when you log in you don’t want to be logged out at (what, for you, will appear to be) a random time of the future.
> That’s a solution for a problem that doesn’t exist. Nobody considers not getting logged out randomly a problem.
Isn’t this contradictory? The double negatives are really throwing me for a loop. Regardless, it’s extremely common for you to be force-logged out of a session for any portal that has sensitive info.
You’re never logged into your bank forever, SSO logins expire. The ones that don’t expire are stuff like YouTube or Netflix, but only if you use it (length of refresh token validity). Checkbox for keeping a session valid is a legitimate solution and I’m grateful it exists. Why do you say it’s a problem that doesn’t exist, when you yourself said it does?
Of course, America.gov uses "SI". From its FAQ: America.gov uses SI to find and explain information from official government sources. SI can make mistakes, so check the sources included with each answer before making an important decision. To report a problem, select the feedback button below the answer and describe what was incorrect or out of date.
This should be updated. It appears they've removed the regex triggered easter eggs, and it's well known that a Super Intelligence system is a combination of off the shelf LLM and hand written regex cases.
This is nothing but an attempt to disenfranchise minorities and people living paycheck-to-paycheck that can afford the time to deal with yet another ID... this is an old technique, just like gerrymandering, poll intimidations, and the all the tactics republicans have been using for years.
pluc | 6 hours ago
Dwedit | 5 hours ago
JSR_FDED | 5 hours ago
verandaguy | 5 hours ago
EGreg | 5 hours ago
lokar | 5 hours ago
What technical reason is there?
bsoqk | 5 hours ago
pixelatedindex | 5 hours ago
bsoqk | 5 hours ago
verandaguy | 4 hours ago
bsoqk | 4 hours ago
pixelatedindex | 4 hours ago
> Because when you log in you don’t want to be logged out at (what, for you, will appear to be) a random time of the future.
> That’s a solution for a problem that doesn’t exist. Nobody considers not getting logged out randomly a problem.
Isn’t this contradictory? The double negatives are really throwing me for a loop. Regardless, it’s extremely common for you to be force-logged out of a session for any portal that has sensitive info.
You’re never logged into your bank forever, SSO logins expire. The ones that don’t expire are stuff like YouTube or Netflix, but only if you use it (length of refresh token validity). Checkbox for keeping a session valid is a legitimate solution and I’m grateful it exists. Why do you say it’s a problem that doesn’t exist, when you yourself said it does?
I do not understand your thesis.
verandaguy | 4 hours ago
We make many UX compromises in the name of security, and this is a place where that is most visible.
lokar | 4 hours ago
verandaguy | 5 hours ago
30 days, for example, is quite long, though NIST does identify 30 days as being the maximum recommended auth token lifetime for low-risk environments.
Higher-risk environments come with 24-hour and 15-minute lifetimes, for context.
ape4 | 5 hours ago
actionfromafar | 5 hours ago
wholinator2 | 5 hours ago
VCFundedGenYer | 5 hours ago
treetalker | 4 hours ago
neuronexmachina | 4 hours ago
kajman | 4 hours ago
Or hand-prompted, more likely.
ukusormus | 5 hours ago
bsoqk | 5 hours ago
integrallis | 4 hours ago
klaff | 4 hours ago