4 ms·
The IP is something someone isn't comfortable with? It seems to be quite trivial to include the IP in the cookie/session and verify it's the right one. Sure it
by dwild 5y ago
The IP is something someone isn't comfortable with? It seems to be quite trivial to include the IP in the cookie/session and verify it's the right one.
Sure it's not perfect in a world where IP are not necessarily static (and a VPN may change it), but having to login again is not that bad, even more so if you are using SSO.
- Jenk 5y ago> The IP is something someone isn't comfortable with? No good. Slack's biggest userbase is corporate, behind corporate VPNs. Many users have the same IP.
- coopsmoss 5y agoStill seems reasonable for preventing an outside attack though.
- meowface 5y agoIt can help, for sure. I think the main reason it typically isn't enabled in general is that it's pretty common nowadays for people to switch IPs regularly. It'd be annoying to have to re-login to Slack multiple times per day as you move around with your phone or take your laptop to different places. (Especially if it's a user who isn't in a corporate environment, where your public IP will probably differ when you connect to different wireless networks. On a corporate network you're more likely to retain the same public IP no matter which room or building you're in.) If they don't, they should provide an option for corporate administrators to enable IP locking for session cookies.
- bboreham 5y agoWhen I commuted to the office my IP would change multiple times as I crossed from 4G to various WiFis. It would be really annoying to have to log in each time.
- simonw 5y agoThis is why pinning user sessions to IPs isn't going to work - in a mobile first world most users have multiple IPs that they might access a service from during the course of a day. Logging people out also isn't a minor inconvenience, especially for users who haven't figured out password managers yet.
- skinnymuch 5y agoIt would be annoying even with a password manager. Most people are going to care a lot more about that multiple times a day inconvenience than the fact that it’s protecting security. On iPhone it is more than the steps of authorizing password manager and having them auto filled. You’ll have to click yes and possibly something else to have touch or Face ID to be activated again. I know this isn’t actually a major thing. It’s a 20 second process. Still a couple times a day is a couple times a day.