3 ms·
Persistent sessions are not a problem – not having any security could be (E.g. Auto logout on location or IP change, and especially two-factor authentication on
by JacobSeated 4y ago
Persistent sessions are not a problem – not having any security could be (E.g. Auto logout on location or IP change, and especially two-factor authentication on various actions), but that would still be depending on the user and various circumstances. The lowest common denominator should not be defining our security practices.
Point is, it is a huge bad practice to automatically log people out without their consent to do so, and it is one of the most horrific annoyances on the sites that do it.
I am not even sure I want that kind of bullshit on my banking accounts, since they got two-factor authorization on account actions anyway. I can not count the amount of times I have lost something I was writing because a site logged me out before I could finish what I was doing.