4 ms·
@sama Jk though I intuitively agree, I think this article doesn't really prove its claim. > Are shared computers without user separation a thing? If so, these
by obblekk 3y ago
@sama
Jk though I intuitively agree, I think this article doesn't really prove its claim.
> Are shared computers without user separation a thing? If so, these shouldn’t be used to access web applications with sensitive information at all, no matter how short the session expiry time is.
I would argue shared computers are one of the primary threats deterred by this.
Additionally, for the attacker has access to device section, the author points out an attacker could still access email. But, email services tend to be more developed and often have the ability to expire all tokens (or logout all browsers). The exact place short session expiration helps is when the service does not provide a feature to log out all sessions remotely. That would be a better deterrent by far, but may be more complex to build than a default timeout.