4 ms·
Killing short sessions would be somewhat nice from a user perspective, but I think this is unrealistic as others point out. Instead, let's focus on what makes s
by ryanianian 3y ago
Killing short sessions would be somewhat nice from a user perspective, but I think this is unrealistic as others point out. Instead, let's focus on what makes short sessions super obnoxious.
In theory I don't mind a fast and painless re-auth that doesn't hugely interrupt my flow. But the current implementations seem to be actively user-hostile and intentionally annoying.
My company has moved to Okta for most things. Fine. But the session expiration and re-auth mechanism is extremely maddening. It comes out of nowhere.
Right in the middle of doing work, I need to re-auth to {jira, github, google suite, whatever} without any warning. Github in particular makes you re-auth to each org independently even if trying to view OSS material that doesn't require auth to begin with.
And of course SSO flows break anchor tags in URLs so good luck if you already closed the link that had the necessary anchor information.
Then let's talk about Okta in particular requiring three separate pages and clicks for user, pass, otp (because a single form with all three is "insecure" in a meaningful way?). And then not respecting dark mode making an otherwise dark-friendly workflow have flashes of bright light at unpredictable times.
Sure, let's make regular re-auth a thing. I'd even do it once every X hours. But come on.
Let's make the re-auth schedule predictable (ugh google suite re-auth right in the middle of screen-sharing or doing deep work on a doc).
Let me pre-emptively re-auth everywhere all at once in a batch (pointing my finger at you, github).
Let's figure out a way to preserve anchor tags (javascript is a thing, sso sites could capture and sso providers could pass this through).
And dear god, Okta, please just support dark mode on your interstitials. I view that bright flash of light about 5 times per day now and it raises my cortisol levels and hurts my eyes every time.
I know TFA isn't about SSO flows, but SSO flows + short sessions highlight how annoying the end-result of this hodge-podge of auth is for users trying to do their job.
- dasponge 3y agoI definitely agree with you that better warnings and more graceful session timeout behavior would be a huge improvement. It's hard with the current auth standards where the IdP is only in the loop during the initial auth; it'd be on each app to gracefully notify and handle soon-to-expire sessions. That's pretty unreasonable across the large swath of SaaS apps and vendors (given how may have pretty buggy/difficult to integrate SAML implementations). When you throw a CASB or proxy like Cloudflare Access in front of everything then you're fully in the loop, but that's a bit much for a lot of use cases. >Then let's talk about Okta in particular requiring three separate pages and clicks for user, pass, otp That's on your IDAM / Security team and how they've configured Okta/mandated requirements. Okta has fully passwordless, phish resistant, automatic flows with Verify on Mac/Win.