4 ms·
For your #1: For sites with low security demands that will be Ok. GMail already does it. When I enter GMail it always gets me logged in by an cookie and that la
by PythonicAlpha 12y ago
For your #1: For sites with low security demands that will be Ok. GMail already does it. When I enter GMail it always gets me logged in by an cookie and that lasts for a month or so, only after that period, I have to enter my pw again. Of course, when you do some security relevant changes (like changing passwors ;) ... just kidding ... changing eMail adress), a reauthentication is needed.
I don't think that this scheme is for any site ... banking sites just want to be more secure... but it is very much better, than setting pw="123" on all websites, you don't care to much.
BTW: I also described a similar idea some time ago in a blog post:
http://strategieneu.blogspot.de/2014/06/email-only-registration.html http://strategieneu.blogspot.de/2014/06/email-only-registrat...
After I wrote it, that such ideas where discussed at HN even some time ago.
- michaelmior 12y agoWhile Gmail sessions are fairly long-lived, I wouldn't say that this is an example of a site with low security demands. Email is pretty sensitive.
- PythonicAlpha 12y agoYes it is. But still Gmail sessions are long-lived. I also would not stretch this system to eMail-access. Blame it on Gmail, that they do not enforce more security.
- mentat 12y agoIt works because they aggressively monitor for session stealing attempts and immediately shut them down. So it's long lived but with an impressive amount of monitoring that really isn't within reach for non-Google companies.
- kuschku 12y agoI can tell you: They do not. I made a small program to access Google Keep automatically. Because I was too lazy to implement proper authentication, I just hardcoded my session keys. The app is started from a different IP, using a different user agent and is STILL able to access the site after weeks! (Nowadays I have proper authentication in there, but it’s still worrying that stealing sessions from Google is so easy. Especially because some Google services submit their sessions keys via HTTP, without SSL)
- abalone 12y agoThat is not enough evidence to conclude that Google does not monitor for session stealing. Lots of people have dynamic IPs and user agent strings are easily spoofed. They're going to be looking at other factors, like where the IP is located.
- mentat 12y agoI can tell you they do. Within seconds of clicking on a compromised URL they had locked down my account requiring a text to unlock it. I was deeply impressed.
- PythonicAlpha 12y agoI don't think, that such a scheme can work, when somebody else is using my laptop. Sometimes the simplest attacks are the most effective.