‹ BackHN Continuity

Thread

A 20-year-long permanent cookie: America.gov and tracking

46 points · 28 comments · paimapi

  1. Dwedit · · focus · HN ↗
    I mean 20 year cookies make sense for a logon cookie, but not something given out to guests.
    1. verandaguy · · focus · HN ↗
      Why do they make sense as logon cookies?
      1. EGreg · · focus · HN ↗
        Why not?
        1. lokar · · focus · HN ↗
          The burden is to justify it.

          What technical reason is there?

          1. bsoqk · · focus · HN ↗
            How long should a cookie you expect to last forever actually last?
            1. pixelatedindex · · focus · HN ↗
              Why should it last forever?
              1. bsoqk · · focus · HN ↗
                Because when you log in you don’t want to be logged out at (what, for you, will appear to be) a random time of the future.
                1. verandaguy · · focus · HN ↗
                  The solution here is a "keep me logged in for 30 days" or "remember me for 7 days" label on the checkbox, not a forever cookie.
                  1. bsoqk · · focus · HN ↗
                    That’s a solution for a problem that doesn’t exist. Nobody considers not getting logged out randomly a problem.
                    1. pixelatedindex · · focus · HN ↗
                      You said:

                      > Because when you log in you don’t want to be logged out at (what, for you, will appear to be) a random time of the future.

                      > That’s a solution for a problem that doesn’t exist. Nobody considers not getting logged out randomly a problem.

                      Isn’t this contradictory? The double negatives are really throwing me for a loop. Regardless, it’s extremely common for you to be force-logged out of a session for any portal that has sensitive info.

                      You’re never logged into your bank forever, SSO logins expire. The ones that don’t expire are stuff like YouTube or Netflix, but only if you use it (length of refresh token validity). Checkbox for keeping a session valid is a legitimate solution and I’m grateful it exists. Why do you say it’s a problem that doesn’t exist, when you yourself said it does?

                      I do not understand your thesis.

                    2. verandaguy · · focus · HN ↗
                      Just because it's not considered a problem by people without a technical or security background doesn't mean it isn't one.

                      We make many UX compromises in the name of security, and this is a place where that is most visible.

                      1. rpdillon · · focus · HN ↗
                        But security is context-dependent. How often does HN log us out?
                  2. rpdillon · · focus · HN ↗
                    That solves "random" but not "I don't wanna type my password every week".
                2. lokar · · focus · HN ↗
                  You think login.gov (Medicare, social security, tsa, irs, etc) should leave people logged in forever?
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.