‹ BackHN Continuity

Thread

A 20-year-long permanent cookie: America.gov and tracking

46 points · 28 comments · paimapi

  1. Dwedit · · focus · HN ↗
    I mean 20 year cookies make sense for a logon cookie, but not something given out to guests.
    1. verandaguy · · focus · HN ↗
      Why do they make sense as logon cookies?
      1. EGreg · · focus · HN ↗
        Why not?
        1. verandaguy · · focus · HN ↗
          Because in most security models, access is often time-limited.

          30 days, for example, is quite long, though NIST does identify 30 days as being the maximum recommended auth token lifetime for low-risk environments.

          Higher-risk environments come with 24-hour and 15-minute lifetimes, for context.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.