Security
A community for discussion about cybersecurity, hacking, cybersecurity news, exploits, bounties etc.
Rules :
- All instance-wide rules apply.
- Keep it totally legal.
- Remember the human, be civil.
- Be helpful, don't be rude.
Icon base by Delapouite under CC BY 3.0 with modifications to add a gradient
Tbh, for typical consumers I think 2-4 hours is fine.
Chances are, if the user cares, they will reuse a session in that timeframe. Otherwise, they log in again.
Any good password manager will clear the clipboard after 10s or so!
Anything that is critical should use a physical key. Is it YubiKey that do this? (I'm sure it's becoming a web standard).
If the YuniKey needs more? Add a biometrics reader on it. Or a password decrypt.
Have multiple identities or are worried about privacy? Have a key that can provide multiple identies, along with the infra to support this.
Even if we make passwords absolutely tied to a physical sack of meat.... There is still social engineering that can use the user to bypass all that!