Session time-out due to inactivity is critical.
In fact, “hacking” companies like NSO steal authentication tokens of services like gmail that DELIBERATELY do not log you out for inactivity for periods like 30 days.
Session time-out due to inactivity is critical.
In fact, “hacking” companies like NSO steal authentication tokens of services like gmail that DELIBERATELY do not log you out for inactivity for periods like 30 days.
I think it is a personally reasonable threat model to consider anyone capable of stealing a token off of my device as capable of stealing my password because if a website has other vulnerabilities allowing credentials to be stolen or misused without my device being compromised then it is a defense in depth technique and it is to cover the ass of the website operator and not me. I shouldn't be liable for a website owner's screw up there.
Now, a genuine two factor authentication changes the picture there and actually adds some security for ultra risky scenarios (like transferring money). But instead of invalidating my session, just ask for a token on every risky transaction. There I can understand a bank wanting to cover their liability a bit more.