Ask HN: Never been logged out of Browser FB/Twttr for years and ok with it. You?
Aggressive arbitrary session timeouts in cloud apps is frustrating, especially if your password manager is inconsistent in its ability to autofill accurately.
Painful 3 step sign-ins - #1) email, #2) password, #3) 2FA - argh.
How do you even decide 24 hrs vs 30 days vs 365 days for sessions?
Is app security often more for show than need, biased towards super edge cases?