Only Persistent LogIn
avodonosov.blogspot.com
avodonosov.blogspot.com
"Passwords are insecure" is not a good enough rebuttal to this, honestly. We have far more robust authentication methods available; and it's possible to make them standard and avoid this "Remember me" nonsense. Instead, we get all of it for what seems to be the sole purpose of even more user tracking.
----------------------------------------
[1] Remember those? A refresher if you don't: https://www.youtube.com/watch?v=iWssRVJgPqc
Meanwhile "are you sure it's you?" questions are free; pay a software engineer to write them, never touch it again, no matter how many customers you have.
So I guess the question you have to answer, is how can a company make more money off of you by changing how you authenticate? If you show them the $$, they'll show you the WebAuthn.
The things that annoy me the most when I travel are rarely banks – those tend to work just fine. It's usually the main trifecta – Facebook, Twitter, and sometimes Gmail.
> If you forget your password, they just email you a new one.
And in fact this is exactly what is so terrifying about Google moving more towards this kind of "oh you're in a different place, you must be a bad person" authentication. Email services are the single point of password recovery for almost all the websites you access. Sure, perhaps you'll lose a token; but most folks will learn to carry a couple over time. On the other hand, if Google locks you out because you look "too risky", you might lose access to multiple websites (because a lot of them these days email you security codes and such if you're logging in from a browser without cookies).
I know this is really sloppy of me but I'd argue my Gmail is as important if not more important than my bank account. If you have access to my bank, you have access to one bank account of mine but if you have control of my Google account, you now have access to all my bank accounts.
I agree though. I opted into two step authentication for a reason. If I give you both my password and two step code, add this entry to an append only table and move on.
I guess Facebook and Twitter will have this problem where people will take over someone's account and lock them out. Without going into too many details, I saw this happen to someone close to me. It is wild that there are scammers who do this for a living.
* User forgot their password.
* User's authentication token was eaten by an alligator.
* User's phone fell down a well.
* User's phone broke and they got a new number from their carrier.
* User's phone, laptop, and hardware token were lost by an airline.
* User's phone and backup codes were simultaneously lost in a fire.
* For Google specifically, user lost access to their email and didn't have a recovery set up.
If you can reasonably authenticate them using any means you probably should let them because every time you have to fall back to human customer support it's $$$. Remembering a password is one of the few things that's resistant to life's bullshit but it's also incredibly insecure so this is the compromise.
> User's phone, laptop, and hardware token were lost by an airline.
> User's phone and backup codes were simultaneously lost in a fire.
There should be a recovery process. However, the recovery process should be tedious and thorough enough to reliably authenticate the user and not be vulnerable to attacks. Charge a cost for the recovery process.
> because every time you have to fall back to human customer support it's $$$
Sometimes, "fuck off" can be the right answer, especially when the downside is a vulnerability that ends up costing more in fraud/reputation/legal liabilities.
House doors don't (yet?) come with a "forgot your key?" button, and the world hasn't ended, so it seems like most people are able to keep track of physical keys and have no problem paying a locksmith to break & replace the locks if needed. Safes don't come with those buttons either, and yet safe manufacturers haven't gone out of business because it takes significant cost, time & effort to open one if you lost the key (that's the whole point of it).
Welp, I do this. I'm incredibly forgetful, adhd is a bitch, so I have a spare key in a lockbox by the door that takes a combination and give copies of my keys to my friends. And I have the combination in my password manager so even if I forget both but have my phone I'm still good. I also keep multiple copies of my credit cards and driver's license. This stuff has saved me literally hundreds of times.
I'm not sure I understand the logic of not letting someone authenticate themselves with the
Sure they do, albeit mine is 9 buttons (the local locksmith's number)
Recovery can be annoying and expensive, but it should always be possible.
It took so long the conversation was over before I had my answer. I had to do 2-factor auth, then another verification, then click a link in my email.
I understand why they do it, because the alternative is a lot of stolen accounts. But there must be a decent middle ground here.
Sending an email as a notification would serve the same purpose.
We implemented this at Mercury recently to stop phishing attacks, and I believe Coinbase implemented it for the same reason [1].
TOTP authenticators are super ineffective at combating phishing. If a user is willing to give their email and password to a phishing site, there's very little standing in the way of them also providing their TOTP code.
WebAuthn solves this by working with the browser to tie authentication to a particular domain, but not everyone has a WebAuthn authenticator yet.
Meanwhile, email verification links are a really simple and effective way to shut down these phishing attacks. The phisher can't click the links, because they don't have access to the user's email. The user can't click the links on behalf of the phisher, because clicking the link only verifies the device that clicks the link.
1. https://www.reddit.com/r/Bitcoin/comments/2rp9o4/beware_coin...
> The phisher can't click the links, because they don't have access to the user's email.
Something here doesn't add up.
Seems like that is the problem they're trying to improve by using 3FA instead of 2FA.
[1] https://riskbasedauthentication.org/ [2] https://www.okta.com/identity-101/risk-based-authentication/ [3] https://www.beyondidentity.com/blog/what-risk-based-authenti...
This is why we see things like Gemini popping up. It's an attempt to set the bar at "do you _really_ want in on this, even though it doesn't have pretty flashing pictures and the toktiks?".
I'm not judging either way, but I sure did like it before the web got utility status.
So you can complain about Google applying additional security but when the obscure npm package you installed steals your passwords and google blocks the login because it was from a known bad IP in Russia, you’ll be thankful it exists.
Also given that installing npms willy-nilly is your go-to example for security risk, maybe that should have a hasslewall around it instead of username:password authentication:
"You are attempting to install a node package for trivially-implemented behavior. To prove your computer-literacy, enter a javascript function that accepts a string as an argument and returns only the characters with prime-numbered indices."
Most people on HN are American so have no direct experience or knowledge of terrorism, but in the UK a favourite trick of Republican terrorists was to call in hoax bomb threat after hoax bomb threat, causing massive disruption with maybe only one or two real devices for every dozen or so incidents. People got a bit blasé about it, so when the real attacks happened they were much worse than they would otherwise have been.
If you continually blast users with "OMG CRIMINALS MIGHT BE STEALING YOUR DATA CLICK HERE TO STOP THEM" then you're just priming them to be a big fat source of information when a suitably-crafted attack site pops up its message.
Ironically, by painting your users as "living in a fantasy land" rather than "focusing on their own business, which doesn't involve taking down large-scale cybercrime", you're the one being unrealistic. A normal user does not know or care what large-scale problems can be solved by the inconvenience they are currently facing.
On top of that, with apple private relay, an iPhone’s IP address changes quite frequently.
Another guilty site is Amazon. As long as you want to buy another phone, they are OK with your session, but if you want to check your order history, suddenly they are not so sure about your identity — no investigate, only buy…
My only sins are having a dynamic IPv4 address, using Linux, using Firefox, and for some of them using Private Browsing windows for temporary sessions.
The whole approach is manifestly bankrupt.
What are more popular but casual apps where this is happening out of curiosity?
If you do use a shared device, you should be using your own user profile on that device. Or, at least, your own browser profile.
You really shouldn't be logging into your sensitive accounts from a public device or computer anyway. Unchecking "remember me" will not make that secure, and to suggest otherwise is a bit misleading.
This kind of functionality is required, for at least one reason: public access to computers in public libraries. So long as some government services can only be accessed online, you will need access to private email accounts from publicly available computers.
Logout after session end is quite useful in that situation, even if only as a backup to manually logging out.
There is also browser ingonito mode that works perfect for this use.
Not sure if any browser has such an option.
However, Google doesn't give a shit about your consent. Whether you like it or not your device information will be tracked along with your account information and they don't even need you to ever signin to begin with either.
This isn't about security, it's about liability on Google's end. But from a security perspective, many users have shares computers at their homes (and even at work) and that isn't a situation they can avoid. Even with different user profiles having the right permission means your browser profile can be accessed by someone else. Oh, and guess what? Even in america poor people use shared computers at libraries and schools and they sometimes forget to sign out of the OS account profile after closing the browser.
When switching Google accounts you’ll probably don’t want it to have permanent logging cookies, especially if you’re in a pinch and not in the appropriate context (e.g. looking at your family mail from your work computer to quickly get an important message)
Putting the data management responsibility on the user is kind of a dick move, at the same level as all the opt-out garbage we have to deal with.
Plenty of people use shared computer, especially in environments with low financial resources (ie people in developing economies, low income families in developed countries, etc). This accounts for hundreds of millions of not billions of people in the world
It's unrealistic to expect all these people to have a non-shared computer to use, and unrealistic to imagine the shared computer to be set up by someone tech savvy enough to create separate profiles for people.
If I were to pick a random library or local school in South America or Asia for example, I would bet they have a shared computer where you just sit down at a logged in windows profile
I don’t really buy this. The tech kid in the village will explain that if abla doesn’t want nene to see her mail every time then abla should use the “new private window” button when she turns on the computer.
There’s no “basic human instinct” to be able to log into mail which this change goes against. Everyone had to be taught how to open the browser in the first place. The instructions have simply changed.
Temporary session are a weak, half-arsed solution. The author of the post is complaining because they're what he's used to, not because they're actually useful.
1) Privacy: I have multiple accounts. I don't always want these linked to each other either. This is not only multiple Google accounts (personal and work) but also this leaks data since Google knows more about what accounts I have.
2) Security: Just because it is my computer doesn't mean it is always safe. I don't want someone to be able to login to other services just because I'm logged into one. This is akin to being logged into your password manager but with less control since you can't login to a site you need and logout of your manager. Security is often about creating barriers.
3) Centralization: power/influence grows faster than linear with respect to control. Or we may refer to this as momentum. We don't want Google, or anyone, to have control over something so important like the internet. The distribution is essential. While centralization can be good, too much can stifle innovation. That's the whole problem with monopolies (which don't need to have absolute control, but just significant).
4) Personal control: It is my computer, my data, and my accounts. Your services should be making things easier but also expand the amount of control that we have. Creating walled gardens goes back to 3. Potentially this can even create fissures. Having personal control also helps innovation. Being able to play around lets people find new ways to do new things.
1) Most people do not have multiple accounts, or at least do not care about those accounts being linked. And if you are in that situation, then you are (hopefully!) already being methodical about signing out and clearing cookies (or using a separate browser profile, private browsing, whatever). And if you aren't being methodical about this, eventually you are going to screw up anyway, no matter what the login flow or session timeout is.
2) Again, if you are worried about this attack vector (and, also again, most people probably are not), then you should be methodical about immediately signing out and clearing cookies when you are finished doing whatever you are doing. Also again, if you are not doing this, eventually you are going to forget, and succumb to an attacker.
3) Absolutely agree, but I don't see what this has to do with the persistent login issue.
4) It is indeed your computer and your data, but it is not "your" account. It is access to a remote computer system that someone else has granted you, and it is perfectly within their rights to decide how that access works. You may not like it, and that's fine: you are perfectly free to use a different service[0]. I think there are many reasons to claim that Google is a monopoly in some area or another, and that opting out of Google isn't feasible for some people, but "I don't like the login flow" is certainly not one of those reasons.
[0] Earlier this year I dropped GMail and moved my mail elsewhere, and I stopped using Google search several years ago. I've also stopped using Google's OAuth service to sign into other third-party websites, and have switched to regular email+password for any sites where I'd already signed up for an account using my Google Account. I'm working on weaning myself off of some of Google's other services, but I will admit this takes time and effort, and I'm not always up for the work involved. But that's on me, not on Google.
2) Again, security practices should simplify not complexify. More complexity less security. Why force this on people? Why victim blame? Try to make fewer victims, not more.
3) Because Google (and others) are using this login method as a means of centralization and standardization. As you are breaking away from Google you're probably seeing that it isn't trivial and that there are a lot of things you lose because of it (despite HN users often saying roll your own email or saying that email is very decentralized). I would argue that Google has some blame for the difficulties to wean yourself off of them. They created a platform with the explicit intent to make it burdensome to leave. That's not ensuring competition is abundant within our communities. (3 is all big picture stuff but this does matter. I have examples if you care)
4) I get your point, but I think there's a middle ground. The bigger problem is that it is difficult to use other services. There are also websites that don't allow me to log in through any other means. (I only use the Google sign-on for a singular website which does this).
I do not feel it is okay to just dismiss these issues outright. I have the right to criticize the framework. You have the right to disagree. Google has the right to ignore my complaints/critiques. But you're not really disagreeing with my comments so much as dismissing them. Effective communication does require us to discuss in good faith with one another.
Many others do not have a device of their own at all.
I think they should be able to access their email.
And it is sad that's an outdated concept.
Containers are similar to browser profiles, except that history, bookmarks, HSTS, saved passwords, and everything else apart from cookies and other persistent data are "containerlized".
There are addons that introduce the concept of "temporary containers", that delete all cookies when you quit that container.
Google Container makes sure that every connection to Google domains (including YouTube) use a Google-specific container. This is the case for recaptcha and other probes Google has.
https://addons.mozilla.org/en-US/firefox/addon/multi-account...
This just verifies my expectation that reviews giving the lowest score tend to be stupid.
I was highly annoyed by the "persistent login via Chrome" thing, because it feels like it breaks the expected seperation of concerns-- the stuff inside the browser frame should stay inside the browser frame.
There also exists extensions and apps that can delete session data automatically, and Chrome has policies you can specify to only remember cookies for specific sites.
Point is, it is a huge bad practice to automatically log people out without their consent to do so, and it is one of the most horrific annoyances on the sites that do it.
I am not even sure I want that kind of bullshit on my banking accounts, since they got two-factor authorization on account actions anyway. I can not count the amount of times I have lost something I was writing because a site logged me out before I could finish what I was doing.
Really needs a ! rather than a ?
This only happens if user explicitly unchecked the "remember me" (aka 'stay signed-in") checkbox. As such, it's a good experience - fulfilling the user request.
I suspect this is partly due to my pervasive use of IPv6; both my Android device and Windows receive IPv6 allocations on my home WiFi. The device fingerprinting that providers use seems to be fooled when the IPv6 Interface ID changes, even if the /64 is identical. So according to their algorithms, my device is perpetually new and untrusted.
Live.com always always pops a dialog to ask me whether I wish to remain logged in; I never remain logged in, but the dialog constantly asks and there's no way for me to dismiss it permanently.
The only time I've seen "Remember me" work properly is when it sets a cookie with my username and does nothing else. Since I use a password manager, I have no use for remembering my username, and in fact it disrupts my flow and presents an unnecessary leak of credential information.
This is simply Google skipping the 'enter your email' text box, which I'd imagine most people are happy about.
Simply speaking, persistent cookies are used unconditionally, while in the past the unchecked "remember me" was setting session cookie instead.
The first screenshot (the one with user name already filled) is when you explicitly log out and then login again.
Also, you are regularly asked to authenticate to google services, and presented with the screen shown. To pretend otherwise is just weird.
You can complain about the default session length, but that’s a much more specific and different rant from the one in TFA.
Also, do you really think the 99.8% of regular gmail and YouTube users want to log in to google every time they close their browser windows?
The problem with short sessions is that users who do not think about them sign in more often. This makes typing your credentials more normal and makes phishing attacks more common. Reducing the rate at which users enter credentials is generally a good thing.
Users who are thinking about having a short session know how to clear site history when they are done, or click "sign out".
Your reasoning is questionable. Fishing attacks more likely? Maybe yes, maybe no. I personally am very cautios of any login initiated from email and other messages.
I do not know how to clear site history (how?), and do not want whole history cleared; it is useful to have login names saved, for example. I only want an option to not keep the browser signed-in persistently.
Manual sign-out from every site I have in many browser tabs is not practically reliable.