16
Do extremely short credential lifetimes actually help security?
(piefed.social)
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
Community Rules
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
Nothing like training users to punch creds into every box that appears! It is absolutely bad. There’s no need to ask for credentials; the refresh token will be invalidated if passwords change etc.
Plus, it’s expensive. 24 times a day, 30 seconds. 12 min per user per day of wasted productivity.
Sounds like someone just read up on token theft and panicked.
Bad thing is, such panicky footgunnery tends to make it into long term policy.