16
Do extremely short credential lifetimes actually help security?
(piefed.social)
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
Community Rules
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
Is it a hard 20min expiration or after 20 min of idle/no use?
We have saleforce at work, and the websites asks for credentials after like 10 min of inactivity. Very frustrating since if you focus on your IDE for 15min then go back to admin panel you need to relogin. So people just developed some extensions that keep the session alive and to also autofill the 2FA. Other wise we loose like 1h of just logininper day.
It's a hard expiration, it can hit while you are using a thing.
Well this not security. I think they just misconfigured something.