Hacker News new | ask | show | jobs
by erhk 1879 days ago
It's punishment for deleting your cookie. Don't sign in we don't want that. Just stay signed in. Trust us.
3 comments

There are some websites that are both super aggressive about timing out your session and also make you play hide and seek for the login button. Of the sites I use frequently UPS used to be about the worst offender but the most recent version of their site does have a usable login link.
Vanguard is another one that drives me up the wall. Going to Vanguard.com doesn't have a sign in area to autofill with a password manager; you have to go to the personal investors page. And sessions are hard limited to 15 minutes so you have to jump through these hoops every time. I have the correct page bookmarked but even on that page the log in boxes don't appear until half way down.
The same Vanguard that could have millions of dollars of investments in your account? What’s the appropriate time out?
I don't think the criticism is the logout time, it's the fact that you have to hunt for the button. The logout time only exasperates the problem.
How about having a short timeout for making transactions and a longer timeout for viewing balances and transactions?
Should probably require a TOTP MFA code for all movements of money anyway regardless of session validity.
Totally agree, Vanguard's landing page is a disaster.

I was able to directly link this page however, which I bookmarked:

https://personal.vanguard.com/us/AuthLogin

Even the solution in the article seems to suggest using cookies.

I don’t understand the problem, if people want to try or sign-up for your service they’ll locate the signup button. That’s a one time problem. A hidden login button just annoys existing customers.

My feeling is that this is down to testing without privacy in mind. Your site might be fine, but others aren’t so a minority of users will clear cookies at the end of each browser session. That’s not a senario most will test for or experience.

Agree, I always use incognito/private mode and maybe that’s the reason I see this more often than others.