Hacker News new | ask | show | jobs
by switch007 1879 days ago
The same Vanguard that could have millions of dollars of investments in your account? What’s the appropriate time out?
3 comments

I don't think the criticism is the logout time, it's the fact that you have to hunt for the button. The logout time only exasperates the problem.
How about having a short timeout for making transactions and a longer timeout for viewing balances and transactions?
Should probably require a TOTP MFA code for all movements of money anyway regardless of session validity.