Hacker News new | ask | show | jobs
by n4jm4 1466 days ago
Reuse the session across applications. Min 24 hour expiration. The more times the user is forced to reauth, the higher the chances of a keylogger or over the shoulder attack successfully retrieving passwords. Also, more time is spent relogging into apps rather than getting things done.