Hacker News new | ask | show | jobs
by lucascantor 1035 days ago
This is why I prefer short sessions and requiring frequent, passwordless, biometric authentication. Still relatively low friction for the user, and no password to remember or forget, while still reasonably high friction for an attacker.