Rendered at 04:04:29 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
ape4 12 hours ago [-]
Of course, America.gov uses "SI". From its FAQ: America.gov uses SI to find and explain information from official government sources. SI can make mistakes, so check the sources included with each answer before making an important decision. To report a problem, select the feedback button below the answer and describe what was incorrect or out of date.
kajman 11 hours ago [-]
This should be updated. It appears they've removed the regex triggered easter eggs, and it's well known that a Super Intelligence system is a combination of off the shelf LLM and hand written regex cases.
Or hand-prompted, more likely.
actionfromafar 12 hours ago [-]
Shit Intelligence?
wholinator2 11 hours ago [-]
Supreme Idiocy, Superego Incinerator, Still Incomplete...
VCFundedGenYer 11 hours ago [-]
Sports Illustrated often makes mistakes.
treetalker 10 hours ago [-]
Saffron Impersonator
neuronexmachina 10 hours ago [-]
Slop Induction
cindyllm 9 hours ago [-]
[dead]
ukusormus 11 hours ago [-]
Most browsers cap cookies' max lifetime to 400 days or less these days
bsoqk 11 hours ago [-]
If this is the worst thing they’ve found in that portal…
pluc 12 hours ago [-]
Never accept cookies from strangers.
integrallis 11 hours ago [-]
This is nothing but an attempt to disenfranchise minorities and people living paycheck-to-paycheck that can afford the time to deal with yet another ID... this is an old technique, just like gerrymandering, poll intimidations, and the all the tactics republicans have been using for years.
klaff 11 hours ago [-]
Who is writing these executive orders?
Dwedit 12 hours ago [-]
I mean 20 year cookies make sense for a logon cookie, but not something given out to guests.
verandaguy 12 hours ago [-]
Why do they make sense as logon cookies?
EGreg 11 hours ago [-]
Why not?
verandaguy 11 hours ago [-]
Because in most security models, access is often time-limited.
30 days, for example, is quite long, though NIST does identify 30 days as being the maximum recommended auth token lifetime for low-risk environments.
Higher-risk environments come with 24-hour and 15-minute lifetimes, for context.
lokar 11 hours ago [-]
The burden is to justify it.
What technical reason is there?
bsoqk 11 hours ago [-]
How long should a cookie you expect to last forever actually last?
pixelatedindex 11 hours ago [-]
Why should it last forever?
bsoqk 11 hours ago [-]
Because when you log in you don’t want to be logged out at (what, for you, will appear to be) a random time of the future.
verandaguy 11 hours ago [-]
The solution here is a "keep me logged in for 30 days" or "remember me for 7 days" label on the checkbox, not a forever cookie.
bsoqk 11 hours ago [-]
That’s a solution for a problem that doesn’t exist. Nobody considers not getting logged out randomly a problem.
pixelatedindex 10 hours ago [-]
You said:
> Because when you log in you don’t want to be logged out at (what, for you, will appear to be) a random time of the future.
> That’s a solution for a problem that doesn’t exist. Nobody considers not getting logged out randomly a problem.
Isn’t this contradictory? The double negatives are really throwing me for a loop. Regardless, it’s extremely common for you to be force-logged out of a session for any portal that has sensitive info.
You’re never logged into your bank forever, SSO logins expire. The ones that don’t expire are stuff like YouTube or Netflix, but only if you use it (length of refresh token validity). Checkbox for keeping a session valid is a legitimate solution and I’m grateful it exists. Why do you say it’s a problem that doesn’t exist, when you yourself said it does?
I do not understand your thesis.
verandaguy 10 hours ago [-]
Just because it's not considered a problem by people without a technical or security background doesn't mean it isn't one.
We make many UX compromises in the name of security, and this is a place where that is most visible.
lokar 11 hours ago [-]
You think login.gov (Medicare, social security, tsa, irs, etc) should leave people logged in forever?
Or hand-prompted, more likely.
30 days, for example, is quite long, though NIST does identify 30 days as being the maximum recommended auth token lifetime for low-risk environments.
Higher-risk environments come with 24-hour and 15-minute lifetimes, for context.
What technical reason is there?
> Because when you log in you don’t want to be logged out at (what, for you, will appear to be) a random time of the future.
> That’s a solution for a problem that doesn’t exist. Nobody considers not getting logged out randomly a problem.
Isn’t this contradictory? The double negatives are really throwing me for a loop. Regardless, it’s extremely common for you to be force-logged out of a session for any portal that has sensitive info.
You’re never logged into your bank forever, SSO logins expire. The ones that don’t expire are stuff like YouTube or Netflix, but only if you use it (length of refresh token validity). Checkbox for keeping a session valid is a legitimate solution and I’m grateful it exists. Why do you say it’s a problem that doesn’t exist, when you yourself said it does?
I do not understand your thesis.
We make many UX compromises in the name of security, and this is a place where that is most visible.