Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do you mean if you open up a website you used two weeks ago you still want to be signed in? For a website you visited daily the cookie could be refreshed.


Depends.

A banking website? No, a quick automatic signout is obviously safe and correct.

An entertainment site, a forum, some kind of social media? Certainly I want to stay signed in.


To the contrary, why would you want to be signed out? Your account, and therefore by extension, your cookies, should only be usable by you.

I cannot think of a reason why I would want to loose my sessions every other day.


If you're religious about locking your phone/PC then you probably don't have anything to worry about otherwise someone could easily just see what you have going on in your browser


Have the best of both worlds with cookie autodelete plugin :) . It's one of the first things I install (along with ublock origin and bitwarden)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: