Replies: 4 comments
-
See #1142 why it is |
Beta Was this translation helpful? Give feedback.
-
I get what you are writing in #1142 but this does not explain to me why the value has to be hardcoded (any why 15 minutes is more secure than 10 minutes or 5 minutes or whatever). And this is what my question is about – I think people should be able to change the setting depending on their (security) needs. The default can be 15 minutes thats not a problem I think – but having this not customizable causes problems for people who are using the signing of mail on a regular basis. I give you an example: I get an encrypted message every half a year so the issue mentioned in #1142 does not really lower my security as most mails are not encrypted. But since this change I have to enter the passwort for mostly every second email I send because the 15 minutes are hard coded. |
Beta Was this translation helpful? Give feedback.
-
Ofcourse. It's a work in progress. |
Beta Was this translation helpful? Give feedback.
-
I've added it. |
Beta Was this translation helpful? Give feedback.
-
Starting as of 2.36.0 a feature was introduced which is called "Remove remembered password after 15 minutes of inactivity". As this is not specified further in the release notes I think it belongs to the OpenPGP passphrase password.
For me this is really annoying as I sign all my outgoing mails properly. So since this update I have to enter this password almost every time I write an email (and when the 15 minutes have passed). Before 2.36.0 the remembered password only "expired" when the tab was reloaded or if I opened a new session.
I could save the password in the browser but for me (and I also think from a security perspective) this does not sound like a good alternative!
I would really love to be able to customize this time frame. I understand that from a security perspective some kind of expiration is useful and should be in place. But as it is also possible to customize the "Auto Logout" I would ask this to be customizable too:
2 votes ·
Beta Was this translation helpful? Give feedback.
All reactions