Forums

Increase website auto log out

Quick find code: 278-279-341-66186785

333333333

333333333

Posts: 36,620 Sapphire Posts by user Forum Profile RuneMetrics Profile
Well, people has different opinions but this comes to my mind: You want to stay online but it kicks you offline! You want to log out but it tries to keep you logged in if you don't do that security validate thing! So this is little strange!

31-Oct-2020 21:35:37

Archaeox
Dec Member 2011

Archaeox

Posts: 53,399 Emerald Posts by user Forum Profile RuneMetrics Profile
Mexk said :
Archaeox said :
No support for weakening site security.


I am honestly not sure how this is a valid concern. If you are using a computer on which your account security would be compromised if you were left logged in for more than 30 minutes, you are probably not using a computer you should be logging into in the first place

It's very simple. The longer your account is logged in while you are not at your computer, the greater the chance of someone else accessing/using it.

If we only relied on what people "should" do, we wouldn't need account security measures in the first place, would we? Because everyone would log out when not interacting with the site, nobody would access the site from a public computer or indeed any computer to which other people (including family members) have access, everyone would have top notch antivirus and antimalware, and nobody would ever fall for phishing scams. In the real world, "should" is not good enough yardstick.
~~~~ Just another victim of the ambient morality ~~~~

~~ Founder of the Caped Carousers quest cape clan ~~

!! Slava Ukraini - heroyam slava !!

01-Nov-2020 07:39:27

Miles Prower
Nov Member 2006

Miles Prower

Posts: 9,764 Rune Posts by user Forum Profile RuneMetrics Profile
Draco Burnz said :
Miles Prower said :
Would be nice to see an option to remain logged in for a few days.


Why?

Why must you remain logged in if you arent interacting with site?

Plus like said here:

Archaeox said :
No support for weakening site security.


this can only lead to bad things.


Because it's convenient - tried, tested and implemented on popular services across the internet. If someone forgets to logout on a public machine, that is no different from any other website. Also, the 'remember me' checkbox would be optional. On a public machine? Don't check it, simple.
Low on bank space? Click here .

01-Nov-2020 09:27:07 - Last edited on 01-Nov-2020 09:30:21 by Miles Prower

Draco Burnz
Dec Member 2011

Draco Burnz

Posts: 79,296 Emerald Posts by user Forum Profile RuneMetrics Profile
Miles Prower said :


Because it's convenient -


Yet this is what leads to ppl getting hacked and their acc stolen.

Making things due to them being "convenient".

Also, just becuase its used elsewhere doesnt mean it should be used here.

I mean ppl have been asking/demanding for up/down votes from reddit yet thats never going to happen.


Miles Prower said :
Also, the 'remember me' checkbox would be optional. On a public machine? Don't check it, simple.


Love how ppl think if things are optional, means they should/will happen all the more.
Draco Burnz
Anime Fanatic
Defender of the logical

01-Nov-2020 10:04:00 - Last edited on 01-Nov-2020 10:06:55 by Draco Burnz

Miles Prower
Nov Member 2006

Miles Prower

Posts: 9,764 Rune Posts by user Forum Profile RuneMetrics Profile
Draco Burnz said :
Miles Prower said :


Because it's convenient -


Yet this is what leads to ppl getting hacked and their acc stolen.

Making things due to them being "convenient".

Also, just becuase its used elsewhere doesnt mean it should be used here.

I mean ppl have been asking/demanding for up/down votes from reddit yet thats never going to happen.


Miles Prower said :
Also, the 'remember me' checkbox would be optional. On a public machine? Don't check it, simple.


Love how ppl think if things are optional, means they should/will happen all the more.


No, it means there is obviously precedent for its widespread use. Hand-holding at the expense of useful functionality for the masses does not make the minority who would check the box anyway learn anything. It just delays the inevitable which they will soon learn from.

It's not a matter of "thinking" it is optional. The reality is that it IS often optional where implemented.
Low on bank space? Click here .

01-Nov-2020 10:12:21 - Last edited on 01-Nov-2020 10:14:12 by Miles Prower

Hmm
Jan Member 2016

Hmm

Posts: 13,000 Opal Posts by user Forum Profile RuneMetrics Profile
When designing secure systems, every other service uses the logic that any interactions involving authentication need to be brief, to the point, and only when required.

E.G, when Windows was making UAC in Windows Vista, it was criticised as being extremely naggy. People were conditioned into pressing yes because they were given choices too often. Eventually, people stop even reading the messages, processing the messages, if it said, "This is a virus, do you wish to continue?" people would still click yes because they are overexposed and simply do not consider the implication of what they are doing.

In Windows 7, significant changes happened to reduce the amount if information on screen and how often it was asked, so that the times it actually was important were more clearly distinguished between the times it was noise.

Similarly, basically every website uses this when it comes to logging in. The more a user is exposed to log in forms, the more they will blindly type in their passwords without considering if its a phishing site, the more they will prefer to use weaker passwords to offset the fact they are entered more regularly, the more they will avoid 2FA because it is annoying.

There is zero benefit to requiring a user to keep logging in more often. Any situation you cannot trust the computer you're on you've already lost. If you are on a public PC, you have lost by default and a timeout is not going to help you, so there's literally no point discussing it. You are entirely placing trust into the PC you are on in every situation, and if you place trust blindly, then no antivirus in the world is going to help you.

And that's what this comes down to. By encouraging users to log in every single time, they begin to trust things more blindly, and the chance of getting phished goes UP, because they are less likely to think "aren't I already logged in" and question what's going on.

This is why literally every other service doesn't demand it.

01-Nov-2020 12:59:05 - Last edited on 01-Nov-2020 13:04:30 by Hmm

Corder
Oct Member 2017

Corder

Posts: 27,892 Sapphire Posts by user Forum Profile RuneMetrics Profile
^ I'm going to use Tranq's lifehack from now on. :)
Tranq said :
As long as I click on a thread at least once an hour I'm not forced to logout until the 6 hour mark.
Life is like a camera: Just focus on what's important, capture the good times, develop from the negatives, and if things don't work out, take another shot !

12-Nov-2020 11:20:16

Quick find code: 278-279-341-66186785 Back to Top