This Forum has been archived there is no more new posts or threads ... use this link to report any abusive content
==> Report abusive content in this page <==
Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Auto Sign in & Sign off?
05-23-2014, 10:07 PM
Post: #2
 
Technically, the highest security option is to not have sessions last for a few days (this is done by sessions, by the way). But, that's so annoying for most users that they'll start letting their browser save passwords, posing an even greater security risk. A lesser of two evils, if you will.

Gmail requires me to re-verify my password every few weeks or so, which isn't too bad. I'm very conscious of security, hence why I don't mind at all that they do that. However, it could annoy some users who don't understand the importance of such a feature.

Auto-sign off after one hour is pointless, you might as well make it sign you off as soon as you close the browser (which is the standard way of doing it if you don't allow long-term sessions).

The amount of time Gmail leaves between requiring you to log on again is a little too short to not annoy most users. To provide an upper boundary, I'm going to use Mediawiki as an example, which logs you off after 60 days. I think it should be somewhere between Gmail and Mediawiki to meet the needs of security and user friendliness most effectively.

Ads

Find all posts by this user
Quote this message in a reply
Post Reply 


Messages In This Thread
Auto Sign in & Sign off? - Alpha - 05-23-2014, 10:01 PM
[] - Agent - 05-23-2014 10:07 PM

Forum Jump:


User(s) browsing this thread: 1 Guest(s)