Textpattern CMS support forum
You are not logged in. Register | Login | Help
- Topics: Active | Unanswered
Uncheck Remember User at Login by default
Hi
I used Textpattern for some time from a public computer (i.e. internet cafe) and there I realized, that the “Rembember User” checkbox at the Login is checked by default. That means that I had to uncheck every time this checkbox, because I did not want my login stored on a public pc.
Wouldn’t it make sense, to uncheck it by default? This would be better security and users who want to store their password just have to tick once.
Cheers
Matthias
Offline
#2 2006-10-24 20:17:38
- Logoleptic
- Plugin Author
- From: Kansas, USA
- Registered: 2004-02-29
- Posts: 482
Re: Uncheck Remember User at Login by default
Agreed. This always seemed like a very poor security choice to me.
Offline
Re: Uncheck Remember User at Login by default
I am always surprised how many people think that entering passwords on an untrusted machine is ok (regardless of the cookie/remember settings).
I am not arguing against the point that it makes more sense from a convenience POV to let one group (the remember people) tick once, rather than having the other group (the not remember me people) having to untick everytime. As a compromise, up to now we saved the unticked box in a preference cookie, so that when you didn’t delete cookies, you would never have to uncheck it again, and if you did in fact delete cookies on a regular basis, it doesn’t matter whether you check the box or not anyhow. Using a different PC everytime is however not solved by that. So it may well change in the near future.
Offline
Re: Uncheck Remember User at Login by default
I would appreciate the change :) I think, it should not be that much change in coding unless you don’t want to integrate the “Mail me my Lost Password” Feature.
Offline
Re: Uncheck Remember User at Login by default
The-Exit wrote:
Hi
I used Textpattern for some time from a public computer (i.e. internet cafe) and there I realized, that the “Rembember User” checkbox at the Login is checked by default. That means that I had to uncheck every time this checkbox, because I did not want my login stored on a public pc.
Wouldn’t it make sense, to uncheck it by default? This would be better security and users who want to store their password just have to tick once.
I second this
Yiannis
——————————
NeMe | hblack.art | EMAP | A Sea change | Toolkit of Care
I do my best editing after I click on the submit button.
Offline