Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 2006-10-09 06:08:55

The-Exit
Member
From: Berlin
Registered: 2005-07-16
Posts: 175
Website

Uncheck Remember User at Login by default

Hi

I used Textpattern for some time from a public computer (i.e. internet cafe) and there I realized, that the “Rembember User” checkbox at the Login is checked by default. That means that I had to uncheck every time this checkbox, because I did not want my login stored on a public pc.

Wouldn’t it make sense, to uncheck it by default? This would be better security and users who want to store their password just have to tick once.

Cheers

Matthias

Offline

#2 2006-10-24 20:17:38

Logoleptic
Plugin Author
From: Kansas, USA
Registered: 2004-02-29
Posts: 482

Re: Uncheck Remember User at Login by default

Agreed. This always seemed like a very poor security choice to me.

Offline

#3 2006-10-24 20:27:33

Sencer
Archived Developer
From: cgn, de
Registered: 2004-03-23
Posts: 1,803
Website

Re: Uncheck Remember User at Login by default

I am always surprised how many people think that entering passwords on an untrusted machine is ok (regardless of the cookie/remember settings).

I am not arguing against the point that it makes more sense from a convenience POV to let one group (the remember people) tick once, rather than having the other group (the not remember me people) having to untick everytime. As a compromise, up to now we saved the unticked box in a preference cookie, so that when you didn’t delete cookies, you would never have to uncheck it again, and if you did in fact delete cookies on a regular basis, it doesn’t matter whether you check the box or not anyhow. Using a different PC everytime is however not solved by that. So it may well change in the near future.

Offline

#4 2006-10-24 20:56:03

The-Exit
Member
From: Berlin
Registered: 2005-07-16
Posts: 175
Website

Re: Uncheck Remember User at Login by default

I would appreciate the change :) I think, it should not be that much change in coding unless you don’t want to integrate the “Mail me my Lost Password” Feature.

Offline

#5 2006-10-25 09:58:08

colak
Admin
From: Cyprus
Registered: 2004-11-20
Posts: 9,023
Website GitHub Mastodon Twitter

Re: Uncheck Remember User at Login by default

The-Exit wrote:

Hi
I used Textpattern for some time from a public computer (i.e. internet cafe) and there I realized, that the “Rembember User” checkbox at the Login is checked by default. That means that I had to uncheck every time this checkbox, because I did not want my login stored on a public pc.
Wouldn’t it make sense, to uncheck it by default? This would be better security and users who want to store their password just have to tick once.

I second this


Yiannis
——————————
NeMe | hblack.art | EMAP | A Sea change | Toolkit of Care
I do my best editing after I click on the submit button.

Offline

Board footer

Powered by FluxBB