<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Is &#8220;Remember me&#8221; still&#160;needed?</title>
	<atom:link href="http://cdevroe.com/notes/rememberme/feed/" rel="self" type="application/rss+xml" />
	<link>http://cdevroe.com/notes/rememberme/</link>
	<description>Personal thoughts and notes.</description>
	<pubDate>Fri, 05 Sep 2008 11:45:03 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Owen</title>
		<link>http://cdevroe.com/notes/rememberme/#comment-85845</link>
		<dc:creator>Owen</dc:creator>
		<pubDate>Fri, 30 Nov 2007 22:21:42 +0000</pubDate>
		<guid isPermaLink="false">http://cdevroe.com/notes/rememberme/#comment-85845</guid>
		<description>While struggling to avoid the reputation that Microsoft gained by allowing their operating system to be very permissive, and effectually insecure, we're trying to create Habari to be secure by default and demand that you knowingly make it less secure rather than casually providing an option without mentioning the ramifications.

By making staying logged in a default on shared machines, forgetting to log out is a very serious security matter, because you probably won't realize that it's happening.  If this option is omitted at login, then you must remember to log out.  Even when you know you should, you don't or can't always do it.  This is not a very secure default.

Currently, without any plugin, Habari logins timeout after 20 minutes of non-use.  (We are considering extending that to an hour.)  Also, if you log out of Habari on one machine, it logs you out of any machine that might be using your login.  There are also measures in place that prevent a hacker from re-using the cookie that keeps you logged in.  There is no "remember me" option at all.

We've been talking this week about how we can make this easier on the user who is used to working with less secure but more convenient systems.  I think many developers on the project are of the opinion that "most secure by default" is the way to go.  We can't expect that every user of our software has a degree in computer security, and it's our responsibility to make some educated decisions for our users.  Only if you really understand the ramifications should you install something that makes your site less secure.

With Habari we have some interesting tricks up our sleeves that might allow the software to be more permissive without completely compromising security, but as a rule, I am pretty emphatic about removing that checkbox, but not because it should remember your login by default; rather, because it shouldn't remember your login at all.</description>
		<content:encoded><![CDATA[<p>While struggling to avoid the reputation that Microsoft gained by allowing their operating system to be very permissive, and effectually insecure, we&#8217;re trying to create Habari to be secure by default and demand that you knowingly make it less secure rather than casually providing an option without mentioning the ramifications.</p>
<p>By making staying logged in a default on shared machines, forgetting to log out is a very serious security matter, because you probably won&#8217;t realize that it&#8217;s happening.  If this option is omitted at login, then you must remember to log out.  Even when you know you should, you don&#8217;t or can&#8217;t always do it.  This is not a very secure default.</p>
<p>Currently, without any plugin, Habari logins timeout after 20 minutes of non-use.  (We are considering extending that to an hour.)  Also, if you log out of Habari on one machine, it logs you out of any machine that might be using your login.  There are also measures in place that prevent a hacker from re-using the cookie that keeps you logged in.  There is no &#8220;remember me&#8221; option at all.</p>
<p>We&#8217;ve been talking this week about how we can make this easier on the user who is used to working with less secure but more convenient systems.  I think many developers on the project are of the opinion that &#8220;most secure by default&#8221; is the way to go.  We can&#8217;t expect that every user of our software has a degree in computer security, and it&#8217;s our responsibility to make some educated decisions for our users.  Only if you really understand the ramifications should you install something that makes your site less secure.</p>
<p>With Habari we have some interesting tricks up our sleeves that might allow the software to be more permissive without completely compromising security, but as a rule, I am pretty emphatic about removing that checkbox, but not because it should remember your login by default; rather, because it shouldn&#8217;t remember your login at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: valerie</title>
		<link>http://cdevroe.com/notes/rememberme/#comment-73766</link>
		<dc:creator>valerie</dc:creator>
		<pubDate>Sat, 27 Oct 2007 14:51:13 +0000</pubDate>
		<guid isPermaLink="false">http://cdevroe.com/notes/rememberme/#comment-73766</guid>
		<description>I prefer to be remembered from the start and I get frustrated with sites on which I click "remember me" and they just refuse to.  I also use my laptop most of the time and stay logged in to just about everything other than secure sites.  When someone else uses my laptop, they know they have to log out of my stuff first or use IE (since I use Firefox).  If a site doesn't have a "remember me" I expect that it WILL remember me.

I feel like most people want to be remembered, except on shared computers, of course, and those people know to log out.  Even my most computer illiterate of friends understand this.  The only people I run in to anymore that worry about cookies are people who are living in 1997 and just &lt;i&gt;don't get it&lt;/i&gt;.  I got some funny friends.  :)

But all in all, at least in the various circles I run in, I feel like "remember me" is unnecessary.</description>
		<content:encoded><![CDATA[<p>I prefer to be remembered from the start and I get frustrated with sites on which I click &#8220;remember me&#8221; and they just refuse to.  I also use my laptop most of the time and stay logged in to just about everything other than secure sites.  When someone else uses my laptop, they know they have to log out of my stuff first or use IE (since I use Firefox).  If a site doesn&#8217;t have a &#8220;remember me&#8221; I expect that it WILL remember me.</p>
<p>I feel like most people want to be remembered, except on shared computers, of course, and those people know to log out.  Even my most computer illiterate of friends understand this.  The only people I run in to anymore that worry about cookies are people who are living in 1997 and just <i>don&#8217;t get it</i>.  I got some funny friends.  <img src='http://cdevroe.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>But all in all, at least in the various circles I run in, I feel like &#8220;remember me&#8221; is unnecessary.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Nicolas</title>
		<link>http://cdevroe.com/notes/rememberme/#comment-73282</link>
		<dc:creator>Daniel Nicolas</dc:creator>
		<pubDate>Fri, 26 Oct 2007 03:15:38 +0000</pubDate>
		<guid isPermaLink="false">http://cdevroe.com/notes/rememberme/#comment-73282</guid>
		<description>I think it's needed.    Just as you said, it's not an issue if you're the only one who uses the computer, or if you never clear your cookies. 

But multiple users (even if it's just a friend checking his email on your system) is a large enough group of people that it's worth having on. 

I think there's some sort of privacy issue but i can't come up with anything at the moment.

Also, I often choose not to use the remember me because I use have a set of passwords for each site and typing the username and password each time helps me memorize them.  If I've only logged in once to a site, I'm pretty much screwed if I have to login a month down the road.  I can guess and go through them all, but it's frustrating to have to send password reminders all the time.</description>
		<content:encoded><![CDATA[<p>I think it&#8217;s needed.    Just as you said, it&#8217;s not an issue if you&#8217;re the only one who uses the computer, or if you never clear your cookies. </p>
<p>But multiple users (even if it&#8217;s just a friend checking his email on your system) is a large enough group of people that it&#8217;s worth having on. </p>
<p>I think there&#8217;s some sort of privacy issue but i can&#8217;t come up with anything at the moment.</p>
<p>Also, I often choose not to use the remember me because I use have a set of passwords for each site and typing the username and password each time helps me memorize them.  If I&#8217;ve only logged in once to a site, I&#8217;m pretty much screwed if I have to login a month down the road.  I can guess and go through them all, but it&#8217;s frustrating to have to send password reminders all the time.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
