@UKTechHub
.
.

Welcome to UKTechHub News & Information

UKTH forums UKTechHub News & Information Welcome to UKTechHub News & Information

Viewing 15 posts - 1 through 15 (of 16 total)
  • Author
    Posts
  • #25020
    UK SentinelUK Sentinel
    Moderator
    • Replies 7,879
    • The Skipper

    After a suggestion from a forum member to try to keep members updated with changes (improvements) that I making to this forum. I have created this new main Forum called ‘UKTechHub News & Information‘ where hopefully members can keep me updated on problems, improvements and ideas they may have to improve this site as well as changes I might be making that effects performance or layout etc.

     

     

    Share the knowledge

    In a completely sane world, madness is the only freedom (J.G.Ballard).

    #25068
    Avatarkev2021
    • Replies 1,141
    • Forum Addict

    So the big question, what changes are on the horizon? :)

    Kev

    Share the knowledge
    #25071
    UK SentinelUK Sentinel
    Moderator
    • Replies 7,879
    • The Skipper

    Completed the first change already, I have changed the way ‘quotes’ are presented and I am sure lots to follow

    Share the knowledge

    In a completely sane world, madness is the only freedom (J.G.Ballard).

    #25080
    GrisuGrisu
    • Replies 971
    • Forum Addict

    Maybe you can now implement an option to stay logged in (not only for 1 day)?

    Share the knowledge
    #25082
    UK SentinelUK Sentinel
    Moderator
    • Replies 7,879
    • The Skipper

    Maybe you can now implement an option to stay logged in (not only for 1 day)?

    I will have a look at this option and will have to consider if there are any impacts on security, best practices, server resources, SSL and cookie policy etc.

    Share the knowledge

    In a completely sane world, madness is the only freedom (J.G.Ballard).

    #25085
    UK SentinelUK Sentinel
    Moderator
    • Replies 7,879
    • The Skipper

    Initial thoughts:

    So had a look at extending the time a forum member can remain logged in even after they shut down their browser, from a technical perspective, when you log in to a website it creates a session, which is usually identified by a token within a cookie. Often, these cookies are set to expire after a certain period of time or when the browser is closed.

    Now currently UKTechHub’s is set to log out whenever the browser is closed (I believe), if this time period is changed to say a day, week or month, then if a forum member is using their own equipment, this is not such a security concern.

    But….

    Now the concern is if the forum member is using a shared or public computer there is the possibility that as the cookie/session are still active, the forum members account could be compromised, moreover a non-shared device that also has an active cookie/session that is then compromised (hacked) could also lead to the forum account being compromised (but is less likely).

    Websites that deal with money, such as banks and e-commerce need to log users out promptly to prevent unauthorised access.

    There is also a server impact but as I only have a small forum currently, not a consideration currently.

    Thoughts most welcomed from all ?

    Share the knowledge

    In a completely sane world, madness is the only freedom (J.G.Ballard).

    #25086
    GrisuGrisu
    • Replies 971
    • Forum Addict

    At least there ist login-button at the end of a thread again, so not really a problem right now.
    Till yesterday it has gone an we needed to use login, after that you ended on a different page.

    I can only say, that in all other large forums which I use, I never have to login, even after browser restart they remain logged in.

    Share the knowledge
    #25088
    Avatarkev2021
    • Replies 1,141
    • Forum Addict

    I’m on another forum and every so often I have to login and use a 2FA code.  I’ve not kept track of the time frame of how long it lets me login for before prompting me again but its not daily.

    TBH I don’t mind logging in each tie I visit as I usually go to the thread I want to read, see replies to and then login at the bottom (now the box is back) and then reply etc from there.  I have my details saved so I simply click the button :)

    Kev

    Share the knowledge
    #25092
    UK SentinelUK Sentinel
    Moderator
    • Replies 7,879
    • The Skipper

    Thanks both @Grisu and @kev2021

    I have checked with a couple of forums I have joined and the first forum logs me out as soon as I close the browser and the second keeps me logged in even after browser is closed and restarted.

    What I would like to do is remove the login-button at the bottom of each topic thread as I dislike this for security and looks perspective, but give the option to allow a logged in user to stay logged in (even after browser is closed) for a recommendation for 30 days or longer, this then also helps remove the need for the login-button at the bottom of each topic and encourage more visits to the forum without the need not to keep logging in each time etc.

    Note, I have already removed the login-button at the bottom of each topic thread and will be working on the option to allow forum members to stay logged in after the browser is closed.

    FWIW, Last year A New law in Italy requires “banner consent at least 6 months” so lots to consider

     

     

    Share the knowledge

    In a completely sane world, madness is the only freedom (J.G.Ballard).

    #25114
    UK SentinelUK Sentinel
    Moderator
    • Replies 7,879
    • The Skipper

    Have changed the Login box that now has a remember me tick box and the Password reset page now look different.

    Early days but the selecting the tick box does seem to enable a forum members user account to remain logged in, even after the browser is restarted and a Windows PC has been rebooted.

    Still need to make the above areas look appropriate, but hopefully the bare bones are now in place

    Share the knowledge

    In a completely sane world, madness is the only freedom (J.G.Ballard).

    #25124
    Avatarkev2021
    • Replies 1,141
    • Forum Addict

    Thanks, I was just about to reply and say the login box at the bottom of the page has gone lol.

    My details were saved from before so the login was auto filled in so will see if it keeps me logged in or not now.

    Are you going to introduce 2FA for additional security i.e. can then allow for 30 days if 2FA, as opposed to someone getting the login creds..

    Kev

    Share the knowledge
    #25126
    GrisuGrisu
    • Replies 971
    • Forum Addict

    Sorry, but this is just a forum and no need for maximum security in my opinion.
    As I wont use 2FA I would leave here, no problem, just for consideration.

    Login at bottom of threads I could live with as Firefox autofilled it and has been only one click.
    If I need to login daily at login-mask and then search thread again for posting would be to troublesome for me.

    Share the knowledge
    #25128
    UK SentinelUK Sentinel
    Moderator
    • Replies 7,879
    • The Skipper

    My details were saved from before so the login was auto filled in so will see if it keeps me logged in or not now.

    If you could this would be most helpful

     

    Are you going to introduce 2FA for additional security i.e. can then allow for 30 days if 2FA, as opposed to someone getting the login creds..

    That is an interesting question, I have personally not experienced any other forums or similar that have implemented  2FA and thinking out loud, I do love good security (policy, standards and procedures), but I am sure (I assume) that most forum users would not welcome this extra layer of authentication.

    Share the knowledge

    In a completely sane world, madness is the only freedom (J.G.Ballard).

    #25165
    Avatarkev2021
    • Replies 1,141
    • Forum Addict

    It kept me logged in today.

    Another forum I’m on uses 2FA but I only do it periodically, every month or 2, the rest of the time it keeps me logged in so it’s not a daily need to 2FA etc.

    That forum also keeps my login details so I literally just open the 2fa app i use on my mobile and enter int he code and that’s it for another month or 2.  Never really kept track of how frequent it is.

    Kev

    Share the knowledge
    #25167
    UK SentinelUK Sentinel
    Moderator
    • Replies 7,879
    • The Skipper

    It kept me logged in today.

    Great news and thanks for letting me know

    2FA is a good security feature and if UKTechHub ever becomes a mega forum, something I will consider

    Share the knowledge

    In a completely sane world, madness is the only freedom (J.G.Ballard).

Viewing 15 posts - 1 through 15 (of 16 total)
  • You must be logged in to reply to this topic.
💫 UKTechHub
Privacy Overview

This Forum uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our Site and helping our team to understand which sections of the website you find most interesting and useful.

Privacy Policy