› UKTH forums › UKTechHub News & Information › Welcome to UKTechHub News & Information
- This topic has 15 replies, 3 voices, and was last updated 1 year, 10 months ago by
UK Sentinel.
-
AuthorPosts
-
June 9, 2023 at 7:09 am #25020
After a suggestion from a forum member to try to keep members updated with changes (improvements) that I making to this forum. I have created this new main Forum called ‘UKTechHub News & Information‘ where hopefully members can keep me updated on problems, improvements and ideas they may have to improve this site as well as changes I might be making that effects performance or layout etc.
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
June 9, 2023 at 7:10 pm #25068June 9, 2023 at 8:39 pm #25071Completed the first change already, I have changed the way ‘quotes’ are presented and I am sure lots to follow
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
June 10, 2023 at 11:06 am #25080Maybe you can now implement an option to stay logged in (not only for 1 day)?
You need to login in order to vote
June 10, 2023 at 12:47 pm #25082Maybe you can now implement an option to stay logged in (not only for 1 day)?
I will have a look at this option and will have to consider if there are any impacts on security, best practices, server resources, SSL and cookie policy etc.
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
June 10, 2023 at 6:55 pm #25085Initial thoughts:
So had a look at extending the time a forum member can remain logged in even after they shut down their browser, from a technical perspective, when you log in to a website it creates a session, which is usually identified by a token within a cookie. Often, these cookies are set to expire after a certain period of time or when the browser is closed.
Now currently UKTechHub’s is set to log out whenever the browser is closed (I believe), if this time period is changed to say a day, week or month, then if a forum member is using their own equipment, this is not such a security concern.
But….
Now the concern is if the forum member is using a shared or public computer there is the possibility that as the cookie/session are still active, the forum members account could be compromised, moreover a non-shared device that also has an active cookie/session that is then compromised (hacked) could also lead to the forum account being compromised (but is less likely).
Websites that deal with money, such as banks and e-commerce need to log users out promptly to prevent unauthorised access.
There is also a server impact but as I only have a small forum currently, not a consideration currently.
Thoughts most welcomed from all ?
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
June 10, 2023 at 8:32 pm #25086At least there ist login-button at the end of a thread again, so not really a problem right now.
Till yesterday it has gone an we needed to use login, after that you ended on a different page.I can only say, that in all other large forums which I use, I never have to login, even after browser restart they remain logged in.
You need to login in order to vote
June 10, 2023 at 10:30 pm #25088I’m on another forum and every so often I have to login and use a 2FA code. I’ve not kept track of the time frame of how long it lets me login for before prompting me again but its not daily.
TBH I don’t mind logging in each tie I visit as I usually go to the thread I want to read, see replies to and then login at the bottom (now the box is back) and then reply etc from there. I have my details saved so I simply click the button :)
Kev
You need to login in order to vote
June 11, 2023 at 6:12 am #25092Thanks both @Grisu and @kev2021
I have checked with a couple of forums I have joined and the first forum logs me out as soon as I close the browser and the second keeps me logged in even after browser is closed and restarted.
What I would like to do is remove the login-button at the bottom of each topic thread as I dislike this for security and looks perspective, but give the option to allow a logged in user to stay logged in (even after browser is closed) for a recommendation for 30 days or longer, this then also helps remove the need for the login-button at the bottom of each topic and encourage more visits to the forum without the need not to keep logging in each time etc.
Note, I have already removed the login-button at the bottom of each topic thread and will be working on the option to allow forum members to stay logged in after the browser is closed.
FWIW, Last year A New law in Italy requires “banner consent at least 6 months” so lots to consider
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
June 11, 2023 at 5:34 pm #25114Have changed the Login box that now has a remember me tick box and the Password reset page now look different.
Early days but the selecting the tick box does seem to enable a forum members user account to remain logged in, even after the browser is restarted and a Windows PC has been rebooted.
Still need to make the above areas look appropriate, but hopefully the bare bones are now in place
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
June 11, 2023 at 7:31 pm #25124Thanks, I was just about to reply and say the login box at the bottom of the page has gone lol.
My details were saved from before so the login was auto filled in so will see if it keeps me logged in or not now.
Are you going to introduce 2FA for additional security i.e. can then allow for 30 days if 2FA, as opposed to someone getting the login creds..
Kev
You need to login in order to vote
June 11, 2023 at 8:09 pm #25126Sorry, but this is just a forum and no need for maximum security in my opinion.
As I wont use 2FA I would leave here, no problem, just for consideration.Login at bottom of threads I could live with as Firefox autofilled it and has been only one click.
If I need to login daily at login-mask and then search thread again for posting would be to troublesome for me.You need to login in order to vote
June 11, 2023 at 8:37 pm #25128My details were saved from before so the login was auto filled in so will see if it keeps me logged in or not now.
If you could this would be most helpful
Are you going to introduce 2FA for additional security i.e. can then allow for 30 days if 2FA, as opposed to someone getting the login creds..
That is an interesting question, I have personally not experienced any other forums or similar that have implemented 2FA and thinking out loud, I do love good security (policy, standards and procedures), but I am sure (I assume) that most forum users would not welcome this extra layer of authentication.
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
June 12, 2023 at 9:22 am #25165It kept me logged in today.
Another forum I’m on uses 2FA but I only do it periodically, every month or 2, the rest of the time it keeps me logged in so it’s not a daily need to 2FA etc.
That forum also keeps my login details so I literally just open the 2fa app i use on my mobile and enter int he code and that’s it for another month or 2. Never really kept track of how frequent it is.
Kev
You need to login in order to vote
June 12, 2023 at 10:58 am #25167It kept me logged in today.
Great news and thanks for letting me know
2FA is a good security feature and if UKTechHub ever becomes a mega forum, something I will consider
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
-
AuthorPosts
- You must be logged in to reply to this topic.