LGF Login Notes 9 - Persistent Login

Charles Johnsonfollow me on twitter
Sun Apr 15, 2007 at 2:42 pm PDT • Views: 226

Here’s an open thread for Sunday afternoon (that’s what these login notes threads all turn into anyway).

Again I’m tweaking and revamping things in the login system, so don’t be surprised if something behaves oddly.

The new feature I’m working on is not fully tested yet, but it’s a change in the way the ‘Remember me’ cookie works. (Update: the feature described below is now activated.)

The old way: your login information was saved in an encrypted cookie and used to pre-fill the login forms. Problem: insecure, for several reasons we won’t go into right now.

The new way: the ‘Remember me’ cookie will be a ‘persistent login’ cookie, that lasts for a week from your last login. If you check ‘Remember me’ when you log in, from that point on you will be automatically logged in every time you visit LGF (as long as you don’t stay away for more than a week), using a token-based authentication scheme that never transmits your password over the web, even in encrypted form. End result: much more secure on the server side, and much more convenient for registered users.

(The technique is similar to the one described in Chris Shiflett’s book, Essential PHP Security. If you must know.)

The ‘log out’ feature will also destroy the ‘Remember me’ cookie, so if you log out, you’re logged out for good—until you check the ‘Remember me’ box and log in again.

You don’t have to use persistent login; you can still log in without it, and it will last to the end of your browser session or until you log out (or for 6 hours, the maximum session lifetime).

Note: many browsers now have an ‘autofill’ feature that remembers login information and pre-fills forms. If you continue to see the forms being filled out automatically even after logging out, it’s probably your browser doing it.

UPDATE at 4/15/07 3:23:22 pm:

I should let you know about one more new feature that IS live now: there’s a ‘throttling’ mechanism in place to prevent automated password-guessing attacks. If you enter an incorrect username or password and receive an authentication failure, you have to wait for a little while before trying again. If you try again before the timeout, you’ll get another error even if the username/password are correct. (The moral is: have patience, grasshopper.)

UPDATE at 4/15/07 3:44:02 pm:

The new persistent login feature described above is now activated. Registered users may wish to log out and log back in, just to make sure you’re starting from the right place.

Advertisement

358 comments

^ back to top ^

Name:

Pass:

Register Forgot Your Password? Re-send Confirmation (To log in, cookies must be enabled in your browser!)

Turn off ads by subscribing!
For about 33 cents a day, our subscription option turns off all advertisements at LGF!
Read more...


► LGF Headlines

  • Loading...

► Tweeted Articles

  • Loading...

► Tweeted Pages

  • Loading...

► Top 10 Comments

  • Loading...

► Bottom Comments

  • Loading...

► Recent Comments

  • Loading...

► Tools/Info

► Tag Cloud

► Contact

You must have Javascript enabled to use the contact form.
Your email:

Subject:

Message:


Messages may be published in our weblog, unless you request otherwise.
Tech Note:
Using the Contact Form

More Partners

Compare Electricity Prices in your area. Texas Electricity is deregulated; you have the right to choose Texas Electric Rates from among many Texas Electric Companies.

Play nice.

TwitterFacebook
LGF Pages
Recent Pages

STLActivist
Irony Alert! Loesch Distracts From Riehl's Misogyny By Tag-Teaming With Another Misogynist
5 minutes ago
Views: 37 • Comments: 0
Tweets: 0 • Rating: 1

Daniel Ballard
Late Afternoon Light-Kalanchoe
17 minutes ago
Views: 19 • Comments: 0
Tweets: 0 • Rating: 2

MikeySDCA
Colin Powell Endorsed Same-Sex Marriage Once It Was Safe, More Evidence He's Hardly a Great Leader.
21 minutes ago
Views: 15 • Comments: 0
Tweets: 0 • Rating: 0

researchok
Attachment Birthers
30 minutes ago
Views: 27 • Comments: 0
Tweets: 0 • Rating: 0

Eclectic Infidel
City College of San Francisco Budget Update
1 hour, 10 minutes ago
Views: 46 • Comments: 0
Tweets: 0 • Rating: 0

Michael McBacon
Kansas governor signs 'Shariah bill' to ban Islamic law
5 hours, 40 minutes ago
Views: 134 • Comments: 5
Tweets: 0 • Rating: 3

Aigle
National Geographic Traveler Veers Off Track
1 day, 5 hours ago
Views: 375 • Comments: 5
Tweets: 0 • Rating: -5

MichaelJ
Apple TV Slated to Debut in December?
1 day, 6 hours ago
Views: 192 • Comments: 0
Tweets: 0 • Rating: 1

Ascher
Israeli Who Saved Turk on Everest: You Never Abandon a Friend - Israel News, Ynetnews
1 day, 8 hours ago
Views: 252 • Comments: 1
Tweets: 0 • Rating: 3

Haywood Jabloeme
The Harrassment of Patterico & Its Roots in Left-Wing Activism
1 day, 8 hours ago
Views: 465 • Comments: 2
Tweets: 0 • Rating: 4

 Frank says:

You can tell what they think of our music by the places we are forced to play it in. This looks like a good spot for a livestock show. -- The Mothers of Invention were opening for Cream in April of 1968 in Chicago. The place was very large and did look like it had been used for displays of cattle and other such animals.