IPB cookies

Suggestions, problems regarding the site and other community facilities.
pkk
Posts: 5419
Joined: Tue Jul 01, 2003 7:00 am
Location: Germany, Munich

Post by pkk »

I hate logging in every time, after I visited this forum from a different computer.

Seems like it is a security function, because I only have this problem on this site (visiting no other IPBoard).

I have no idea if it can be turned off... :iluv:
The Escapist (Justin Emerson) @ Dec 21 2010, 02:33 PM:
The history of open-source Allegiance is paved with the bodies of dead code branches, forum flame wars, and personal vendettas. But a community remains because people still love the game.
notjarvis
Posts: 4629
Joined: Tue Jun 03, 2008 11:08 am
Location: Birmingham, UK

Post by notjarvis »

pkk wrote:QUOTE (pkk @ Nov 7 2009, 09:00 PM) I hate logging in every time, after I visited this forum from a different computer.

Seems like it is a security function, because I only have this problem on this site (visiting no other IPBoard).

I have no idea if it can be turned off... :iluv:

Thats strange cos I never have this problem.

I log in from multiple computers on a regular basis and I don't often need to relohgin....
Adam4
Posts: 2144
Joined: Sun Sep 03, 2006 9:05 am
Location: England

Post by Adam4 »

notjarvis wrote:QUOTE (notjarvis @ Nov 7 2009, 10:05 PM) Thats strange cos I never have this problem.

I log in from multiple computers on a regular basis and I don't often need to relohgin....
madpeople
Posts: 4787
Joined: Tue Dec 16, 2003 8:00 am
Location: England

Post by madpeople »

I have the logout problem. Further to that, logging in once on Computer B can mean that I need to login every time I visit on Computer A for a long time after.

FF 3.5.5 / 3.5.3
Tigereye
Posts: 4952
Joined: Mon Jul 28, 2003 7:00 am
Location: Toronto, Ontario

Post by Tigereye »

As pkk speculated, this is a security feature of IPB and is on by default.

I can disable it. Actually, come to think of it, considering our entire forum is in the clear (no SSL cert used) there's no real security gained by this setting...
If someone can sniff your sessionID, they can sniff your password while logging into the forum anyways.If someone wants to force you to log into your account, they can invalidate your session for you, forcing you to log in (so they can sniff your password in plaintext)If someone is at your computer copying your cookie from your harddrive, they can copy your browser passwords too using any number of local attacks.
I'll turn this off when I get home which should allow a session to persist regardless of IP.

I believe the result would be: you'll need to log in once from that machine and then your cookie will save your login session until you clear cookies on that machine. Logging in on another machine would duplicate the cookie there without invalidating the first machine's cookie.

If we ever enable SSL on our forum (which wouldn't add any value except for the ZLs and myself), I'll reconsider this setting, but for now it doesn't add any real security.

In the meantime:Community leaders (ZLs, SLs, etc): watch where you log into our forum. Script-kiddies love sniffing :P Everyone: I recommend you use a different password for this forum than everything else (including ASGS).
--TE
(PS: for those of you who are suddenly worried, we've lived like this for the last 8-9 years so don't sweat it)
Last edited by Tigereye on Tue Nov 10, 2009 3:28 am, edited 1 time in total.


The Allegiance community currently hates their sysadmin because he is doing: [Too Much] [____________|] [Too Little]
Current reason: Removing the PayPal contribute page. Send Bitcoin instead: 1EccFi98tR5S9BYLuB61sFfxKqqgSKK8Yz. This scale updates regularly.
pkk
Posts: 5419
Joined: Tue Jul 01, 2003 7:00 am
Location: Germany, Munich

Post by pkk »

Tigereye wrote:QUOTE (Tigereye @ Nov 10 2009, 04:25 AM) (PS: for those of you who are suddenly worried, we've lived like this for the last 8-9 years so don't sweat it)
Nope, we didn't. We live with that feature, since pook switched from phpnuke/phpbb to IPB in June 2006. ;)

Seems like nobody else took care of it. :P
The Escapist (Justin Emerson) @ Dec 21 2010, 02:33 PM:
The history of open-source Allegiance is paved with the bodies of dead code branches, forum flame wars, and personal vendettas. But a community remains because people still love the game.
Tigereye
Posts: 4952
Joined: Mon Jul 28, 2003 7:00 am
Location: Toronto, Ontario

Post by Tigereye »

Neither of the PHPnuke or phpbb forums were protected with an SSL certificate, so we've had unencrypted forums for the last 8-9 years. I don't even think the Microsoft Gaming Zone had a cert back when Allegiance was on it :P

--TE


The Allegiance community currently hates their sysadmin because he is doing: [Too Much] [____________|] [Too Little]
Current reason: Removing the PayPal contribute page. Send Bitcoin instead: 1EccFi98tR5S9BYLuB61sFfxKqqgSKK8Yz. This scale updates regularly.
Dorjan
Posts: 5024
Joined: Sun Oct 07, 2007 9:56 am
Location: England

Post by Dorjan »

I just assumed this was the security feature by IP so never complained. It'll save me from having to log in everyday at home / work.

Thanks TE / pkk
I decided to relive the days gone by in my new blog.
---
Remember, what I say is IMO always. If I say that something sucks, it actually means "I think it sucks" OK?
Cookie Monster wrote:QUOTE (Cookie Monster @ Jan 31 2012, 03:09 PM) True story.

Except the big about dorjan being jelly, that's just spidey's ego.
ImageImage
Cadillac
Posts: 11578
Joined: Fri Sep 01, 2006 9:42 am
Location: London, UK

Post by Cadillac »

Can you delete this thread now, I've been tormented enough.
Image Image Image
"If you wish to make an apple pie from scratch, you must first invent the universe." Carl Sagan ("The Lives of the Stars" ep. 9 Cosmos)
Rants Blog Cadillac, *Wurflet@Event, ?GoldDragon@Alleg, ^Biggus*#$@us@XT, +Ashandarei@Zone
pkk
Posts: 5419
Joined: Tue Jul 01, 2003 7:00 am
Location: Germany, Munich

Post by pkk »

Cookie Monster wrote:QUOTE (Cookie Monster @ Nov 20 2009, 06:04 PM) Can you delete this thread now, I've been tormented enough.
Nope, someone turned that setting back on... :P
The Escapist (Justin Emerson) @ Dec 21 2010, 02:33 PM:
The history of open-source Allegiance is paved with the bodies of dead code branches, forum flame wars, and personal vendettas. But a community remains because people still love the game.
Post Reply