Login timeout

Hi Sim, is it possible to increase the time limit before being logged out?
I think it's only 10 minutes at the moment.
I can click the box to remember me but I don't want to be logged in for infinity if I forget to log out.
 

Sim

Administrator
Session timeout is currently set to 15 minutes.

If you're on your own computer, then using the "remember me" box is the ideal solution.

If you're not on your own computer, having a long session timeout is a security risk, since you'll still be logged in if you walk away from your computer without explicitly logging out - kind of defeats the purpose of not using the remember me box.

If you don't want to be kept logged in by using the remember me feature, then having the computer log you out automatically after 15 minutes of idle activity is reasonable don't you think?

What do you think the ideal balance between security and convenience would be?
 
Hi Sim

Considering it can take more than 15 minutes to read a single thread, might be worthwhile upping this a bit.( slow readers )
I usually have to re-login around 5-8 times a day.
Just my 2 cents worth :)
 

Sim

Administrator
Considering it can take more than 15 minutes to read a single thread, might be worthwhile upping this a bit.( slow readers )
I usually have to re-login around 5-8 times a day.
You don't need to be logged in to read a thread.

If you are constantly browsing the forum throughout the day, then using the "remember me" checkbox is the correct way to stay logged in.
 

Sim

Administrator
Hmm, thought I had this checked, possibly not.
Use a password management tool so will test without :)
That was going to be my other suggestion - password managers FTW.

I have no idea what my password is for Somersoft, or any of the other websites I access daily (although I can find out if I need to - but I generally don't).

While I do use the "remember me" functionality for the forum, the admin area uses a separate session management system with a fairly short timeout period.

As such, I typically have to log in to the admin area multiple times every day.

This isn't really a problem for me, since I use a password management tool which integrates into my browser and does all the hard work for me - it automatically inserts my username and (long random) password for me, so I don't have to type them (or even know them!).
 
Yep, Couldn't Live without it :)
Thanks Again for the responses, Not sure how many people on the forum appreciate the work that goes into keeping systems running!
 
If you don't want to be kept logged in by using the remember me feature, then having the computer log you out automatically after 15 minutes of idle activity is reasonable don't you think?

What do you think the ideal balance between security and convenience would be?
I think 30 minutes before getting logged out is a good balance between security and convenience but security shouldn't be a real concern on this forum so it could possibly be longer.

I've seen comments from people who lost their posts after composing and hitting the submit button but now I know they're saved if you log back in again. It seems the posts are only lost if you hit the 'back' button.
 
Top