Announcement: Be excellent to each other.


Caravel Forum : Caravel Boards : The Site : more password oddities (something weird this way comes)
New Topic New Poll Post Reply
Poster Message
leroy00
Level: Master Delver
Avatar
Rank Points: 155
Registered: 09-30-2003
IP: Logged
icon more password oddities (0)  
Since the last thread got kind of off-topic, I am starting a new one here.

I access DROD.net from two separate computers. As a consequence of not being able to send an email through a profile, I recently changed my password (while using computer #1) to one which conforms to the new policies. This morning, I logged on to DROD.net using computer #2, running Mozilla, which had the old password saved in my Mozilla profile. The weird things is that I was register as logged on, i.e. at the bottom I could see my name as one of the those logged on and I also saw the "Not leroy00?" thing at the bottom. However, entering "My Profile" just gave me the guest profile. So I wasn't really logged in, which would have been even stranger.

Also, it might be a good idea to prevent multiple log-ins under the same user name concurrently, although if it is from the same IP, I guess it shouldn't matter.

-leroy

____________________________
You can hear happiness staggering on down the street -- footless, dressed in red.
-Jimi Hendrix, "The Wind Cries Mary"
07-04-2005 at 11:58 AM
View Profile Send Private Message to User Send Email to User Show all user's posts Quote Reply
eytanz
Level: Smitemaster
Avatar
Rank Points: 2708
Registered: 02-05-2003
IP: Logged
icon Re: more password oddities (+1)  
leroy00 wrote:
Also, it might be a good idea to prevent multiple log-ins under the same user name concurrently, although if it is from the same IP, I guess it shouldn't matter.

-leroy

I don't think that can be done in any real way in an HTML-based forum, since the system doesn't know whether you are still logged in or not at a computer at the time you log in to another one. I guess it'd be possible to have a minimum time limit - say, you can't log in twice in five minutes - but you'd be causing more harm than good there.

____________________________
I got my avatar back! Yay!
07-04-2005 at 02:48 PM
View Profile Send Private Message to User Show all user's posts This architect's holds Quote Reply
rowrow
Level: Smiter
Rank Points: 432
Registered: 08-17-2004
IP: Logged
icon Re: more password oddities (+1)  
I had this problem a long time ago. Here is the topic.
The solution was that I was blocking cookies. If your browser blocks cookies, unblock it and sign on and let your browser save the cookie and it will be fine. After that you can return it to its previous setting.
That's what I did everytime that happened.

____________________________
B'hakhgra Du S'tra Moth'ness Ti!

[Last edited by rowrow at 07-04-2005 06:16 PM]
07-04-2005 at 03:51 PM
View Profile Send Private Message to User Send Email to User Show all user's posts This architect's holds Quote Reply
Schik
Level: Legendary Smitemaster
Avatar
Rank Points: 5413
Registered: 02-04-2003
IP: Logged
icon Re: more password oddities (0)  
leroy00 wrote:
I access DROD.net from two separate computers. As a consequence of not being able to send an email through a profile, I recently changed my password (while using computer #1) to one which conforms to the new policies. This morning, I logged on to DROD.net using computer #2, running Mozilla, which had the old password saved in my Mozilla profile. The weird things is that I was register as logged on, i.e. at the bottom I could see my name as one of the those logged on and I also saw the "Not leroy00?" thing at the bottom. However, entering "My Profile" just gave me the guest profile. So I wasn't really logged in, which would have been even stranger.
I can't reproduce this. In fact, someone privately reported this same bug a while back, and I fixed it. At least I thought I had. Are you sure that PC #2 wasn't bringing up a cached page or something?

____________________________
The greatness of a nation and its moral progress can be judged by the way it treats its animals.
--Mahatma Gandhi
07-05-2005 at 04:27 AM
View Profile Send Private Message to User Send Email to User Show all user's posts High Scores Quote Reply
leroy00
Level: Master Delver
Avatar
Rank Points: 155
Registered: 09-30-2003
IP: Logged
icon Re: more password oddities (0)  
Schik wrote:
I can't reproduce this. In fact, someone privately reported this same bug a while back, and I fixed it. At least I thought I had. Are you sure that PC #2 wasn't bringing up a cached page or something?

Yeah Schik, now that you mention it, I guess this is the most plausible explanation, I guess I should have thought of that on my own. Sorry for the noise.

-leroy

____________________________
You can hear happiness staggering on down the street -- footless, dressed in red.
-Jimi Hendrix, "The Wind Cries Mary"
07-06-2005 at 11:06 AM
View Profile Send Private Message to User Send Email to User Show all user's posts Quote Reply
Schik
Level: Legendary Smitemaster
Avatar
Rank Points: 5413
Registered: 02-04-2003
IP: Logged
icon Re: more password oddities (0)  
leroy00 wrote:
Yeah Schik, now that you mention it, I guess this is the most plausible explanation, I guess I should have thought of that on my own. Sorry for the noise.
No problem at all... in fact, can you try to reproduce this again? I want to make sure that this bug is fixed - maybe I just can't reproduce it for whatever reason.

____________________________
The greatness of a nation and its moral progress can be judged by the way it treats its animals.
--Mahatma Gandhi
07-06-2005 at 09:05 PM
View Profile Send Private Message to User Send Email to User Show all user's posts High Scores Quote Reply
leroy00
Level: Master Delver
Avatar
Rank Points: 155
Registered: 09-30-2003
IP: Logged
icon Re: more password oddities (0)  
Well, it's not quite as simple as the page having been stored in cache. I repeated the process, and when I logged in from the second computer with the now outdated password, my login name was still shown at the bottom as well as "Not leroy00?". I manually reloaded the page, cleared cache, reloaded again, and at each stage I was shown at the bottom of the page as being logged in, but clicking on profile always took me to the guest profile. And no, I wasn't still logged in on the first computer. If it helps any, the "save user name and password" option in my profile is set to "yes", although it is not clear to me what this option means. Hope that helps.

-leroy

____________________________
You can hear happiness staggering on down the street -- footless, dressed in red.
-Jimi Hendrix, "The Wind Cries Mary"
07-08-2005 at 10:03 AM
View Profile Send Private Message to User Send Email to User Show all user's posts Quote Reply
jamie
Level: Smiter
Rank Points: 365
Registered: 04-15-2005
IP: Logged
icon Re: more password oddities (0)  
eytanz wrote:

I don't think that can be done in any real way in an HTML-based forum, since the system doesn't know whether you are still logged in or not at a computer at the time you log in to another one. I guess it'd be possible to have a minimum time limit - say, you can't log in twice in five minutes - but you'd be causing more harm than good there.

Simply make the new login session automatically logout the old one

____________________________
#f3i2g# Disclaimer: I'm Welsh, left-handed, and stupid. #f3i2g#
07-10-2005 at 08:44 AM
View Profile Send Private Message to User Send Email to User Visit Homepage Show all user's posts Quote Reply
eytanz
Level: Smitemaster
Avatar
Rank Points: 2708
Registered: 02-05-2003
IP: Logged
icon Re: more password oddities (+1)  
jamie wrote:
eytanz wrote:

I don't think that can be done in any real way in an HTML-based forum, since the system doesn't know whether you are still logged in or not at a computer at the time you log in to another one. I guess it'd be possible to have a minimum time limit - say, you can't log in twice in five minutes - but you'd be causing more harm than good there.

Simply make the new login session automatically logout the old one

No, that's exactly what's impossible to do, because the server doesn't really know who is logged in. If you log in, it's saved as information in your browser, which will identify you for every action you do. There's no real sense of a "login session" except in the mind of the user.

The server does know who logged in over the past few minutes (that's what it tells you on the bottom of the main page), so you could tell the server "don't accept the same user coming from different IPs within timeframe X". But that's pre-emptive blocking, not backwards logging out - if I log in from computer A, I won't be able to log in from computer B for a while, which is sort of the opposite of the behavior you are suggesting.

Note - Schik, feel free to correct me if I'm wrong on any of this.

There's a second, more general point, which is that logging out the old session doesn't really make the user any more secure. It's done by several programs (such as MSN messanger), but it's more of a bookkeeping/privacy measure than a security measure. IM software needs to know where you are because it needs to send you messages there. Sending you messages on every computer you ever logged in from is a waste of bandwidth. Furthermore, you run the risk of sending information to the wrong person, which is a problem since all IM'd messages are private to some extent. Forum messages are by-and-large public, and are pulled by the user rather than pushed by the server, so you can't get someone's private messages unless you actively go out looking for them.

Edit: Actually, come to think of it, there is the minor risk of someone using a public computer, then leaving it, and someone else using the same computer to access that person's account. But that risk is independent of the first person happening to log in from another computer. This is a pretty negligable risk IMO, but if it is to be reduced, the only way to do it is to add a "public computer, don't save login info beyond browser session" option at login. Logging out an old session - even if it were possible, which it isn't - would not help in this case since the problem is an insecure login from the same session.


____________________________
I got my avatar back! Yay!

[Last edited by eytanz at 07-10-2005 09:56 AM]
07-10-2005 at 09:35 AM
View Profile Send Private Message to User Show all user's posts This architect's holds Quote Reply
New Topic New Poll Post Reply
Caravel Forum : Caravel Boards : The Site : more password oddities (something weird this way comes)
Surf To:


Forum Rules:
Can I post a new topic? No
Can I reply? No
Can I read? Yes
HTML Enabled? No
UBBC Enabled? Yes
Words Filter Enable? No

Contact Us | CaravelGames.com

Powered by: tForum tForumHacks Edition b0.98.8
Originally created by Toan Huynh (Copyright © 2000)
Enhanced by the tForumHacks team and the Caravel team.