Panel Security Hole

Panel Security Hole

Posted by: Anonymous
Posted on: 2005-08-24 16:11:00

When logging into Dreamhost's web-based panel, there needs to be an AUTO-LOGOUT function implemented.

I recently made a quick change in Dreamhost's Control Panel from a client's computer and forgot to logout. When I returned a few days later my client still had full access to ALL my domains, email addresses, billing information, and other sensitive data.

I know I should remember to logout after every session, but the reality is that sometimes I'm in a huge rush and it doesn't happen.

Every other password-protected site I use (i.e. banks, credit cards, ISP, etc.) automatically logs the users off after a certain amount of time. There's no reason why Dreamhost's Panel shouldn't do the same.

Re: Panel Security Hole

Posted by: TorbenGB
Posted on: 2005-08-25 00:47:00

That's a good point, since the DH panel can actually give you access to things that end up costing you money, as well as trouble if strangers meddle.

I would personally prefer to be always logged in, since I only touch the panel from my own computers. An auto-disconnect would bug me. But it could be a per-user preference setting.

Did you already put this into the Suggestions box?

TorbenGB

Re: Panel Security Hole

Posted by: wjd
Posted on: 2005-08-25 02:52:00

In reply to:

I would personally prefer to be always logged in, since I only touch the panel from my own computers. An auto-disconnect would bug me. But it could be a per-user preference setting.


Exactly!

:-)

happylittlethings.com
Promo Code: WJD50 - $50.00 off any DreamHost plan

Re: Panel Security Hole

Posted by: guice
Posted on: 2005-08-25 10:06:00

Just a simple "keep me logged in" box (default unchecked) on the login page will solve that. If it's not checked, set the cookie to expire at the end of session (browser closes).

Problem solved. It'll take ... 3 lines of code? At the most.

Re: Panel Security Hole

Posted by: conspicuous
Posted on: 2005-08-25 11:52:00

I wouldn't want to be auto logged out. I'm in and out of my account several times a day and having to login all the time would be a drag. An extra bonus of staying logged in is that I get taken back to the page I was last working on when I go to https://panel.dreamhost.com.

Dreamhost has always catered to a level of user that doesn't need spoonfeeding (hence the lack of WYSIWYG editors and templates). Working on a secure computer or clicking "log out" when you're done doesn't seem that onerous.

Just my two cents.

Re: Panel Security Hole

Posted by: netdcon
Posted on: 2005-08-25 11:58:00

In reply to:

I recently made a quick change in Dreamhost's Control Panel from a client's computer and forgot to logout.


That isn't a Dreamhost problem.

It's an ever-so-slight defect with your hosting plan's administrator.

I know this because my hosting plan's administrator occasionally has the same problem.

Re: Panel Security Hole

Posted by: lu_bhz
Posted on: 2007-07-20 07:03:00

Every other webservices that I use (and require a minimum of security) do the 'autologout' as I close the browser.

Why shoudn't DreamHost Panel?

That's default all over the internet.

Re: Panel Security Hole

Posted by: dinochopins
Posted on: 2007-07-20 08:34:00

In reply to:

That's default all over the internet.


Not with friendster.

But I think it is still a good idea to automatically log us out for an exceeded period of time.


Dino

Re: Panel Security Hole

Posted by: Lensman
Posted on: 2007-07-20 08:44:00

I like the idea of a user option on this - actually more of a login radio button like there are on most sites, because I too have a preference for staying logged in on my work and home computer but would like to be logged out on computers where I'm only a "guest".

Re: Panel Security Hole

Posted by: matttail
Posted on: 2007-07-20 09:23:00

This is a nice idea and all, but why bump up a two year old post?



--Matttail
art.googlies.net - personal website

Tags: email addressesdreamhostlogoutcredit cardscontrol panelsecurity holepassword protectedfull accesslogginglogsbillingrushdomainsispbanksreason