DreamHost Web Hosting
Discussion Forum


Forums
   >> Curious About DreamHost?
*Threaded Mode

Subject Panel Security Hole  
Posted byAnonymous (Unregistered)
Posted on08/24/05 04:11 PM



When logging into Dreamhost's web-based panel, there needs to be an AUTO-LOGOUT function implemented.

I recently made a quick change in Dreamhost's Control Panel from a client's computer and forgot to logout. When I returned a few days later my client still had full access to ALL my domains, email addresses, billing information, and other sensitive data.

I know I should remember to logout after every session, but the reality is that sometimes I'm in a huge rush and it doesn't happen.

Every other password-protected site I use (i.e. banks, credit cards, ISP, etc.) automatically logs the users off after a certain amount of time. There's no reason why Dreamhost's Panel shouldn't do the same.



Subject Re: Panel Security Hole new [re: Anonymous]  
Posted byTorbenGB (DH Smarty Pants)
Posted on08/25/05 00:47 AM



That's a good point, since the DH panel can actually give you access to things that end up costing you money, as well as trouble if strangers meddle.

I would personally prefer to be always logged in, since I only touch the panel from my own computers. An auto-disconnect would bug me. But it could be a per-user preference setting.

Did you already put this into the Suggestions box?

TorbenGB
Try out DreamHost with a free WebID -- Prices, options


Subject Re: Panel Security Hole new [re: TorbenGB]  
Posted bywjd (DH Smarty Pants)
Posted on08/25/05 02:52 AM



In reply to:

I would personally prefer to be always logged in, since I only touch the panel from my own computers. An auto-disconnect would bug me. But it could be a per-user preference setting.


Exactly!

:-)

happylittlethings.com
Promo Code: WJD50 - $50.00 off any DreamHost plan

Subject Re: Panel Security Hole new [re: wjd]  
Posted byguice (DH Enthusiast)
Posted on08/25/05 10:06 AM



Just a simple "keep me logged in" box (default unchecked) on the login page will solve that. If it's not checked, set the cookie to expire at the end of session (browser closes).

Problem solved. It'll take ... 3 lines of code? At the most.



Subject Re: Panel Security Hole new [re: Anonymous]  
Posted byconspicuous (DH Smarty Pants)
Posted on08/25/05 11:52 AM



I wouldn't want to be auto logged out. I'm in and out of my account several times a day and having to login all the time would be a drag. An extra bonus of staying logged in is that I get taken back to the page I was last working on when I go to https://panel.dreamhost.com.

Dreamhost has always catered to a level of user that doesn't need spoonfeeding (hence the lack of WYSIWYG editors and templates). Working on a secure computer or clicking "log out" when you're done doesn't seem that onerous.

Just my two cents.



Subject Re: Panel Security Hole new [re: Anonymous]  
Posted bynetdcon (DH Dreamling)
Posted on08/25/05 11:58 AM



In reply to:

I recently made a quick change in Dreamhost's Control Panel from a client's computer and forgot to logout.


That isn't a Dreamhost problem.

It's an ever-so-slight defect with your hosting plan's administrator.

I know this because my hosting plan's administrator occasionally has the same problem.



Subject Re: Panel Security Hole new [re: guice]  
Posted bylu_bhz (DH New User )
Posted on07/20/07 07:03 AM



Every other webservices that I use (and require a minimum of security) do the 'autologout' as I close the browser.

Why shoudn't DreamHost Panel?

That's default all over the internet.



Subject Re: Panel Security Hole new [re: lu_bhz]  
Posted bydinochopins (DH Regular)
Posted on07/20/07 08:34 AM



In reply to:

That's default all over the internet.


Not with friendster.

But I think it is still a good idea to automatically log us out for an exceeded period of time.


Dino
Get YOUR $97 off on yearly plan with YOUGET97 promo code. Sign Up NOW

Subject Re: Panel Security Hole new [re: dinochopins]  
Posted byLensman (DH DreamNinja)
Posted on07/20/07 08:44 AM



I like the idea of a user option on this - actually more of a login radio button like there are on most sites, because I too have a preference for staying logged in on my work and home computer but would like to be logged out on computers where I'm only a "guest".

Free unique IP and $67 off with promo code FLENSFREEIP67 or use FLENS97 for $97 off. Click here for more options


Subject Re: Panel Security Hole new [re: lu_bhz]  
Posted bymatttail (DH DreamMaster!)
Posted on07/20/07 09:23 AM



This is a nice idea and all, but why bump up a two year old post?



--Matttail
art.googlies.net - personal website



*Threaded Mode
Jump to