Re: Time Out, Close Session and Reauthentication Timing
Skot Nelson <[email protected]>
| Newsgroups | gmane.comp.web.chi-web |
|---|---|
| Message-ID | <[email protected]> |
On Sep-25-2007, at 04:26 , Deb Brown wrote:
> Our applications are
> medium security - they don't deal with state secrets - but do
> handle all
> documentation (sometimes very sensitive) for companies.
Sounds like the perfect application for a 'slightly longer than a
work day' credential timeout. You say "very sensitive" which suggests
that there's some value to requiring a login. Having a 12 hour
timeout would allow a person to login in the a.m. and not be required
to login again.
Are inactivity timeouts truly necessary? For banking applications I
see the value. For many others they're typically annoying. (You don't
mention the type of application specifically, nor whether sessions
are portable across logins to multiple machines -- if I log out on
machine A, does machine B pick my session up? Would logging in on
another machine ever happen?)
I'd general timeout a session with the 12 hour timeout as well. (Or
whatever you choose for a "long session timeout.)
--
Skot Nelson
skot (at) penguinstorm (dot) com
http://www.penguinstorm.com/
p. 206.629.8735
skype. skot.nelson
http://www.linkedin.com/in/skotnelson
"In anything at all, perfection is finally attained not when
there is no longer anything to add, but when there
is no longer anything to take away."
-- Antonine de Saint-Exupéry, Wind, Sand and Stars
--------------------------------------------------------------
Tip of the Day: Use the archives to research common questions
CHI-WEB: www.sigchi.org/web POSTINGS: mailto:[email protected]
MODERATORS: mailto:[email protected]
SUBSCRIPTION CHANGES & FAQ: www.sigchi.org/web/faq.html
--------------------------------------------------------------