Live data from Hacker News

Has the time come to kill the Remember Me checkbox? (2009)

37signals.com

11–20 of 38 posts

Re: Has the time come to kill the Remember Me checkbox? (2009)

#12
No, it's time to kill passwords. If I need to log in, send me two links and/or temporary auth codes: a persistent login clearly labeled, and a transient login for use in public places. If you're a serious site (banks, utilities, etc), use two-factor auth, don't accept anything less and of course, don't persist my login.

Alternatively, I keep hoping to see user-controlled federated ID gaining traction - you know, a personal 'wallet' that I maintain myself and store all of my identity in. And when you want to know who I am, you contact my server and it tells if if I approve it. I'd happily take this extra step every time. However, I've realized that this will never happen - too many people don't care, and no major tech companies are willing to push it for fear for backlash.

While I'm wandering further off-subject (but still reasonably tangential): dear people who make marketing email systems, please stop requiring me to log in when I follow your unsubscribe link. One might begin to expect that you add this extra stumbling block to make it harder for me to do what I want - and that's certainly no way to get my business. Every time I get an email from you, I'm reminded that I don't want to be receiving them.

I suppose it's possible that someone has hijacked my email credentials and that they may be fraudulently unsubscribing me. But that's a risk I'm willing to take. You - you hypothetical marketer you - should be too, unless you're a bank. A pissed off customer is not one who will do business with you no matter how many mailings you send.

edit: typos and correctness

Re: Has the time come to kill the Remember Me checkbox? (2009)

#13
Are people really unable to imagine alternatives to a "yes/no" debate? Certain websites should never have Remember Me checkboxes and should log you out when you close the tab, like banking websites (mine does have a Remember Me checkbox, for shame). There should be a convenience cost for security, or else you're probably not doing security right. Unless it's Reddit or something, there should be no Remember Me and the cookie should expire shortly or on closing the page.

Re: Has the time come to kill the Remember Me checkbox? (2009)

#14

No, it's time to kill passwords. If I need to log in, send me two links and/or temporary auth codes: a persistent login clearly labeled, and a transient login for use in public places. If you're a serious site (banks, utilities, etc), use two-factor auth, don't accept anything less and of course, don't persist my login. Alternatively, I keep hoping to see user-controlled federated ID gaining traction - you know, a pe…

Being that you support wild-abandon ubiquitous centralized digital identity, I'm guessing you use Gmail, in which case you can easily make a filter for the spam rather than going through the trouble of unsubscribing.

Re: Has the time come to kill the Remember Me checkbox? (2009)

#15

No, it's time to kill passwords. If I need to log in, send me two links and/or temporary auth codes: a persistent login clearly labeled, and a transient login for use in public places. If you're a serious site (banks, utilities, etc), use two-factor auth, don't accept anything less and of course, don't persist my login. Alternatively, I keep hoping to see user-controlled federated ID gaining traction - you know, a pe…

>No, it's time to kill passwords. >don't persist my login

You say no, but it reads yes.

Re: Has the time come to kill the Remember Me checkbox? (2009)

#16

No, it's time to kill passwords. If I need to log in, send me two links and/or temporary auth codes: a persistent login clearly labeled, and a transient login for use in public places. If you're a serious site (banks, utilities, etc), use two-factor auth, don't accept anything less and of course, don't persist my login. Alternatively, I keep hoping to see user-controlled federated ID gaining traction - you know, a pe…

Mozilla's Persona seems like an option. You can self-host and it seems to do what you want.

Re: Has the time come to kill the Remember Me checkbox? (2009)

#18
post #7

Earlier quoted context omitted.

Logout button?

I'm forgetful. If I forget to log out, my account is open to everyone. If I forget to click "remember me", I have to sign in twice. Making systems that fail safely in case of human error is a good thing. Although one of my favorite ideas was a system I saw at a hardware store. You could use their terminals to look up products. The terminals had a pressure pad in front of them, and as soon as you stepped off the pad,…

Out of curiosity, what store (assuming its a chain, or large enough to be known outside local circles)? That's pretty nifty.

Re: Has the time come to kill the Remember Me checkbox? (2009)

#19
post #13

Are people really unable to imagine alternatives to a "yes/no" debate? Certain websites should never have Remember Me checkboxes and should log you out when you close the tab, like banking websites (mine does have a Remember Me checkbox, for shame). There should be a convenience cost for security, or else you're probably not doing security right. Unless it's Reddit or something, there should be no Remember Me and the…

In my experience, "remember me" on banking sites usually saves only your username/login name. Useful on your personal computers when your bank uses your 16 digit card number for login name.

Re: Has the time come to kill the Remember Me checkbox? (2009)

#20

No, it's time to kill passwords. If I need to log in, send me two links and/or temporary auth codes: a persistent login clearly labeled, and a transient login for use in public places. If you're a serious site (banks, utilities, etc), use two-factor auth, don't accept anything less and of course, don't persist my login. Alternatively, I keep hoping to see user-controlled federated ID gaining traction - you know, a pe…

> dear people who make marketing email systems, please stop requiring me to log in when I follow your unsubscribe link.

Isn't this illegal according to the CAN SPAM act, at least for the types of emails it covers? http://www.business.ftc.gov/documents/bus61-can-spam-act-com...

Post reply on HN