Live data from Hacker News

Has the time come to kill the Remember Me checkbox? (2009)

37signals.com

31–38 of 38 posts

Re: Has the time come to kill the Remember Me checkbox? (2009)

#31

I don't think so. Not in every case, anyway. The number of times I've been in an Internet cafe or hotel using a shared PC, in a rush because my taxi is waiting outside and I need to book a hotel in the next city... It's one less thing to worry about. Sure, they could have a keylogger, or a dodgy version of their web browser - but it's one less thing to worry about when you're already in a rush.

For the super rare exception, why not just explicitly log out?

Re: Has the time come to kill the Remember Me checkbox? (2009)

#32
post #29

It seems like it should be a setting on the browser i.e. if it's your own personal laptop then you probably want to always be remembered and if it's an internet cafe then the browser should never remember your password. Maybe the browser could send a header indicating the preference(it could always be ignored - for bank websites etc).

This is one of the more ideal scenarios. Aren't browsers doing something similar when they send a "Do not Track header"? I can think of other instances where this kind of browser configuration can be very useful.

Re: Has the time come to kill the Remember Me checkbox? (2009)

#34
post #29

It seems like it should be a setting on the browser i.e. if it's your own personal laptop then you probably want to always be remembered and if it's an internet cafe then the browser should never remember your password. Maybe the browser could send a header indicating the preference(it could always be ignored - for bank websites etc).

I don't see how that helps things. Instead of "remember to log out after using a public computer", then you would have to "remember how to find the settings for every browser to check if the internet cafe set the right 'remembered' setting or just still remember to always log out at public computers".

Re: Has the time come to kill the Remember Me checkbox? (2009)

#36
post #17

I've got nothing against 'Remember Me' checkboxes, if they were always unchecked by default.

The only major site where I see it checked by default is GMail. Any others?

SigFig - a website to monitor (but not change) your financials.

I e-mailed them asking them to make the default unchecked, but I just got a canned response:

"Thank you for the suggestion. We currently do not offer that feature, but we are always open to new feedback. We have added this to our list of feature requests and ideas."

Re: Has the time come to kill the Remember Me checkbox? (2009)

#37
post #19
post #13

Are people really unable to imagine alternatives to a "yes/no" debate? Certain websites should never have Remember Me checkboxes and should log you out when you close the tab, like banking websites (mine does have a Remember Me checkbox, for shame). There should be a convenience cost for security, or else you're probably not doing security right. Unless it's Reddit or something, there should be no Remember Me and the…

In my experience, "remember me" on banking sites usually saves only your username/login name. Useful on your personal computers when your bank uses your 16 digit card number for login name.

I agree with the above, except I'd replace "Useful" with "Horrifying"

Re: Has the time come to kill the Remember Me checkbox? (2009)

#38
post #37
post #19

Earlier quoted context omitted.

In my experience, "remember me" on banking sites usually saves only your username/login name. Useful on your personal computers when your bank uses your 16 digit card number for login name.

I agree with the above, except I'd replace "Useful" with "Horrifying"

IMVHO, if someone has access to your cookies, you are likely dealing with problems bigger than protecting your bank card number. That implies having access to your files, physical access to the machine, or MITMing the connection to your bank. I can think of worse things that can be done with that level of access.

Maybe I'm missing something.

Post reply on HN