Hacker News new | past | comments | ask | show | jobs | submit login

If you want to do this, at least make the login cookie expire at the end of the session.

I had a friend forward me an OKCupid e-mail when they sent mis-matches for April Fools - a few days later I realized that I had somehow been logged in as said friend and was majorly creeped out. Had I been less mature about it there was major potential for trolling said friend - particularly on OKC.




Mistakes like this will inevitably occur even with a cookie that expires as you suggest. Not as often as with a non-expiring token, but there are plenty of people who will leave a browser tab up for days at a time, keeping the session alive.

The convenience is tempting but it seems careless.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: