pianotuna
Nov 22, 2023Nomad III
sign in
I much preferred being able to view messages without having to sign in each and every time
The password requirements are more complex and there's no "Remember Me" to keep the session alive for days/months like on RV.NET.
And yes, it could be more secure through MFA, but do we really want to do that?
At least the session time-outs give us more protection against someone getting into one of our accounts with elevated permissions and deleting a bunch of posts or banning a bunch of accounts. It's not perfect, but it's more secure than the old site was.
As much as a PIA 2FA/MFA are, I absolutely want them on my financial apps. But for this forum (and other RV type forums): absolutely not.
Still, these things help identify us and ensure to G.S. that we are who we say we are. It does nothing to make the forum more secure. If I was worried about someone hijacking my session, either through my keyboard or intercepting my HTTPS connection, I would definitely logoff after every visit.
I just don't understand how a timeout makes the G.S. forum more secure.