Thanks for responding Isaac. I appreciate you taking the time.

Please know that I'm not trying to belabor a point at all. I like UBB Threads and have used it for many years. My intention is only to help make good software even better by contributing good ideas. That's all.

So, this issue really isn't big in terms of my own situation. It only means a little inconvenience. It means that I have to find-and-modify the code each time I install an update, and that's not too hard and something I can live with.

I do hope the information below will help.

In short, forcing periodic logins does not increase security for this reason.

Scenario #1:

When cracker gets access to an account, the very first thing a cracker may do is:

1. Change the password.
2. Log out.
3. Log back in with the new password.

In this scenario, if periodic logins are forced:
This locks the original user out (because the cracker logged them out) and gives the cracker exclusive access to the account.

In this scenario, if periodic logins are not forced:
If the cracker does not log the user out (and if a password-change does not forcibly log the user out), the cracker can use/monitor the account without the user knowing.

In this situation, requiring periodic logins does not increase security. It only decreases the window of time a user has access to a compromised account (unless the user is logged our by the cracker or the software), and prevents the user from re-changing the password (during that window of time) to recover the account.

Scenario #2:

If a cracker obtains access to an account by spoofing a cookie and does not change the password (ostensibly to use/monitor the account without the user knowing), then if a user logs in again, the cracker will just spoof the cookie again using the same method they used the first time. So in this scenario, forcing periodic logins does not increase security. Other means (like SSL) would have to be implemented to improve security.

In conclusions, forcing users to re-login periodically does not improve security.

So really, a few rules that would improve security (from a software perspective) would be:

1. Require email verification on each password change. Big social media does this.

2. Notify a user when the forum is accessed from another IP (actually from a different CIDR so as to eliminate multiple notifications when ISPs round-robin their IP addresses) or a different device. Big social media does this too.

3. Force a logout during a password change. This will allow the user to know that their account has been compromised the very next time they visit.

4. Require a multi-stage login/user verification. Big social media does this too.

etc.

I truly hope this helps. Again, I'm only trying to offer information to make the software we all use better in the long run.

Facebook, Twitter, and virtually all the other big players in social media do not use periodic forced logins, and for good reason. They don't increase security but they do decrease user engagement (obviously a bad thing), because people hate re-entering their credentials and big social media knows this.

So really, I would still suggest not capping the admins' cookie-lifetime that they set in the control panel. It ultimately only reduces user engagement and offers no real security advantage.

Your software is very good and I appreciate all the work that you do. That is why we keep periodically renewing our subscription.

Thanks again and all the best.


Today they call you "crazy".
Tomorrow they call you "ahead of your time".