An open community 
of Macintosh users,
for Macintosh users.

FineTunedMac Dashboard widget now available! Download Here

Previous Thread
Next Thread
Print Thread
Page 2 of 2 1 2
Re: What just blew through FTM?!
artie505 #34313 05/16/15 11:41 AM
Joined: Aug 2009
Likes: 3
Moderator
Offline
Moderator

Joined: Aug 2009
Likes: 3

Here's an informative experiment:

While logged into FTM in your usual browser, launch another browser and try to log in from there.



dkmarsh—member, FineTunedMac Co-op Board of Directors
Re: What just blew through FTM?!
dkmarsh #34317 05/16/15 08:44 PM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
OK, I was able to log in to FTM in Firefox while I was logged in in Safari, but I don't know if that's the answer for which I'm looking.

The important question is would somebody be able to log in from a different computer at a different IP Address at the same time I was logged in? (Sorry, but I've got no way to experiment.)

And further, were I to experiment, could I extrapolate my FTM results as being applicable to all websites?


The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire
Re: What just blew through FTM?!
artie505 #34319 05/16/15 09:48 PM
Joined: Aug 2009
Likes: 3
Moderator
Offline
Moderator

Joined: Aug 2009
Likes: 3
I am currently logged into FTM on both my phone and my computer, if that helps clarify things for you.



dkmarsh—member, FineTunedMac Co-op Board of Directors
Re: What just blew through FTM?!
grelber #37071 11/08/15 06:08 PM
Joined: Aug 2009
Likes: 4
grelber Offline OP
OP Offline

Joined: Aug 2009
Likes: 4
Originally Posted By: grelber
Originally Posted By: artie505
And, by the way, I never log out on my own; it just happens on it's own, usually while I'm away from my deuced Mac(hina). It's never happened suddenly as you've described, but I assume it would if I was visiting FTM when it happened.

Neither do I. You'll recall that tacit mentioned the new setup would only permit a finite (ca 4-week) login period. I just wait until that happens.
As mentioned, I wasn't logged out when the bizarre behavior happened. But logging out and back in resolved the issue.

It's baaack! The issue was ostensibly fixed by tacit to the maximum allowable within UBB.threads' constraints (see above), but all of a sudden it seems that the problem crops up weekly (not monthly). Anybody know what's up?

Re: What just blew through FTM?!
grelber #37076 11/08/15 10:14 PM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
I dunno what's up with you, but as far as I can tell I'm still on a monthly schedule...longer if anything, but certainly not shorter.

It may be a 31 day month, because I remember the first time I found myself logged out being on the 4th, and although I haven't been keeping track of the exact date, I know it's definitely happening later now.


The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire
Re: What just blew through FTM?!
dkmarsh #37077 11/08/15 10:15 PM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
Originally Posted By: dkmarsh
I am currently logged into FTM on both my phone and my computer, if that helps clarify things for you.

Not that security is much of an issue at FTM, but doesn't that strike you as being a serious security issue?


The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire
Re: What just blew through FTM?!
artie505 #37078 11/09/15 12:53 AM
Joined: Aug 2009
Likes: 16
Moderator
Online
Moderator

Joined: Aug 2009
Likes: 16
Originally Posted By: artie505
Not that security is much of an issue at FTM, but doesn't that strike you as being a serious security issue?

I know several supposedly highly secure financial sites and any number of e-commerce sites that allow simultaneously logons using the same userid and password.

Perhaps you could elaborate on why you see that as a serious security issue.


If we knew what it was we were doing, it wouldn't be called research, would it?

— Albert Einstein
Re: What just blew through FTM?!
joemikeb #37079 11/09/15 01:21 AM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
Originally Posted By: joemikeb
Originally Posted By: artie505
Not that security is much of an issue at FTM, but doesn't that strike you as being a serious security issue?

I know several supposedly highly secure financial sites and any number of e-commerce sites that allow simultaneously logons using the same userid and password.

Perhaps you could elaborate on why you see that as a serious security issue.

I really can't say definitively, but it just seems pretty unreasonable that two of me should be able to be logged in from different machines in different locations at the same time.

I can't see any purpose for it other than mayhem.

Why shouldn't a simultaneous login to an account be challenged to either alert the real me that a phony me is already logged in or to stymy a phony me when the real me is already logged in?

What say you, grelber? wink grin


The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire
Re: What just blew through FTM?!
artie505 #37082 11/09/15 09:23 AM
Joined: Aug 2009
Likes: 4
grelber Offline OP
OP Offline

Joined: Aug 2009
Likes: 4
Originally Posted By: artie505
I dunno what's up with you, but as far as I can tell I'm still on a monthly schedule...longer if anything, but certainly not shorter.
It may be a 31 day month, because I remember the first time I found myself logged out being on the 4th, and although I haven't been keeping track of the exact date, I know it's definitely happening later now.

Maybe it was just a glitch (somewhere along the line), but it's been 2 Sundays in a row when I've been required to log in anew. Prior to the switch back to regular time it was on a monthly basis (as noted).

Re: What just blew through FTM?!
artie505 #37083 11/09/15 09:27 AM
Joined: Aug 2009
Likes: 4
grelber Offline OP
OP Offline

Joined: Aug 2009
Likes: 4
Originally Posted By: artie505
I really can't say definitively, but it just seems pretty unreasonable that two of me should be able to be logged in from different machines in different locations at the same time.
I can't see any purpose for it other than mayhem.
Why shouldn't a simultaneous login to an account be challenged to either alert the real me that a phony me is already logged in or to [stymie] a phony me when the real me is already logged in?
What say you, grelber? wink grin

I say either "Hang 'em from the yardarm!" or "Makes me no nevermind." tongue

Re: What just blew through FTM?!
grelber #37084 11/09/15 09:40 AM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
Originally Posted By: grelber
[stymie]

Originally Posted By: Wiktionary
Verb
stymy ‎(third-person singular simple present stymies, present participle stymying, simple past and past participle stymied)
Alternative spelling of stymie

It came up in spell-check.


The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire
Re: What just blew through FTM?!
grelber #37085 11/09/15 09:42 AM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
Originally Posted By: grelber
Originally Posted By: artie505
I really can't say definitively, but it just seems pretty unreasonable that two of me should be able to be logged in from different machines in different locations at the same time.
I can't see any purpose for it other than mayhem.
Why shouldn't a simultaneous login to an account be challenged to either alert the real me that a phony me is already logged in or to [stymie] a phony me when the real me is already logged in?
What say you, grelber? wink grin

I say either "Hang 'em from the yardarm!" or "Makes me no nevermind." tongue

Where's that legendary paranoia? grin


The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire
Re: What just blew through FTM?!
artie505 #37086 11/09/15 10:01 AM
Joined: Aug 2009
Likes: 4
grelber Offline OP
OP Offline

Joined: Aug 2009
Likes: 4
Originally Posted By: artie505

Originally Posted By: Wiktionary
Verb
stymy ‎(third-person singular simple present stymies, present participle stymying, simple past and past participle stymied)
Alternative spelling of stymie

It came up in spell-check.

Apple dictionary (2.2.3) only gives the preferred spelling and presents a different present participle:
verb (stymies, stymieing, stymied).
But point taken.

Re: What just blew through FTM?!
artie505 #37087 11/09/15 10:03 AM
Joined: Aug 2009
Likes: 4
grelber Offline OP
OP Offline

Joined: Aug 2009
Likes: 4
Originally Posted By: artie505
Where's that legendary paranoia? grin

In this case I packed it in and agree with joemikeb (for the same reasons).

Re: What just blew through FTM?!
grelber #37088 11/09/15 10:15 AM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
Originally Posted By: grelber
Originally Posted By: artie505
Originally Posted By: Wiktionary
Verb
stymy ‎(third-person singular simple present stymies, present participle stymying, simple past and past participle stymied)
Alternative spelling of stymie

It came up in spell-check.

Apple dictionary (2.2.3) only gives the preferred spelling and presents a different present participle:
verb (stymies, stymieing, stymied).
But point taken.

It's not in Dictionary.app v 2.1.3, but it turns up in spell-check all the same.


The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire
Re: What just blew through FTM?!
grelber #37089 11/09/15 10:17 AM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
Originally Posted By: grelber
Originally Posted By: artie505
Where's that legendary paranoia? grin

In this case I packed it in and agree with joemikeb (for the same reasons).

joemike didn't offer any reasons.

Quote:
I know several supposedly highly secure financial sites and any number of e-commerce sites that allow simultaneously logons using the same userid and password.

Perhaps you could elaborate on why you see that as a serious security issue.


The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire
Re: What just blew through FTM?!
artie505 #37090 11/09/15 11:10 AM
Joined: Aug 2009
Likes: 4
grelber Offline OP
OP Offline

Joined: Aug 2009
Likes: 4
Originally Posted By: artie505
joemike didn't offer any reasons.

Quote:
I know several supposedly highly secure financial sites and any number of e-commerce sites that allow simultaneously logons using the same userid and password.
Perhaps you could elaborate on why you see that as a serious security issue.


I took the reasons to be implicit, namely that there are apparently no serious security issues, and I agree with that.
Some SSL/https sites (eg, Google) might alert the user(s) regarding simultaneous usage but they allow it.
Chacun à son goût.

Re: What just blew through FTM?!
joemikeb #37097 11/09/15 01:21 PM
Joined: Aug 2009
Offline

Joined: Aug 2009
Originally Posted By: joemikeb
Originally Posted By: artie505
Not that security is much of an issue at FTM, but doesn't that strike you as being a serious security issue?

I know several supposedly highly secure financial sites and any number of e-commerce sites that allow simultaneously logons using the same userid and password.

Perhaps you could elaborate on why you see that as a serious security issue.

Reminds me a little of several providers' features of "log out al other instances of my account". Gmail has this. It's useful if, for example, you left yourself logged in at the library, or you borrowed someone's phone to access your email and it insisted on remembering the password. You login on their web site and tell gmail to log you out everywhere, and it expires all valid tokens and cookies.

Also if someone happens to steal/acquire your password, they probably can't change it on you (since they don't control the verification email address) but you'd need some way to get them out. This may be the only way to do it.


I work for the Department of Redundancy Department
Page 2 of 2 1 2

Moderated by  alternaut, cyn, dkmarsh 

Link Copied to Clipboard
Powered by UBB.threads™ PHP Forum Software 7.7.4
(Release build 20200307)
Responsive Width:

PHP: 7.4.33 Page Time: 0.030s Queries: 51 (0.023s) Memory: 0.6728 MB (Peak: 0.8216 MB) Data Comp: Zlib Server Time: 2024-04-18 19:10:24 UTC
Valid HTML 5 and Valid CSS