Results 1 to 9 of 9

Thread: ?? Completely quit your browser after connecting to sites that require logging in ??

  1. #1
    Senior Member
    Join Date
    Sep 2005
    Posts
    587
    Thanks
    7
    Thanked
    7 times in 7 posts

    ?? Completely quit your browser after connecting to sites that require logging in ??

    I have heard that you have to close your browser after visiting a secure page in order to stay safe. Is this really true?

    I'm not so much worried about someone walking up to my computer and re-logging-in when I'm not looking... I lock the desktop when I'm away. I'm more worried that if I don't close the browser, the next site I visit might see my POSTDATA or previous URL or something and be able to get my login name + pass that way.

    What about in FireFox --- does closing the Tab work or does the whole thing need to be closed?

    http://www.washington.edu/computing/...practices.html

    Completely quit your browser after connecting to sites that require logging in

    Browsers remember your ID and password until you completely quit the browser. Simply closing the window you logged in to the service will not clear its memory. You must close all windows of the browser program and quit the program itself.

    Otherwise, after you leave your computer, someone could bring up one of the unclosed windows, go to the service, and get in without being prompted for an ID or password. The browser will thoughtfully provide the ID and password from its memory.

    In a related situation, anytime you have to give your UW NetID and password to get into a computer, such as in a computer lab or when using a kiosk, you should go through the complete logout and exit process before leaving the computer. DO NOT just walk away from your session.
    Thanks
    Last edited by latrosicarius; 07-08-2007 at 01:20 PM.

  2. #2
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts
    Yes. To be absolutely sure - shut down the browser. (Whichever one you are using). This will ensure that the secure session terminates.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  3. #3
    Senior Member Andaho's Avatar
    Join Date
    Jul 2007
    Posts
    591
    Thanks
    241
    Thanked
    8 times in 8 posts
    • Andaho's system
      • Motherboard:
      • ASUS iX2 GTXS
      • CPU:
      • XC18650 4.2GHz 10664FSB 16 Core
      • Memory:
      • 64GB (2x32GB sticks) PC21320 Corsair Domititan Magnetic RAM 0 latency
      • Storage:
      • 16TB Western Digital SATAV 28800RPM Ultra Edition 1GB Cache
      • Graphics card(s):
      • XFX AMD 9985GTS LP 25Watt
      • PSU:
      • 150W Corsair
      • Case:
      • Lian-Li Aluminium ABX-951
      • Monitor(s):
      • SG-942IPS 42" 3840x2160 0.01ms 5,000,000,000:1
      • Internet:
      • 10Gb Virgin Media Cable
    If it's an important site like online banking, they have a logout button - it's best to always click that before browsing else-where, and that insures your account cannot be accessed without signing it again - although you can still sometimes press the back button to see a cached copy of the page you were on.

  4. #4
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts
    Incidentally, if you have multiple copies of IE running (multiple windows) you need to shut them all down to bve sure of ending a password enabled session (ie, remove the cached password)
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  5. #5
    Nothing runs like a Deere cotswoldcs's Avatar
    Join Date
    Mar 2004
    Location
    Bang in the heart of the cotswolds
    Posts
    793
    Thanks
    40
    Thanked
    18 times in 18 posts
    • cotswoldcs's system
      • Motherboard:
      • Asus P4C800-E Deluxe
      • CPU:
      • Pentium 4 3.0Ghz Northwood (@3.4Ghz on water)
      • Memory:
      • 1.5Gb Corsair TwinX PC3200/PC3700
      • Storage:
      • 150Gb Raptor
      • Graphics card(s):
      • XFX 6600GT 128Mb (w waterblock)
      • PSU:
      • Seasonic S12-380
      • Case:
      • Antec Sonata I
      • Monitor(s):
      • 3 x Iiyama 19" LCD (5:4) on Comrac Tripple Mount
      • Internet:
      • PlusNet 1.6Mb ADSL
    I must say I'm not very good at logging out of internet banking sites - I usually close the browser of navigate elsewhere. Like you I'm not worried that someone might access my computer but if there is a risk by browsing other sites without logging off first maybe I will have to rethink my security.

  6. #6
    Senior Member
    Join Date
    Sep 2005
    Posts
    587
    Thanks
    7
    Thanked
    7 times in 7 posts
    Thanks for the tips I guess I'll keep closing it. And pushing log off of important sites like banks.

  7. #7
    Senior Member
    Join Date
    Jun 2006
    Location
    London, UK
    Posts
    710
    Thanks
    33
    Thanked
    5 times in 5 posts
    Very interesting, I do logoff from banking but not always when shopping - and often have loads of browser windows on the go.

    Thanks all

    DM

  8. #8
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    It is most likely referring to "session cookies".

    A browser opens a page on a website and the user enters some credentials which are stored in the memory of the browser process so that you can navigate between pages on that site without being prompted on every page to re-authenticate.

    Navigating away from the page, or even the site, does not clear session cookies - so you can go through the browser history to return to the site later without needing to authenticate.

    If you close the browser, the process is terminated and all the memory released - open the browser again and you will need to authenticate once more.

    Alternatively, the website provides a "log out" button which erases the session cookie information, so navigating back to the page doesn't automatically authenticate you.

    Note that this is per process, so a single instance of a browser with multiple tabs will be sharing memory, but separate browsers will have their own private session cookies.


    "Permanent" cookies are stored as files on disk, to allow things like auto-logons for sites such as this one, for example.

    With these cookies used, multiple browsers would be reading from (and writing to) the same cookie file.


    HTTPS sites requiring authentication should only ever use session cookies, to ensure that a "genuine" logon is occurring.
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  9. #9
    Senior Member
    Join Date
    Aug 2006
    Posts
    1,182
    Thanks
    133
    Thanked
    46 times in 45 posts
    You are best to use any log out facilities that are on the sites especially on line banking ones. I try not to leave hexus without logging out -just habit.

    If you are really worried than run ccleaner before resuming browsing that should clear your cookies.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •