[imp] Windows XP caches login credentials.

Ryan Gallagher ryan@studiesabroad.com
Thu, 18 Jul 2002 13:35:15 -0500


Quoting Chuck Hagenbuch <chuck@horde.org>:

> Quoting Eric Rostetter <eric.rostetter@physics.utexas.edu>:
> 
> > I think we should consider security above user choice here.  So in general
> > I support adding the tag to login forms.  My only objection is, as someone
> > noted, that it is not xhtml complaint.  But it certainly would help the
> > security rating of Horde/IMP (for those using it in public places, shared
> > web browsers, etc).
> 
> I'm waffling here, as might be obvious. Another option is to turn it off, 
> but add a hotmail-like "Remember me on this computer" option.
> 
> Both sides seem like they have good arguments to me. Anyone else want to 
> weigh in?
> 
> -chuck

Maybe an acceptable goal would be to implement several approaches and make them
configuration options.  This would give the administrators who run horde/imp
more control on the issues of security which most affect them and their users.

The admins know their users environment and it's needs the best.

But personally I oppose password caching of most every variety.

-ryan