[imp] Windows XP caches login credentials.

Andrew Morgan morgan@orst.edu
Thu, 18 Jul 2002 11:56:50 -0700 (PDT)



On Thu, 18 Jul 2002, Ryan Gallagher wrote:

> Quoting Chuck Hagenbuch <chuck@horde.org>:
>
> > Quoting Eric Rostetter <eric.rostetter@physics.utexas.edu>:
> >
> > > I think we should consider security above user choice here.  So in general
> > > I support adding the tag to login forms.  My only objection is, as someone
> > > noted, that it is not xhtml complaint.  But it certainly would help the
> > > security rating of Horde/IMP (for those using it in public places, shared
> > > web browsers, etc).
> >
> > I'm waffling here, as might be obvious. Another option is to turn it off,
> > but add a hotmail-like "Remember me on this computer" option.
> >
> > Both sides seem like they have good arguments to me. Anyone else want to
> > weigh in?
> >
> > -chuck
>
> Maybe an acceptable goal would be to implement several approaches and make them
> configuration options.  This would give the administrators who run horde/imp
> more control on the issues of security which most affect them and their users.
>
> The admins know their users environment and it's needs the best.
>
> But personally I oppose password caching of most every variety.
>
> -ryan

Let me add a simple "me too" to Ryan's comments.

	Andy