Help / Forums / Discogs News

Current Discussion

Summary of Guideline changes - 17th November 2008
Latest: about 18 hours ago
Recommendations now online
Latest: 1 day ago
Submission Guidelines changelog
Latest: 2 days ago
Full data export
Latest: 3 days ago
FIXED - Uploading Images, Audio, and CSV imports temporarily down
Latest: 8 days ago
Unplanned Downtime - Oct 12
Latest: 9 days ago
Notifications Changes
Latest: about 1 month ago
Search Collection and Wantlist
Latest: about 1 month ago
Unplanned Downtime - Sept 16
Latest: 2 months ago
Voting in Disbugs
Latest: 3 months ago
more...
  

Changes to login system

teo wrote:
During this week you may have noticed that you were asked to re-enter your password. We made some changes to the login process so that it is more secure. Now anyone who uses the "remember me on this computer" option will now have to re-enter their password after 2 weeks.
posted 4 months ago. ( permalink | report )
Distrexx wrote:
Right, don't really see the benefit in this. If i want to be rememberd on my computer, i expect it to be longer then 2 weeks.

But then again i can see the security upgrade in it. Also i can see the irritation in it after a few weeks...
posted 4 months ago. ( permalink | report )
meckah wrote:


Distrexx
If i want to be rememberd on my computer, i expect it to be longer then 2 weeks.


I want to be logged in forever. Yeah logging in once per two weeks doesn't seem much, but considering how many sites does this in total the number of logins per day is quite a few. I don't like it.
posted 4 months ago. ( permalink | report )
It was so relaxing to be logged in for a full year until I had to re-login last week. If it adds security then I'm all for it though, despite the discomfort.

There's a site I use where you get kicked out if you don't perform an action in 15 minutes (or so). Now THAT'S annoying. :)
posted 4 months ago. ( permalink | report )
meckah wrote:
The "security" it adds is so marginal it is not worth it.
posted 4 months ago. ( permalink | report )
^^ Well, I wouldn't know to be honest.
posted 4 months ago. ( permalink | report )
jweijde wrote:
Again I don't see why time has to be spend on a security 'improvement' like this when there are so many issues that are MUCH more important.
posted 4 months ago. ( permalink | report )
^^ True
posted 4 months ago. ( permalink | report )
I can only support what jweijde wrote, why wasting precious resources on this (minor) security improvement when we have long lists of burning issues (e.g. getting rid of V4) waiting for solution??
posted 4 months ago. ( permalink | report )
HTTPS
posted 4 months ago. ( permalink | report )
disregard, legumes-SALES expressed himself a little too short = misunderstanding. :)
posted 4 months ago. ( permalink | report )
SmotheredHope edited this message 4 months ago.
disregard, legumes-SALES expressed himself a little too short = misunderstanding. :)
posted 4 months ago. ( permalink | report )
SmotheredHope edited this message 4 months ago.


SmotheredHope
legumes-SALES
HTTPS


Ah, that's welcomed. I didn't see it [...]


errrrrr


;)
posted 4 months ago. ( permalink | report )
should have posted: HTTPS please!
posted 4 months ago. ( permalink | report )


legumes-SALES
should have posted: HTTPS please


Yes, you should have. :) I thought you meant it was https finally. :)
posted 4 months ago. ( permalink | report )
V-12 wrote:
This new feature sucks of course. I've been remembered from my computer for years and never had any troubles. Now I will need to enter my password again too often? Crap.
posted 4 months ago. ( permalink | report )
shadowslip wrote:
this should get rid of the last few long timers that are causing trouble eh Teo. They won't beable to remember their password and probably using a new email.

just weeding huh.

i had so much faith here once
posted 4 months ago. ( permalink | report )
Mr.Mystery wrote:


V-12
This new feature sucks of course. I've been remembered from my computer for years and never had any troubles. Now I will need to enter my password again too often? Crap.

Yeah, how dare they waste precious seconds of your life.

Really now...
posted 4 months ago. ( permalink | report )
shadowslip wrote:


Mr.Mystery
Yeah, how dare they waste precious seconds of your life.

Really now...


you miss the point
posted 4 months ago. ( permalink | report )
TomKay wrote:
I'm not that fussed about logging in every two weeks, but I'm not mad keen on the fact that my system seems to reject my password now again for laughs even though it's exactly right...
posted 4 months ago. ( permalink | report )
Mr.Mystery wrote:


shadowslip
you miss the point

Uh huh.
posted 4 months ago. ( permalink | report )
shadowslip wrote:
living up to your name I see.


there's always one
posted 4 months ago. ( permalink | report )
teo wrote:
V-12, this is not a "feature". It's just a necessary change to keep things secure.
posted 4 months ago. ( permalink | report )
are there so many account security complaints from users to start this 'once per 2-week' pswrd re-enter?

as passwords surround modern people everywhere, and keeping the papersheet list of them is insecure, under some conditions (half-asleep & tired, drunk, excited by a girlfriend etc) remembering the pswrd may be VERY problematic

---1
posted 4 months ago. ( permalink | report )
simfonik wrote:


IntelliGiant
under some conditions (half-asleep & tired, drunk, excited by a girlfriend etc) remembering the pswrd may be VERY problematic

Get some sleep. Stop drinking so much. Pay attention to your girlfriend.

:)
posted 4 months ago. ( permalink | report )
deejsasqui wrote:

simfonik
Get some sleep. Stop drinking so much. Pay attention to your girlfriend.

Indeed - the internet shouldn't keep you up at nights or keep you away from your girlfriend. Drinking .. that's up to you. =)
posted 4 months ago. ( permalink | report )
maxxyme wrote:
Use Firefox and its "Remember this login" feature.
posted 4 months ago. ( permalink | report )
vargind wrote:
what, are they hoping this will stop people randomly doing edits to the database in an incorrect manner ?
posted 4 months ago. ( permalink | report )
Sputnik86 wrote:
Why does this "feature" have to expire in the middle of a browsing session?
Just had it happen to me.
posted 4 months ago. ( permalink | report )


Sputnik86
Why does this "feature" have to expire in the middle of a browsing session?
Just had it happen to me.


Just happened to me as well. I ignored it though and clicked away on my Discogs inbox and wasn't asked to log in. So this seems to be working so-so.
posted 4 months ago. ( permalink | report )
jweijde wrote:
Even such a seemingly simple thing as this can't be done right?
Shocking! But not surprising really...
posted 4 months ago. ( permalink | report )
jweijde edited this message 4 months ago.
I have to log in every time i visit, and keep getting warnings telling me to enable cookies when they already are. Cool upgrade, i feel very secure against being able to auto log into my account, but that's about it.
posted 4 months ago. ( permalink | report )
alex_s wrote:

legumes-SALES
should have posted: HTTPS please


Works for quite a while already:

https://www.discogs.com/users/login
posted 4 months ago. ( permalink | report )
meckah wrote:
Had to relogin today, guess what, it did not accept the password, it just threw me back to the "your session expired" or whatever it said. Had to delete the discogs cookie to be able to use my account again. I do not like that.
posted 3 months ago. ( permalink | report )
meckah wrote:
Just wrote a long reply to post in the forums, pressed preview, and it asked me to log in again. Guess what happened when I got to the preview? The message was not there. Fortunatly it could be gotten by using the back button and copied and then pressing reply again, but that just can't be right. This is annoying.
posted 3 months ago. ( permalink | report )

alex_s
legumes-SALES
should have posted: HTTPS please


Works for quite a while already:

https://www.discogs.com/users/login



ok, first of all it did not work when I wrote the post you quoted. I tested it.

then again, thanks for the notice! wouldn't have noted it otherwise.


btw, the forum-quote function does not work, when using HTTPS for me (firefox3.0.1 / winxp), but works under HTTP for some reason.
posted 3 months ago. ( permalink | report )
legumes-SALES edited this message 3 months ago.
alex_s wrote:
Yes, not all pages are working properly when using https, example:

https://www.discogs.com/submissions

The left pane shows less information compared to the http page and the links do not work.

Firefox 2 and IE6.

But at least you can transmit your login data encrypted now.
posted 3 months ago. ( permalink | report )
 

This topic is older than 90 days and cannot be replied to.

My Discogs Submissions Watchlist Drafts Collection Wantlist more...
Help Contributing to Discogs Quick Start Guide Buying Selling Help Forums more...
  About Discogs Developers API Widgets
 
Discogs™ website Copyright © 2008 Discogs Terms of Service Privacy Policy