Menu

#3 Logout is not Secure

open
3
2002-05-02
2002-05-02
No

When logging out using the logout button, it is possible to re-enter the QAT system without providing a userid and password. The userid and password from the last login is reused.

Most browsers will remember the userid and password from the last login and reuse them when a server requests authentication. We cannot count on the browser to provide the security of forgetting previous logins.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB