Customer thinks removing login/logout button helps with security (magento)

Status
Not open for further replies.

TechBoyJK

Lifer
Oct 17, 2002
16,699
60
91
yep.

Hosting a customer that has a Magento shopping cart. I was helping them with something and couldn't find the login button. Moved onto something else, which got me logged in another way, then couldn't find the logout button.

I ask and I'm told it's for security.... Let's remove the login/logout button from the header template because it invites people to mess with the system. Let's tell users that they have to add /login or /logout to do that.

I tried to explain that it destroys the user experience and that if a site is so insecure that petty things like hiding a login/logout button are required, it shouldn't be online.

oh wtf.
 

KB

Diamond Member
Nov 8, 1999
5,406
389
126
Does he actually sell anything? Sounds like bankruptcy is in his future.
 

Cogman

Lifer
Sep 19, 2000
10,286
145
106
If they think removing a login/logout button makes their site secure, they undoubtedly have some pretty huge security holes.
 

Markbnj

Elite Member <br>Moderator Emeritus
Moderator
Sep 16, 2005
15,682
14
81
www.markbetz.net
Are they lawyers? Lawyers and associated businesses have the worst websites in the known world. 15 years behind everyone else.
 

Leros

Lifer
Jul 11, 2004
21,867
7
81
Are they lawyers? Lawyers and associated businesses have the worst websites in the known world. 15 years behind everyone else.

Sigh. I know a lawyer who has god level access (higher than admin) at his company yet refused to put a passcode on his mobile device. Anybody could pick up his phone and instantly have god level access to the entire company.
 

inachu

Platinum Member
Aug 22, 2014
2,387
2
41
Are they lawyers? Lawyers and associated businesses have the worst websites in the known world. 15 years behind everyone else.

When law.com was first created with their very first site back between 1996-97 They used to have a chat room and I would teach them HTML using live code within their chatroom.

It was so easy back then and yes Lawyers are always far behind the time.
 

slugg

Diamond Member
Feb 17, 2002
4,723
80
91
The customer is always right. Hide the button and charge him a pretty penny. You both go home happy.
 

VirtualLarry

No Lifer
Aug 25, 2001
56,587
10,225
126
I'm pretty (upset) that BestBuy does NOT seem to have a "logout" button anymore. What if I were using a public computer?
 
Last edited:

ninaholic37

Golden Member
Apr 13, 2012
1,883
31
91
I'm pretty (upset) that BestBuy does NOT seem to have a "logout" button anymore. What if I were using a public computer?
Are you using NoScript? I just made a dummy account to test, and I see the "Sign Out" link/text on each page between the "Welcome, Name!" and "My Account" at the top right (takes a sec to pop up though) but I'm not in the US. The page definitely looks messed up here though, headers are running on top of headers... it looks like it expects a screen resolution of at least 1600x900.D:

edit: Wow, nevermind. The US site looks completely different.

edit2: Ok, I can sign out by hovering my mouse in between the "Hi, Person!" and "Account" at the top right, then a little menu pops up with "Sign Out" at the bottom of it (in italics even, like that's supposed to help you find it - lol). A lot of sites work like this now though, Google+, photobucket, to name some....
 
Last edited:

MongGrel

Lifer
Dec 3, 2013
38,466
3,067
121
Sigh. I know a lawyer who has god level access (higher than admin) at his company yet refused to put a passcode on his mobile device. Anybody could pick up his phone and instantly have god level access to the entire company.

Was kinda funny about 15 years ago, my wife was office manager of a travel agency and the owner put up a remote type of set up in the office.

They wife put it up at home, I was at home messing around a couple days later and went to the site and was messing around and could get into everything, their banks accounts etc, called the wife up and told her to tell Andy about it and get his [stuff] secured.

No swearing in the technical forums, please -- Programming Moderator Ken g6

Was even funnier the day he went home early and left his computer on at that office and had a link to it from home and the girls were watching all the p0rn on his sick day at home were watching remotely and giggling about it :)

Things were even less secure long ago I guess if you could crack into things even.

I don't even play with it these days, would rather mess around with the drumset.
 
Last edited by a moderator:

Ken g6

Programming Moderator, Elite Member
Moderator
Dec 11, 1999
16,695
4,658
75
I think this thread has run its course. Time to close it before it goes any further into Off-Topic-Land.

-- Programming Moderator Ken g6
 
Status
Not open for further replies.