Ghabra Posted May 15, 2021 Share Posted May 15, 2021 (edited) I've changed my password a couple of times over the past month for personal reasons , and i've noticed that every time i do , the forum session does not get disconnected. I thought it might be related to the dashboard session so i logged out of that , but nope , no matter how many times i change my password and log out of the dashboard , the forum stays logged in. I would not say this is a major security flaw , but it does bring up some concerns. What if someone gets hacked or gets their account stolen , they change the password but the account thief would still be logged in on forums , which could lead to some trouble if the account thief decides to mess on forum with the stolen account . I know there is probably somewhere a "disconnect all devices" button on the dashboard but this could be easily missed or forgotten about. And i know the account owner can be easily proven innocent in case the thief messes around on forum due to the account thief having a different IP and checking the logs , but why not prevent this in the first place by disconnecting all devices upon changing the password? This is what i personally noticed , i could be wrong about this somehow so please correct me of i am. Edited May 15, 2021 by Ghabra Link to comment https://pokemonrevolution.net/forum/topic/176389-a-security-flaw/ Share on other sites More sharing options...
Ghabra Posted May 16, 2021 Author Share Posted May 16, 2021 bump Link to comment https://pokemonrevolution.net/forum/topic/176389-a-security-flaw/#findComment-985583 Share on other sites More sharing options...
Ghabra Posted May 17, 2021 Author Share Posted May 17, 2021 bump Link to comment https://pokemonrevolution.net/forum/topic/176389-a-security-flaw/#findComment-986220 Share on other sites More sharing options...
Ghabra Posted May 18, 2021 Author Share Posted May 18, 2021 bump Link to comment https://pokemonrevolution.net/forum/topic/176389-a-security-flaw/#findComment-986799 Share on other sites More sharing options...
Ghabra Posted May 20, 2021 Author Share Posted May 20, 2021 bump Link to comment https://pokemonrevolution.net/forum/topic/176389-a-security-flaw/#findComment-987882 Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now