21

I sometimes forget to close the tab to my bank's website. I flip back to it, hours, or even days later. As soon as the tab becomes active the "You'll be logged out in 60 second" timer starts ticking. Literally, days after I logged in, I can click "Stay logged in" and it works!

Their session timeout logic is all fucking Javascript based!? Don't they log out the session server-side at some point? How the fuck is my session still valid 2 days after initial login?

Comments
  • 8
    Clearly it is client side. Yikes.
  • 3
    Same. On an online broker...
  • 8
    That is unacceptable.

    My bank logs me out in about 5 min of inactivity, server side.
  • 4
    @Voxera Same. It's a local bank in an easterm-European country. They just grew a lot in my eyes.
  • 1
    Stay away of such shit bank if you can.

    Actively fight that, open a complain or send a letter to them. If a bank don't have money to develop and implement such thing ... who haves?????

    Optionally, use your phone browser if makes any difference, or use bank app if any, but i dont recommend installing shit for something you can do in the browser.
Add Comment