Tuesday, March 17, 2009

Session timeout? WTF?

Don't you hate it when sessions time out on your own private PC, especially when you're doing several things in parallel, like budgeting in Excel while doing transfers through online banking, or working on a presentation that you wanted to attach to a message that you started writing in an Outlook Web session and suddenly realised that the attachment wasn't finished, so while you work on finishing the presentation, the web session times out and you don't realise it until you actually hit "Send" and suddenly need to rewrite the message from scratch?

Here is how I think session time out messages should read:

Sorry, your session has timed out.  We may pretend that this is for your safety, but given that all web browsers in common use can fill out your username and password automatically, and we haven't bothered to try and use a very simple and well known solution to prevent this even greater security hole, you will soon realize that we are actually more concerned with not storing a measly 100 bytes or so of information on our massively powerful cluster of web servers for more than 30 minutes, just so that you can leave a window open in the background of your pesky little laptop and do several other things in parallel without having to reenter your password several times a day on your machine which you sit at all day and nobody else can touch without your knowledge because 1) you are always chained to your desk and/or 2) you always lock your screen whenever you walk away from your desk.

Anyway.... ahem :-P  Hooray to Google for keeping login cookies active indefinitely!

No comments: