Do you require IP address and user agent for login? 
Posted: 15 May 2008 09:10 PM   [ Ignore ]  
Grad Student
Rank
Total Posts:  33
Joined  01-08-2006

I’m hoping to get some feedback from other site owners regarding how they view and have handled this issue.

I have an AOL user that is trying to register/login, but is receiving the “You are not authorized to perform this action” error message. I’ve read threads and the Kbase entry which explains what the issue is and the work around that says to turn off “Require IP Address and User Agent for Login” in Admin > System Preferences > Security and Session Preferences

I’m not sure if I should turn it off and would like to get others input.

My questions are:

1. Is this a big security issue?
2. Are you doing this? And if so, have they seen issues relating to it?
3. Would you recommend it?
4. Do you know of any other solutions that work?

thanks

Profile
 
 
Posted: 17 May 2008 06:10 AM   [ Ignore ]   [ # 1 ]  
Summer Student
Avatar
Total Posts:  30
Joined  03-09-2006

I can only answer #2; I built a website using EE for someone on AOL last year.  She had some login issues that I solved initially by changing the user session type to cookies only; the final solution was to have her use IE instead of AOL’s built-in browser.  It wasn’t any more of a hassle for her, and it easily solved the problem without potentially compromising her site’s security.  I’m not sure if that’s feasible for your users, but it worked in this particular case.

 Signature 
Profile
 
 
Posted: 17 May 2008 07:22 AM   [ Ignore ]   [ # 2 ]  
Administrator
Avatar
RankRankRankRankRankRankRank
Total Posts:  15006
Joined  06-03-2002

Disabling the Secure Forms feature is generally enough for AOL / Proxy users, though depending on how you accept user input and your Google rankings, you may find yourself hit occasionally by spam bots.

 Signature 
Profile
MSG
 
 
   
 
 
Post Marker Legend
New Topic New posts Hot Topic Hot Topic with new posts New Poll New Poll Moved Topic Moved Topic Sticky Topic Sticky topic
Old Topic No new posts Hot Old Topic Hot Topic with no new posts Old Poll Old Poll Closed Topic Closed Topic Announcement Announcements
Theme
Change Theme
Visitor Statistics
The most visitors ever was 1149, on July 16, 2007 10:33 AM
Total Registered Members: 61042 Total Logged-in Users: 27
Total Topics: 73833 Total Anonymous Users: 15
Total Replies: 398294 Total Guests: 405
Total Posts: 472127    
Members ( View Memberlist )
Newest Members:  akafuriousbozdagLajnermatthinckleykirriewanweiRichard DyckArania JainEspenshawnblanc