Do you require IP address and user agent for login? 
Posted: 15 May 2008 09:10 PM   [ Ignore ]  
Grad Student
Rank
Total Posts:  31
Joined  2006-01-08

I’m hoping to get some feedback from other site owners regarding how they view and have handled this issue.

I have an AOL user that is trying to register/login, but is receiving the “You are not authorized to perform this action” error message. I’ve read threads and the Kbase entry which explains what the issue is and the work around that says to turn off “Require IP Address and User Agent for Login” in Admin > System Preferences > Security and Session Preferences

I’m not sure if I should turn it off and would like to get others input.

My questions are:

1. Is this a big security issue?
2. Are you doing this? And if so, have they seen issues relating to it?
3. Would you recommend it?
4. Do you know of any other solutions that work?

thanks

Profile
 
 
Posted: 17 May 2008 06:10 AM   [ Ignore ]   [ # 1 ]  
Summer Student
Avatar
Total Posts:  30
Joined  2006-03-09

I can only answer #2; I built a website using EE for someone on AOL last year.  She had some login issues that I solved initially by changing the user session type to cookies only; the final solution was to have her use IE instead of AOL’s built-in browser.  It wasn’t any more of a hassle for her, and it easily solved the problem without potentially compromising her site’s security.  I’m not sure if that’s feasible for your users, but it worked in this particular case.

 Signature 
Profile
 
 
Posted: 17 May 2008 07:22 AM   [ Ignore ]   [ # 2 ]  
Administrator
Avatar
RankRankRankRankRankRankRank
Total Posts:  13817
Joined  2002-06-03

Disabling the Secure Forms feature is generally enough for AOL / Proxy users, though depending on how you accept user input and your Google rankings, you may find yourself hit occasionally by spam bots.

 Signature 
Profile
 
 
   
 
 
Post Marker Legend
New Topic New posts Hot Topic Hot Topic with new posts New Poll New Poll Moved Topic Moved Topic Sticky Topic Sticky topic
Old Topic No new posts Hot Old Topic Hot Topic with no new posts Old Poll Old Poll Closed Topic Closed Topic Announcement Announcements
Theme
Change Theme
Visitor Statistics
The most visitors ever was 1149, on July 16, 2007 10:33 AM
Total Registered Members: 58134 Total Logged-in Users: 22
Total Topics: 68142 Total Anonymous Users: 17
Total Replies: 366990 Total Guests: 392
Total Posts: 435132    
Members ( View Memberlist )
Newest Members:  Doug LernerATATJacob SmithalixJonathon VSgoodbergerDelia RitherdonbborunXofzainabob