Moved to: https://webmasters.stackexchange.com/questions/31834/remember-me-or-not
Is it safe to have the remember me feature? Would it be somewhat safe (knowing it won't be 100% safe) to allow users to close their browser and come back still logged in? I am not exacting sure which way I should go after reading different things about safety. I learned about session fixation and implemented security to add more protection.
From experience, if remember me is checked then only your username/email appears and requires you to re-enter your password. Other sites allow you to come in and out as much as you way without logging out after the browser has closed.
If it is safe, what is the current best way of implementing remember/stay logged in?
- Best practise for remember me feature
- What is the code for Stay logged in or Remember me while user login in PHP
- http://bytes.com/topic/php/answers/881197-stay-logged-remember-me-php-sessions-cookies
- https://security.stackexchange.com/questions/41/good-session-practices
Also: The site I am working on is email & password login type.