Results 1 to 9 of 9

Thread: PH Shop site - Auto-login

  1. #1
    Senior Member Jan Spies's Avatar
    Join Date
    Jan 2010
    Location
    Somerset West, Cape Town
    Age
    26
    Posts
    171
    Thanks
    42
    Thanked 236 Times in 158 Posts
    Rep Power
    7

    Question PH Shop site - Auto-login

    Firstly, the upgraded site looks quite nice

    Just a thought though, is it not possible to have a 'Remember Me' check box put in? I know I'm being lazy, but it would make life just a little bit easier then having to remember to log in before doing anything...

    [edit] I think I may have put this in the wrong section...please feel free to move this to the PH - Shop suggestions board
    Last edited by Jan Spies; 23-05-2011 at 11:28 AM. Reason: mah bad
    it's a trap!!11!

  2. #2
    Administrator Firestar's Avatar
    Join Date
    May 2005
    Location
    Johannesburg
    Age
    34
    Posts
    17,361
    Thanks
    1,351
    Thanked 614 Times in 464 Posts
    Rep Power
    25
    Hey Jan,

    Sorry man, but I'm afraid not. It wasn't immediately obvious to me either, but there are a TON of security concerns with having a remember me tick box, as that creates a cookie on your machine, which makes your password visible (we don't have a proper encryption system installed for this type of thing). Basically, we'd have to rewrite our entire security module, as well as our log in module, to do this safely and securely. So, for now, we've decided to not do that.

    Hope you understand!


    The Prophecy Shop - http://www.prophecy.co.za


    • Got a question about your order? Email us at orderupdates at prophecy dot co dot za (include your order number please) or phone us at 011 888 2858.
    • Want a product that's not on our shop? Post a new thread over here.
    • Got a comment or have a problem with the shop? Post a new thread over here.
    • Need some advice on what to buy? Post a new thread over here.
    • PM me about a shop/order problem/query/question? Please put your order number in the subject of the PM.
    • Need an update on your RMA, or have a problem with one of your products, ordered from us? Send an email to techsupport at prophecy dot co dot za and include your order number and a detailed fault description.

    Got Facebook? Join the "I shop @ Prophecy.co.za" group.


    My Personal Blog

    VERY IMPORTANT: DO NOT PM ME FOR FORUM HELP/ISSUES. THERE ARE MODS FOR A REASON.

  3. The Following User Says Thank You to Firestar For This Useful Post:


  4. #3
    She's a he she... O.o phalen's Avatar
    Join Date
    Jan 2007
    Age
    33
    Posts
    3,842
    Thanks
    147
    Thanked 262 Times in 170 Posts
    Rep Power
    14
    are you using OSC or Zen-cart? having a brief look at the structure & code it seems so. i used to work on both. (coding/back & front-end)

    if so:

    adding a secure module would be 'not-so-difficult' - the community (osc/zencart) has thousands of custom modules that are easy to install.


    btw - will we ever be able to pay by credit card online? or use something like Pay-pal?

  5. #4
    Administrator Firestar's Avatar
    Join Date
    May 2005
    Location
    Johannesburg
    Age
    34
    Posts
    17,361
    Thanks
    1,351
    Thanked 614 Times in 464 Posts
    Rep Power
    25
    Hi Phalen,

    I'll definitely look into it. We have a bit of a problem with a developer at the moment. Once we get our new developer, we'll get going on a whole bunch of stuff, and who knows, perhaps even this

    Credit cards are a bit of a tough choice for us. Paying by credit card makes little sense, if you're going to give away half your markup to a credit card gateway. We could charge more, but that would be unfair to the customers who don't want to pay via card. It's something we want to make work, and it's something we are looking into probably twice to three times a year, but at the moment, we just cannot make it work. Paypal is something we'll definitely consider, once Paypal approves working with ZAR as a currency. At the moment, it's only for export services, and we'll get into trouble with SARS if you make use of it at the moment (I did find out and it's only if you export products or services out of the country, which we don't).

    Anyways, thanks for the questions. Keep them coming


    The Prophecy Shop - http://www.prophecy.co.za


    • Got a question about your order? Email us at orderupdates at prophecy dot co dot za (include your order number please) or phone us at 011 888 2858.
    • Want a product that's not on our shop? Post a new thread over here.
    • Got a comment or have a problem with the shop? Post a new thread over here.
    • Need some advice on what to buy? Post a new thread over here.
    • PM me about a shop/order problem/query/question? Please put your order number in the subject of the PM.
    • Need an update on your RMA, or have a problem with one of your products, ordered from us? Send an email to techsupport at prophecy dot co dot za and include your order number and a detailed fault description.

    Got Facebook? Join the "I shop @ Prophecy.co.za" group.


    My Personal Blog

    VERY IMPORTANT: DO NOT PM ME FOR FORUM HELP/ISSUES. THERE ARE MODS FOR A REASON.

  6. The Following User Says Thank You to Firestar For This Useful Post:


  7. #5
    Professional SeriousCat SCHUMI_4EVER's Avatar
    Join Date
    Sep 2008
    Age
    24
    Posts
    3,346
    Thanks
    130
    Thanked 400 Times in 340 Posts
    Rep Power
    15
    I don't think it's right for a shop login to be auto-remembered so regardless of strength of security module I don't think that would be a good idea, it would be kinda like doing the same thing with the online site of your bank though perhaps not quite as damaging as making your bank account that easy to access.
    Intel Core2Quad Q9550 (2.83Ghz (stock)), ASUS P5Q, ASUS ENGTX260/HDTP/896M, Transcend JetRam DDR2-800 2x2GB, 2x Seagate Barracuda 500GB, Gigabyte Odin 720W, Gigabyte G-Power 2 Pro CPU cooler,
    CoolerMaster Ammo 533, Leadtek Winfast DTV2000H, Cyber Snipa Stinger lazer gaming mouse, Cyber Snipa Sonar 5.1 Headset, Windows Vista Home Premium SP2 64bit

  8. #6
    Administrator Firestar's Avatar
    Join Date
    May 2005
    Location
    Johannesburg
    Age
    34
    Posts
    17,361
    Thanks
    1,351
    Thanked 614 Times in 464 Posts
    Rep Power
    25
    Well, Schumi, not really. We do not carry any banking or payment details, nor any CC info whatsoever. Literally, the only thing that could be stolen, is a name/surname, address, phone number and email address. Nothing else.

    Heck, you cannot even place orders and get products for free/fraud, since you will still have to make payment via EFT, even if your account is hacked. For us, there is almost nothing worth stealing, tbh. I know phone/email/address info is kind of sensitive, but it's already pretty much public domain data, so it's kinda pointless for someone to steal it (generalising, not all of it is, but most is).


    The Prophecy Shop - http://www.prophecy.co.za


    • Got a question about your order? Email us at orderupdates at prophecy dot co dot za (include your order number please) or phone us at 011 888 2858.
    • Want a product that's not on our shop? Post a new thread over here.
    • Got a comment or have a problem with the shop? Post a new thread over here.
    • Need some advice on what to buy? Post a new thread over here.
    • PM me about a shop/order problem/query/question? Please put your order number in the subject of the PM.
    • Need an update on your RMA, or have a problem with one of your products, ordered from us? Send an email to techsupport at prophecy dot co dot za and include your order number and a detailed fault description.

    Got Facebook? Join the "I shop @ Prophecy.co.za" group.


    My Personal Blog

    VERY IMPORTANT: DO NOT PM ME FOR FORUM HELP/ISSUES. THERE ARE MODS FOR A REASON.

  9. #7
    She's a he she... O.o phalen's Avatar
    Join Date
    Jan 2007
    Age
    33
    Posts
    3,842
    Thanks
    147
    Thanked 262 Times in 170 Posts
    Rep Power
    14
    so why do all gaming sites, like Steam, SOE etc have the option to keep you logged in. they sit with not only your personal details, but your banking details too.

    but they have the over-the-top security dont-know-what 'stuff' that should make it... you know, secure. (and for all that SOE still got their asses hacked to hell)

    i dont see the harm in having the site keep me logged in. especially if you dont keep my banking details.


  10. #8
    Administrator Firestar's Avatar
    Join Date
    May 2005
    Location
    Johannesburg
    Age
    34
    Posts
    17,361
    Thanks
    1,351
    Thanked 614 Times in 464 Posts
    Rep Power
    25
    Steam, SOE, etc, has got millions at their disposal, allowing them to be (at the very least), ok with their security. We don't, I'm afraid.

    It doesn't really matter what gets stolen. If we get hacked, and customer information gets stolen, it's a very real risk to our company. And, it's one we're not prepared to take. I don't hand out your email addresses, and I don't keep your password in an unencrypted text file in your computer. Your browser has a remember password facility, and that will have to do for the time being.


    The Prophecy Shop - http://www.prophecy.co.za


    • Got a question about your order? Email us at orderupdates at prophecy dot co dot za (include your order number please) or phone us at 011 888 2858.
    • Want a product that's not on our shop? Post a new thread over here.
    • Got a comment or have a problem with the shop? Post a new thread over here.
    • Need some advice on what to buy? Post a new thread over here.
    • PM me about a shop/order problem/query/question? Please put your order number in the subject of the PM.
    • Need an update on your RMA, or have a problem with one of your products, ordered from us? Send an email to techsupport at prophecy dot co dot za and include your order number and a detailed fault description.

    Got Facebook? Join the "I shop @ Prophecy.co.za" group.


    My Personal Blog

    VERY IMPORTANT: DO NOT PM ME FOR FORUM HELP/ISSUES. THERE ARE MODS FOR A REASON.

  11. The Following User Says Thank You to Firestar For This Useful Post:

    Oj

  12. #9
    Oj
    Oj is offline
    Senior Member Oj's Avatar
    Join Date
    Jun 2007
    Age
    22
    Posts
    2,826
    Thanks
    380
    Thanked 235 Times in 181 Posts
    Rep Power
    11
    Quote Originally Posted by Firestar View Post
    I don't keep your password in an unencrypted text file
    Sony is seething at that statement, ROFL

    Phenom 2 965BE @ 3.6GHz 1.2v || MSI 790FX-GD70 || 2GB OCZ DDR2000 NVIDIA SLI Ready @ DDR1500 6-6-6-18 1.96v || GTX460 1GB || GeForce GTX260 896MB @ 720/1100 ||2x Samsung F3 1TB RAID0 shortstroked

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •