• Jim P. (2/18/2014)


    Robert.Sterbal (2/18/2014)


    With our online accounts what we need are logs, and access to them. Why shouldn't every login I make be written to a read only log?

    Well if you go to the bottom of a gmail account there us a "Last account activity: 1 hour ago Details" link. It just tracks the IP and location that the account was accessed from in the recent past.

    I'm pretty sure my online banking and credit card accounts all do that--they have a note saying "You last logged in on X". They don't give full details of what transactions were carried out then, mind you.

    Security varies between those accounts quite significantly, though--the bank account requires a one-time authentication using my debit card and PIN number (using a card reader device they supplied) as well as my login details; the first credit card account requires a username, password *and* PIN; but the other credit card is just plain username and password. OK, it does the usual trick of asking you to enter certain letters from your password rather than just typing the whole thing, but I actually think that's counterproductive because it encourages you to choose a shorter password (can you imagine trying to mentally count through your lovely secure 23-letter password to find the 22nd letter?).