Roll20 uses cookies to improve your experience on our site. Cookies enable you to enjoy certain features, social sharing functionality, and tailor message and display ads to your interests on our site and others. They also help us understand how our site is being used. By continuing to use our site, you consent to our use of cookies. Update your cookie preferences .
×
Create a free account
This post has been closed. You can still view previous posts, but you can't post any new replies.

HUGE SECURITY RISK . Major account management 101 fail

The problem I encountered in this site is BY FAR the weirdest most awful problem I encountered in a site ever . just had to say some heads up because its really weird . Detailed Description of the Problem  : sometimes I find myself logged in with someone else account . as if I was using his account with full access to games messages and dare I say if I tried I might got access to his account options . which is super scary . the first time I encountered this problem I found my self have tons of massages and many games to be played but I didnt understand what happened how did I got this popular Until I looked to the name in the upper right and IT WAS NOT MY NAME !!!! it happened 4 times so far 3 times with the same account but last time I found myself in somebody new account ..... it even happened while writing this thing now !!!!! this is A HUGE ISSUE and must be resolved ASAP . I fix it by logging out and thin log in to my own account . but my fear is a less honorable person would use this access for awful things . Steps to Reproduce the Problem  : Happens randomly but what is common I think is that I open the editor alot and the first time It happened my editor got access to a map of the other person game ... no way to be sure that the editor is responsible . so short verdict (random) ... maybe the auto log in or cookies are responsible . Description of Your Setup (Browser + Version, Operating System, etc.) browser : Chrom (Version 52.0.2743.116 m (64-bit)) OS : Windows 7 Home (Up to date) didnt put screen shots because 1 I didnt think of taking them and 2 I find it breaching the effected personal privacy if I were to do so in the future .
Hey there! We're not totally sure what's going on here but we're tracking the issue in this thread already, so if you could take a look at my last response and let me know what you found that would be great: &nbsp; <a href="https://app.roll20.net/forum/permalink/3961684/" rel="nofollow">https://app.roll20.net/forum/permalink/3961684/</a> We're using the same type of account login structure that pretty much every site uses, which is SSL encryption along with a session cookie that is set to only be sent over HTTP and only sent over SSL. In theory it should not be possible for this cookie to be sent to another computer but it seems like either the VPN you are using or the ISP in your country is messing with your data.