Skip to content

Settings and activity

4 results found

  1. 9 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    Adam Spiers supported this idea  · 
  2. 142 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    Adam Spiers supported this idea  · 
  3. 24 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    Adam Spiers supported this idea  · 
  4. 1,064 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    Hi everyone, we appreciate the interest surrounding this idea, however we want to be open that we're unable to extend our log-out time past 60 minutes. Xero hold a lot of sensitive information including bank data and we're required to be as secure as online banking.
    Any session information running on a web browser can potentially be stolen. If the session does not time out. You then have an infinitely long vulnerability window to session hijacking. Our best option is to keep a tight expiration window on the session cookie, and regenerate them frequently. Even setting a long timeout doesn't help with this - too long a timeout will greatly increase the risk of invasion or potentially jeopardise your personal data and the safety and integrity of the Xero application itself. This is why we maintain control of this.
    If we detect there's been no activity on a page (e.g…

    An error occurred while saving the comment
    Adam Spiers commented  · 

    I'm afraid that fixing the session automatic expiry to 60 minutes is a very unsatisfactory decision by your product team. Incredible to see that these complaints have been going for years and are still not addressed.

    It is incorrect to assume that every user of Xero has exactly the same security requirements. For example I only use it at home as a single user, where no one else has access to the computer, so it's plenty secure even if it stays logged in for days. In contrast, in an open office then of course security is a much more sensitive concern.

    Why do you think that gmail lets people stay logged in for days or even weeks? And email is far more sensitive than an accounting platform, because (unless two factor authentication is used) any attacker can click a "Forgot password" button and then a recovery link is sent to the owner's email account which can let the attacker into the recovered account.

    It should be up to users to decide what level of security they need, rather than a blanket decision by a product team. By all means impose a maximum session length of a week if you must, but 1 hour is ridiculous.

    Adam Spiers supported this idea  ·