In-reply-to » @bender Hmmmm I'm not sure about this... 🧐 Does anyone have any other opinions that know this web/session security better than me?

@prologic@twtxt.net Visiting the login page would give you something like this:

Username: _<focused field>____
Password: ____________________
[x] Remember me (Enabling this feature will keep
    you logged in, even after closing your browser.
    Do not active this setting on shared devices.)
[Login]

The “remember me” checkbox could be already activated by default. This would benefit people like @bender@twtxt.net.

An alternative would be to make the session lifetime configurable in the user profile. So bender would then set this to forty-two years. :-) Definitely something for power users who know what they’re doing. More dangerous for the average Joe, though.

⤋ Read More