Description: We've identified an issue where, after a password change, all active sessions remain logged in. Ideally, for security reasons, all sessions should be automatically logged out whenever a password is changed.
Steps to Reproduce:
- Log in to your OpenAI account on multiple devices/browsers.
- Change your password on one of the devices.
- Check your account status on the other device(s).
Expected Result: All sessions should be logged out and require the new password to log back in.
Actual Result: The sessions remain active even after the password change.
Frequency: This issue has been reported by multiple users and appears to be consistent.
Additional Information: This issue poses serious security risks as unauthorized users may maintain access to the account even after a password change.
See: #1154123038053380126 #1157322575941210224 #1158746675490324511 #1156924651654619206
#Session Persistence After Password Change
1 messages · Page 1 of 1 (latest)
agreed this is important especially when 2FA does not currently exists as it was removed months ago
https://help.openai.com/en/articles/7967234-does-openai-offer-multi-factor-authentication-mfa-two-factor-authentication-2fa
yes. If your account gets compromised for any reason you are completely screwed.
Or just you logged in in someone's computrer and forgotten to logout
i think they have fixed this now, #1162189283784937502 message
Oh well this is great.