I caught this once when I sent a link to my friend/co-worker from nashbar when I was logged in. He replied with something like "sweet thanks.. I can even order it under your account!" I looked, and sure enough, he was logged in as me on his pc and had access to all my account info on nashbar.... Now I'm very careful about not doing that anymore.
Coming from system admin and development experience, it is very poor coding and design to allow a flaw such as that on any site, and the risk Nashbar is placing on their unknowing end users/customers is as unprofessional as it gets.



Reply With Quote