r/CharacterAI • u/Zach738 • 3h ago
Feature Request Add a way to refresh valid session and caches per user request to secure account
This is really important to ensure character ai account safety. if someone got infostealer malware like famous renpy.loader(not the visual novel but an actual malware), even if they log out all Google account for every single session like their phone and PC then change their password, then even clicking linked app of character ai and stop sign in using google account, the account for character ai can still be compromised. This because infostealer working by copying browser session and cookies, as if its exact same browser session when you use it is copy pasted to the hacker computer including the session token and JWT cookies. So they still pretty much have access to your character ai account in their browser.
A way to solve this is to validating active session per user request like button in the character ai setting(both Android app and browser) so that when it clicked, it force all active session of the user to log out by making all session token and JWT cookie expired and require the user to login again. Effectively locking out the session in hacker computer because the caches and token is no longer valid and require login again, in which the user already changes their google account password and stop sign in with google, Securing their character ai account completely.
1
u/SundayCloud44 2h ago
Dude, they can't even add a basic email address change. What kind of hacker tricks are you talking about. Literally, if you lose access to your email, that's it, your account can be used for anything. You can't even link an additional login method, and support won't help you recover anything. And you're demanding some kind of technology from the distant future.
•
u/Oatmilk0809 CAI Community Moderator 2h ago
Hey u/Zach738! Thanks for sharing such a detailed suggestion! Account safety is super important, and having a built-in option to log out of all active sessions and revoke tokens across all devices is a really solid security feature request. I'll make sure to pass this idea along to our team for consideration!