<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Oct 27, 2015 at 11:04 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><span class="">>However, with Mozilla Firefox 41, the sp and idp session still on even after closing the browser.<br>
<br>
</span>Also dependent on settings, but very difficult to avoid with Firefox.<br>
<br>
That's how the web works now.</blockquote></div><br>Yup. This combination of behavior of browsers and SSO session cookies seems hard to explain to users, and leads to reasonable questions about how to use web SSO safely. The old standby advice to "close your browser" when finished isn't worth much and needs to be retired. But with what?  I've recommended that public computers require login and rebuild the system image for a logout-login sequence, but is there something short of that we can recommend?</div><div class="gmail_extra"><br></div><div class="gmail_extra">David</div></div>