Web Apps Should Always Have a Log
I’m working on an event log for a client (of my employer): At a bare minimum, an event/security log offloads some of the responsibility to the user. If you show fail and successful login attempts hopefully a user will catch when their own account has been compromised even if you can’t (I.E. their password was …