So, with most webmail tools, if you hit the “logoff” button, no amount of URL tomfoolery will allow a nefarious person to re-connect to your mailbox from the browser or session without your password.
This is As It Should Be.
I’ve just noticed, however, that Outlook Web Access apparently sees it differently. When you hit the logoff link in OWA, you get this warning:
At this point, the URL has shifted from our base OWA URL to something that ends with “/auth/logoff.aspx?Cmd=logoff”, which gives the user the distinct idea that their session has been zapped safely. Sure, it’s probably safer to quit the browser at this point, but in this age of weeks-long uptimes for even Windows boxes, who does that?
I sure don’t. However I just had a need to log into our support mailbox, and haven’t used OWA in at least 24 hours. The minute I pointed Safari at OWA, I was looking at my inbox. No login. No challenge. No nothing.
What the fuck?