Currently, when a user logs out of the POS (Menu → Store Settings → Logout), the email and password fields remain pre-populated on the login screen. Anyone with physical access to the terminal, for example, during a break-in after hours, can see the saved credentials and sign in without needing to know them.
Requested fix: Clear the email and password fields after logout so the login screen resets to blank rather than staying pre-filled.
Also worth noting: merchants should be using unique, individual passwords per staff member rather than one shared login, but that alone doesn't solve this issue, since the same persistence problem applies regardless of whose password it is. Any saved password, unique or shared, needs to clear on logout for this to actually be secure.
Submitted by: Sam Sonntag, Automated Transaction Services
Priority: Medium
