thanks for your reply. sorry if this issue is off the focus of this forum.
i knew there was no exactly right forum for this topic. the clients are not security alerted enough and the sales person usually tend to listen to the clients. So i tend to my fellow programmers here who I belived that care about security more than sales department to help me convince them to see how you guys do and convince clients and sales department that here, "log in every time" is a good choice.
when use "remember me", of course we will
1) first, the site will have a note to remind the users that "remember me" should be used only on secured computer in his office or home, NOT ON PUBLIC COMPUTERS.
2) second, the e-commerce accounts on our site will never save the crucial financial information, the credit card payments is through the 3rd party transaction sites such as authorizenet etc. To finish the purchase, the shoppers still have to fill out the form on authorizenet, the account information on our site is for the auto filling address and save the shopping cart, wish list etc.
But still, I would prefer not set up the "remember me" for the e-commerce sites. the end user is not "security alerted" enough to follow the advice such as only use it on secured computer in home or office.
Thanks!