Educause Security Discussion mailing list archives
Re: Interesting Research
From: Gael Frouin <gfrouin () BERKLEE EDU>
Date: Tue, 2 Apr 2019 16:27:35 -0400
Instead of storing the password in plain text, wouldn't it be better to run the quality checks on the password upon registration of the account (or password change)? If your quality rules are defined and assess prior to storage, you would eliminate the risk of insecure storage while maintaining the ability to report on the password quality criteria that were defined. Gaël On Tue, Apr 2, 2019 at 16:24 Hiram Wong <hiram.wong () domail maricopa edu> wrote:
Hi Ron, Another concern is liability issues if the information collected is compromised. You may want to run this by you Legal Counsel and Risk Management. Hiram On Tue, Apr 2, 2019 at 1:14 PM Brad Judy <brad.judy () cu edu> wrote:Given the popularity of password reuse, I think there is the potential for ethical and security concerns in this research. Have they run it by the Institutional review board yet? Human subject research that potentially puts passwords at risk that might be used for a variety of personal, financial, social, etc. purposes needs to have appropriate controls and monitoring. How would they be incentivizing students to use this portal? Brad Judy Information Security Officer Office of Information Security University of Colorado 1800 Grant Street, Suite 300 <https://maps.google.com/?q=1800+Grant+Street,+Suite+300+%0D%0ADenver,+CO+%C2%A080203+%0D%0A+Office:+(303&entry=gmail&source=g> Denver, CO 80203 <https://maps.google.com/?q=1800+Grant+Street,+Suite+300+%0D%0ADenver,+CO+%C2%A080203+%0D%0A+Office:+(303&entry=gmail&source=g> <https://maps.google.com/?q=1800+Grant+Street,+Suite+300+%0D%0ADenver,+CO+%C2%A080203+%0D%0A+Office:+(303&entry=gmail&source=g> Office: (303 <https://maps.google.com/?q=1800+Grant+Street,+Suite+300+%0D%0ADenver,+CO+%C2%A080203+%0D%0A+Office:+(303&entry=gmail&source=g>) 860-4293 Fax: (303) 860-4302 www.cu.edu [image: cu-logo_fl] *From: *EDUCAUSE Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of "King, Ronald A." <raking () NSU EDU> *Reply-To: *EDUCAUSE Listserv <SECURITY () LISTSERV EDUCAUSE EDU> *Date: *Tuesday, April 2, 2019 at 2:11 PM *To: *EDUCAUSE Listserv <SECURITY () LISTSERV EDUCAUSE EDU> *Subject: *[SECURITY] Interesting Research Fellow security pros, I have an interesting research request come in my inbox today. A researcher wants to setup a portal for students to self-register with a username and password. The kicker is passwords will be stored in plain text and collected. The premise is to gauge whether students are actually adhering to suggested practices in password design. My first reaction is “(heck) no,” but I realize I may be overreacting. So, I decided to see if anyone has dealt with this kind of research and how you handled it. While I see the value in the research, my security senses tell me students will be using their standard password they use for everything. Thus big risk. Feel free to contact me directly. Thank you, Ron *Ronald King* *Chief Information Security Officer* *Office of Information Technology* (757) 823-2916 (Office) raking () nsu edu www.nsu.edu @NSUCISO (Twitter) [image: NSU_logo_horiz_tag_4c - Smaller]-- [image: eSig Logo] Hiram Wong, CISA, CISM Internal Audit 2411 West 14th Street, Tempe AZ 85281 <https://maps.google.com/?q=2411+West+14th+Street,+Tempe+AZ+85281&entry=gmail&source=g> phone | 480-731-8827 email | @domail.maricopa.edu website | https://www.maricopa.edu [image: eSig facebook] <https://www.facebook.com/maricopa.edu>[image: eSig twitter] <https://twitter.com/mcccd>[image: eSig linkedin] <https://www.linkedin.com/company/maricopa-community-colleges>[image: eSig youtube] <https://www.youtube.com/user/themcccdEDU>[image: eSig instagram] <https://instagram.com/maricopacc/> [image: facebook] <http://www.facebook.com/maricopa.edu>
Current thread:
- Re: Interesting Research, (continued)
- Re: Interesting Research Clark Gaylord (Apr 02)
- Re: Interesting Research Bridges, Robert A. (Apr 02)
- Re: Interesting Research Bridges, Robert A. (Apr 02)
- Re: Interesting Research Bridges, Robert A. (Apr 02)
- Re: Interesting Research Tanner, Andrea (Apr 02)
- Re: Interesting Research Von Welch (Work) (Apr 02)
- Re: Interesting Research John Chapman (Apr 03)
- Re: Interesting Research King, Ronald A. (Apr 09)
- Re: Interesting Research Mark Poepping (Apr 09)
- Re: Interesting Research Brad Judy (Apr 02)
- Re: Interesting Research Hiram Wong (Apr 02)
- Re: Interesting Research Gael Frouin (Apr 02)
- Re: Interesting Research Hiram Wong (Apr 02)
- Re: Interesting Research Clark Gaylord (Apr 02)