Educause Security Discussion mailing list archives

Re: Vendor Participation on List and Proper Identification


From: Harry A'Hole <madman () MYEASTSIDE COM>
Date: Fri, 29 Jul 2005 14:03:05 -0700

Jason,

It's hard to complain to educase "protecting its members" when you send
your email with your name, title, school and department, phone, fax and
email address at the bottom.  A group list by definition will send your
message to everyone on the list, and the list doesn't require people to
pass a security test in order to join. One odd bit is that educase does
send the email from your email, display as A00JER2 () WPO CSO NIU EDU, and
educase probably should avoid leaking that.

Harry


Jason Richardson wrote:

As troubling to me were the e-mail AND phone call that I received from
the labor union representing hotel service employees who are striking to
force a new contract with hotels in San Francisco.  Apparently, by
becoming a member of Educause I exposed my contact info to this union
who has been spamming me to boycott the hotels.  I called Educause to
complain and they apologized (as they have to many others who called)
and removed me from their public directory.  I have not had this problem
by becoming a member of other professional orgs.  IMO, Educause needs to
do a better job of protecting its members.

---
Jason Richardson
Manager, IT Security and Client Development
Enterprise Systems Support
Northern Illinois University
Voice: 815-753-1678
Fax: 815-753-2555
jasrich () niu edu



Current thread: