Educause Security Discussion mailing list archives

Re: Multiple of Single User Accounts


From: "Flynn, Gerald" <flynngn () JMU EDU>
Date: Thu, 22 Oct 2009 08:50:20 -0400

-----Original Message-----
Another issue that is rarely mentioned in this debate is the need to
protect some credentials more than others. A situation has recently
come to light here where a privileged user here exposed their
credentials to key infrastructure while accessing student systems. The
exposure was obscure (and certainly unintentional) but exists none the
less. Keeping accounts separate helps mitigate that accidental exposure
of credentials.

Speaking of account credentials, sync outsourced student email passwords
with campus passwords or not? I vote no. Too many external account/password
integration and syncing and phishing threats. Federation, when it becomes
available, is a better and acceptable solution. But until then...no
automated password syncing.

Outsourced faculty collaboration cloud accounts? This one could be trickier
depending upon what sort of data faculty place in the cloud.

Current thread: