Educause Security Discussion mailing list archives

Re: University credentials used by third parties


From: Walter Petruska <wpetruska () USFCA EDU>
Date: Tue, 17 Aug 2010 11:06:47 -0700

I find this completely unacceptable, and fair game for complaint and for
blocking.



Any outrage/shock elsewhere?





*Walter E. Petruska,  CISSP, CISA, CGEIT*

*USF Information Security Officer*

* *

*University of San Francisco*

*Lone Mountain North - 226*

2130 Fulton Street

San Francisco, CA 94117

ITS Help Desk Phone: 415-422-6668

Fax: 415-422-6719







*From:* The EDUCAUSE Security Constituent Group Listserv [mailto:
SECURITY () LISTSERV EDUCAUSE EDU] *On Behalf Of *Justin Sherenco
*Sent:* Tuesday, August 17, 2010 10:13 AM
*To:* SECURITY () LISTSERV EDUCAUSE EDU
*Subject:* [SECURITY] University credentials used by third parties



Hello,

Recently a local on-line news site (
http://www.annarbor.com/news/university-of-michigan-students-can-wager-on-grades-via-website/)
wrote an article about a new website that lets students bet on their own
grades.  The betting aspect aside I was intrigued by this line “they have to
register and upload their schedules to grant the site access to school
records.”  To investigate further I went through the account set up process
and found that the student has the option to allow the site to automatically
download their student records (see attached ultinsic2.jpg).  It actually
asks for their academic user name and password!  EMU is currently not on
their list of supported schools but they mention will be rolling out
nationally.  We have policies and standards in place that say don’t give out
you password and in my opinion giving credentials to this site would violate
them.  Are there any other Universities investigating the use of usernames
and passwords used by third party web applications not sanctioned by the
University?  Any talk on actually blocking a site like this from
automatically logging in (system stability/privacy/security issues?) or is
this more of users choice?





Regards,

Justin



-------------------------------------

Justin Sherenco, CISSP

Easten Michigan University

Security Analyst

http://it.emich.edu/security

Attachment: smime.p7s
Description:


Current thread: