Educause Security Discussion mailing list archives

Re: Back on topic.... Re: [SECURITY] University credentials used by third parties


From: Mike Porter <mike () UDEL EDU>
Date: Wed, 25 Aug 2010 11:55:21 -0400

On Wed, 25 Aug 2010, Jesse Thompson wrote:

On 08/24/2010 11:08 AM, Joel Rosenblatt wrote:
Just to thorough another thought into this mix, does anyone prevent
their students (or other users) from turning over their credentials to
Gmail or Blackberry?

We see lots of authenticated logins from these services - and if I were
to come down hard on this Ultrinsic using our sharing of password policy
(which we do have) I'm sure that this would amount to having to change
our policy to - you can't share your credentials - except with (gmail,
Blackberry, etc.)

I really hate inconsistent enforcement of policies, so it's either
change the policy or cut off everyone.

+1

Our help desk created end-user instructions for IMAP-syncing email accounts with Gmail, despite the fact that it completely violates password policy. They did this specifically because they get flooded with "how do I save my email" requests when we deactivate email accounts, but other users take advantage of it as well.

Yet, when we propose the idea of officially embracing this Gmail-IMAP-sync option as a more reliable alternative to forwarding - essentially treating Gmail the same as any other IMAP client - the idea is immediately shot down because it violates password policy.

What was the violation?  The problem that users woud need to store
a password, likely the regular one, at gmail in order to use imap?

We ended up with a convoluted system to avoid some of those issues.


Mike

Mike Porter
Systems Programmer V
IT/NSS
University of Delaware


Jesse
(an email admin at Wisconsin)



-
Mike Porter
PGP Fingerprint: F4 AE E1 9F 67 F7 DA EA  2F D2 37 F3 99 ED D1 C2


Current thread: