Educause Security Discussion mailing list archives

Re: Enabling a job applicant to resume a submission later


From: Jeffrey Schiller <jis () MIT EDU>
Date: Wed, 15 Dec 2010 20:30:11 -0500

One of the things that I work on at MIT is a web survey service. This
service permits people to revisit a survey and they will see their
previous answers. This is a very similar problem. Because these are
mostly "one time" surveys (we don't maintain a lasting relationship
with the people filling it out), we use an ad-hoc way of
authenticating them. In cases where we don't know who will visit, we
generate an access code that we give them (either on the first or last
page, or on both) which can be re-used to enter the same survey
instrument.

A solution I would propose for you would be to create a temporary
access code that is displayed on each page. For additional security
you can also prompt them for a user selected password (not displayed
on each page :-) ) to be used in addition to the access code. You can
then prompt them for an e-mail address to use to send a code reminder.

The trick here is that *if* they require their code mailed to them,
you remove sensitive information from their application at that time.
They then have to re-enter it when they re-visit. Some e-commerce
sites do this, when you request a password reset, your credit card
data is removed.

                -Jeff


-- 
_______________________________________________________________________
Jeffrey I. Schiller
Information Services and Technology
Massachusetts Institute of Technology
77 Massachusetts Avenue  Room N42-283
Cambridge, MA 02139-4307
617.253.0161 - Voice
jis () mit edu
http://jis.qyv.name
________________________________________________________________________

Attachment: smime.p7s
Description:


Current thread: