Educause Security Discussion mailing list archives

Re: Password change procedures


From: Roger A Safian <r-safian () NORTHWESTERN EDU>
Date: Fri, 2 May 2014 18:12:57 +0000

We were able to use our own security questions.  We tried to make them a little less easier to search for, but, with a 
young population I still have this concern.

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Dennis 
Levine
Sent: Friday, May 2, 2014 12:49 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Password change procedures

Hi Everyone,
  I'm wondering if I could get some feedback as to how you have your schools procedures set up to change a user's 
password. Not when or how long it should be, ( we already beat that to death in the last thread with the Heartbleed 
bug) I'm talking about do you have a web based user self-portal that allows someone to enter name and ID number, answer 
a security question or two to get to a password change screen if they forgot their password. If so, did you get push 
back because of the security questions that may have been asked such as "pick an address you may have lived at" or 
"what is your mother's maiden name" etc. and all the wonderful problems that come with FERPA or PII info? Do you do it 
another way?

Thanks,
Dennis Levine

Dennis Levine | Network and Security Administrator | 120 Boylston Street  Boston, MA  02116-4624 | (617) 824-8972 | 
Dennis_Levine () emerson 
edu<https://urldefense.proofpoint.com/v1/url?u=http://mailto:Dennis_Levine%40emerson.edu&k=l8X370NuK2YPwmDgp3pt%2BA%3D%3D%0A&r=U4W1fO6l%2Bw0ACd8ZT7mJOIOlBbVZ0JL8g85O1dW5RAY%3D%0A&m=JlUgS4L88e2gDWoEMgJYye4kTXAo4Ztmt5c2TKRLrJk%3D%0A&s=2fc44af654ead7b55074c81efb42d4be5eae722d96124a8a02632c0bd37f34ca>
 | 
www.emerson.edu<https://urldefense.proofpoint.com/v1/url?u=http://www.emerson.edu&k=l8X370NuK2YPwmDgp3pt%2BA%3D%3D%0A&r=U4W1fO6l%2Bw0ACd8ZT7mJOIOlBbVZ0JL8g85O1dW5RAY%3D%0A&m=JlUgS4L88e2gDWoEMgJYye4kTXAo4Ztmt5c2TKRLrJk%3D%0A&s=7b700b37ec078f5175c5f4f7715131175d92f0f5957157e4fc3a36873cf64a72>
[emerson]


Current thread: