Educause Security Discussion mailing list archives

My final word on OneLogin - they are somewhat redeemed


From: Emily Harris <emharris () VASSAR EDU>
Date: Thu, 8 Jun 2017 14:49:36 -0400

I promise this is my last note about this since most of you are not
OneLogin customers.

They are posting a customer update within the next hour with specific
language on the password cache issue.  I'm thankful for this list for
putting me in touch with other OneLogin customers, as this was how Vassar
became aware of it in the first place.

My call with them yesterday must have struck the right note, as today the
CEO and VP of communications were in touch.  They contacted me directly to
review the update they are posting.

I'm just glad the pressure worked and that the agreed it was an issue work
communicated.  Of course, we are still not happy about the breach in the
first place.

----
Emily Harris, CISSP
Information Security Officer, CIS
Vassar College
845-437-7221

Current thread: