Educause Security Discussion mailing list archives

Re: Interesting Research


From: Hiram Wong <hiram.wong () DOMAIL MARICOPA EDU>
Date: Tue, 2 Apr 2019 13:23:53 -0700

Hi Ron,

Another concern is liability issues if the information collected is
compromised.  You may want to run this by you Legal Counsel and Risk
Management.

Hiram

On Tue, Apr 2, 2019 at 1:14 PM Brad Judy <brad.judy () cu edu> wrote:

Given the popularity of password reuse, I think there is the potential for
ethical and security concerns in this research. Have they run it by the
Institutional review board yet? Human subject research that potentially
puts passwords at risk that might be used for a variety of personal,
financial, social, etc. purposes needs to have appropriate controls and
monitoring.



How would they be incentivizing students to use this portal?



Brad Judy



Information Security Officer

Office of Information Security

University of Colorado
1800 Grant Street, Suite 300
Denver, CO  80203

Office: (303) 860-4293

Fax: (303) 860-4302

www.cu.edu



[image: cu-logo_fl]





*From: *EDUCAUSE Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of
"King, Ronald A." <raking () NSU EDU>
*Reply-To: *EDUCAUSE Listserv <SECURITY () LISTSERV EDUCAUSE EDU>
*Date: *Tuesday, April 2, 2019 at 2:11 PM
*To: *EDUCAUSE Listserv <SECURITY () LISTSERV EDUCAUSE EDU>
*Subject: *[SECURITY] Interesting Research



Fellow security pros,



I have an interesting research request come in my inbox today. A
researcher wants to setup a portal for students to self-register with a
username and password. The kicker is passwords will be stored in plain text
and collected. The premise is to gauge whether students are actually
adhering to suggested practices in password design.



My first reaction is “(heck) no,” but I realize I may be overreacting. So,
I decided to see if anyone has dealt with this kind of research and how you
handled it.



While I see the value in the research, my security senses tell me students
will be using their standard password they use for everything. Thus big
risk.



Feel free to contact me directly.



Thank you,

Ron



*Ronald King*

*Chief Information Security Officer*



*Office of Information Technology*

(757) 823-2916 (Office)

raking () nsu edu

www.nsu.edu

@NSUCISO (Twitter)

[image: NSU_logo_horiz_tag_4c - Smaller]





-- 
[image: eSig Logo]
Hiram Wong, CISA, CISM
Internal Audit
2411 West 14th Street, Tempe AZ 85281
phone | 480-731-8827
email | @domail.maricopa.edu
website | https://www.maricopa.edu
[image: eSig facebook] <https://www.facebook.com/maricopa.edu>[image: eSig
twitter] <https://twitter.com/mcccd>[image: eSig linkedin]
<https://www.linkedin.com/company/maricopa-community-colleges>[image: eSig
youtube] <https://www.youtube.com/user/themcccdEDU>[image: eSig instagram]
<https://instagram.com/maricopacc/>


[image: facebook] <http://www.facebook.com/maricopa.edu>


Current thread: