Educause Security Discussion mailing list archives
Re: Interesting Research
From: "Jones, Mark B" <Mark.B.Jones () UTH TMC EDU>
Date: Tue, 2 Apr 2019 20:20:09 +0000
I suggest that the analysis of the chosen password be done at the time it is set before the password is protected. It requires that the collection tool be more complicated, but the dataset would be too dangerous left in clear text. * Allow the user to set any password they like * Apply any 'password strength algorithm' that would usually be applied before allowing the password * Record the results of the strength algorithm * Protect the chosen password as it is stored From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of King, Ronald A. Sent: Tuesday, April 02, 2019 3:01 PM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: [SECURITY] Interesting Research **** EXTERNAL EMAIL **** Fellow security pros, I have an interesting research request come in my inbox today. A researcher wants to setup a portal for students to self-register with a username and password. The kicker is passwords will be stored in plain text and collected. The premise is to gauge whether students are actually adhering to suggested practices in password design. My first reaction is "(heck) no," but I realize I may be overreacting. So, I decided to see if anyone has dealt with this kind of research and how you handled it. While I see the value in the research, my security senses tell me students will be using their standard password they use for everything. Thus big risk. Feel free to contact me directly. Thank you, Ron Ronald King Chief Information Security Officer Office of Information Technology (757) 823-2916 (Office) raking () nsu edu<mailto:raking () nsu edu> www.nsu.edu<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.nsu.edu_&d=DwMFAg&c=bKRySV-ouEg_AT-w2QWsTdd9X__KYh9Eq2fdmQDVZgw&r=Lgw4Sh6g47kM5A_tpEcLZDyPGvmOKdeDlyp60PwA78c&m=9KkXBqRl0WZrydfb0oXt6rX5EwNiz_sQnNTR2sMHlgI&s=k0Ji8B4x7IaVr2LuFwcbBGeopwPAXMktXW9DyVdR6BE&e=> @NSUCISO (Twitter) [NSU_logo_horiz_tag_4c - Smaller]
Current thread:
- Interesting Research King, Ronald A. (Apr 02)
- Re: Interesting Research Jones, Mark B (Apr 02)
- Re: Interesting Research Albrecht, Travis (Apr 02)
- Re: Interesting Research Laverty, Patrick (Apr 02)
- Re: Interesting Research Barton, Robert W. (Apr 02)
- Re: Interesting Research Greg Williams (Apr 02)
- Re: Interesting Research Ashlar Trystan (Apr 02)
- Re: Interesting Research John McCabe (Apr 02)
- Re: Interesting Research Clark Gaylord (Apr 02)
- Re: Interesting Research Bridges, Robert A. (Apr 02)
- Re: Interesting Research Bridges, Robert A. (Apr 02)
- Re: Interesting Research Bridges, Robert A. (Apr 02)
- Re: Interesting Research Tanner, Andrea (Apr 02)
(Thread continues...)