Jump to content

Recommended Posts

Posted

Excellent response

 

Firstly, to DSapseid. I've heard this argument used a number of times now. I've heard people say that having the extra password box 'adds an extra layer of security'.

 

You are right, a member of staff can walk away from their laptop without locking it. But what difference does having the extra login box make?

 

Staff are just as likely to leave their laptop unlocked with SIMS running as they are without it running!

 

They may KNOW not to leave SIMS open, but actually they should KNOW not to leave ANYTHING open!

 

Alternatively, even if SIMS isn't left open, they may leave their email open - which in a school environment where staff email parents, could be equally damaging in terms of data security!

 

The key is to teach staff to ALWAYS lock Windows. And get them to sign an agreement saying they will do so.

 

In fact, using Windows authentication (i.e. the removal of the SIMS username and password) will increase total security as long as staff lock laptops.

 

The reason for this is that you can prevent people from logging on to SIMS from another person's Windows logon. Everything can then technically be tracked back to someone's Windows logon. SIMS logon is ALWAYS tied to Windows logon.

 

Furthermore, you can't set password policies for SIMS, but you can for a Windows domain.

 

Also, passwords aren't sent unencrypted :p

 

Other security principles are in force with Single Sign-on:

 

1) The more time your user enters a password, the more likely it is to be overseen by someone else

 

2) The more passwords your users have, the more likely they are to write them down

 

etc.

 

In conclusion, to a layman it would seem more secure to have an extra prompt to enter a password - it would seem like an extra 'level' of protection.

 

In actual fact, the less thoughtful your users are, the more important it is to use Single Sign-on, flowed authentication, and the reduction of number of passwords (note: the increase in password complexity).

 

We use Windows Authentication for SIMS, and... it works. I don't trust anyone who says it's a risk... it's a risk not to!

Posted
I understood (from the consultant who came to move our SIMS installation to our new server) that SIMS doesn't check passwords, it simply trusts the username it is passed.

 

Is this true?

 

Yes. The SIMS client will check the username it is passed from Windows and, if set up to do so, will automatically log that user in to SIMS. This is the same as NTLM authentication as used by web browsers (although I don't know if this is actually NTLM authentication, I can't be bothered to go and look it up).

 

This system works well for us using SIMS over Terminal Services - the user logs in to the TS server, the SIMS client automatically starts up and logs them in, as far as the user is concerned they've just logged in to SIMS using their standard AD username and password. You can set the password-protected screensaver to start on the TS server after 3 minutes, so anyone wandering away from their workstation gets it automatically locked pretty quickly and everyone only has one username and password to remember.

 

--

David Hicks

Posted
have you tested to see if oldpassword1, oldpassword2, oldpassword3 works? :)

 

I'd rather they had _one_ good, hard-to-guess or bruteforce password that they were careful not to disclose.

 

 

Password sharing is a problem here :mad: so we make them change their password every 45 days and it has to be 8+ characters and alpha numeric. I'm ok with them writing it down and keeping it in their purse or wallet tbh, at least then they have good passwords that help secure our remote access.

  • 1 year later...
Posted
Hello,

 

As anybody been able to integrate Active Directory and SIMS.Net together? We've just moved to SIMS.Net and if possible would like the ability for SIMS.Net not to bring up the prompt but instead log them straight in based on their AD Credentials.

 

Thanks,

 

Rob

 

YES!

in your connect.in use

 

Connectiontype-TrustedAuto

This will suppress the intial login screen and solong as youve set the users with AD credential in system manager this should work.

  • 4 months later...
Posted

Hello,

 

We're just gone to using AD logons for sims and everything seems to be working well however when users start NOVA T it asks them for username and password? is there any addition settings that need to be set for this to work?

 

TIA,

 

Ash.

  • 6 years later...
Posted
SSO is a big issue - staff hate multiple logons to different sites but i'd rather keep everything separate for security.

Did I miss an actual update to this thread or was this just the mother of all necroposts?

 

p.s. we've just agreed to enforce a fairly strict auto-lock on unattended staff PCs, that will help a bit - and also make the staff moan some more.

 

Give it a few more years and staff PCs will just do iris recognition or some other passive system to ensure security.

No more banging your head against the brick wall of attempting to change human behaviour by diktat!

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...