hotwired007 Posted March 28, 2008 Posted March 28, 2008 Hi all i'm trying to find out what the current legislation is on passwords and automatic resets... in my old job i worked for charity dealing with disabled people and we had best practice rulings as to passwords.. ie 24 password memory, min 8 characters, must have 3 different types of character, 40 day reset. in my new place i have absolutely nothing in place... any advice?
Jona Posted March 28, 2008 Posted March 28, 2008 current legislation I don't think there are any laws on this just reasonable security steps in the data protection act, etc. I think it's an fine balance between security and the user actually being able to remember it with out writing it down (which compromises your security). I would personally suggest maybe 6 chars or longer with at least one numeric? AU's password policy which is very draconian is here: How do I choose a suitable password? this is actively enforced e.g. it checks language dictionaries and such. Wikipedia has something vaguely helpful to say: Password policy - Wikipedia, the free encyclopedia
K.C.Leblanc Posted March 28, 2008 Posted March 28, 2008 Bare in mind in a school if you make it too complicated you'll have two problems. A. No one will like you. B. A phenomial number of people won't take passwords seriousely. You'll get loads writen down or told to all an sundry. Make sure you have SLT on side and make sure they're aware of the potential pit falls.
hotwired007 Posted March 28, 2008 Author Posted March 28, 2008 A. No one will like you. now thats interesting coment... most of the kids don't like me coz i stop them doing all the fun things... then again a lot of the kids respect the authority... in my old post i had 50 women who hated the thought of having to work with a decent password policy... it took a couple of moths for them to get used to the system and they got on with it... NB - is it possible to set up a system so that all login's can be recorded and programs run are logged also? i've never used it before and school administration is a lil different to what i'm used to...
gaz350 Posted March 28, 2008 Posted March 28, 2008 (edited) 'smoothwall' Tom posted about a nice document about passwords in schools its some where on the forum here it is http://download.smoothwall.net/pdf/password-advice-for-schools.pdf Edited March 28, 2008 by gaz350
srochford Posted March 28, 2008 Posted March 28, 2008 One of the key things which might help is to stop talking about "passwords" and to use the term "passphrase". Passwords like O9**HHb23 are secure but are not easy to use. Passphrases like Dudden Hill Lane NW10 2XD are easy to remember and can be secure (provided you don't use an address which is easily associated with you!) It doesn't even have to be real (eg if you only half remember the address where you grew up then that's fine!). There are loads of other phrases that you can use which include numbers and punctuation; they can be easy to work with but hard for a dictionary attack to find.
PEO Posted March 28, 2008 Posted March 28, 2008 typical username and password for a user User Mark Bell username 09MBELLI9F password ntlznh4b took about a month for kids and staff to get used to the new username password policy but its worked. Its completely cut out the problems we had before i.e. kids loging on to other kids email accounts, loging on to network to delete work.
Michael Posted March 28, 2008 Posted March 28, 2008 (edited) Well I operate mostly in primary schools and setup the following: 10 remembered passwords Minimum 5 characters 200 days remembered However, all children use the same password which they cannot change. All staff are forced and reminded (5 days before) to change every 200 days by GPO. Usually I operate the username format jbloggs for staff and 07jbloggs (for example) the year the children joined the school. Edited March 28, 2008 by Michael
FN-GM Posted March 28, 2008 Posted March 28, 2008 We don't use this as the kids have trouble remembering passwords as it is
jcollings Posted March 28, 2008 Posted March 28, 2008 1. Our staff would crumble if I enforced regular changes - they struggle to remember 1 2. Interesting about usernames. We use 07BloggsJ as username and [email protected] as their email (that way they only have to remember 1 username) - a guy from Shirelands (our VLE provider) was suggesting Becta has said 07BloggsJ was no longer acceptable as it identified the age of the student and their surname. What do others do for student email addresses?
hotwired007 Posted March 28, 2008 Author Posted March 28, 2008 we have [email protected] as email and logon is first.last... the way we oganise the accounts is al setup in active directry used users>pupils>year intake.. is 2007 intake = yr7 etc...
tom_newton Posted March 28, 2008 Posted March 28, 2008 Remember, there's little chance of a traditional dictionary attack on these passwords, so using a "real" word has fewer disadvantages. For Kids passwords, and this mostly goes for teachers too, your biggest risks are: 1. Guessability 2. Written-passwords 3. Shoulder surfing A dictionary word is easier to shoulder surf, but difficult for a human to guess, because there are a few of them. Enforcing too long, or over complex passwords opens users up to #2 - have heard of kids being encouraged to write passwords in jotters etc. Unmemorable passwords (or phrases - that is a good idea) will cause much more hassle than insecure ones. There's a big difference between "memorable" and "guessable" though. Harder with kids, as they have less "life experience" to draw on, old addresses, etc. and will often take examples too literally, leading to obvious patterns. Its also worth noting how many people will "stick with" the default, unless enforced otherwise.
stratisphere Posted March 28, 2008 Posted March 28, 2008 now thats interesting coment... most of the kids don't like me coz i stop them doing all the fun things... then again a lot of the kids respect the authority... in my old post i had 50 women who hated the thought of having to work with a decent password policy... it took a couple of moths for them to get used to the system and they got on with it... NB - is it possible to set up a system so that all login's can be recorded and programs run are logged also? i've never used it before and school administration is a lil different to what i'm used to... I'm working on a tool at the moment (actually, a suite of tools) which will do all this. It also has a password manager (basically shows you the security of your password in a nice friendly bar... like those 2.0 websites). At the moment it's in an alpha development phase (i.e. i'm not happy to send it out to anyone). But over the next few weeks i'll be releasing a beta version of it. The thread is http://www.edugeek.net/forums/network-classroom-management/17339-imperium-ideas-help.html if you want to keep an eye on it.
Michael Posted March 28, 2008 Posted March 28, 2008 Interesting about usernames. We use 07BloggsJ as username and [email protected] as their email (that way they only have to remember 1 username) - a guy from Shirelands (our VLE provider) was suggesting Becta has said 07BloggsJ was no longer acceptable as it identified the age of the student and their surname. What do others do for student email addresses? That's what I love about BECTA. They come out saying it's not acceptable, but at the same time, they don't offer an alternative. Really constructive. The point is BECTA are only offering guidance, it isn't mandatory. If you're like me and it works in many schools, with no issues, then leave well alone The only alternative would be to give pupils a random 4 digit pin to logon as. For example, 1234, 4321, 3421 etc... however it's going to be really problematic as I obviously teachers or myself wouldn't be able to remember which number is for which child.
elsiegee40 Posted March 28, 2008 Posted March 28, 2008 (edited) I force passwords changes on all staff in the second week of every half term. It wasn't popular when I first did it, but they're used to it now. They much prefer this to the nagging "your password will expire in x days, do you want to change it now?" message. As for the kids, because our youngest users are aged 4 we have a simpler policy than I would like. The kids password is set once and cannot be changed... although from next September Year 5 & 6 will be setting their own passwords (should be fun!) As for user names: 07AliciaS is the standard here: 07 is the year they start in Reception and that is followed by the child's forename and the first initial of the surname. We always use the preferred abbreviation for the forename that the child uses... so Madeleines are Maddy or Maddie, etc (we only get away with this because the school is so small!) Staff logons are JSmith; i.e. Initial of forename followed by surname Emails are the same as the user's logon above @school.co.uk Edited March 28, 2008 by elsiegee40
tom_newton Posted March 28, 2008 Posted March 28, 2008 re: usernames... when I was at uni my department used to use a rotating letter to identify the year... example: I was ctztdn ct (course) z (97 entry) tdn (my initials) Had I been a year ealier, i'd have been ctytdn, then ctx.. This allows internal users a mnemonic for each year (and of course a non-changing username) IIRC there were only vwxyz in the rotation, as that more than covered a few years. I think it is useful to use more than initials, however, as these soon get exhausted and you end up with "td2n" and things - yak.
OverWorked Posted March 28, 2008 Posted March 28, 2008 2. Interesting about usernames. We use 07BloggsJ as username and [email protected] as their email (that way they only have to remember 1 username) - a guy from Shirelands (our VLE provider) was suggesting Becta has said 07BloggsJ was no longer acceptable as it identified the age of the student and their surname. What do others do for student email addresses? I undertand that on email addresses it must not be possible to work out the name, age or gender of the child. I think I read that on becta somewhere. We previously had no password policy, even blank were allowed. I was horrified to find that a teacher had a blank password - he just couldn't see the point of setting one. It hadn't occurred to me that staff might have no password. When I did set a policy following this incident (and notified the whole school a month in advance) I got some nasty ear ache off the staff (none from the kids) about it for months afterwards. I dug my heels in and now they just accept it and get on with it when they're forced to change them.
dancingdruid Posted March 28, 2008 Posted March 28, 2008 I force passwords changes on all staff in the second week of every half term. It wasn't popular when I first did it, but they're used to it now. I don't see the point of this. I guess many do what my mum used to do when she had enforced password changes at the bank. She had a list of them in the back of her diary and rotated through them. I know for a fact that our office manager has done this too for county payroll and admin systems. Does this make for a more or less secure system?
zag Posted March 28, 2008 Posted March 28, 2008 The most secure password systems are those which do not enforce changes
witch Posted March 28, 2008 Posted March 28, 2008 Our teacher passwords are set once and then never changed. Most have the same password for logging on locally to their laptop as they do to the network. I have complained but no one cares about security so.... The children have similar to most of you: yearsurnamefirst3lettersoffirstname (07smithemm). They don't have email addresses here.
tom_newton Posted March 28, 2008 Posted March 28, 2008 Changing passwords is only really useful for damage limitation once someone's got in. With the primary adversary being kids here, i really think you're going to notice almost immediately you are compromised... this would, in my eyes mean the benefits are outweighed by irritations (more forgetters, writing down, etc). Worth communicating "what to do if you think someone has your password" though.
Sylv3r Posted March 28, 2008 Posted March 28, 2008 typical username and password for a user User Mark Bell username 09MBELLI9F password ntlznh4b took about a month for kids and staff to get used to the new username password policy but its worked. Its completely cut out the problems we had before i.e. kids loging on to other kids email accounts, loging on to network to delete work. Do you have more instances of the students forgetting their passwords now though? Infact what about staff forgetting their passwords if they use a similar context? Thanks
Sylv3r Posted March 28, 2008 Posted March 28, 2008 Usernames to login are: 07AIBSMITH (Year of Entry + First 2 Letters of Form + Initial + Surname) e-mail addresses are: bsmith@stbedes......... (for staff and students but both on different domains, but im going to introduce a new e-mail system for students so we will probably create a new formula such as gs100@stbedes..... (initials + number starting at 100) for our student accounts. Printed out on sticky labels so they can stick into their planners at the start of the year - not with their passwords on of course.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now