Jump to content

Recommended Posts

Posted (edited)

We're currently using SIMS Options Online and are interested in broadening this to their new Parent App Lite - basically two web-based tools which allow parents to view information about their child, so the specifics aren't actually important as there are plenty of other services out there which do similar. The catch is the registration process - we send an email invite to the parent and they then create an account with the service. At our most recent "GDPR working group" meeting, the security of this was questioned, as anyone could access the email and then activate the access (especially for those services which permit multiple accounts per invite).

 

What do you think? Is this acceptable or should we look for alternative ways of granting access?

Edited by enjay
Posted

It depends on the invite I think. If the invite is permanent and anyone clicking it can set up a validated account at any time then yeah that sucks. If it's a one-time use link and is time limited (say the invite link only works for 3 days or something) then that's fine really.

 

My justification for that is; the risk of interception isn't GCHQ or the NSA or anything like that. It's really unlikely anyone is watching these emails in real time, so the risk would be someone finding it after trawling emails they collect over a period of time for anything containing the word "username" or "account" or something, by which point the invite has expired.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...