Jump to content

Recommended Posts

Posted
Respectfully, you are being ridiculous. For MFA to work you need to use multiple effective challenges - a password, an app on your phone, a security USB key etc etc.

 

Relying solely on a password and the domain status of a device is not effective MFA.

 

It's not relying just on domain status. There's a certificate on the machine that's used for access, broadly similar to the USB key you suggest. If the machine has a TPM it's further secured there too. I doubt most schools infosec threat model includes targeted physical attacks against high value individuals.

  • Thanks 1
Posted

I assume the security issues are a) random people on the internet using automated attacks, and b) teachers shouting their passwords across the classroom

 

But yeah, just make it a policy that all admin access needs TOTP, and then when the Head's account requires a TOTP every 5 mins they'll get annoyed and ask you to remove their admin rights.

Posted
It's not relying just on domain status. There's a certificate on the machine that's used for access, broadly similar to the USB key you suggest. If the machine has a TPM it's further secured there too. I doubt most schools infosec threat model includes targeted physical attacks against high value individuals.

 

And it does nothing to prevent shoulder surfing - attacks are not only external.

  • Thanks 1
Posted (edited)

TBH a teachers account being compromised by a student shoulder surfing should not be the demise of your network/ cloud deployment.

 

If I am to believe that you are really giving out privilege access to teachers (head teachers) then you are not letting that machine connect to your important infrastructure as you do not install any kind of admin tools/ allow connections to the admin portals directly from these. You are surly using gateway boxes for the purpose of any type of admin function right (like you don't log on to a DC to admin your domain).

 

We are assigned laptops and are not allowed to install admin tools of any type on those and if we need to use our elevated creds then this is done via a purpose built set of servers (that are limited from where we can connect to them from) and even then those accounts are not members of Enterprise or Domain admin groups (if you do this then stop).

 

So yeah risks are not just external (not quite the headline figure of 7 billion that has been banded around there are only ~7.8 billion of us on the planet, and 98% of those don't just don't care. :-p) that said not all risks are going to kill your network and steal your data. They may/ should just be embarrassing for an individual teacher.

 

Anyhow back to additional factors for auth...

Edited by HPlum78
Posted
TBH a teachers account being compromised by a student shoulder surfing should not be the demise of your network/ cloud deployment.

 

If I am to believe that you are really giving out privilege access to teachers (head teachers) then you are not letting that machine connect to your important infrastructure as you do not install any kind of admin tools/ allow connections to the admin portals directly from these. You are surly using gateway boxes for the purpose of any type of admin function right (like you don't log on to a DC to admin your domain).

 

We are assigned laptops and are not allowed to install admin tools of any type on those and if we need to use our elevated creds then this is done via a purpose built set of servers (that are limited from where we can connect to them from) and even then those accounts are not members of Enterprise or Domain admin groups (if you do this then stop).

 

So yeah risks are not just external (not quite the headline figure of 7 billion that has been banded around there are only ~7.8 billion of us on the planet, and 98% of those don't just don't care. :-p) that said not all risks are going to kill your network and steal your data. They may/ should just be embarrassing for an individual teacher.

 

Anyhow back to additional factors for auth...

 

My point is more regarding data protection than anything else. If you're a student logged on with a teacher account then there's a lot of data accessible and that's now a data breach.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...