Jump to content

Recommended Posts

Posted

I understand some staff at some schools ask students to write their email address & password in their planners.

 

Planners are taken home and could of course be mislaid, lost, stolen.

 

Therefore I am not satisfied that this is a sensible policy; I also believe it gets students into bad habits.

 

Is it reasonable to say that teachers should not be asking students to write passwords in planners, but maybe a password hint is reasonable?

 

What are peoples thoughts on this?

 

Does anyone work at a school that has a clear policy on this?

Posted

Recently, the school moved to not have planners, so problem solved.

 

When we had planners, there was a space for "Usernames" but not passwords. The page said "do not write passwords" etc. But there was also plenty of notes pages at the back. Nothing to stop students writing it in anywhere, really. Even now they could put it in a textbook if they wanted to. That's just a human thing you can never stop, but the way it was taught in IT/Computing was that writing passwords down is bad.

 

However no, teachers should not be telling students to write passwords down. That's terrible practise. GDPR, security, etc. Mitigated if you have 2FA enabled but horrible advice.

 

I know that there are some children with learning difficulties and for them it might be more acceptable but I always look for alternative solutions such as setting fixed passwords that the supporting staff know, rather than writing it in their book.

Posted

At a previous school, we set a randomised password for students and they couldn’t change it. Teachers were given access to a list so there was no need for password related excuses to not do their work, or to leave the classroom.

 

In another school I worked at, students could set their password but select staff had delegated access to reset student passwords. I’m sure some students wrote theirs down in their planner but we never told them to do so. The AUP listed never writing passwords down which they all accepted.

 

Why do teachers need the passwords? If it’s to access work, a technical solution may be an option to access student files.

Posted

Because children are idiots who forget passwords.

 

Q1: Do they have more than 1 account? If so fix that, the main problem is having 10 accounts and 10 passwords. Tell every company that doesn't do oauth you'll only renew next year if they add it.

 

Q2: What does the username/password combo let them access? A homework site? No one cares. Remotely access your LAN? More valuable

 

Q3: Why haven't you implemented a password manager for them?

 

Writing down your passwords means you can have better passwords. The attack surface of internet accounts is 509 600 000 square km, the attack surface of your LAN accounts is <1 km^2

 

https://www.ncsc.gov.uk/collection/passwords/updating-your-approach

Posted

For our frequent fliers who really do have problems remembering passwords, we check that their phone has a PIN / fingerprint lock set and a notes application (or similar). If so, we suggest they put their new password into the notes app until they remember it, protected by the phone PIN/biometric lock.

 

Then we send a:

 

Bob in 7B has problems remembering their password.

 

To make their, our and your lives easier, Bob has been encouraged to save their password as a note on their phone (protected by a PIN) until they remember it.

 

They may briefly get their phone out when logging in during lessons.

 

Please let them do so, unless they're clearly taking the mickey.

 

IT

 

email to the "Teachers of Bob 7B" distribution list.

Posted
setting fixed passwords that the supporting staff know, rather than writing it in their book.

 

I promise you, your supporting staff have written that password down.

Posted

Students used to write passwords down, especially lower ability students and Year 7s. Teachers can reset passwords, but it can take a long time at the start of the lesson, especially early in the academic year when students are still getting used to everything. We no longer have paper planners, so students are instead encouraged to store them on their phone or on a slip of paper in their pencil case.

 

I don't think a student password getting out into the wild is really much a problem. Students don't have access to any sensitive information except class lists, and the likelihood of someone stealing their planner, logging in as them, doing a "forgotten password" on Kerboodle or whatever, then logging in to that platform and accessing the class list is tiny. Let's also not forget students often have incredibly simple passwords anyway, so anyone with a brute force tool could probably get passwords in a matter of minutes!

 

Yes, it isn't great security practice, but weighed up against the risk and impact on T&L of doing something else, I'm okay with it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...