Jump to content

If your DA password is/was "Horse Fence Ditch", you're in The Register


Recommended Posts

Posted

I'd like to think it's made up, but these days, I'd suspect it probably has happened. And as much as I'd like to preach solidarity, if real I would hope anyone involved in the IT of that school was immediately marched off site under gross misconduct never to be let near anything electronic ever again.

  • Like 1
Posted

I had a "you realise most AD fields are visible to normal users, right?" conversation with a technical person while visiting a school that shall remain nameless (and wasn't a school we were responsible for).

 

The problem I spotted there was "maybe don't save your unprofessional comments about the user in world-readable fields on the user account?".

Posted

Education IT is undeniably an underfunded sector, but that only gets you so much latitude. Even if it is underfunded, you should know enough to never put a secure credential in a place where anyone can get it.

Posted

Ha! Password1 is too complex! I made sure to override those annoying Microsoft password policies - that way I can make sure that my passwords are the same as the usernames - that way I'll never forget them and they're super secure too!

  • Haha 2
Posted
22 minutes ago, E_G_R2 said:

The user could still get done under the misuse of computers act

 

Sure, if the organisation wanted to create a public record that they'd done the IT equivalent of posting credentials on a billboard outside Tesco and then acted surprised when someone tried them.

 

Suspect it'd get dismissed though.

Posted
1 hour ago, sigma said:

Shoul I put a fake password in the description against an account as a honey trap?

 

Danger of a misguided whistleblower running around all the local papers saying "Sigma at SchoolName puts admin credentials in the description fields of user accounts" though.

 

We tend to use these https://canarytokens.org/nest/generate for honeypot-type activities.

  • Haha 1
Posted
6 hours ago, pete said:

I had a "you realise most AD fields are visible to normal users, right?" conversation with a technical person while visiting a school that shall remain nameless (and wasn't a school we were responsible for).

 

The problem I spotted there was "maybe don't save your unprofessional comments about the user in world-readable fields on the user account?".

 

Had that with GPO Names they were pretty mild like Software-Microsoft-Office-fixstupidissuewithOutlook 

Posted

Kids these days, over complicating the process.

 

I just walked in to the computing room and read the commissioning engineers notes while he was on a lunch break. ::shrug:: 

 

Posted
12 minutes ago, psydii said:

Kids these days, over complicating the process.

 

I just walked in to the computing room and read the commissioning engineers notes while he was on a lunch break. ::shrug:: 

 

 

I mean, back in the day that'd just get you the cheatsheet for Granny's Garden*.

 

*https://en.wikipedia.org/wiki/Granny's_Garden

  • Haha 1
Posted

Joking aside, its probably worth searching AD for accounts with the description field set, or enabling the column in AD users + Computers.

 

I did spot this on some of our user accounts by chance. It seemed to have been added by an automated account creation system that I know other schools on here use. I won't name names. 

 

Its certainly something I would never have done, and was too many for them to be done one by one. I'm assuming it was done for diagnostic purposes and then never turned off.

Posted
8 hours ago, Chris_Cook said:

Joking aside, its probably worth searching AD for accounts with the description field set, or enabling the column in AD users + Computers.

 

I did spot this on some of our user accounts by chance. It seemed to have been added by an automated account creation system that I know other schools on here use. I won't name names. 

 

Its certainly something I would never have done, and was too many for them to be done one by one. I'm assuming it was done for diagnostic purposes and then never turned off.

I think there used to be a spate of people doing this on the assumption that no one could "see" the directory they were connected to, a mistaken belief that the account details in fields like that were 'secure'.

Posted

I mean, in fairness, unless you happen to know that those fields are potentially readable by curious regular users, there's nothing in ADUC and the like that specifically spells that out. If you're using ADUC, and stuff like phone numbers, line management, department, etc aren't being used by end users in a business context (as they might in a very different sector to edu), then it's all going to have the air of being for the admin's eyes only.

 

Even so, having any sensitive passwords written out in plain text ought to 'feel' icky anyway.

  • Like 1
Posted

^

That stuff (description, dept, line manager, extension, office etc) is all very visible as soon as you sync to M365 and hover over a person or click on them.  Can't remember how much Google Workspace sync off the top of my head, but there are some optional synced attributes from AD you can turn on.

Posted

I believe many use the 'Pager' field in AD for storing ID Card numbers as well. We did when we first introduced ID cards as you could sync it directly to Papercut. However Office 365 shows this in 'Contact Information', so it had to be removed.

While it's not a direct password, once someone works out what the number is, it saves them scanning the physical card to make a copy of it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...