Jump to content

Recommended Posts

Posted

Our kids think it's hilarious to repeatedly attempt to log onto another kids account till it gets locked out. Now, i'm assuming this is a problem at other schools also, and i'm wondering what strategies others might have used to deal with this, as along with resetting passwords, it's a huge time drain.

 

Anyone car to share?

Posted

Make the number of failures a bit higher but not too high.

 

Also remove the username from the logon box so that they have more to type and can't just press enter to their hears content.

Posted

we clear last user at logon through GP, but in general it's done with malicious intent. I've thought about upping the number of failures a bit but they'll just sit and hit enter a few more times and we're back to square one...

 

it's a toughy

Posted

This has to be treated like vandalism. Which is another crime that can't be detected unless you use video cameras and such.

 

Also check logs if the same student is on computers near or logins after on computers where lockouts happen it may point to the culprit.

Posted
Yeah it's almost impossible to detect the culprit. Only ever caught one herbert, and that was only after following a lead (namely that he boasted repeatedly to his victim)
Posted

I'd turn off account lockout. You can always look at ways of recording failed login attempts centrally if you're worried about serious hacking attempts.

 

What happens when they start locking out staff accounts? Or your Head's account? No thanks!

Posted

@NetworkGeezer

I have considered supplementing the Axis cameras with Nerf sentryguns.

 

@sahmeepee

A good proportion of our users have passwords like "rabbit". It takes ~1 minute to unlock an account and up to 15 mins to restore deleted files from tapes. Assuming the user has noticed, and thus the tape isn't offsite.

 

What happens when they start locking out staff accounts? Or your Head's account? No thanks!

 

a) They're not _that_ stupid. :)

b) I'd rather they locked out a staff member than discovered the crap passwords some of our staff use.

c) If they did the larting process would be speeded up / supported, so it's a win-win.

 

Pete (who works with Ken)

Posted

We're getting the same problem

usernames are hidden, and lockout set to 5 invalid attempts (locks them out for 5 mins then resets the lock - i would have it longer but teachers decied to go over my head on the matter - as per usual!)

Did have "Password must meet complexity requirements" enabled but again teachers moaned too much about it.

 

So now im back to simple passwords, a lockout of 5 mins after 5 failures, and accounts being deliberately locked out again.

 

Not gonna enable "account cannot be locked" setting cos of malicious file deletion when i started.

Posted

@sahmeepee

A good proportion of our users have passwords like "rabbit". It takes ~1 minute to unlock an account and up to 15 mins to restore deleted files from tapes. Assuming the user has noticed, and thus the tape isn't offsite.

 

I guess you do what works with your network or, more to the point, with your users. For us it's not such a big problem, so we don't enforce a policy. With volume shadow copy /previous versions restoring deleted files is pretty easy.

 

I think 5 in 5 minutes is a good level to choose though: the time has to be short enough that it's not worth sending the pupil to the techies to get unlocked!

Posted

This isnt somthing we have run into but i think sahmapee is right. You have to make waiting for the time out to expire less of an inconvenience than asking for a manual reset. Introduce some 'identity checks' before resetting a password, the kind that take 10 minutes to complete.

If you want to use a big stick, enable Auditing of failed Account Logon events, this will give you a machine name so that it you're quick enough or have cctv, you can catch those responsible.

Posted
Do you want to try create 1500 unique usernames manually?

 

Just use a password generator for the username instead of the password - I can see it now...

 

"OK, your username is 44M2oP2@"(,ii2j# and your password is 'dog'."

Posted
RFID tags embedded in their hands.

If they want to steal each others accounts they'll have to nick a hand too :twisted:

 

No, we'll have Food Tech moan at us for people stealing their carving knives. :D

 

I've considered tokens of some kind (usb stick w/ certficate or signed key) but we don't allow USB drives, RSA hardware gets expensive _fast_ and biometric solutions are a sensitive issue and don't get reliable until you start spending $big_number.

 

Has anyone deployed a large scale authentication setup using iButtons? (Dallas semiconductor) I have one for a server room at $moonlighting_work. They're cheap (quid a go) and indestructable, but I've never really deployed it beyond a couple of solenoid locks at home.

Posted
At my old school we used a chip system that also tied in with a cashless dinner card system, the cards had the students picture and name on, we could then use this info when they wanted password changes. One thing we also did re password changes was to enable key trusted staff members the rights to change passwords in the students domain, this then became much easier for staff to manage as they didn't have to send pupils to us and loose them for the lesson! (of couse some still did!) If I can remember what the system was called i'll update the post!!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...