ken_kaniff Posted May 17, 2006 Posted May 17, 2006 Our kids think it's hilarious to repeatedly attempt to log onto another kids account till it gets locked out. Now, i'm assuming this is a problem at other schools also, and i'm wondering what strategies others might have used to deal with this, as along with resetting passwords, it's a huge time drain. Anyone car to share?
Norphy Posted May 17, 2006 Posted May 17, 2006 We just changed the lockout policy for our Student domain so that didn't happen.
NetworkGeezer Posted May 17, 2006 Posted May 17, 2006 Make the number of failures a bit higher but not too high. Also remove the username from the logon box so that they have more to type and can't just press enter to their hears content.
ken_kaniff Posted May 17, 2006 Author Posted May 17, 2006 we clear last user at logon through GP, but in general it's done with malicious intent. I've thought about upping the number of failures a bit but they'll just sit and hit enter a few more times and we're back to square one... it's a toughy
webman Posted May 17, 2006 Posted May 17, 2006 When you catch them, send them through the school's punishment system for misuse of the networked computers.
NetworkGeezer Posted May 17, 2006 Posted May 17, 2006 This has to be treated like vandalism. Which is another crime that can't be detected unless you use video cameras and such. Also check logs if the same student is on computers near or logins after on computers where lockouts happen it may point to the culprit.
ken_kaniff Posted May 17, 2006 Author Posted May 17, 2006 Yeah it's almost impossible to detect the culprit. Only ever caught one herbert, and that was only after following a lead (namely that he boasted repeatedly to his victim)
NetworkGeezer Posted May 17, 2006 Posted May 17, 2006 I think there's nothing for it. The computer should be rigged to trigger the release of an electric shock upon lock-out That'll learn 'em 8O
sahmeepee Posted May 17, 2006 Posted May 17, 2006 I'd turn off account lockout. You can always look at ways of recording failed login attempts centrally if you're worried about serious hacking attempts. What happens when they start locking out staff accounts? Or your Head's account? No thanks!
pete Posted May 17, 2006 Posted May 17, 2006 @NetworkGeezer I have considered supplementing the Axis cameras with Nerf sentryguns. @sahmeepee A good proportion of our users have passwords like "rabbit". It takes ~1 minute to unlock an account and up to 15 mins to restore deleted files from tapes. Assuming the user has noticed, and thus the tape isn't offsite. What happens when they start locking out staff accounts? Or your Head's account? No thanks! a) They're not _that_ stupid. b) I'd rather they locked out a staff member than discovered the crap passwords some of our staff use. c) If they did the larting process would be speeded up / supported, so it's a win-win. Pete (who works with Ken)
Gatt Posted May 18, 2006 Posted May 18, 2006 We're getting the same problem usernames are hidden, and lockout set to 5 invalid attempts (locks them out for 5 mins then resets the lock - i would have it longer but teachers decied to go over my head on the matter - as per usual!) Did have "Password must meet complexity requirements" enabled but again teachers moaned too much about it. So now im back to simple passwords, a lockout of 5 mins after 5 failures, and accounts being deliberately locked out again. Not gonna enable "account cannot be locked" setting cos of malicious file deletion when i started.
sahmeepee Posted May 18, 2006 Posted May 18, 2006 @sahmeepee A good proportion of our users have passwords like "rabbit". It takes ~1 minute to unlock an account and up to 15 mins to restore deleted files from tapes. Assuming the user has noticed, and thus the tape isn't offsite. I guess you do what works with your network or, more to the point, with your users. For us it's not such a big problem, so we don't enforce a policy. With volume shadow copy /previous versions restoring deleted files is pretty easy. I think 5 in 5 minutes is a good level to choose though: the time has to be short enough that it's not worth sending the pupil to the techies to get unlocked!
_Bob_ Posted May 18, 2006 Posted May 18, 2006 This isnt somthing we have run into but i think sahmapee is right. You have to make waiting for the time out to expire less of an inconvenience than asking for a manual reset. Introduce some 'identity checks' before resetting a password, the kind that take 10 minutes to complete. If you want to use a big stick, enable Auditing of failed Account Logon events, this will give you a machine name so that it you're quick enough or have cctv, you can catch those responsible.
ajbritton Posted May 18, 2006 Posted May 18, 2006 What about giving them usernames which cannot easily be guessed?
NetworkGeezer Posted May 18, 2006 Posted May 18, 2006 Do you want to try create 1500 unique usernames manually? Also if maclicous intent is involved, the perp can just stalk their victim, nab the username and then attack.
OutToLunch Posted May 18, 2006 Posted May 18, 2006 Do you want to try create 1500 unique usernames manually? Just use a password generator for the username instead of the password - I can see it now... "OK, your username is 44M2oP2@"(,ii2j# and your password is 'dog'."
ajbritton Posted May 18, 2006 Posted May 18, 2006 all right, all right !! Not the most popular idea ever expressed!! What some form of hardware access token?
webman Posted May 18, 2006 Posted May 18, 2006 Now we're getting into the realms of biometrics; finger prints and retina scans
Irazmus Posted May 18, 2006 Posted May 18, 2006 RFID tags embedded in their hands. If they want to steal each others accounts they'll have to nick a hand too :twisted:
pete Posted May 18, 2006 Posted May 18, 2006 RFID tags embedded in their hands. If they want to steal each others accounts they'll have to nick a hand too :twisted: No, we'll have Food Tech moan at us for people stealing their carving knives. I've considered tokens of some kind (usb stick w/ certficate or signed key) but we don't allow USB drives, RSA hardware gets expensive _fast_ and biometric solutions are a sensitive issue and don't get reliable until you start spending $big_number. Has anyone deployed a large scale authentication setup using iButtons? (Dallas semiconductor) I have one for a server room at $moonlighting_work. They're cheap (quid a go) and indestructable, but I've never really deployed it beyond a couple of solenoid locks at home.
buzzard Posted May 18, 2006 Posted May 18, 2006 At my old school we used a chip system that also tied in with a cashless dinner card system, the cards had the students picture and name on, we could then use this info when they wanted password changes. One thing we also did re password changes was to enable key trusted staff members the rights to change passwords in the students domain, this then became much easier for staff to manage as they didn't have to send pupils to us and loose them for the lesson! (of couse some still did!) If I can remember what the system was called i'll update the post!!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now