Jump to content

Recommended Posts

Posted

So I am having an issue with mail delivery (mail is going round in a loop and then rejected).

 

I log a call with the EMBC help desk who then ask for my login credentials to look into the problem.

 

Now, perhaps I am wrong, but should the synetrix staff need to have my credentials to fix a problem. Surely they can see whats going on right?

 

This doesn't seem right to me does it?

Posted

Perhaps the idea is to fix it, test it, sort out remaining issue and then get back to you when it is working, rather than keep you on the phone for x minutes / hours whilst things are tested (especially if it has to be bounced to second / third line). Remember that many of the schools they deal with directly can be primary and don't have the time to spend on the phone (or the wish to either).

 

Damn ... being reasonable and understanding again. I must go and take my medication!

Posted
Synetrix historically have always requested details to resolve issues; and whilst I think it's slightly edgy behaviour I do appreciate where they are coming from and changing my password isn't ever a big problem for me.
Posted
Are there not privacey issues involved with this? Im sure depending on who's email it is there could be alot of sensitive inforation.
Posted

Theoretically Sytnetrix (as with other RBCs) are a trusted supplier, the same way that you *can* access the pay information at your school but do not do so unless you are asked to support recovering data, sorting out access or configuring the program.

 

Basically, it is part of their job the same way that being an admin is part of yours.

Posted

Hmm I see you are saying, just seems bad practise to routinely request login details for your customers.

 

Thing is, the problem is sending any mail between the .leics.sch.uk addresses for any of my sites, I have sent the error message returned and the EMF log and I can't see what giving my details is going to add. Oh well.

Posted
the same way that you *can* access the pay information at your school but do not do so unless you are asked to support recovering data, sorting out access or configuring the program.

 

Heh, good point, hadn't thought of it like that.

Posted
Theoretically Sytnetrix (as with other RBCs) are a trusted supplier, the same way that you *can* access the pay information at your school but do not do so unless you are asked to support recovering data, sorting out access or configuring the program.

 

Basically, it is part of their job the same way that being an admin is part of yours.

 

Not quite, no support should request your actual password for any reason, pretty much ever. That's the reason why passwords are usually stored without reversible encryption.

 

I'm not saying that it doesn't happen, but it shouldn't.

Posted

@GrumbleDook:

Bankers are supposed to be trusted members of the public but look at what they have done to the country!

I would not give anyone my passwords upon pain of death!! trusted or not!

It is not the done thing.

If you ring the bank up to query why you cannot withdraw money from one of their cash machines they don't ask you for your pin number so they can try it do they. :-)

Posted
A question for people then ... do you ever tell users that you will have to reset their password to test something? Would people prefer that instead even though it would change access to other services (eg school admin tools, filter internet access, etc) for a short period of time?
Posted
A question for people then ... do you ever tell users that you will have to reset their password to test something?

 

Yes, reset their password - but only if entirely necessary. We never ask them to tell us their password.

Posted
Yes, reset their password - but only if entirely necessary. We never ask them to tell us their password.

 

Absolutely, plus if that ever happens its followed by instructing the user to alter their password again themselves.

Posted
Could you not just have a test account for such requests? If problems are occuring with all accounts then it doesn't matter which account they use. At least thats why I have always used staff and student test accounts so I dont have to ask students for their password or reset it to test something.
Posted
Could you not just have a test account for such requests? If problems are occuring with all accounts then it doesn't matter which account they use. At least thats why I have always used staff and student test accounts so I dont have to ask students for their password or reset it to test something.

 

We usually do. First, we reset the profile of a test account, change the group membership/user type to make it identical to the one that is having problems, and investigate. If we can't reproduce this problem we then look closer at the actual user and their own account. And as sparkeh says, getting them to change their password back again is always a must.

Posted
no support should request your actual password for any reason, pretty much ever. That's the reason why passwords are usually stored without reversible encryption.

I'm in complete agreement with DMcCoy on this one. No support staff should ever ask for a user's password.

 

There are plenty of good reasons why, but the most important one is that your average user uses the same password for most of their computer logins, work and personal (even if we encourage them not to, and I most certainly encourage them quite vigorously). It also fosters the notion in user's minds that divulging passwords is 'normal' and acceptable which makes them more vulnerable to social engineering tactics such as phishing.

 

I have to say it's rare that we need access to a users actual account to diagnose problems, but when we do we either have them log on for us, or (rarely) inform them that we will be changing their password temporarily and have them change it back afterwards by setting the 'user must change password at next logon' flag in the AD.

Posted

GrumbleDook Said ” A question for people then ... do you ever tell users that you will have to reset their password to test something?”

Very rarely and when I do I prefer to reset the password over knowing the real password. Most people use the same password for more than one thing so I do not want to know it.

 

Synetrix should gives us a choice or by default reset our master password to “1234” or something while they test. Then we can reset it back after.

EDIT: If you look at the gaming world and someone forgets the password or tech support needs it they generate a random secure password like 56sf73s.

Posted
Could you not just have a test account for such requests? If problems are occuring with all accounts then it doesn't matter which account they use. At least thats why I have always used staff and student test accounts so I dont have to ask students for their password or reset it to test something.

 

Some support requests are specific to an individual user / account. This ranges from email and filtering through to access to authenticated resources such as Expresso @ home. For these you *have* to test the user account in question.

 

Thanks for the feedback folks, I'll talk about it in our next LA meeting but one thing you could do in the meanwhile is if you are making a support call where testing will be needed then reset the password to a generic one and pass that on rather than the password the user usually uses. make sure you let the user know this though so it doesn't mess up other services (eg internet access!)

  • 10 months later...
Posted

I work for LA support and routinely have to ask users in schools for their passwords, this occurs mostly when I'm on a remote support link and it is going to take a long time to resolve the issue. I don't like doing it and feel somwhat embarrassed when I have to do so. However people don't like waiting around on the phone whilst I'm working on a time consuming problem.

 

It's all because default passwords are a big "no no" and in most cases if you don't have a password to access the affected system (mainly in order to test your changes work) then you simply can't help.

 

It all boils down to trust, in the OP's instance these people run your support service and as someone else has already said, if you aren't happy then change your password afterwards. Otherwise you have two options either live with the problem or fix it yourself.

Posted
I work for LA support and routinely have to ask users in schools for their passwords, this occurs mostly when I'm on a remote support link and it is going to take a long time to resolve the issue. I don't like doing it and feel somwhat embarrassed when I have to do so. However people don't like waiting around on the phone whilst I'm working on a time consuming problem.

 

It's all because default passwords are a big "no no" and in most cases if you don't have a password to access the affected system (mainly in order to test your changes work) then you simply can't help.

 

It all boils down to trust, in the OP's instance these people run your support service and as someone else has already said, if you aren't happy then change your password afterwards. Otherwise you have two options either live with the problem or fix it yourself.

 

Couldn't the LA just have some sort of policy where schools set up a couple of support user accounts (with different rights, eg, Student, Staff, Admin) and then have have the details added to a LA database or the likes so that people don't need ask for passwords for absolutely required.

 

This method also gives benefits such as:

* audit trail (Although Limited in Userfullness because it would be a shared account)

* Worse case (ef: if the LA needs access for example if the IT manager came down with a illness for extended period they could helpout)

Posted
As mentioned previously, some of the faults might be account specific and have to be tested on *that* account. Setting up generic accounts can deal with some issues ... and suppliers like Synetrix already have a raft of test accounts in test schools to see if things are broken. Having a test user for each role in each school doesn't add that much more to the diagnosis.
Posted

I still prefer the method of resetting a users password. I just think it covers everyone. I have been in the situation where I have been troubleshooting a teachers logon/account and told them I will have to have access to their account when they have voluntarily provided me with their password. Now they know I wont misuse this, but knowing that they use the same password for most of their online accounts I would rather not know in the first place.

 

I know it can make things easier, but resetting a password rather than asking for one just seems better practice to me.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...