sparkeh Posted April 2, 2009 Posted April 2, 2009 So I am having an issue with mail delivery (mail is going round in a loop and then rejected). I log a call with the EMBC help desk who then ask for my login credentials to look into the problem. Now, perhaps I am wrong, but should the synetrix staff need to have my credentials to fix a problem. Surely they can see whats going on right? This doesn't seem right to me does it?
GrumbleDook Posted April 2, 2009 Posted April 2, 2009 Perhaps the idea is to fix it, test it, sort out remaining issue and then get back to you when it is working, rather than keep you on the phone for x minutes / hours whilst things are tested (especially if it has to be bounced to second / third line). Remember that many of the schools they deal with directly can be primary and don't have the time to spend on the phone (or the wish to either). Damn ... being reasonable and understanding again. I must go and take my medication!
kmount Posted April 2, 2009 Posted April 2, 2009 Synetrix historically have always requested details to resolve issues; and whilst I think it's slightly edgy behaviour I do appreciate where they are coming from and changing my password isn't ever a big problem for me.
CHR1S Posted April 2, 2009 Posted April 2, 2009 Are there not privacey issues involved with this? Im sure depending on who's email it is there could be alot of sensitive inforation.
GrumbleDook Posted April 2, 2009 Posted April 2, 2009 Theoretically Sytnetrix (as with other RBCs) are a trusted supplier, the same way that you *can* access the pay information at your school but do not do so unless you are asked to support recovering data, sorting out access or configuring the program. Basically, it is part of their job the same way that being an admin is part of yours.
sparkeh Posted April 2, 2009 Author Posted April 2, 2009 Hmm I see you are saying, just seems bad practise to routinely request login details for your customers. Thing is, the problem is sending any mail between the .leics.sch.uk addresses for any of my sites, I have sent the error message returned and the EMF log and I can't see what giving my details is going to add. Oh well.
sparkeh Posted April 2, 2009 Author Posted April 2, 2009 the same way that you *can* access the pay information at your school but do not do so unless you are asked to support recovering data, sorting out access or configuring the program. Heh, good point, hadn't thought of it like that.
DMcCoy Posted April 2, 2009 Posted April 2, 2009 Theoretically Sytnetrix (as with other RBCs) are a trusted supplier, the same way that you *can* access the pay information at your school but do not do so unless you are asked to support recovering data, sorting out access or configuring the program. Basically, it is part of their job the same way that being an admin is part of yours. Not quite, no support should request your actual password for any reason, pretty much ever. That's the reason why passwords are usually stored without reversible encryption. I'm not saying that it doesn't happen, but it shouldn't.
bossman Posted April 2, 2009 Posted April 2, 2009 @GrumbleDook: Bankers are supposed to be trusted members of the public but look at what they have done to the country! I would not give anyone my passwords upon pain of death!! trusted or not! It is not the done thing. If you ring the bank up to query why you cannot withdraw money from one of their cash machines they don't ask you for your pin number so they can try it do they. :-)
GrumbleDook Posted April 2, 2009 Posted April 2, 2009 A question for people then ... do you ever tell users that you will have to reset their password to test something? Would people prefer that instead even though it would change access to other services (eg school admin tools, filter internet access, etc) for a short period of time?
webman Posted April 2, 2009 Posted April 2, 2009 A question for people then ... do you ever tell users that you will have to reset their password to test something? Yes, reset their password - but only if entirely necessary. We never ask them to tell us their password.
sparkeh Posted April 3, 2009 Author Posted April 3, 2009 Yes, reset their password - but only if entirely necessary. We never ask them to tell us their password. Absolutely, plus if that ever happens its followed by instructing the user to alter their password again themselves.
penfold Posted April 3, 2009 Posted April 3, 2009 Could you not just have a test account for such requests? If problems are occuring with all accounts then it doesn't matter which account they use. At least thats why I have always used staff and student test accounts so I dont have to ask students for their password or reset it to test something.
webman Posted April 3, 2009 Posted April 3, 2009 Could you not just have a test account for such requests? If problems are occuring with all accounts then it doesn't matter which account they use. At least thats why I have always used staff and student test accounts so I dont have to ask students for their password or reset it to test something. We usually do. First, we reset the profile of a test account, change the group membership/user type to make it identical to the one that is having problems, and investigate. If we can't reproduce this problem we then look closer at the actual user and their own account. And as sparkeh says, getting them to change their password back again is always a must.
AngryTechnician Posted April 3, 2009 Posted April 3, 2009 no support should request your actual password for any reason, pretty much ever. That's the reason why passwords are usually stored without reversible encryption. I'm in complete agreement with DMcCoy on this one. No support staff should ever ask for a user's password. There are plenty of good reasons why, but the most important one is that your average user uses the same password for most of their computer logins, work and personal (even if we encourage them not to, and I most certainly encourage them quite vigorously). It also fosters the notion in user's minds that divulging passwords is 'normal' and acceptable which makes them more vulnerable to social engineering tactics such as phishing. I have to say it's rare that we need access to a users actual account to diagnose problems, but when we do we either have them log on for us, or (rarely) inform them that we will be changing their password temporarily and have them change it back afterwards by setting the 'user must change password at next logon' flag in the AD.
Pottsey Posted April 3, 2009 Posted April 3, 2009 GrumbleDook Said ” A question for people then ... do you ever tell users that you will have to reset their password to test something?” Very rarely and when I do I prefer to reset the password over knowing the real password. Most people use the same password for more than one thing so I do not want to know it. Synetrix should gives us a choice or by default reset our master password to “1234” or something while they test. Then we can reset it back after. EDIT: If you look at the gaming world and someone forgets the password or tech support needs it they generate a random secure password like 56sf73s.
GrumbleDook Posted April 3, 2009 Posted April 3, 2009 Could you not just have a test account for such requests? If problems are occuring with all accounts then it doesn't matter which account they use. At least thats why I have always used staff and student test accounts so I dont have to ask students for their password or reset it to test something. Some support requests are specific to an individual user / account. This ranges from email and filtering through to access to authenticated resources such as Expresso @ home. For these you *have* to test the user account in question. Thanks for the feedback folks, I'll talk about it in our next LA meeting but one thing you could do in the meanwhile is if you are making a support call where testing will be needed then reset the password to a generic one and pass that on rather than the password the user usually uses. make sure you let the user know this though so it doesn't mess up other services (eg internet access!)
superfletch Posted February 27, 2010 Posted February 27, 2010 I work for LA support and routinely have to ask users in schools for their passwords, this occurs mostly when I'm on a remote support link and it is going to take a long time to resolve the issue. I don't like doing it and feel somwhat embarrassed when I have to do so. However people don't like waiting around on the phone whilst I'm working on a time consuming problem. It's all because default passwords are a big "no no" and in most cases if you don't have a password to access the affected system (mainly in order to test your changes work) then you simply can't help. It all boils down to trust, in the OP's instance these people run your support service and as someone else has already said, if you aren't happy then change your password afterwards. Otherwise you have two options either live with the problem or fix it yourself.
p858snake Posted February 27, 2010 Posted February 27, 2010 I work for LA support and routinely have to ask users in schools for their passwords, this occurs mostly when I'm on a remote support link and it is going to take a long time to resolve the issue. I don't like doing it and feel somwhat embarrassed when I have to do so. However people don't like waiting around on the phone whilst I'm working on a time consuming problem. It's all because default passwords are a big "no no" and in most cases if you don't have a password to access the affected system (mainly in order to test your changes work) then you simply can't help. It all boils down to trust, in the OP's instance these people run your support service and as someone else has already said, if you aren't happy then change your password afterwards. Otherwise you have two options either live with the problem or fix it yourself. Couldn't the LA just have some sort of policy where schools set up a couple of support user accounts (with different rights, eg, Student, Staff, Admin) and then have have the details added to a LA database or the likes so that people don't need ask for passwords for absolutely required. This method also gives benefits such as: * audit trail (Although Limited in Userfullness because it would be a shared account) * Worse case (ef: if the LA needs access for example if the IT manager came down with a illness for extended period they could helpout)
GrumbleDook Posted February 27, 2010 Posted February 27, 2010 As mentioned previously, some of the faults might be account specific and have to be tested on *that* account. Setting up generic accounts can deal with some issues ... and suppliers like Synetrix already have a raft of test accounts in test schools to see if things are broken. Having a test user for each role in each school doesn't add that much more to the diagnosis.
penfold Posted March 1, 2010 Posted March 1, 2010 I still prefer the method of resetting a users password. I just think it covers everyone. I have been in the situation where I have been troubleshooting a teachers logon/account and told them I will have to have access to their account when they have voluntarily provided me with their password. Now they know I wont misuse this, but knowing that they use the same password for most of their online accounts I would rather not know in the first place. I know it can make things easier, but resetting a password rather than asking for one just seems better practice to me.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now