Jump to content

Do you use SIMS Trusted Logins  

32 members have voted

  1. 1. Do you use SIMS Trusted Logins

    • Yes
      8
    • No - because of security concerns
      16
    • No - other reasons
      8


Recommended Posts

Posted

Hi Everyone,

 

I'm trying to put a case for using SIMS trusted logins (integrated with active directory). Can you please vote and reply with any useful security information both for and against.

 

Thanks

Posted

:eek: No, no, no, never, not even if I am instructed to do so under pain of unemployment.

 

Not moving to this until the staff understand the risks associated with students knowing their passwords.

Posted
:eek: No, no, no, never, not even if I am instructed to do so under pain of unemployment.

 

Not moving to this until the staff understand the risks associated with students knowing their passwords.

 

Wow strong response! But I can certainly understand if staff are sharing their passwords with students!!! Maybe you should use LART to get the message across.

Posted

Absolutely not :mad:

 

Teachers and Support staff will not carry the responsibility let alone accept it for the security of their user account even with an AUP in place.

 

They are just full of excuses as to why they are so irresponsible when it comes to IT security.

Posted
We don't use it here, simply because everyone already has a SIMS username and password, and we've had no reason to change yet. However, I will be bringing the subject up at some point, as I want to reduce the number of usernames as much as possible.
Posted

We use trusted logons here, but SIMS is only on office and staff room computers, so none which students have access to.

 

We used to have lots of paper-based records of parents' contact details, which for administrative (and other) reasons, we got rid of, meaning teachers had to use SIMS to get a phone number. Those who didn't use it very often could never remember their passwords and demanded the paper copies back, so as a compromise we switched to trusted logons.

 

If your students know staff passwords, then access to the MIS is far from your only concern, IMHO.

Posted

No - for other reasons.

 

I use it myself, however it's trusted not full trustedauto for the reason that for troubleshooting i like to be able to log in as other people, or if they come to see me i can get them logged in, without the hassle of me logging off the PC and them logging on.

 

Also, for whatever reason, due to lack of computers / laziness / speed, many of my users (especially admin/support/medical ..) share a logged in computer to use SIMS. For this reason, i could never have full trusted auto, and it is for this reason i have held back a full roll out.

 

I know, that if the log in screen changes to the Trusted version allowing single sign-on or username and password, i will end up with no end of support calls :eek: with confused users, despite the fact that the log in screen is self-explanatory and all they have to do is press OK to log in!!! I just know that a million people will ring me and ask what their username and password is.

 

I'm going to have to wait until i can get a whole school meeting or an INSET day to explain it!

 

What i don't really understand is why this debate always raises the same old issues over security and teachers not locking their workstations etc. etc. Can nobody see that if the teachers are logged in to SIMS when they walk off it's the same as if they have single-sign on or not. The issues are the same!!! :mad:

 

Every time our network policy causes a password change, i have the same set of wisened users saying they have forgotten their sims password so that i will reset it, allowing them to bring it into line with their new network password. Now there is a 'change password' option on log on, they wont even need to do that.

 

If staff are lax with one password, why not with two? I know it's no different here.

 

For me, the benefit of single sign-on and speed of access far outweighs any security risks that are ever present the minute you let users onto a computer!

 

When we get the SIMS learning gateway working, that will also be single sign-on as well, and carry with it similar security issues, but i'm not going to make people log in to use the intranet!

 

The only thing that i could really use is the ability for a user to retain their old sims username and password, as an alternative to the trusted authentication. Much like new laptops will accept a fingerprint or username / password combo. That would be the ideal for me. None of the other issues are relevant as far as i'm concerned.

  • Thanks 2
Posted
We don't use it here. Usernames and passwords are issued by the MIS manager and that's that. Have nothing more to do with SIMS, other than upgrades.
Posted

The only thing that i could really use is the ability for a user to retain their old sims username and password, as an alternative to the trusted authentication. Much like new laptops will accept a fingerprint or username / password combo. That would be the ideal for me.

You can set it that way, he have here. All teaching and admin staff have trusted logons, mine is set on a username and password still. This means that they can open SIMS, realise they can't do something, call me and I can log in to SIMS and do whatever the task is without having to log out of the whole computer (which can take a while depending on what else is open at the time). It also means that I can get at SIMS from whichever of my 3 logons I'm using at that moment.

 

In the System Manager, where you associate a SIMS account to a domain account, you just enter a username and password instead. Simple as.

Posted

If your students know staff passwords, then access to the MIS is far from your only concern, IMHO.

 

Tell me about it :(

Posted

Cheers Nick, i knew that already. What i want is both options at once for a single user, but that is just an ideal.

 

What i have at the moment is myself with trusted authentication and everyone else with a username/password combo. I have set my own connect.ini to have trusted authentication, whilst everyone else uses a central one on the SIMS server. So on my workstation i have ease of use, and the option to log in as another user.

 

If i am doing remote support i have another SIMS account, my predecessor's actually, that i use to do any other tasks whilst someone else is logged in.

 

What for me would be handy is if once everyone has trusted authentication, some users could still have the option of using a username and password or trusted authentication. e.g. in the clinic we have 3 staff plus me when i visit to help out (with the computers not administering first aid!), but only 2 PCs. It's pretty important for us that whoever logs medical events and notes is logged into SIMS for tracking purposes.

 

Yes it would be possible to just leave all of those users on username/password, i'd just like a cleaner solution, without having to create extra accounts for them as i have done for myself. If you look at our list of marksheets, it looks like the old SIMS guy is still setting up and managing the reporting system as i quite often work on another computer or do cloning elsewhere and it leaves his name on all the files!

 

I believe that with trustedauto in the connect.ini if the user isn't set up to have single sign-on then after a while it prompts for a username and password anyway. I'd prefer it to be quicker and am just looking for an ideal, which is probably only relevant for me and my school, and not something that would be important for Capita to work on.

 

Regardless of that minor issue for me, i favour trusted authentication all the way, as soon as possible. The less obstacles there are and fewer clicks for the user the better it is for all of us.

Posted

For classroom teachers (limited access) and admin staff (secure, well-monitored environment) we do use it. For system manager level access I don't, but that's largely because I don't want SIMS credentials associated with the account I use for upgrades and troubleshooting.

 

We force a 15 minute screen lock on registration thin clients (we use PARS) - the session is locked and the terminal disconnects the session.

 

Two rubbish passwords aren't more secure than one rubbish password, especially when (if you can't ensure they're different) those passwords are likely to be the same. One good password is better, assuming you can drum that into your staff. Rubbish passwords/not logging off are a human/HR/management problem, not a technical one.

Posted

This is my personal opinion and interpretation of the data handling guidance (and open to debate) but this would immediately fall foul of the guidance. A single username and password which would allow access to sensitive and protected information about students including SEN, child protection issues (children in care, etc) and possibly staff personal details too depending on the roles in SIMS of various staff logging into the machine.

 

If held upside down in a barrel of burning oil I would resist but should you not be the SIRO and have raised the concern and alarm with all the relevant people subsequently issued with the decree from manglement of 'Do it or else!" (and the union not backing your stance) then password protected screensaver set to 3 minutes is a minimum, strict policies that it is not to be running whilst connected to a data projector, a blanket ban on students using staff machines (logged in on a student account or staff 'just letting them on for a minute!') and making it a disciplinary offence for sharing your password with a student.

 

Even then I would not do it for certain SIMS roles (anyone with system manager access, full SEN access, any member of senior manglement, exams roles, attendance officer or admin assistant)!

 

And after you have done all of this, turn all the computers and servers off to make it all secure again.

 

I cannot stress how ill thought out I believe this to be and would welcome a response from Phil on Capita's position on what guidance they give, to schools who go down this route, to ensure the security of data and information is maintained.

Posted

We changed to the Trusted logons when we reinstalled or reattached or upgraded (I dunno it was the previous SIMS manager) something went wrong and it lost all the user passwords. At the time it was decided that it was easier to link them to the AD users then retype the passwords, expecially as SIMS made them all those stupid XKCDWVZXSJ type passwords.

We don't have trustedAuto, cause we found some users (using Nova T4/Cover x) needed to be able to logon differently and SIMS .net couldn't cope.

 

But at least I've managed to do away with the XLS file with all the usernames and passwords, which I was given when the SIMS manager left.

Posted (edited)

@Bossman: "They are just full of excuses as to why they are so irresponsible when it comes to IT security."

 

Sadly he's right - it is our job to fix this.

 

---------------------

 

@Nick Ross: "If your students know staff passwords, then access to the MIS is far from your only concern, IMHO."

 

True, but it is probably the biggest (or near biggest) concern. Afterall the MIS is where the schools most wothwhile, useable, and most sensitive data exists. Especially if they are a (wait for it...) "Power Teacher".

 

--------------------

 

The whole "No - For other Reasons" connundrum:

 

I totally agree with VikPaw:

 

"Also, for whatever reason, due to lack of computers / laziness / speed, many of my users (especially admin/support/medical ..) share a logged in computer to use SIMS. For this reason, i could never have full trusted auto, and it is for this reason i have held back a full roll out."

 

 

I myself feel that to troubleshoot issues non integrated logins help you. Sometimes a SIMS or FMS problem exists due to an issue with a Windows user profile. Non trusted logins helps you understand and resolve this issue when it occurs.

 

---------------------

 

@dyoung5: "I'm trying to put a case for using SIMS trusted logins (integrated with active directory). Can you please vote and reply with any useful security information both for and against."

 

 

I voted "no - for security reasons" I'd love to see integrated logins in action but I think it is too dangrous to use throughout a school as a whole.

 

Example:

 

Who cares if a random teacher with low, low access to MIS leaves their PC unguarded and the class gets in, they can't do anything or see that much (until they learn how to find a marksheet).

 

However, if an SLT does the same then all of a sudden the class who get to look at the data can see (and edit) pretty much whatever they like.

 

What I'd really like to see in a 2ndry is a decision whereby the office has integrated logins but not the teachers, (is/how easy is, this to implement)??

 

---------------------

 

@User3204: "expecially as SIMS made them all those stupid XKCDWVZXSJ type passwords."

 

Surely you mean "secure" passwords??

 

---------------------

 

 

!!!Christ I sound like I work for Capita - scurries away with hand over back of head...

 

My 2p

Edited by superfletch
Crap grammar
Posted

@Grumbledook et al - I take your points over the guidelines, security etc. etc. I just have to reiterate one point:

 

Whoever the user, whatever their level of power, however security conscious they are and however much we beat them for doing things wrong, imagine this scenario. They walk into a classroom, log into a PC, and need to do the register because we use Lesson Monitor, so they log into SIMS, using a different username and different password to the regular network one. Now the lesson starts and they don't log out of SIMS, because they will use it to review marks, check photos, add achievements or behaviour, access their lesson plans (We just bought CLP!)...... We are still in an insecure environment trusting the teacher and whatever settings they have for locking the machine, either enforced by policy or not.

 

If they logged into SIMS securely, used it and logged out every time, fine. In a 40 minute lesson that isn't going to happen! In fact in any length of lesson, the more SIMS is used, it just isn't going to happen. So, be it Mr. Lowly Teacher user, or Mrs. Senior Manglement Phd. in a classroom environment they need to have SIMS open and will use it throughout. Making them log in an extra time doesn't achieve anything in my opinion except annoy them.

 

We are trying to solve the wrong problem. We don't need to add obstacles to the workflow to increase security, we need to alter the bad practises that these people use. Regardless of whether SIMS is open or not, the workstation should be secured, students shouldn't have access. Most kids probably couldn't be bothered with mucking around with SIMS (with that interface - would you?), there's much more fun to be had, reading and sending emails, accessing shared areas, detention reports, meeting notes, and other confidential material, triggering the internet filters. . . . .

Posted

@Nick Ross: "If your students know staff passwords, then access to the MIS is far from your only concern, IMHO."

 

True, but it is probably the biggest (or near biggest) concern. Afterall the MIS is where the schools most wothwhile, useable, and most sensitive data exists. Especially if they are a (wait for it...) "Power Teacher".

 

I assume you mean me when you say Nick Ross :-) I think that in part depends on how much information you keep in your MIS. Ours, for example, doesn't contain much beyond names and addresses; attendance, assessment, reports, SEN/AEN, behaviour and other such "juicy" things are handled elsewhere, so in this school, pupils accessing the Staff Docs shared area is a greater concern than them seeing SIMS.

Posted
We don't have trustedAuto, cause we found some users (using Nova T4/Cover x) needed to be able to logon differently and SIMS .net couldn't cope.

 

Possibly too late to offer you assistance on T4 now, but we found it to be because T4 cannot handle usernames longer than 8 characters, which some network IDs are. When we went to trusted logons, we offered affected users the choice between logging in twice or changing their network ID.

Posted
This is my personal opinion and interpretation of the data handling guidance (and open to debate) but this would immediately fall foul of the guidance. A single username and password which would allow access to sensitive and protected information about students including SEN, child protection issues (children in care, etc) and possibly staff personal details too depending on the roles in SIMS of various staff logging into the machine.

 

If held upside down in a barrel of burning oil I would resist but should you not be the SIRO and have raised the concern and alarm with all the relevant people subsequently issued with the decree from manglement of 'Do it or else!" (and the union not backing your stance) then password protected screensaver set to 3 minutes is a minimum, strict policies that it is not to be running whilst connected to a data projector, a blanket ban on students using staff machines (logged in on a student account or staff 'just letting them on for a minute!') and making it a disciplinary offence for sharing your password with a student.

 

Even then I would not do it for certain SIMS roles (anyone with system manager access, full SEN access, any member of senior manglement, exams roles, attendance officer or admin assistant)!

 

And after you have done all of this, turn all the computers and servers off to make it all secure again.

 

I cannot stress how ill thought out I believe this to be and would welcome a response from Phil on Capita's position on what guidance they give, to schools who go down this route, to ensure the security of data and information is maintained.

 

I disagree. The guidance doesn't require, or request separate sources of information be password protected separately. And on a practical level, doing so doesn't add any extra security. All the guidance says is that access to the various levels of information should come with greater security as it increases sensitivity.

 

Adding an extra level of login actually, in my opinion, just makes it less secure. I think nearly every user of SIMS.net in this school writes it down in their planner or somewhere like that. There is no way this is ever going to stop, teachers have enough to remember as it is.

 

As someone else said, 1 secure password is better than 2 insecure ones (or in many schools cases, 3,4 or 5 insecure passwords).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...