Jump to content

Recommended Posts

Posted

It looks like CLEO have made all their moodle users do a forced password change :(

 

I am asking Westfield to check this out for non-admin users but I was made to change my password on 2 sites that i've checked and 1 ICT co-ord has told me that he had to change his.

 

Will let you know whether its true or not.

 

(I had an emails last week saying password security had been upgraded but I don't remember any mention of forced changes :()

 

 

regards

 

Simon

Posted

The last update of Moodle added in password complexity rules which can be disabled in the administration --> site policies area.

 

Looks as if they've left this on which will default flag all users as being forced to change their password.

 

Quick SQL statement on the DB can fix this though so I'd get on to them before everyone wonders why they are having to change passwords :D

Posted
Looks as if they've left this on which will default flag all users as being forced to change their password.

 

That doesn't seem to be it - Password Policy is unticked (and default is No)

 

regards

 

Simon

Posted

Hi,

 

It looks like CLEO have made all their moodle users do a forced password change :(

 

Only administrators are being forced to do this, this is a precautionary measure introduced by Moodle core in Moodle 1.9.7. See Moodle release notes.

 

Please note that we did not take the decision to leave this password change step in the upgrade lightly and decided to keep it in the Moodle upgrade for CLEO to ensure that administrators passwords are forced to be salted. We implemented password salting in the CLEO moodle instance some time ago, but recently there have been a number of public discussions of how to take an unsalted password hash and use a lookup table to reverse this. It seemed prudent that we take our best efforts to ensure old adminsitrator accounts in CLEO had their passwords salted to avoid this being exploited.

 

The last update of Moodle added in password complexity rules which can be disabled in the administration --> site policies area.

 

We disabled this part of the CLEO upgrade as the cost of applying this across all 230,000 users in CLEO did not seem to outweigh the benefits, though we would still strongly recommend that Moodle administrators choose to turn this option on we felt it better to leave this up schools.

 

cheers,

 

Dan Poltawski

(CLEO Moodle Tech Lead)

 

Ps. you might be interested in the official CLEO Moodle User Group http://vle.cleo.net.uk - you can get acccess by contacting the CLEO Office.

  • Thanks 1
Posted
Another reason not to use LEA services and to do it yourself....

The CLEO Moodle is run exceptionally well, I have seen far worse LEA VLE systems, and agree with what they have done. Fine I am no longer in a CLEO school so don't see the comms from them but a quick email to the schools warning wouldn't go a miss but the CLEO Moodle is not bad at all.

Posted
Another reason not to use LEA services and to do it yourself....

So they updated and removed a security risk (using non salted passwords on admin accounts, which can be cracked quite easy...) and are forcing said users to update their passwords (could be the same one, it would just salt it) and that is a issue how?

 

It's no different than updating a server to stop malicious hack X or Y.

Posted
So they updated and removed a security risk (using non salted passwords on admin accounts, which can be cracked quite easy...) and are forcing said users to update their passwords (could be the same one, it would just salt it) and that is a issue how?

 

It's no different than updating a server to stop malicious hack X or Y.

 

I am not saying what they did is a bad thing. But its better to have control of your own setup and for you to decide what happens.

 

I think its good that i has been kicked in

Posted

As others have said - a little note would have been handy - I was sent emails about the upgrade - but no hint about the need for password changes :(

 

The main effect is that we are encouraged to set all teachers/tas as admins (so everyone has the same screen layout during training sessions :) ) so it effects all of them as well :(

 

So they'll either end up changing their passwords to something very simple (or use the same one as their internet banking one :eek:)

 

regards

 

Simon

Posted (edited)

we are encouraged to set all teachers/tas as admins (quote)

Who encourages that?

I know you deal in primaries so there are fewer teachers in the schools but nonetheless....

:eek:

Also - on the CLEO moodle forums Dan Poltawski mentioned it did actually say (quote again)

 

One key feature is that anyone who holds an administrator account on your school Moodle will be promted to change their password the first time they log in after the upgrade. so we were warned.

 

I understand your feelings about it being better to run your own install FN_GM - it is frustrating at times when you want to do additional stuff and can't -but on the other hand I very much appreciate having someone else carry the load of doing the upgrades/security patches etc. I think CLEO are doing a very good job. (no I don't work for them; I teach children(some of whom are adults!)

Edited by secretlife
Posted
As others have said - a little note would have been handy - I was sent emails about the upgrade - but no hint about the need for password changes :(

 

Good criticism, I agree and it was entirely my fault for not ensuring that this happened with the upgrade notifications.

 

Also - on the CLEO moodle forums Dan Poltawski mentioned it did actually say (quote again)

 

One key feature is that anyone who holds an administrator account on your school Moodle will be promted to change their password the first time they log in after the upgrade. so we were warned.

 

Actually secretlife, I think that was posted after the upgrade had happened (or while in process) and not before.

 

 

So they'll either end up changing their passwords to something very simple (or use the same one as their internet banking one :eek:)

 

You could switch on the password policy to prevent that. Obviously i'd like to see that go hand in hand with user education about using strong passwords. An unenviable task, but i'd rather see that than student details being compromised or a schools' reputation being discredited due to adult related spam....

 

 

I am not saying what they did is a bad thing. But its better to have control of your own setup and for you to decide what happens.

 

Better for you, but certainly not all schools. If I were a school tech I expect i'd like to run my own moodle system and have control much like you - as i've got the skills to do it. But that might not be the best thing for my school long term (what happens when I leave, can I train and support it, do I have the funds to find the infrastructure to ensure it works all the time?).

 

 

In CLEO we're not perfect (who is?), but I personally believe passionately that we offer a good service which makes efficient use of taxpayer funding. Instead of spending a load of money on licensing costs, money has been used to fund:

  • Massive training programmes for teachers and staff (and whats the point of having it if the teachers dont use it)
  • Massive investment into hardware and infrastructure to ensure its highly available
  • Support structures to ensure we find and fix faults, you can call someone if it breaks

 

We've also been able to make significant contributions to the Moodle project which benefit all schools around the world and made customisations for schools to make it fit more for the environment. Hopefully this will continue to a greater and greater extent as the years go by. We are able to do this as we have dedicated expertise due to the scale of the CLEO offering. This also helps us be able to influence the direction of Moodle.

 

(sorry, i'll stop selling it now - I truly do believe in it which is why I enjoy working on the project).

Posted

(sorry, i'll stop selling it now - I truly do believe in it which is why I enjoy working on the project).

 

No need to apologise, some of us would be very grateful to have this passion and support available to us............

Posted

(sorry, i'll stop selling it now - I truly do believe in it which is why I enjoy working on the project).

Feel free to come sell me CLEO but you will have to step over the border into Yorkshire I'm afraid, I really do miss CLEO :(

Posted

Just as an aside - (and while I've got direct attention of someone who can do rather than go through my friends in Leyland :) ) - I had to go through a school and globally delete all pupils and re-add them.

 

I found I could only delete them in batches of 5 otherwise it didn't work (and sometimes even that failed and would only delete 4)

 

For ref it was middleforth.lancs.sch.uk

 

regards

 

Simon

Posted
we are encouraged to set all teachers/tas as admins

 

Who encourages that?

 

Teachers :p

 

(The Lancs primary teacher advisors actually :) )

 

regards

 

Simon

Posted
You could switch on the password policy to prevent that. Obviously i'd like to see that go hand in hand with user education about using strong passwords.

 

In primaries, we require simple passwords for the pupils so unless Moodle is modified to handle different complexites for students we can't switch it on :(

 

regards

 

Simon

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...