MACIT Posted June 26, 2012 Posted June 26, 2012 We have this morning noticed (although i suspect this has been the case for while) that all sims passwords are no longer case sensitive!! Is anyone else aware of this I asume its not local to us We are on 7.144 Regards Neil
Iain.Faulkner Posted June 26, 2012 Posted June 26, 2012 I can't ever remember them being case sensitive! Same here
laserblazer Posted June 26, 2012 Posted June 26, 2012 I just tried ours (7.144) and it's not case sensitive. I always assumed it was, @Sivadam could well be right.
Rawns Posted June 26, 2012 Posted June 26, 2012 SIMS .net and FMS are not case sensitive for passwords.
Sivadam Posted June 26, 2012 Posted June 26, 2012 I just tried ours (7.144) and it's not case sensitive. I always assumed it was, @Sivadam could well be right. He usually is ............!!!!
vikpaw Posted June 26, 2012 Posted June 26, 2012 Never been case sensitive. It's the first thing people ask when you've reset it to NKAJFUWEIA and i always say, just type it in.
MACIT Posted June 26, 2012 Author Posted June 26, 2012 Well I've learnt something new today! To be honest though considering the massive amount of highly confidential data Sims holds i believe this to be wholly indadequate and Capita should sort it out and quick!
pete Posted June 26, 2012 Posted June 26, 2012 When I started here, everyone assumed passwords weren't case sensitive. It wasn't until I first poked into SIMS that I found the culprit.
matt40k Posted June 26, 2012 Posted June 26, 2012 To be honest though considering the massive amount of highly confidential data Sims holds i believe this to be wholly indadequate and Capita should sort it out and quick! It's called Trusted logins.
Edu-IT Posted June 26, 2012 Posted June 26, 2012 It's called Trusted logins. Isn't two factor security (system logon and SIMS logon) more secure though? At least if you can't enforce SIMS security, you can enforce system security.
vikpaw Posted June 26, 2012 Posted June 26, 2012 It's not really two factor though is it, it's two - step, and usually they will make the two passwords match! At least with trusted, you can force it to be complex just in case they do decide that 1234 is a suitable sims password. I'd like to see some kind of physical device required like banks use, so when the system is open to the world via portals, there is an extra layer of security.
matt40k Posted June 26, 2012 Posted June 26, 2012 Isn't two factor security (system logon and SIMS logon) more secure though? At least if you can't enforce SIMS security, you can enforce system security. Nope, like vikpaw says, it isn't two-factor. Plus they normally don't change it, give it a pupil so they can mark the register, have it written on the laptop or on a piece of paper in the laptop bag. SIMS SQL logins has been done really well by Capita, but it's a false sense of security, at least from the point of view of SIMS in the classroom. Think of it like this, when you open Outlook, do you put a password in? No, what about when you go into the staff shared area? No. Well both hold sensitive data. Best thing is to teach staff "Windows + L", it takes seconds so they're is no excuse. They're professional, they're expected to follow the security rules.
matt40k Posted June 26, 2012 Posted June 26, 2012 I'd like to see some kind of physical device required like banks use, so when the system is open to the world via portals, there is an extra layer of security. It's generally accepted that being onsite connected to a internal network to be a layer of security. Basically you must have a "key" to get onsite and into a classroom, I mean if I walk into your school, I assume I would have to pass some sort of physical security to get into a classroom, even if it is a member of staff. That's all assuming you don't have network sockets in the reception area or car park, or a insecure wifi network
pete Posted June 26, 2012 Posted June 26, 2012 I'd like to see some kind of physical device required like banks use, so when the system is open to the world via portals, there is an extra layer of security. The last time I asked SIMS about this in person, they did a good impression of attempting to run away while staying in one place. On further questioning the half-answer I got was "if you're hosting it yourself and can make it work with sharepoint, woohoo, but we don't support it and the government says we don't need to". This was the same conversation which involved "wait, so there's no audit trails for it either?"
vikpaw Posted June 26, 2012 Posted June 26, 2012 There was quite a hoo haa not long ago about sharepoint and sims security, because it gave a window into the school, effectively removing that physical factor of needing to get to a machine on site with software installed and linked to the server. In fact, that's a consideration for anyone opting for cloud / web based solutions. If someone hacks your email OWA access you could live with it, but if someone now gets into your DB and looks up kids photos and phone numbers, it's a whole heap of trouble you don't wanna deal with.
ICT_Pro Posted June 26, 2012 Posted June 26, 2012 Just thinking if SQL encryption can be used with SIMS db? is somebody used or tried?
matt40k Posted June 26, 2012 Posted June 26, 2012 Don't get why you would want to encrypt the database... are you planning on taking your server on holiday? @vikpaw - you can purchase third party add-ons to do two factor authentication for SLG and OWA, pretty sure a few LAs already do this.
vikpaw Posted June 27, 2012 Posted June 27, 2012 Don't get why you would want to encrypt the database... are you planning on taking your server on holiday? @vikpaw - you can purchase third party add-ons to do two factor authentication for SLG and OWA, pretty sure a few LAs already do this. Got any recommendations? Might be useful for a few projects i'm working on.
ICT_Pro Posted June 27, 2012 Posted June 27, 2012 Don't get why you would want to encrypt the database... are you planning on taking your server on holiday? @vikpaw - you can purchase third party add-ons to do two factor authentication for SLG and OWA, pretty sure a few LAs already do this. Hi Vik No plan for taking on holidays :-) But worse case if your network security compromised minimum your confidential information is secure.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now