Jump to content

SIMS AD intergration - Put a password in a second time?


Recommended Posts

Posted
Spot on Stuart!! Teachers are professionals and should be treated as such, they are capable of locking their laptop and you shouldn't create unnecessary barriers because a few are, in your opinion, an idiot. Even if you are right lol
Posted

While all arguments are true, the unfortunate reality is when security is breeched, everyone is quick to point the finger, usually in the direction of IT, the software, in fact anyone but themselves or staff who choose not to follow basic rules and lock the computer!

 

I cannot say I agree with the 'there is enough confidential info already on the system'... surely that should be highlighting ANOTHER issue, not as a reason 'not to bother any further'? I'm not disagreeing with your decision that is fine... just worried by the reasoning! :)

Posted

Graham, by your logic, you would need to close your browser when leaving your machine unattended and have it set to purge the cache each time you close it. Unfortantely, it doesn't happen.

 

Admittly your Team HTML5 and @PhilNeal is in Team App and your trying to sell the extra login as a security feature. Just incase anyone hasn't noticed :p

Posted

Not quite. I am suggesting that PCs are still locked. This is the most secure method for securing a workstation, not just for the benefit of the MIS but all information. Although loggin out and/or closing browser (closing the session is Aspen logs you out) is not a bad point -would you leave you online bank page open on a public library PC (anyone who responds with 'I wouldn't use a public PC for banking'... feel my wrath!)?

 

My suggestion here though is using this concept of 'auto-logging in' to save time on passwords is flawed. It is as bad as having your password on a sticky note on your monitor. It takes one time forgetting to lock the PC (we all do it), and the little buggers will have access not just to what is open, but everything else too. What about leaving the laptop on a bus? Now with SSO (the traditional thought of SSO), finder now can get at all your linked accounts. Left laptop on bus with just windows logged in, and they can auto login to SIMS (Well, in theory, if SIMS were web based ;)) With SaSO (remember, Same Sign On... my term, trademarked!) they would need to know your password, so there is that additional layer of security protecting systems. And what is the downside: Wow, I have to put my SAME username and password in again, something most do a couple of times a day for years.

Posted

Admittly your Team HTML5 and @PhilNeal is in Team App and your trying to sell the extra login as a security feature. Just incase anyone hasn't noticed :p

 

I am Team HTML5 (I'm getting a tshirt with that on!). I don't believe I'm selling it as a feature, more I'm clearing up a mistaken concept and pointing out the negatives of it that has long been held as a way forward... it is, but it is not without some huge drawbacks.

Posted
Basically you idea is, if you device is not trusted, auto logout and reauthenticate. But if you trust your device, ie a desktop, you can give a little and let it auto sign in?
Posted
Basically you idea is, if you device is not trusted, auto logout and reauthenticate. But if you trust your device, ie a desktop, you can give a little and let it auto sign in?

No, all devices whether trusted or not require sign-in, it's just the same credentials you have to provide. This idea i like, but could be a pain, if say, you use your intranet / VLE to springboard into 5/6/7 different other systems / apps. I wouldn't want the hassle of signing in to each different site and then it times me out so i have to do it again, through the day. I suppose you could trust one portal app to have Single Sign-On to other linked sites, but the portal itself is SAme Sign On with the desktop.

 

Not sure what the plan with apps would be, it's a pain to have to login all the time. Saying that, i only have a few apps that actually require login, or that i've set to require login. Emerge asks for a pin for every access if it's been minimised, and a password for a longer timeout. It's a bit of a pain, but not that bad actually. The only pain is that it's not the same credentials as AD. This was asked about on an Emerge thread, but apparently it's not easy to implement.

Posted
I'm involved in several projects right now to look at SaSO vs SSO and the impact it has in different users. For instance, a possibility is that pupils have an extended SSO facility to ge into learning platforms, a reasonable argument, and the data held in here and most (not all) associated pupil used apps contain less confidential info... Compared to staff who access she'd loads of confidential info, perhaps in school and LA systems. Much less SSO and more SaSO for staff due to the nature of the informaion. Talking convenience only (not practicality): going back to the banking idea, would you be happy having SSO into all your online accounts, or rather SaSO (forgetting for the moment you should have different passwords for this really, but we are just looking at convenience!)
Posted
No, all devices whether trusted or not require sign-in,

 

More saying about the app vs html5 idea. ie it's users use the current login - ie no prompt, or the html5 prompt you again (for the same password).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...