Ads by TechWords

See your link here
Receive the latest technology news and information.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Back to School

August 5, 2002 12:00 PM ET

Computerworld - Let's say this upfront: That Princeton University admissions director was wrong. He was wrong to "test security" on a Yale University admissions Web site designed to let prospective Yalies find out whether they'd been accepted. He was wrong to repeatedly access would-be students' records using names, birth dates and Social Security numbers from Princeton's admissions files - including that of President Bush's niece, Lauren . He was wrong, yes - and criminally dumb on all counts. Now let's move on to the other criminally dumb figure in this fiasco. That Yale Web site was designed by a self-promoting Yale sophomore who brags that he has worked for Microsoft since he was 14. He's the genius who decided that birth dates and Social Security numbers would make the perfect passwords because of their "personally identifiable nature," according to the Yale Daily News, the student newspaper that broke the story late last month before it was picked up by The Washington Post and the wire services.
"Personally identifiable"? What was this kid thinking? If there's one thing we don't want a password to be, it's a piece of information that's easy for an unauthorized person to guess or learn. And that's exactly the kind of "authentication" you get from birth dates and Social Security numbers.
Yes, they're easy for users to remember. They're also incredibly easy for outsiders to acquire. Employers ask for them. Credit-reporting companies are awash in them. Many states even include them in publicly available driver's license records.
Which means they're worse than useless for authenticating that a particular user is who he claims to be. Asking for such easily acquired information as a password is like begging unauthorized users to walk in.
Does this seem obvious? Good - that means you haven't forgotten Security 101. You haven't been sucked in by the idea that in a world of firewalls and VPNs and crypto and biometrics, the old rules about security no longer matter.
Sure, those security technologies are a good and valuable thing. These days, no one can protect systems without them. Piling on as many barriers as possible to protect proprietary information and user privacy just makes good sense.
But that's only a beginning. It's no replacement for real security.
That's why good passwords still matter. So does regularly examining access logs - the logs for that Yale admissions site clearly showed the suspicious cluster of accesses from Princeton, but no one reviewed them until after the unauthorized access was exposed.
Outside audits of security still matter,



Jump to comments

Opinions/Blogs

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.