home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!elroy.jpl.nasa.gov!swrinde!cs.utexas.edu!torn!cunews!nrcnet0!bnrgate!bmerh85!bcars64a!bqneh3!schow
- From: schow@bqneh3.bnr.ca (Stanley T.H. Chow)
- Newsgroups: comp.unix.large
- Subject: Re: User registration on diverse computer systems
- Message-ID: <1992Aug27.190847.10292@bcars64a.bnr.ca>
- Date: 27 Aug 92 19:08:47 GMT
- References: <5673@mccuts.uts.mcc.ac.uk> <yvcnv6a@lynx.unm.edu>
- Sender: news@bcars64a.bnr.ca (Usenet News)
- Organization: Bell Northern Research Ltd, Ottawa
- Lines: 37
-
- In article <yvcnv6a@lynx.unm.edu> sfreed@lacerta.unm.edu (Steve Freed) writes:
- >The way it works (in a nutshell) is a list of all persons affiliated with the
- >university (students, faculty, staff, etc.) is generated on the IBM mainframe
- >and sent to the Unix system(s). Everyone on the list is entitled to an account
- >on any (all) of our systems.
- >
- >Anyone wanting a computer account logs into any Unix system as the user "new"
- >where they are prompted for a variety of information including UNM ID number,
- >Name, date of birth, the system(s) they want accounts on (MVS, CMS, VMS,
- >Unix, etc.), the login name they wish to use and the password they want.
- >
- >The info is verified (real pearson, valid login ID, clever password) and
- >if all ok, thengivin some instructions on what to do, particularly if
- >there are any problems.
- > [...]
- >This whole process is done without human intervention. (Look ma, no hands!!!)
- >and seems to work rather well. The code is going through a cleanup process
- >this fall, with hopefully a release that is presentable to the public
- >by December or January. (there are currently some security concerns that
- >need to be resolved first).
-
- Without human intervention, how do you verify ID?
-
- Another way of looking at it is that anyone knowing the UNM ID number and
- birthdate of someone can get accounts in the victim's name. This is particularly
- bad for some staff/faculty who does not normally need an account and will
- never try to get one. The crook can get away with this for years!
-
- In one of the recent issues of RISKS digest, there was discussion of problems
- with a registration system like this.
-
-
- --
- Stanley Chow InterNet: schow@BNR.CA
- Bell Northern Research UUCP: ..!uunet!bnrgate!bqneh3!schow
- (613) 763-2831
- Me? Represent other people? Don't make them laugh so hard.
-