[23499] in APO-L

home help back first fref pref prev next nref lref last post

Re: [APO-L] Question of posting National Board Policy Manual online

daemon@ATHENA.MIT.EDU (Matt Cross)
Mon Feb 3 21:40:51 2003

Date:         Mon, 3 Feb 2003 21:38:01 -0500
Reply-To: mrforklift@cfl.rr.com
From: Matt Cross <mrforklift@cfl.rr.com>
To: APO-L@LISTSERV.IUPUI.EDU
In-Reply-To:  <3E3C8000.2070400@cs.com>

As a network administrator, I have to point out some logistical issues =
to
what is being proposed.

1)  As Robert has pointed out, using a method that involves transmitting =
the
username and password in cleartext is not a viable solution.  Just as =
there
are people that can view this list, they could also grab that info very
easily.

2)  How to distribute the "common" username and/or password?  By email?  =
I
hope none was thinking of doing that.  Email is not secure; the cardinal
rule for email is don't put something in email that you do not want to =
see
on the front page of the paper tomorrow.

3)  Do we use individualized usernames and passwords?  That would work,
except who is going to input the list and then maintain said list.  I do =
it
for 400 people and sometimes it takes more than a minute here or there.

Overall, there is nothing TECHNOLOGICALLY speaking that prevents us from
placing it online.  The problems that we, as a National Fraternity, face =
are
those of logistics: who manages?; how is it distributed? What will it =
cost
the Fraternity?

I understand that Chapters, and even Sections/Regions, have implemented
secure areas with success.  However that is with a small group and I =
would
be highly surprised if more than 1% used SSL or other encryption
capabilities.

The idea of creating a secured area may be something the National =
Fraternity
wants to research over the next few months/years, but implementing =
something
now in a haphazard fashion would not keep us on the right path.

Matt Cross, MCSE
Network Design & Administration
SAIC -- Orlando, FL
Voice: (407) 243-3707     FAX: (407) 243-3351
mailto:matthew.j.cross@saic.com

Matt Cross
Section 74 Chair -- Alpha Phi Omega
(888) 270-0074
mailto:section.74.chair@apo.org
http://www.section74.org

-----Original Message-----
From: Alpha Phi Omega Discussion List [mailto:APO-L@LISTSERV.IUPUI.EDU] =
On
Behalf Of Robert Dean
Sent: Saturday, February 01, 2003 9:19 PM
To: APO-L@LISTSERV.IUPUI.EDU
Subject: Re: [APO-L] Question of posting National Board Policy Manual =
online


Not to put a damper on this, but .htaccess is not a secure solution, =
just
like Telnet or FTP aren't secure.  They transmit the security controls
(username/password) in cleartext, which makes them wholly unsuitable for
real security of information.

If the information is considered wholly confidential, we should either =
make
it a request-only situation (information on hardcopy), or go all the way =
and
implement SSL.  This will keep the security controls AND the information
safe from people with packet sniffers.

With the concerns about security that have been popping up lately, I =
don't
think it's appropriate to use a solution that gives, at best, a false =
sense
of security.

--Robert



derek.cashman@vcu.edu wrote:
>>Post it online in PDF format, as previously done before its removal.=20
>>However, we can password-protect it as the Order of the Arrow (OA)=20
>>material is.  APO does not have levels of access to materials dealing
>
> with > a given Honor level and those below, but we can use the same=20
> idea.  Use
>
>>something unique to APO that is from the Initiation Ceremony, as the
>
> OA
>
>>uses for each of its types of initiation ceremonies.  Ideas?  Everyone
>
>
>>with an idea, chime in; register your $.02 so that we have "~$15K" of=20
>>ideas.
>
>
> Basic password-protection is, in fact, already being used by many=20
> regions & sections on their websites to protect critical information.=20
> And I have noticed that an increased number of individual chapters=20
> have incorporated a "Brothers Only" section into their chapter=20
> websites as well. The common "dividers" I have seen so far are=20
> basically for STAFF ONLY pages where a username & password is=20
> distributed out to members of the section or region staff, as well as=20
> chapters having a BROTHERS ONLY section that a username/password is=20
> distributed out to brothers of the chapter.
>
> The most common information to put in this section is probably=20
> address/phone number info. This type is generally the type of=20
> information that brothers do not want on the regular web (mainly to=20
> keep away from stalkers and spammers). Some chapters maintain a=20
> listing of AIM screen names which they do not want published as well.=20
> Region III keeps a staff directory in it's Staff Resources section, as =

> well as several other documents related to regional business. No, the=20
> BOD policy manual is not in this section (yet),... we're holding off=20
> on this for a bit (although it's probably on it's way there=20
> eventually,... ;-)
>
> Also, you generally don't need to have individual usernames/passwords=20
> for everyone that requires access. One single username/password would=20
> suffice, and you just give that out to everyone that you want to have=20
> access to your members only section. Although for security reasons,=20
> you might change the username/password every two years or so (whenever =

> there's a change in the board), just as a preventative measure,...
>
> Anyway, if Regions, Sections, & Chapters can do this easily, I see no=20
> reason why the National Office can't do it, too! The HTML coding for=20
> it is actually quite simple. It requires merely a small bit of=20
> knowledge of .htaccess & .htpasswd files, which you can easily glean=20
> from doing a search for ".htaccess" and ".htpasswd" on www.google.com=20
> (man's best friend, next to the dog; then again, google is a gift from =

> god, so dyslexics won't know the difference! :-) ... Some providers=20
> make it even easier than that! For example, apo83.org uses yahoo! as a =

> web-hosting service, and they have a program in the configuration=20
> section that configures the password and any directories you want=20
> protected automatically!
>
>
>   _____
>
> Derek J. Cashman (derek.cashman@vcu.edu)
> Technology & Electronic Communications (TEC) Coordinator Alpha Phi=20
> Omega; Region III Graduate Student, Department of Medicinal Chemistry
> MCV Campus of Virginia Commonwealth University
>
>   _____
>
> "A Drug is any substance which, when injected into a rat, produces a=20
> publishable, scientific paper."

home help back first fref pref prev next nref lref last post