3 ms·
I work as a contingent faculty member at a private liberal arts college. When searching for someone's email address recently, I discovered published on the web
by plitfabi 12y ago
I work as a contingent faculty member at a private liberal arts college. When searching for someone's email address recently, I discovered published on the web a list names, email addresses, and ID numbers for all staff and faculty. I notified the responsible department through a trusted tenured faculty member. The response was "oh, that's just test data," which turned out to be false, and then "oh, it's not a big deal anyway." This was also false, for any number of reasons. Among them is the institution's use of swipe cards to control access to buildings and labs, and a ridiculously simple swipe payload (essentially just the unencrypted ID number).
They removed that information from the site and probably no one with ill intent accessed it. However, the security situation at that institution would be in better shape today if there had been an open discussion about this leak and its implications. Because I didn't feel comfortable approaching decision makers about this without risking retaliation against me, that discussion never happened.