The Register Home Page

back to article Headteacher had the most guessable username-password combo you could imagine

PWNED Welcome, once again, to PWNED, the weekly column where we show you how not to use your computer or your network. In this week’s fable of fecklessness, we talk about a teacher who had a lot to learn about security. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. …

  1. Joe W Silver badge

    Not a problem

    The CCTV thingy running XP is not a problem - provided it is on a separate network and cannot be reached from the outside. And why should it have connections to the outside world?

    1. Stuart Castle

      Re: Not a problem

      Where I work, we have a few machines that require specialist control software that requires Windows XP. (and some that require 7). These machines would need to be replaced or have major upgrades to work with newer versions of the software. In either case, the cost would start in the high five figure range, venturing into the six figure range if the machine does need replacing.

      So, we opted to remove them from the network, blocklist their MAC addresses on the the network, and restrict physical access. Not saying a hacker won't get them on the network, but it'd be bloody difficult..

      1. Calum Morrison

        Re: Not a problem

        I can't believe one of the "replace it all with Linux" brigade hasn't been along to tell you why you're doing it wrong ;-)

        1. Stuart Castle

          Re: Not a problem

          Oh, I have run ins with them before.. I am actually a fan of Linux, but there have been a few times on here where I've asked a question about something (for example, remote fleet management for Linux similar to System Center), and the only answers I've got have been given were downvotes and responses of "Google it"..

          I'd like to see more Linux use where I work, but I've been told, to put it bluntly, that the problem with Linux (and all Open source software) is we didn't purchase it, so have no rights if it fails to work as advertised, and we also have no one we can sue. Microsoft can afford better lawyers than we can, so any legal action is likely to fail, but with Windows, at least we do have a entity we can sue.

          I'd still like to see more use of Open Source..

          1. Anonymous Coward
            Anonymous Coward

            Re: Not a problem

            ... we didn't purchase it, so have no rights if it fails to work as advertised, and we also have no one we can sue.

            Yes?

            So you would sue ...

            Microsoft?

            Good luck filing a lawsuit against M$ for using XP on your hardware.

            The terms unsupported and EOL right before software and hardware respectively would be seen in the heading to their reply.

            And it would most probably be a boiler-plate one at that.

            .

          2. R Soul Silver badge

            Sue the bastards!

            "I'd like to see more Linux use where I work, but I've been told, to put it bluntly, that the problem with Linux (and all Open source software) is we didn't purchase it, so have no rights if it fails to work as advertised, and we also have no one we can sue."

            Read the small print of any commercial software licence. It'll pretty much say "We make no claims and offer no warranties whatsoever about the functionality of our software. You agree we have no responsibility for anything. Have a nice day." Of course you'd still be welcome to sue M$ or Oracle or Palantir or.... but that'll crash and burn - much like their software - before the case gets near a court.

            1. Excused Boots Silver badge

              Re: Sue the bastards!

              Yes I know but it’s simply a box ticking exercise. In theory you ‘could’ sue MS, and that’s enough to satisfy the box tickers.

              There is no 'Linux Corp' to sue which makes it an ‘unacceptable risk’ for corporate arse-coverers.

              1. rmallins

                Re: Sue the bastards!

                > There is no 'Linux Corp' to sue

                That's one of the appeals of Red Hat; they sell you a Linux distro alongside commercial support. Canonical also offer paid support for Ubuntu.

                1. Doctor Syntax Silver badge

                  Re: Sue the bastards!

                  Also Suse, Zorin and others.

                  "Nobody to sue" is yet another of the myths as, of course, is the idea that you could usefully sue Microsoft (other than in the small claims court which, I believe, has been done).

            2. the Jim bloke Silver badge
              Windows

              Re: Sue the bastards!

              Even the airline inflight entertainment apps, to download inflight media to your personal device,

              .. expect you to assume all responsibility for any consequence from the software and data they are pushing onto your device.

              and young people think WE are tech illiterate...

        2. Doctor Syntax Silver badge

          Re: Not a problem

          Why? If it's specialist S/W tied to a specific Windows version then that's what it needs to be. The same would apply if it were an S-100 ox running CP/M, a Linux box running a kernel in the 4 range or even a MicroVAX running VMS. Just treat it as the dedicated appliance it is, but isolate it. The real problem comes when the H/W dies, of course.

      2. fnusnu

        Re: Not a problem

        Can you even install 7 or XP on modern hardware? This is the biggest risk in my mind.

        1. Lon24 Silver badge

          Re: Not a problem

          Dunno, but you can certainly install them on modern hypervisors on modern hardware. Got Windows VMs running back to from XP to Win95. Haven't tried WfW yet and I'm not sure I'd inflict ME on any device.

          1. Doctor Syntax Silver badge

            Re: Not a problem

            The special control boxes might be running special interface cards. They might not even plug into a modern motherboard and even if they did modern bus speed might mess with them.

        2. theDeathOfRats

          Re: Not a problem

          As for 7? Yes, it can be done.

          It will not use many of the actual thingies we are used to, but it will work.

          Haven't tried it with XP, though. I might give it a try in a few weekends time (as Lon24 said, a VM works, but I wanna try a "bare metal" approach).

        3. blu3b3rry Silver badge

          Re: Not a problem

          Depends how modern you want to go. I got XP SP3 running happily on a 1st gen Intel NUC (dual core Celeron 847), I think the build date on the underside is 2013 or so.

          Driver support exists but is a bit limited, with only one HDMI port out of the two willing to function, however there is XP driver support for the iGPU and it will run a 1920 x 1200 display happily.

          As weak as the CPU in that NUC is, It's entertainingly whizzy running XP. I should see about spinning up some late 90s / early 2000s games on it and seeing how it gets on.

          I've tinkered around with a few "newer" systems but the driver support for XP falls off a cliff as you approach any hardware around intel core 4th gen.

    2. Anonymous Coward
      Anonymous Coward

      Re: Not a problem

      Our CCTV system is accessible from Windows 11, but only in Edge running in Internet Explorer mode because it uses an ActiveX plugin to display the video streams.

      We have to reset it to Internet Explorer mode every 90 days because Edge won't allow it to stay on the IE Mode site list longer than that (the default is 30 days but that can be extended to a maximum of 90 days with a registry hack).

      1. Anonymous Coward
        Anonymous Coward

        Re: Not a problem

        If that's HikVision's IE activex plugin you're using, then Hikvision have a LocalServiceComponent workaround for Chrome, Edge and family.

        Listed on their Support /Tools/ HiTools page

        1. Sandtitz Silver badge

          Re: Not a problem

          Not too many years ago (2021-2022?) Dahua still made IP cameras and DVR's that require ActiveX plugin. Utter garbage.

    3. DS999 Silver badge

      Re: Not a problem

      why should it have connections to the outside world?

      Because inevitably there will be someone or someones who want to be able to remotely access the videos. Say an alarm is triggered at the school on a weekend, unless that is routed straight to the police (which has its own risks, especially in the US) someone like a school security officer, custodian, or assistant principal will want to take a look to know if it is a real issue like intruders or if it an employee like a teacher or coach who accidentally set it off.

      A CCTV system without a connection to the outside world 1) cannot be backed up or accessed via cloud which means 2) intruders can take/destroy the CCTV computer or its storage device to erase all evidence of their breakin.

    4. Excused Boots Silver badge

      Re: Not a problem

      Come on, of course it’s connected to the internal network, (VLANS, what is this magic of which you speak)? The Head absolutely needs to have the ability to view the cameras from home, or while on holiday - for no good reason, but still.

    5. AVR Silver badge

      Re: Not a problem

      I saw a MSDOS machine running a program to control which doors each access card could open in about 2005. No actual access to the Internet but I was assured that the Lemmings Christmas Edition program on it couldn't actually be there; floppy disks aren't a major access flaw once they're no longer easy to get I guess.

  2. Who-me

    Oh, tell me about it. Been there, done that. The primary schools I serviced were exactly the same. You also left out the fact that they don't generally have a tech full-time, and they don't pay anything like enough for you to run yourself into the ground for them.

  3. Alan J. Wylie

    FIELD / SERVICE

    There are plenty of previous comments about the default passwords on VMS.

    It's strange that "UETP" doesn't show up on The Register's search.

  4. GlenP Silver badge

    It's not always that much better in business.

    We had a sister company that had IT oversight for us who kept a handwritten list of all their user's passwords in their office where almost anyone could have found it - when they did "demand" my password to do something I made a point of changing it before and after. They really should have known better and were always bleating on about "Sarbanes Oxley doesn't allow..." whilst ignoring basic principles themselves.

    Hopefully people have got past using such obvious things but one colleague was always talking about her horse, Oliver, guess what her password was? Everyone on the office knew that until she was persuaded to change it to something more secure.

    When I joined the current employers the servers were in a locked cupboard. The clearly labelled key to the cupboard was hanging in an open keysafe in the lab office which wasn't permanently manned or locked. I fixed that when we moved - I inherited a reinforced room with a Chubb safe door (formally used as a property deeds store), there were two keys, one in my possession and one in a hidden key safe that only a couple of very senior people had the number for.

    1. Doctor Syntax Silver badge

      "one in a hidden key safe that only a couple of very senior people had the number for."

      Sitting in the Crown Room at Crumlin Rd courthouse, waiting for the trial I was involved with to start. One of the police witnesses - photographer, mapper or whatever was also sitting there. There was a key safe lying about so to pass the time he picked it up and started trying the combination lock. After a few minutes he had it open.

      1. Phil O'Sophical Silver badge
        Coat

        Was it 999 ?

        1. R Soul Silver badge

          No. The court was in Northern Ireland, the code must have been 1690.

    2. Anonymous Coward Silver badge
      Joke

      > "one colleague was always talking about her horse, Oliver"

      Did Oliver have extensive knowledge of battery staples?

      1. Excused Boots Silver badge
  5. elsergiovolador Silver badge

    The only combo

    AzureDiamond

    hunter2

    ???

  6. Aladdin Sane Silver badge

    Satire is dead.

    Nelson 'Big Head' Bighetti: My username is "password" and my password is "password."

    Richard Hendricks: Your username is "password"?

    Nelson 'Big Head' Bighetti: It was just easier.

  7. Mark #255
    Headmaster

    did the login work?

    We're not told whether the displayed user name/password combination actually logged you into the machine...

    "I've set up your new laptop, it's on your desk. The user name and password are on a sticker underneath, make sure you change the password ASAP."

    1. Calum Morrison

      Re: did the login work?

      Unless they were specifically ordered not to, the fault for that one lies with the IT Admin who didn't set the password to require changing on first login.

      1. Will Godfrey Silver badge

        Re: did the login work?

        Ideally, the user should have to reset these before the first login is completed.

    2. geekinchief

      Re: did the login work?

      Yes, the login worked.

    3. Ken Shabby Silver badge
      Holmes

      Re: did the login work?

      As Slowly As Possible?

    4. LessWileyCoyote

      Re: did the login work?

      User changes password to 'ASAP'.... "well you told me to!"

  8. Fursty Ferret

    >> and one critical system that users could only access from an ancient laptop.

    That actually sounds quite secure to me...

    1. Doctor Syntax Silver badge

      And even more secure once the ancient laptop goes to join that great landfill in the sky.

    2. doublelayer Silver badge

      Why? From the data we have, we don't know that the laptop was offline, just that you had to have it involved. One tactic I've seen used for things that only can be accessed from a old machine is to install some remote access software on said old machine so you don't have to go physically to it, like these guys did. They're not getting the best of praise in the comments over there.

      Even if they hadn't done that, we still don't know if it was offline, and it frequently wouldn't be if, for example, they had to email results off it to someone else. Even if we assume it's offline, that does fix much of the security problem, after all it is unlikely someone's going to try a Stuxnet approach on a school system, but it likely still has problems of dependence on something that's more likely to break. The fact that you couldn't use another machine suggests backups either didn't exist or wouldn't work when restored to something else without doing the work that would have liberated them from reliance on that laptop. I think it sounds secure to you because you're being charitable with your assumptions.

  9. jake Silver badge

    Sometimes you'll find this kind of stupidity ...

    ... in places you (might) least expect it.

    Part of pen testing is proving to the C*s that human stupidity knows no bounds, and that they are not immune ... I once found a comprehensive list of machine names and login/password pairs written in sharpie on the underside of the leaves of a faux ficus in the office of the secretary of a VP. They included complete access to the corporate mainframes various LPARs (including HR and R&D). Quite a few people got reamed, and I'm absolutely certain that Amdahl's internal security culture was much better by the time Fujitsu bought them ...

    1. segfault188
      Joke

      Re: Sometimes you'll find this kind of stupidity ...

      I once found a comprehensive list of machine names and login/password pairs written in sharpie on the underside of the leaves of a faux ficus

      Hopefully the miscreants have seen the errors of their ways and turned over a new leaf.

    2. Bebu sa Ware Silver badge
      Coat

      I'm absolutely certain that Amdahl's internal security … better by the time Fujitsu

      I wouldn't be so sure.

      You can also imagine Fujitsu's culture being contaminated and degraded by Amdahl's.

      I must admit writing credentials on the underside of the foliage of office potted plants is a new one for me. Pen. testers must devious minds; necessarily so I suppose.

      The name or brand of the monitor, computer, keyboard or something in the office was pretty much first cab of the rank in earlier times. Given our *ix hosts all used a single NIS (yellow pages) service anyone could ypcat the passwd map and run it through John the Ripper. I ran it preemptively (once) - pretty horrible.

    3. geekinchief

      Re: Sometimes you'll find this kind of stupidity ...

      This sounds like a great story. Would you be able to share it for a future PWNED? Drop me a line at avram.piltch@sitpub.com if you can.

      1. Martin an gof Silver badge

        Re: Sometimes you'll find this kind of stupidity ...

        How come you don't get the little Vulture icon like other Reg hacks do?

        M.

        1. LessWileyCoyote

          Re: Sometimes you'll find this kind of stupidity ...

          Trust no one!

      2. This post has been deleted by its author

  10. Bebu sa Ware Silver badge
    Facepalm

    No Imagination ?

    As head teacher he might have chosen Blackbeard as his password (aka Captain Teach.)

    I suspect the lack of critical thinking symptomatic of le malaise américain is augmented by an imaginatory deficit.

    I have just noticed the American malady in francophone media "Paroles de scouts : Le malaise américain" — a different sort of buggery altogether.

    1. Evil Scot

      Re: No Imagination ?

      Didn't Teach join the Silver Hoard?

      Ah... Interesting times.

    2. parlei

      Re: No Imagination ?

      I, being of devious mind and paranoid disposition, might have had such a password sticker on the underside of my keyboard. It would of course mainly be used to trace the times of any unathorized login attempts, not actually do anything.

      Well, there is allways honeypots...

  11. MorningLightMountain

    While Mr Walker's advice, essentially KISS, is evergreen advice it unfortunately doesn't combat the most persistent and stubborn of reasoning for why so many good ideas are never implemented. Things cost money, either directly in terms of licenses and/or hardware or indirectly in time needed to set them up. Usually some mix of both.

    At our company we can't even get sign-off on provisioning accounts for a password manager, despite departments like Logistics needing one for each of the couriers we use and then Customer Services needing a metric shedload of passwords for various systems and webshops. Depending on what PWMan we went with, we'd could be looking at costs anywhere from £15 - £40 per seat per month. In this day and age, unfortunately that should just be the cost of doing business. I'm not going to pretend our Customer Service people are paragons of Cyber Security, but at the very least we should be using tools that would allow us to force their hands when it came to password security.

    1. Calum Morrison

      Use Keepass then - it's FOSS. Hell, even a browser would be better than nothing.

      1. Screepy

        Keepass isn't multiuser though.

        Only one person can be accessing the kdbx file at time. Which is fine if the team is 2 or 3 people but once it gets into the +5 then one of them is going to open Keepass to grab a PW and then forget to close it and go to lunch. Leaving the DB locked for the next poor soul who just gets a message "Retail password.kdbx is locked by another user" and has to wait until the luncheoner has returned.

        We used Keepass at our org for years, but eventually we had to go with a multi-user solution.

        Keepass is excellent though if it fits your use case.

        1. Excused Boots Silver badge

          "We used Keepass at our org for years, but eventually we had to go with a multi-user solution.

          Keepass is excellent though if it fits your use case.”

          Which is a very good point - yes FOSS solutions do exist, but not always geared for multiuser access, aimed at a single user, ‘can’ be made to work in a multiuser environment, but only if everyone behaves properly - which they won’t.

          1. Calum Morrison

            I'm torn between coming up with free ways to get around a situation like this and complete disdain for any organisation that can have a team of more than a couple of IT spods and not spend a few quid a month on a password solution.

            TBH, if none of those spods can make a business case for it that management finds acceptable, my disdain lies with them. But... when Keepass becomes unwieldy, couldn't they have a Firefox or Chrome account that they all sign into and store passwords there? If that won't work and none of them have the chops to write something that does, I'm starting to think they're a significant part of the problem.

        2. Doctor Syntax Silver badge

          'Leaving the DB locked for the next poor soul who just gets a message "Retail password.kdbx is locked by another user"'

          Keepass is a many-headed beast these days. I use KeePassX. If it accidentally gets closed without saving it asks if I want to open it read-only which would fit your use case.

          Also I use NextCloud to sync it between devices. I'm not sure what would happen if it synced in locked condition but I haven't seen an issue with it.

  12. Stuart Castle

    Re "“A headteacher’s laptop is not just a laptop; it's an entry point to the most sensitive information a school holds,” Walker told us. If a cybercriminal got access, they could effectively break into the school without ever setting foot in the building. "

    This is something people forget..

    Whie a senior management user may assume that hackers would have little interest in their day to day responsbilities (and, tbf, hackers probably do have little interest in the day to day responsibilites of the manager), they forget that they often have a lot of rights to access a lot of company systems. Even assuming that company has compartmentalized it's security, that compartmentalization often doesn't apply to management. Sometimes because they need access to everything, and sometimes because they shouted when they found they didn't have access to something they didn't really need access to.

  13. Brave Coward Bronze badge

    Yeah, folks

    One has to admit that, outside the professional IT world itself, computers suck, and using computer is (was?) mostly seen as a pain in the ass.

    (For the record, I've worked as an IT trainer for many years.)

    1. Lanta

      Re: Yeah, folks

      I've got 2 lessons to plan, a child throwing up in the back row, playtime duty starting in 5 minutes, and you choose NOW to insist I change my password?

      1. Anonymous Coward
        Anonymous Coward

        Re: Yeah, folks

        In that specific case, my sympathy depends on whether they received and ignored password change reminders. We seem to start getting those a coupe of weeks before expiry.

    2. Philo T Farnsworth Silver badge

      Re: Yeah, folks

      Precisely.

      In fact, I think in this story, as journalists put it, they've buried the lede in the last graf, to wit, “Make the safe thing the easy thing,” Walker said. “Give staff password managers. Use multi-factor authentication. Review accounts properly. Test backups. Remove shared admin logins. Keep systems updated. . . ."

      As I said in the comments in another of this series, "Getting work done interprets security as damage and works around it."

      I remember working on a multi-campus project with a couple of other universities that as part of what it was fashionable at the time to call a collaboratory, implemented among other things a shared file system across campuses.

      Security was so unimaginably onerous that it literally took an all day seminar to learn all the ins and outs of credentials and authentication and keys to just use the blasted thing. And when I say literally, i mean literally, as in an entire wasted day.

      As an applications programmer who just needed to work with it, I found myself completely bewildered, and I had a few decades of experience working in the business. Most of the actual scientists who just wanted to share and access data were left glassy-eyed in confusion.

      And these were not stupid people (okay, with one possible, nay, definite, exception, me), they had advanced degrees in subjects that make my head hurt and a facility with mathematics that just leaves me gasping like a guppy out of water.

      The safe thing was not the easy thing and I suspect that's one major reason why the project slowly slipped into obscurity and disuse.

      1. Doctor Syntax Silver badge

        Re: Yeah, folks

        I define security as the ratio between the ease the good guys and the bad guys have getting access, Poor access for those entitled to use it is just as bad security as not being difficult to by-pass.

  14. Excused Boots Silver badge

    "There was also a machine with a “Do Not Turn Off” note posted to it sitting in a corner that everyone was afraid to touch.”

    Ah yes the 'mystery machine’ - not uncommon, I tend to slightly pull the network cable out and wait a few days/weeks and see who screams! If challenged, the cable is old and must have come loose, (bonus points for snapping off the latch on the RJ-45 plug) I’ll replace it with a new cable so this doesn’t happen again!

    1. Anonymous Coward
      Anonymous Coward

      "dear facilities management team, DO NOT even think of turning this cabinet off" - notice on the cabinet housing the alarm/door entry system for the building!

      The building had few offices in use due to remote working (after a move to "centres of excellence", not just WFH), so they had a habit of just powering down stuff and waiting for complaints... or in this case, the ability for them to get out of the building

  15. Doctor Syntax Silver badge

    I'd expect the local fire officer to come round periodically to check the fire readiness of the school: working alarms, fire doors not blocked or locked, etc.

    It's a pity there isn't a similar inspection routine for school IT security -all that personal information held on youngsters. This is one instance where "think of the children" might actually get meaningful results.

    1. retiredFool Silver badge

      The fire dept in my area comes around every few months to open all the fire hydrants and check pressure I guess. Not sure. I just wish they'd water my (or anyone's) lawn with the massive water flush instead of down the curb drains. As you say, I expect they do that more often than any sort of security IT checks in the city or schools.

      1. NorthIowan

        Re: open all the fire hydrants

        As I've heard it, it's to flush the crud out of the lines. Often accompanied by warnings not to wash light colored clothes on the days they are doing it.

        And you might want to only drink bottled or filtered on those days?

        1. Excused Boots Silver badge

          Re: open all the fire hydrants

          As I've heard it, it's to flush the crud out of the lines. Often accompanied by warnings not to wash light colored clothes on the days they are doing it.

          And you might want to only drink bottled or filtered on those days?

          Sorry, sorry, you’ve lost me - just what sort of oddball fresh water supply do you have in your neck of the woods?

  16. Anonymous Coward
    Anonymous Coward

    Great training

    Working in a school is a great training ground for a career in infosec.

    Basically the kids are all bad actors / terrorists but provided with physical and logical access to the network, the staff are all hostile as well and will attempt to block most changes to prevent the hostile actions of the kids or are so stupid the kids aged 6 can social engineer them.

    At the same time all the data is sensitive, much of it critical and you're expected to be an expert in networking, firewalls, proxies, websites, webdev, system admin, Data Protection, photocopier maintenance, union negotiations, psychology, child protection law and provide 99.9% uptime on a budget of 50p. All delivered by your crack team; consisting of you and only you.

    If you can manage that for a few years everything else is easy.

    1. Philo T Farnsworth Silver badge

      Re: Great training

      > Basically the kids are all bad actors. . .

      I wish people would stop saying that.

      I've heard that William Shatner is actually a pretty nice person when you get to know him.

    2. BigKev

      Re: Great training

      Couldn't agree more - after 20 years in corporate, I thought I knew about computers...and then I started work in a school after an unexpected redundancy - what a shock!

      I had a group of teachers who liked to reward "good" students by giving them their passwords and letting them fill in the register, thus giving them access to lots of sensitive data on their classmates. I couldn't get SMT to order them to stop doing it (they were TEACHERS by god and would not take orders from ancillary staff!) and restricting their access got me put on a charge - so I just went into CYA mode and emailed everyone concerned with each breach as it happened until I got out

      I found schools very "officers and other ranks" and teachers were clearly the only officers, after repeatedly being told that I ought to break the system for them, or it was essential that they had full admin access because they had "qualifications", my assistant (a very clever chap with in a stop gap job) and myself (degrees and a bunch of post nominals) had name plaques made to go on our office door, showing these off as a bit of a laugh - we were ordered to remove them straight away as it was affecting staff morale :D

  17. Yet Another Anonymous coward Silver badge

    I've got a great idea

    Why not NOT make primary schools responsible for their computer systems?

    Perhaps have some sort of education authority locally responsible for hiring IT staff, purchasing hardware and software and administering it ? A Local Education Authority if you would.

    I know we spun off every aspect of public service into some sort of independent anarcho-syndicalist commune, in order to be hyper-dynamic and not at all as a precursor to privatisation, but perhaps it's better to make someone king.

    We don't make every train driver responsible for building their bit of HS2

    1. MangoQPR

      Re: I've got a great idea

      This is a great idea!

      The LEA could then force the worst MIS system in human memory onto schools and make it ridiculously expense and difficult to get out of contracts! Then, they could probably ask the same company to do all of the network backbone.

      After spending 10 years working in education support, if I had a pound for every time a teacher told me their password was...teacher... I'd have enough money to retire to the Seychelles or the Maldives, or even enough for a punnet of popcorn at the local Odeon cinema.

    2. Someone Else Silver badge

      Re: I've got a great idea

      Great Idea. And I assume you would have no problem paying for it with the appropriate level of property tax....yes?

      1. Yet Another Anonymous coward Silver badge

        Re: I've got a great idea

        Isn't it cheaper to have 100s of schools with one centralised IT support rather than them all hiring their own people to do their own thing?

        Or has the theory of the firm got it all wrong for 200 years and we would be better all having our own back-yard fabs?

        1. Excused Boots Silver badge

          Re: I've got a great idea

          In theory, yes you are right a centralised system should be best. But, of course, in theory Communism is the best form of government because everyone is equal, everything is resolved by consensus and everyone looks out for everyone else.

          Or not.

          A centralised system tends to fossilise, one single system, supplier, model is chosen and has to work for everyone. Except, the outliers, where it doesn’t work. But the knee-jerk reaction is to try to force them to conform to ’the system’ rather than allow ‘dissidents’.

          There is no easy or perfect answer or solution.

  18. billdehaan Silver badge

    We don’t need to worry about cybersecurity. They're only a primary school.

    Memories of "We don’t need to worry about cybersecurity. It's only a fish tank" come to mind...

    1. Anonymous Coward
      Anonymous Coward

      Re: We don’t need to worry about cybersecurity. They're only a primary school.

      Once upon a time I had conversation with the university's safety officer. The biggest concern by far on campus was the fish tank in the foyer of the accountancy department. Where the head of department kept a shoal(?) of piranha.

      Sorry - no IT angle.

  19. trevorde Silver badge

    Post-It Note level security

    Many years ago, I was responsible for maintaining some in-house, password protected software. The password was only valid for a month and the boss was very paranoid, so only gave out 3 months passwords in advance. The users immediately wrote them down on a Post-It Note and stuck it to their monitors.

    1. MorningLightMountain

      Re: Post-It Note level security

      Honestly as a naive measure, the best thing we could do to improve the security at our company is go around with a black bin bag and grab all the sticky notes we find used or unused and then lock down the stationery ordering such they are never ordered again. Mind our staff would just start writing passwords on entire A4s instead.

  20. steviebuk Silver badge

    Its fine

    like the leisure centre we used to support. The reception to the gym had the user name and password they used for that computer, stuck to the monitor for all gym visitors to see.

    Can't fix stupid.

    1. Excused Boots Silver badge

      Re: Its fine

      It’s less stupid than ignorance, and the latter is not a derogatory term. Yes I have an honours degree in Physics, but I am an incompetent brain surgeon.

      They simply don’t know or understand the risks. Hopefully you pointed this out to them, and ideally they took steps. And if not, then yes that is stupid.

  21. xyz123 Silver badge

    a certain fruity phone company for a few years had their external-accessible HR system.

    password was company name and so was the username

  22. J.G.Harston Silver badge

    "blah blah list of recommendations...."

    and WTF is does the headteacher have Admin access to the whole system??????

  23. Marty McFly Silver badge
    Pint

    Password is "PENCIL"

    'No problem, I know where they write it down.'

    GenX will know the movie.

  24. jeremya

    Passwords are a Pointless Pain

    As anyone who has ever used a Microsoft network with mandatory password changes will know, passwords are a pointless pain.

    You write down your new password and put it on a post-it note somewhere, and it will be variant of the old password anyway.

    If you actually have some data to protect - most use-cases don't - then a security access device with 2FA makes most sense.

    Another easy alternative is an Authenticator system with or without 2FA.

    Personally I have all my master passwords printed out and stuck on my monitor. It allows access for others if I am unavailable and also provides a degree of plausible deniability

  25. jezmck

    > “Make the safe thing the easy thing,” Walker said. “Give staff password managers. Use multi-factor authentication. Review accounts properly."

    Those three things are not easy, especially not for people not interested in tech.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon