You are not logged in. Login Now
 0-24   25-49   27-51   52-76   77-101   102-126   127-151   152-176   177-184 
 
Author Message
25 new of 184 responses total.
aruba
response 52 of 184: Mark Unseen   Sep 5 05:20 UTC 2002

I'm not sure I followed that, Todd, but: yes, Grex has a policy of requiring
a court order before turning over ID information.  To date we've never
turned ID over to anyone, ever.

It's not Grex that would want to find someone who had done something
illegal, it's law enforcement.  We just want to have the "raw material",
as Marcus put it, to help them.  So either a passport or driver's license
is fine, and you didn't goof.
mdw
response 53 of 184: Mark Unseen   Sep 5 11:22 UTC 2002

I don't believe SSN numbers are any more or less of an issue than DL#'s.
Either works as a sufficient key into credit databases, and is
sufficient for identity theft, and I don't believe there is any
meaningful difference in the law's treatment of the two forms of
identification information to matter to us.  If we were a public
institution, there are more strigent requirements regarding SSN's in
particular, but what we're doing would still be allowed.

I think Todd is confusing 2 issues: what we accept as sufficient
identification information, and when we might disclose such information.
For the latter, #52 is right on the spot, althought there are some
nagging little details about the Patriot law that nobody really
understands (it loosened some features of federal law, but didn't create
new structure, so there is more grey area that nobody really wants to
explore, at least not yet.)  For forms of what we *accept*, we don't
actually have 100% fast rules about this.  We have things we *generally*
accept, but we reserve the right to refuse them if in any individual
case we think something fishy is up.  Our responsibilty is to avoid
fraud; so even though we generally accept school ID, if you *mail* us
your school ID (and not just a photocopy), and don't want it back, we
*are* going to think something is up, and we will *not* accept it.
(Believe it not, this really happened, and yes it turned out it had been
stolen.)
scott
response 54 of 184: Mark Unseen   Sep 5 12:57 UTC 2002

(I think there's a bit of a pattern, with M-Net people like Tod and Jamie
used to *not* being able to trust the leadership.)
jmsaul
response 55 of 184: Mark Unseen   Sep 5 13:28 UTC 2002

(I could turn that around, by suggesting instead that there's a pattern of
 Grex people like yourself having blind faith in the leadership.  I don't
 think it would make for productive discussion, though.  And incidentally,
 Tod was part of M-Net's leadership for quite some time.)
scott
response 56 of 184: Mark Unseen   Sep 5 13:33 UTC 2002

(I suppose if I had had some experience with Grex leadership deliberately
acting in bad faith I'd be less trusting.  In my, um, 8 years (?!?) on Grex
that's never happened.  Dunno how M-Net's record has been; I do recall there
having been a number of mishaps with money but I don't recall if there was
any malice involved)
cmcgee
response 57 of 184: Mark Unseen   Sep 5 14:11 UTC 2002

I think that Grex and aruba are doing a fine, minimalist job of verifying
people's identity, and holding on to sufficient information to show we were
acting reasonably if a court sees fit to issue an order involving us and our
information.  

Remember that this information is only divulged to anyone other than the
treasurer if there is a court order in place.  Many of you would be surprized
to know that my Grex membership is not under cmcgee, but another login ID.
But aruba knows how to link that login to a real person, if he is required
to by our court system.  Short of that, my identity is "safe".  

For active participants in conferences, there are far more revealing
details about our identities and whereabouts than an old driver's license
would reveal.  And that information is available to _anyone_. 

I don't see any reason to change how much information we collect, nor how we
retain it.  Mark has gone far beyound reasonable in taking the credit card
stuff off his computer.

And the people complaining the loudest have left a permanent, public
record of their profesions, physical locations, photos and other
identifying information
han Grex would
_ever_ ask for.
tod
response 58 of 184: Mark Unseen   Sep 5 16:49 UTC 2002

re #53
I feel like there are two issues that need to be addressed:
1) Authentication
2) Liability
Authentication is usually something instituted for access control purposes.
When authentication is being utilized, you want to have identification,
authentication, authorization, and finally accountability(liability).
So yes, I'm curious what is sufficient identification/authentication method.
I am also curious about the administrative, physical controls, technical
controls, and policies that encompass the liability/accountability portion.
Examples: administrative(supervisory structure), physical(copies),
techical(auditing trail), and policies(self evident).

re #54
Finding a pattern between myself and others that are also users on M-Net is
a nice spin, but a wasted effort.  I'm a Grex member. I've been a Grex user
off and on since its inception.  I've even donated hardware in the past.
Try not to dismiss my sincerity with simple prejudgice.
Contrary, I'm actually creating "trust" with "leadership" by examining the
necessary controls to ensure that the intended security of Grex is not
compromised.  My background is very extensive with security so you can imagine
my concerns are legitimate when I am providing copies of my identification
and want to know the depths that it will be used.

re #55
Thanks Joe.  I sympathize with Scott's defensiveness.  Maybe, he'll take off
the M-Netter goggles and lower the hostility, maybe not. ;)
aruba
response 59 of 184: Mark Unseen   Sep 5 21:34 UTC 2002

Re #58: Administrative: it's just me.  I am responsible to the board and the
members, if that's what you mean.  But we are all volunteers.

physical controls: I lock the door when I leave the house.

policies: We've talked about that a lot already; I think all the relevant
policies have been stated.

Is that what you mean?  I am happy to be subject to scrutiny, if it will
help build trust and serve the goals I stated around here someplace.  Like
you, Todd, I prefer it when the discussion is civil.
jmsaul
response 60 of 184: Mark Unseen   Sep 5 22:53 UTC 2002

I've served in leadership positions on M-Net myself, including President, and
I don't enjoy feeling hassled either -- but it's important to separate out
the personal emotional reaction ("get off my ass, you never do anything for
the system") from the possible genuine issues that may be behind the hassle.
It isn't easy to do, speaking from personal experience.

There really is an issue here with retention of personal information, though.
Actually a couple:  (1) does everyone know what information Grex is retaining
about them, and (2) should Grex be retaining that information.  Based on this
and parallel discussions, I couldn't answer "yes" with confidence to either
question.  Could you?
scott
response 61 of 184: Mark Unseen   Sep 5 23:14 UTC 2002

The FAQ seems to cover those questions, Joe.
tod
response 62 of 184: Mark Unseen   Sep 6 00:06 UTC 2002

Other has answered any questions I've posted.  Whether those results are acted
on is an entirely different ball of wax, but I do appreciate that everyone
has shown some interest.
jp2
response 63 of 184: Mark Unseen   Sep 6 00:10 UTC 2002

This response has been erased.

tod
response 64 of 184: Mark Unseen   Sep 6 00:15 UTC 2002

It shouldn't.
other
response 65 of 184: Mark Unseen   Sep 6 02:19 UTC 2002

Grex and M-Net have only the slimmest of relevant similarities.
jmsaul
response 66 of 184: Mark Unseen   Sep 6 02:32 UTC 2002

I disagree, but the only reason I'm mentioning it is to say that I know what
it feels like to get criticized when running a volunteer organization.

Re #61:  I suspect most people aren't aware you retain credit card numbers
         (though who knows), and I personally wouldn't answer yes to the 
         question about whether you should be retaining the information.

         But whatever.  I'll take this up when and if I donate.
cmcgee
response 67 of 184: Mark Unseen   Sep 6 02:39 UTC 2002

For donations you don't need to give us ID.  For a membership (which
includes outbound telnet access) you do.  
jmsaul
response 68 of 184: Mark Unseen   Sep 6 13:49 UTC 2002

Ooh.  Outbound telnet access.  That's scary, and impossible to get anywhere
else, especially on a college campus where hundreds of students run illicit
servers connected to UM's network.  You're right to lock it up as tightly as
possible.
scott
response 69 of 184: Mark Unseen   Sep 6 15:48 UTC 2002

It's very difficult to get an anonymous telnet access, and for good reason.
tod
response 70 of 184: Mark Unseen   Sep 6 17:16 UTC 2002

re #66
Arbornet service should include VA benefits. ;)
cross
response 71 of 184: Mark Unseen   Sep 6 20:21 UTC 2002

Regarding #69; Really?  Any Internet cafe is essentially anonymous.  The
New York public library is anonymous.  College campuses are the same
thing.  Here at Columbia, we have public-access kiosks all over the place
that give outbound telnet access.
jmsaul
response 72 of 184: Mark Unseen   Sep 6 20:30 UTC 2002

(Sssshhh... they think it's still 1990.)
mary
response 73 of 184: Mark Unseen   Sep 6 20:48 UTC 2002

Do internet cafes offer an email program that allows you to be anonymous? 
Is Hotmail still anonymous?  Or do you get to browse all you want without
having to login but as soon as you want to actually send mail, or buy
something, or participate in a forum you need to give some identifying
information to the provider, or store, or host?  That's how libraries I've
visited handle it. 

tod
response 74 of 184: Mark Unseen   Sep 6 21:20 UTC 2002

Hotmail asks you for another e-mail address and for your personal information
while you're online. It does NOT ask for a copy of your ID.
Internet cafes ask for money.
Libraries? You can show them a letter from zippy the postman to prove you're
a local resident and that's enough.
None of the above make a copy of your ID that I'm aware.
other
response 75 of 184: Mark Unseen   Sep 7 03:30 UTC 2002

Do any of these services offer shell accounts?  

Disk storage?  

Compiler access?

Scripting support?


Yeah, thought so.  What was your point again?
mary
response 76 of 184: Mark Unseen   Sep 7 03:39 UTC 2002

No, really, I'm curious, Tod.  Can you walk into your library
and end up sending email without going through an account
which has required some form of ID?

Does an internet cafe offer you more than internet browsing?
For anything else don't you pretty much have to login to 
a server where you are known?
 0-24   25-49   27-51   52-76   77-101   102-126   127-151   152-176   177-184 
Response Not Possible: You are Not Logged In
 

- Backtalk version 1.3.30 - Copyright 1996-2006, Jan Wolter and Steve Weiss