Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Software Your Rights Online

Pinnacle, Online Grades, Skipping School and More 912

Ishkibble writes "The Matrin County School Board has a new way of post a student's grades online for a parent to check. Pinnacle is the name of the program, a simple java applet. Not only does Pinnacle log student's grades, but also attendance and conduct. The way grades are accessed are by inputting the first 6 digits of your social security number and the first 5 letters of your last name. With a logon system as simple as this, one has to question the security and privacy of the students. This has been making my life a living hell for the past 2 months, every night my parents go on and check to see if i have any homework and won't let me do anything till it's done"
This discussion has been archived. No new comments can be posted.

Pinnacle, Online Grades, Skipping School and More

Comments Filter:
  • already been done (Score:3, Informative)

    by odyrithm ( 461343 ) on Thursday April 10, 2003 @09:15AM (#5700748)
    ccm [ccmsoftware.com] have done this for years with ePortal.
  • by Anonymous Coward on Thursday April 10, 2003 @09:16AM (#5700757)

    I a Customer who uses this *thing*. It has a Win32 "thick client" that back-ends into a Sybase SQL Anywhere database, and this Java client to allow external users to access the database. The dumb thing uses its own security database, so now when we add new teachers to the district-wide LDAP single-sign-on system, we also have to go manually add them to the "Pinnacle" database.


    The company that installed it into my Customer site encouraged teachers to use *hard* to guess passwords like their first names. Further, anybody with an ODBC driver for Sybase SQL Anywhere can just "connect" to the back-end database and "go at it". Couple this with the *rancid* filesystem permissions that the installer put on it ("Oh-- why is is a problem that any user can write to the directory where the "thick client" EXE is installed... Ho, hum."), and you've got a recipe for disaster...


    Oh, to be young again...


  • Re:So... (Score:2, Informative)

    by wo1verin3 ( 473094 ) on Thursday April 10, 2003 @11:45AM (#5702218) Homepage
    \windows\system32\drivers\etc\hosts
    127.0.0.1 stupidschool@stupidschoodomain.com

The use of money is all the advantage there is to having money. -- B. Franklin

Working...