24 November 2008

Register as Alumni Need a new identity?[More:] So this private school that I spent 8 years of my life at will allow you to register on the site as any one of the graduates from the past 41 years. Just pick a name, (best to check that it hasn't already been registered) enter your email and desired password and go!

I didn't graduate from the school, so I'm not listed as an option.
Wha...? That is messed up.
posted by amro 24 November | 13:26
Ok, that's nuts.
posted by ThePinkSuperhero 24 November | 13:32
This may not last long. It could be a serious security compromise for, say, some rich guy who needs to be discrete and doesn't need the world knowing his history. Should be interesting.

(Insert jokes about Episcopalians here)
posted by Melismata 24 November | 13:35

To protect your identity, do not share your Password or Secret Answer with anyone. ... We'll share your full name for you.
posted by danostuporstar 24 November | 13:35
posted by Melismata 24 November | 13:37
I've emailed the webfriar (who just happens to be a person that I grew up with at that school) to tell him of the potential serious problem.
I appreciate their literal interpretation of the definition for alumnus, but I also think it's kind of snotty[typical of everything I ever experienced there] that they would only allow you to register if you actually graduated from the 12th grade.
posted by Medium Format 24 November | 13:42
This is a serious security issue, and considering that that's true, I don't think we should be linking to the site as it stands. I hope the mods will remove the link.
posted by ThePinkSuperhero 24 November | 13:45
Yeah... I don't think we want to advertise that specific hole here, so I removed the link (and also the specific Name/Year that was mentioned). but I had a look, and yes - totally wide open. eek.
posted by taz 24 November | 14:57
Well, I'd back off of "serious" as it's not clear that there's anything of value here beyond a small-pond version of It can be astonishingly easy to get class lists (see the aforementioned) and even a requirement that you enter your name and class year would be something someone could overcome. But somebody could wreak prank-level havoc if they wanted to, and I suppose someone could use the site to phish someone as a "fellow classmate" or whatever.

So, a bit dumb, but I dunno that I'm up in arms about it.
posted by stilicho 24 November | 14:59
You're right, not really a "serious" risk as there wasn't much on the site that wasn't available for public consumption anyway, but in the interest of protecting those that might unwittingly post personal information perhaps it's best that the link is removed. -30-
posted by Medium Format 24 November | 15:23
