[WG: Sakai QA] Changes to display of potentially sensitive data

Oliver Heyer oliver at media.berkeley.edu
Tue Sep 1 16:26:45 PDT 2009


UCB's recent upgrade to 2.6 has gone quite smoothly. Thanks again to 
everyone who worked so hard to put the release together.

One 2.6 change to the default behavior of the Forums tool described in  
http://jira.sakaiproject.org/browse/SAK-12427 did catch us a bit off 
guard. The UCB Sakai instance is configured to show the SID as the 
displayID for disambiguation, since the campus long ago made a decision 
to use EIDs that are not generally well known to our end users. The SID 
numbers are still considered private data at UCB, so we expose them only 
to instructors. The privacy issue was raised and addressed through 
http://jira.sakaiproject.org/browse/SAK-16445, but, unfortunately, we 
missed the discussion in this and the other JIRA.  We do have a local QA 
process, although our team is small, and they can cover only so much.

I'd like to appeal to those seriously considering any work affecting the 
display of potentially sensitive user data to raise these prospective 
changes on one of the lists for discussion. Clearly, that would not 
guarantee anything, but it does provide an extra bit of notice that 
could help forestall the kind of situation UCB briefly found itself in. 
Thanks,

Oliver


-- 
Oliver Heyer
Manager, Learning Systems Group
Educational Technology Services
U.C. Berkeley
(510) 529-5177



More information about the sakai-qa mailing list