[WG: Sakai QA] Changes to display of potentially sensitive data
Oliver Heyer
oliver at media.berkeley.edu
Tue Sep 1 16:26:45 PDT 2009
UCB's recent upgrade to 2.6 has gone quite smoothly. Thanks again to
everyone who worked so hard to put the release together.
One 2.6 change to the default behavior of the Forums tool described in
http://jira.sakaiproject.org/browse/SAK-12427 did catch us a bit off
guard. The UCB Sakai instance is configured to show the SID as the
displayID for disambiguation, since the campus long ago made a decision
to use EIDs that are not generally well known to our end users. The SID
numbers are still considered private data at UCB, so we expose them only
to instructors. The privacy issue was raised and addressed through
http://jira.sakaiproject.org/browse/SAK-16445, but, unfortunately, we
missed the discussion in this and the other JIRA. We do have a local QA
process, although our team is small, and they can cover only so much.
I'd like to appeal to those seriously considering any work affecting the
display of potentially sensitive user data to raise these prospective
changes on one of the lists for discussion. Clearly, that would not
guarantee anything, but it does provide an extra bit of notice that
could help forestall the kind of situation UCB briefly found itself in.
Thanks,
Oliver
--
Oliver Heyer
Manager, Learning Systems Group
Educational Technology Services
U.C. Berkeley
(510) 529-5177
More information about the sakai-qa
mailing list