-
Notifications
You must be signed in to change notification settings - Fork 7
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add section about how to manage passwords #35
Comments
Some context: Since December, the Admin team has adopted But |
I analyzed the content of the on-boarding section and I feel like this section should be one of the first that a newcomer should read (since ALL his credentials should follow this security rules, even the first he will get from CAS) Actually the really first page, named What about feeling this page with some basic information on common topic that EVERYBODY should know when working in the lab:
When I on-board in companies or even in non-profit, it's really common to have these kind of documents before ANYTHING, just to put the basic and be sure that the newcomer understand the context in which it will evolve. After that it continue with the on-boarding issue and the different technical and theoric informations as we already have. @kousu @joshuacwnewton would you have some feedback since you worked on the on-boarding and know the lab ? |
Related to #23 |
Also related to the language policy too. |
I really agree that we should have a good baseline for everyone to start from. Personally, my experience getting onboarded was very chaotic, and I don't think it really finished until a year and a half in, so I constantly felt drowned in systems people expected me to be familiar with but wasn't. I would really like to see that improve so people, especially interns, don't feel so drowned. We had a discussion on Slack last summer about improving this, about looking at "lab manual"s that other labs have, which I summarized and started tracking in #25 (comment) I think password management (this issue) is a subset of Lab Manual (that issue). They certainly need to be fit together smoothly. Can we start with a separate password management page? It wouldn't have to be in the onboarding section, but we could link to it from onboarding saying "you must use one of these options". |
The lab has very sensitive data and we don't want lab members to write their password in files that could be found (we recently had an incident where a student pushed a VPN username and password on github).
So: we should have a section on the onboarding that explicitly says to not write username and password in plain text (even in local laptops), and use password manager platforms (eg: Apple's keychain, google password)
The text was updated successfully, but these errors were encountered: