Re: Re: New Online Payroll Service- ezSurePay

Date view Thread view Subject view Author view

From: David Kalins (dkalins@library.berkeley.edu)
Date: Tue Aug 28 2001 - 13:38:08 PDT


Greg and all -- This has been a very illuminating discussion, but have the
people who really need to hear this gotten the message? I.e., Assistant
Chancellor Cummins and the Payroll people and the Human Resources people
in general should be alerted that it's not good to announce to the whole
campus a service which violates campus security concerns. A discreet memo
from the SNS group, I would think, would be in order.

HR certainly should be alerted to the fact that they should not be using
a temporary certificate.

And it might not be a bad thing for them to hear about the concerns of our
community about "opting in" rather than "opting out".

So has anyone (viz. someone with campus clout!) addressed these issues
with Cummins or the HR groups? Thanks.

David Kalins, Library Systems Office

On Tue, 28 Aug 2001, Greg Small wrote:

> Micronet,
>
> The ezSurePay application is still using a VeriSign test certificate.
> I recommend that you not use this site until a bona fide certificate
> is obtained.
>
> Do not install the test certificate on your workstation. If you are not
> worried about privacy or authenticity, you may accept use of the
> certificate to display your SurePay form, but do not install the test
> certificate on your workstation (yes, I said it twice).
>
> You can not rely on the test certificate to assure security and privacy
> of the Web network connection or identification of the web server. The
> test certificates are issued by VeriSign without verification that the
> requester is authorized to use the common name (DNS host name) that is
> checked by your browser. Test certificates should not be used on web
> sites using real, private data (even just for testing).
>
> Greg Small gts@uclink.Berkeley.EDU
> Security Infrastructure Project Paranoia is good thinking!
> Workstation Software Support WSS/IST Systems Programmer for 34
> University of California at Berkeley years and it's still fun!
> 0--------1---------2---------3---------4---------5---------6---------7--
> "http://wssg.berkeley.edu/public/Projects/SecurityInfrastructure.html"
>
> > From other_978-owner@uclink4.berkeley.edu Tue Aug 21 19:18:42 2001
> >From: "John F. Cummins, Assistant Chancellor (Chancellor's Office)"
> ><calmailsupport@marble.berkeley.edu>
> >To: "Academic Senate Faculty, All Academic Titles, Staff":
> >
> >--------
> >August 22, 2001
> >
> >To: Faculty and Staff
> >
> >Re: New Online Payroll Service- ezSurePay
> >
> >I am pleased to announce that UC Berkeley faculty and staff can now
> >view their surepay earnings statements in a secure, online environment
> >using the new ezSurePay service from BAS/Business Services Payroll.
> >The web site address for EzSurePay is:
> >
> >http://bas.berkeley.edu/ezPayroll/ezSurePay/
>
>
> ------------------------------------------------------------------------
> The following was automatically added to this message by the list server:
>
> For information about Micronet, its meetings and events, and its
> mailing list, including information on subscribing and unsubscribing,
> see the Micronet Web site at <http://wss.berkeley.edu/micronet/>.
>

------------------------------------------------------------------------
The following was automatically added to this message by the list server:

For information about Micronet, its meetings and events, and its
mailing list, including information on subscribing and unsubscribing,
see the Micronet Web site at <http://wss.berkeley.edu/micronet/>.


Date view Thread view Subject view Author view

This archive was generated by hypermail 2b29 : Tue Aug 28 2001 - 13:40:28 PDT