{"id":459,"date":"2015-12-31T17:47:34","date_gmt":"2015-12-31T17:47:34","guid":{"rendered":"https:\/\/psblab.org\/?p=459"},"modified":"2015-12-31T17:50:13","modified_gmt":"2015-12-31T17:50:13","slug":"single-use-website-privacy-in-academia","status":"publish","type":"post","link":"https:\/\/psblab.org\/?p=459","title":{"rendered":"Single use website privacy in academia"},"content":{"rendered":"<p>It&#8217;s grad&#8217; school admissions time again (yay!) which means I&#8217;m knee-deep in requests for letters of recommendation. Just as an example, one student has requested letters for 7 different institutions. Writing the actual letters is not a big deal (hey Nick you owe me a beer!) but the websites some Universities use for admissions are a royal P.I.T.A.<\/p>\n<p>One such website (used by a mid-size college in that big metropolis near Cape Cod MA) is &#8220;<a href=\"https:\/\/evaluator.liaisoncas.com\/evaluator\/login\">LiasonCAS<\/a>&#8220;.\u00a0 The premise seems rather innocent and simple at first &#8211; the University uses such a site to coordinate the upload of application materials, so nothing gets lost along the way, and presumably this saves a lot of collating work that would have previously been done by a grad&#8217; school administrator. The problem is, there are hundreds of these sites, all commercially operated, and all requiring their own User ID \/ Password combination.\u00a0 This creates 2 problems&#8230;<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Problem 1 &#8211; too many passwords<\/strong><\/span><\/p>\n<p>I&#8217;m a strong believer in never using the same password twice, hence my reliance on the open source <a href=\"http:\/\/keepass.info\/\">KeePass <\/a>application, which stores passwords (typically random strings of 20+ characters) in an encrypted file. All told, I have 200+ unique log in IDs. Just to emphasize the size of the problem here, I recently consolidated my logins for Elsevier journals into a single user ID, and it broke the portal set up to do this. It turns out I had reviewed for 37 separate Elsevier journals over the years, and some extensive &#8216;phone tech support was required to give me a single account to manage them all.<\/p>\n<p>So the problem here is <em>do I really want to register for yet another website<\/em>, create a unique user ID, have all my contact info&#8217; out there in the cloud?\u00a0 Am I ever going to use this website again?\u00a0 Probably not, which means it&#8217;ll just sit there waiting to be hacked a decade from now, resulting in a bunch of spam and junk-mail or &#8216;nuisance phone calls. Over the years, on top of the 200+ login UN\/PW combo&#8217;s mentioned above, I would guess I&#8217;ve accumulated at least that number again in single-use website visits.\u00a0 This is not good for security.\u00a0 And no, it&#8217;s not as simple as me going to the trouble of making another 200+ unique UN\/PW combos for all these sites. I don&#8217;t want a KeePass database filled with junk.<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Problem 2 &#8211; Draconian privacy policies<\/strong><\/span><\/p>\n<p>Like most admissions portals, the one mentioned above requires that you agree to their <a href=\"http:\/\/help.unicas.com:8888\/unicasHelpPages\/evaluator-instructions\/privacy-policy\/index.html\">privacy policy<\/a> as a condition of signing up for the privilege of submitting materials.\u00a0 Most people breeze through these things when signing up for a site, which is no big deal if you&#8217;re going to use it regularly and it&#8217;s a necessity for your job. Apple&#8217;s iTunes EULA is notoriously squirrely about privacy issues, but if you wanna use an iPhone, deal with it.<\/p>\n<p>However, in the case of a single-use site, these policies need a bit more scrutiny. What exactly are you agreeing to, for this one-time use?\u00a0 Here&#8217;s the section from LiasonCAS&#8217; policy on what they (the site owner and the University by extension) can do with your information. There&#8217;s a bunch of guff about using your contact info&#8217; for contests, surveys and promotions, which is worrying in itself. But then there&#8217;s this:<\/p>\n<p style=\"padding-left: 30px;\"><span style=\"text-decoration: underline;\"><b>3.10. Other Uses.<\/b> <\/span>In addition to the uses specifically identified in this Section 3 (Our Uses of Your Personal Information), we may use Personal Information you submit in any other manner we reasonably deem necessary in order to provide you with the information, products and services you request from us&#8230;.<\/p>\n<p>Essentially what they&#8217;re saying here, is they can do what the hell they like with your data, so long as they can write it off as &#8220;necessary&#8221; for the service you request.\u00a0 What you&#8217;re requesting of course, is the privilege of uploading stuff for admissions. And the price you pay is them having the freedom to shill your data out to their spammy partners under the guise of necessity.<\/p>\n<p>This is not cool.<\/p>\n<p>So what to do instead? In this case I found the email address of the Dean for the graduate school in question, and emailed them the letter directly. Sure, it took another 5 minutes but at least all my personal contact info isn&#8217;t sitting out there on some nondescript company&#8217;s website waiting to be sold.<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>New Year&#8217;s Resolution<\/strong><\/span> for academics &#8211; fight the requirement to create a new User ID \/ Password for any website that you know you&#8217;ll probably never use again.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s grad&#8217; school admissions time again (yay!) which means I&#8217;m knee-deep in requests for letters of recommendation. Just as an example, one student has requested letters for 7 different institutions. Writing the actual letters is not a big deal (hey &hellip; <a href=\"https:\/\/psblab.org\/?p=459\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-459","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/psblab.org\/index.php?rest_route=\/wp\/v2\/posts\/459","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/psblab.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/psblab.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/psblab.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/psblab.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=459"}],"version-history":[{"count":3,"href":"https:\/\/psblab.org\/index.php?rest_route=\/wp\/v2\/posts\/459\/revisions"}],"predecessor-version":[{"id":462,"href":"https:\/\/psblab.org\/index.php?rest_route=\/wp\/v2\/posts\/459\/revisions\/462"}],"wp:attachment":[{"href":"https:\/\/psblab.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/psblab.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/psblab.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}