<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Using BYU&#8217;s LDAP server in Address Book</title>
	<atom:link href="http://mac.byu.edu/2004/09/08/using-byus-ldap-server-in-address-book/feed/" rel="self" type="application/rss+xml" />
	<link>http://mac.byu.edu/2004/09/08/using-byus-ldap-server-in-address-book/</link>
	<description>A better way</description>
	<pubDate>Sat, 05 Jul 2008 00:52:03 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: Wade Preston Shearer</title>
		<link>http://mac.byu.edu/2004/09/08/using-byus-ldap-server-in-address-book/#comment-5</link>
		<dc:creator>Wade Preston Shearer</dc:creator>
		<pubDate>Fri, 08 Sep 2006 20:56:44 +0000</pubDate>
		<guid isPermaLink="false">http://mac.byu.edu/?p=101#comment-5</guid>
		<description>There is a major security issue with BYU's LDAP server. Since it does not require authentication, anyone from around the globe that chooses to connect to the LDAP server can harvest the entire database of names and phone numbers. I understand that no more information is made public here then each student has selected to make public in their profiles, but I do not think that that answer is acceptible. Personal information like this should be protected by default and only revealed at the specific request of each individual; not the other way around. We should have to take an extra step to make things public, not fight to keep it from being broadcast to the world and those that choose to abuse it.</description>
		<content:encoded><![CDATA[<p>There is a major security issue with BYU&#8217;s LDAP server. Since it does not require authentication, anyone from around the globe that chooses to connect to the LDAP server can harvest the entire database of names and phone numbers. I understand that no more information is made public here then each student has selected to make public in their profiles, but I do not think that that answer is acceptible. Personal information like this should be protected by default and only revealed at the specific request of each individual; not the other way around. We should have to take an extra step to make things public, not fight to keep it from being broadcast to the world and those that choose to abuse it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
