LETTERS: ‘StalkerNet’ gets too up close and personal
March 2, 2010
In response to Justin Niichel’s letter, “Keep spam from filling inbox,” I agree that spam is a frustrating issue, and perhaps a little light can be cast on the reasons why. The list of student contact information is sold by the Office of the Registrar for a small fee. I have not confirmed whether they sell this information to non-ISU organizations, though I’ve been told they do.
Forgive me, we’re about to go technical here, but this is something students should know.
For those who are tech-savvy, grabbing your personal information from Iowa State’s servers is incredibly easy. Iowa State operates an LDAP server that is accessible from any computer with an internet connection. What is LDAP? Think of it like a giant YellowPages database. Iowa State keeps some student information in this database. What you see on the ISU Directory Information site (StalkerNet, as we all so affectionately call it) is most likely taken from this LDAP server.
ISU’s LDAP server can be accessed by anyone without any credentials or verification of the user’s identity. A savvy user, using some free software, can actually dump the entire database and keep it for whatever use they so choose. I’ve pulled my record to give you an example of the information in this database. Don’t worry about what these things all mean, just pay attention to what they actually contain:
uid: msulliv
cn: Matthew Edward Sullivan
cn: Matthew E Sullivan
cn: Matthew Sullivan
displayName: Matthew Edward Sullivan
sn: Sullivan
givenName: Matthew
title: Matthew Edward Sullivan – student – MIS
ou: MIS
isuPersonCollegeAbbrev: BUS
isuPersonCollege: College of Business
isuPersonMajor: MIS
isuPersonStudentMajor: MIS
isuPersonStatus: active
isuPersonMiddleInitial: E
isuPersonMiddleName: Edward
userClass: student
telephoneNumber: +1 641 xxx xxxx
postalAddress: 3323 Frederiksen Ct $ $ Ames IA $ 50010
postOfficeBox:
street: 3323 Frederiksen Ct
l: Ames
st: IA
postalCode: 50010
mail: [email protected]
homePhone:
homePostalAddress: 240 N Miles St $ $ Fremont IA $ 52561
eduPersonAffiliation: student
eduPersonPrimaryAffiliation: student
eduPersonOrgDN: o=Iowa State University, dc=iastate, dc=edu
eduPersonOrgUnitDN: ou=MIS, o=Iowa State University, dc=iastate, dc=edu
eduPersonPrincipalName: [email protected]
Not only could an organization send me spam to my e-mail from these public records, but they could also to my apartment in Freddy, or my parents’ home in small-town Iowa.
Seems a little bit much, don’t you think?
Matthew Sullivan is a junior in management information systems.