...
1.
...
Background
...
The
...
High
...
Impact
...
Data
...
Protection
...
(HIDP)
...
project
...
team
...
was
...
convened
...
in
...
late
...
July
...
2008
...
to
...
determine
...
a
...
solution
...
to
...
mitigate
...
the
...
threat
...
to
...
sensitive
...
Institute
...
data
...
posed
...
by
...
lost
...
or
...
stolen
...
portable
...
devices
...
(laptop
...
computers
...
and
...
mobile
...
devices).
...
PGP's
...
Whole
...
Disk
...
Encryption
...
(WDE)
...
product
...
has
...
been
...
chosen
...
as
...
the
...
best
...
solution,
...
and
...
a
...
deployment
...
plan
...
is
...
currently
...
under
...
development,
...
focusing
...
on
...
a
...
targeted
...
set
...
of
...
MIT
...
users
...
with
...
access
...
to
...
sensitive
...
data.
...
2.
...
Findings
...
- LDAP
...
- Dependency
...
There
...
- is
...
- concern
...
- over
...
- the
...
- assumption
...
- that
...
- LDAP
...
- authentication
...
- utilizing
...
- Kerberos
...
- passwords
...
- will
...
- be
...
- available
...
- for
...
- roll
...
- out
...
- as
...
- the
...
- current
...
- ldap.mit.edu
...
- infrastructure
...
- does
...
- not
...
- support
...
- this
...
- method
...
- of
...
- authentication.
...
- The
...
- next
...
- generation
...
- directory
...
- system
...
- may
...
- support
...
- such
...
- authentications,
...
- but
...
- issues
...
- around
...
- access
...
- and
...
- proper
...
- use
...
- must
...
- be
...
- addressed
...
- before
...
- it
...
- can
...
- be enabled.
3. Recommendation from the TAP Consultation
Note |
---|
"Approved with Concerns": |