Patron Registration - Not Obvious Last 4 of Phone Used for Password

Bug #1817357 reported by Robert J Jackson
20
This bug affects 4 people
Affects Status Importance Assigned to Milestone
Evergreen
New
Wishlist
Unassigned

Bug Description

webclient 3.2

When a site sets the "Patron: password from phone #" in library settings editor it is not clear that the last 4 of the phone number is being used.

Would be good to leave the pwd field blank in this case until the phone number is entered.

description: updated
Revision history for this message
Terran McCanna (tmccanna) wrote :

+1

Changed in evergreen:
importance: Undecided → Wishlist
tags: added: patron
Revision history for this message
Nathan Eady (mrmcquack) wrote :

Any four-digit number would be a ridiculously insecure password, and the last four digits of a phone number is even worse. If a patron specifically tells me, "set my password to 1234", that's one thing; but automatically doing this sort of thing without an explicit say-so from the patron is borderline criminal in states with privacy laws. The patron thinks they've signed up to check items out from the library, and in fact they've signed up to donate a list of all the books they've checked out to anyone who can look up or guess the last four digits of their phone number.

Revision history for this message
Lugene Shelly (lugene) wrote :

In my experience, libraries choose the last four of phone option at migration because it is easy for the patron to remember when they first login to their account. I agree that the last four of the phone is not a secure choice, but the patron always has the option to use the phone number for their first OPAC login, and change it after that. In fact, that should always be a standard follow through, even if a random password is generated at login. That password is not secure either because the library staff member who registered the patron knows what it is.

As for the original post, I agree that some staff may be unaware that the password will change when a phone number is entered, and give the patron the incorrect password. It would be helpful if there was some way to manage that in the registration screen.

Lynn Floyd (lfloyd)
tags: added: orgunitsettings
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.