Discuss Scratch
- leahcimto
-
Scratcher
1000+ posts
Student Account Default Passwords
When a teacher makes a student account, they have the choice to set the password for them (through .csv upload) or create accounts individually, where the password is set to the teacher's username automatically. Then, the user is forced to change the password after their first login.
This is unsecure for many reasons, such as if a user finds a new student account, they can easily guess that that account's password will be the teacher's username, and if correct, gain access to the student account. The account would be empty, and easy to reset, but it would be a better practice to ask the teacher to choose a default password that would be used to prompt the student to change their password, instead of risking unauthorized access.
In the image below you can see that when a teacher adds a student their password is set to the teacher's username.

This also happens if the teacher chooses to reset their password using a password prompt on their next login.

This is unsecure for many reasons, such as if a user finds a new student account, they can easily guess that that account's password will be the teacher's username, and if correct, gain access to the student account. The account would be empty, and easy to reset, but it would be a better practice to ask the teacher to choose a default password that would be used to prompt the student to change their password, instead of risking unauthorized access.
In the image below you can see that when a teacher adds a student their password is set to the teacher's username.

This also happens if the teacher chooses to reset their password using a password prompt on their next login.

Last edited by leahcimto (Jan. 8, 2024 23:56:30)
- unmissable
-
Scratcher
1000+ posts
Student Account Default Passwords
I was about to make a suggestion for this
SUPPORT, anyone can passguess accounts like this. What if a teacher makes a bunch of accounts but forgets to set the password of one?
SUPPORT, anyone can passguess accounts like this. What if a teacher makes a bunch of accounts but forgets to set the password of one?
- ilikescratch7169
-
Scratcher
59 posts
Student Account Default Passwords
Support. Students NEED to have their accounts secure at ALL times
- unmissable
-
Scratcher
1000+ posts
Student Account Default Passwords
Related to this, when a student is asked to change password I think it also resets to the teacher's username. I may be incorrect but I feel like this should also be added to the topic as it's similar enough
- RecessFailsOffical
-
Scratcher
1000+ posts
Student Account Default Passwords
Support for reasons in OP.
- EDawg2011
-
Scratcher
1000+ posts
Student Account Default Passwords
Support for reasons in OP.That's unconstructive.

“Sorry, you have to wait 60 seconds between posts.”
- EDawg2011
-
Scratcher
1000+ posts
Student Account Default Passwords
What if a teacher makes a bunch of accounts but forgets to set the password of one?Adding to @unmissable's post, if a teacher makes a ton of accounts, they wouldn't need to spend nearly as much time.

- leahcimto
-
Scratcher
1000+ posts
Student Account Default Passwords
Related to this, when a student is asked to change password I think it also resets to the teacher's username. I may be incorrect but I feel like this should also be added to the topic as it's similar enoughYes, this is true. I'll add that to the OP with a screenshot.
- -Rodri
-
Scratcher
1000+ posts
Student Account Default Passwords
support because this would make things way easier for teachers and some school programs already do this.
- 106809nes
-
Scratcher
1000+ posts
Student Account Default Passwords
*me realising my username has the initials of my schools name*
–
Semi-Support. It would get easier to hack student accounts and get them banned.
I'd say have an email sent to the teacher to log in.
- ajskateboarder
-
Scratcher
1000+ posts
Student Account Default Passwords
I'm going to note it's still quite hard to find teacher accounts without knowing the teacher's username, since those accounts aren't listed on class pages or individual student accounts. Still though, having the teacher choose an initial password for all students would obviously be more secure
Last edited by ajskateboarder (Jan. 9, 2024 00:12:53)
- Crispydogs101
-
Scratcher
1000+ posts
Student Account Default Passwords
Support. Security is important. Including school districts. In that case students can worry less about their work being ruined or even worse deleted.
- unmissable
-
Scratcher
1000+ posts
Student Account Default Passwords
I'm going to note it's still quite hard to find teacher accounts without knowing the teacher's username, since those accounts aren't listed on class pages or individual student accounts. Still though, having the teacher choose an initial password for all students would obviously be more secureNope!
By default, students follow teachers and vice versa (so they're extremely easy to find). I would know as my previous student account got passguessed because of this issue, and I only found out a few days ago.
- 106809nes
-
Scratcher
1000+ posts
Student Account Default Passwords
Support. Security is important. Including school districts. In that case students can worry less about their work being ruined or even worse deleted.
support because this would make things way easier for teachers and some school programs already do this.guys-
Semi-Support. It would get easier to hack student accounts and get them banned.
I'd say have an email sent to the teacher to log in.
- leahcimto
-
Scratcher
1000+ posts
Student Account Default Passwords
I disagree because the point of the default password is so the student can set their own password, not for the teacher for them.Support. Security is important. Including school districts. In that case students can worry less about their work being ruined or even worse deleted.support because this would make things way easier for teachers and some school programs already do this.guys-Semi-Support. It would get easier to hack student accounts and get them banned.
I'd say have an email sent to the teacher to log in.
- unmissable
-
Scratcher
1000+ posts
Student Account Default Passwords
Okay.Support. Security is important. Including school districts. In that case students can worry less about their work being ruined or even worse deleted.support because this would make things way easier for teachers and some school programs already do this.guys-Semi-Support. It would get easier to hack student accounts and get them banned.
I'd say have an email sent to the teacher to log in.
So you mean to say children with student accounts are dumber than children without student accounts? And that students won't make correct passwords?
Also, bump.
- kkidslogin
-
Scratcher
1000+ posts
Student Account Default Passwords
Support. This seems like a large security gap for students.









