A ten-week field audit of café Wi-Fi password chalkboards finds a third running months out of date despite a stated rotation policy.
Ten weeks auditing forty-six chalkboards found a third running a password no one had rotated in months.
A password chalked once and never revisited is not a security failure so much as an administrative one — and for ten weeks, a School of Emergent Priorities team treated forty-six café Wi-Fi boards as exactly the kind of overlooked register nobody had thought to audit. The University considers the resulting taxonomy a modest but useful addition to its long-running interest in credentials nobody thinks to check twice.
A chalkboard doesn’t file an incident report when it goes stale. Nothing tells you the promise has lapsed until you go and check it yourself, which is exactly what nobody was doing.
— Dr Marek Solheim, Lecturer and Deputy Convenor, Horizon Register
Over ten weeks, the team photographed each board weekly, verified the displayed password against the live network, and checked it against whatever rotation policy — written or simply remembered — the venue said it followed. Where the two diverged, the board was classified into one of five standing categories: current, stale, illegible, wrong, or absent. Interruption counts, logged during fixed thirty-minute counter windows, tracked which boards were actually costing staff time to explain.
“An indicator earns its keep by being checked, not by being posted,” said Dr Renke Sabel, Senior Lecturer and Convenor of the Indicator Commons. “A chalkboard is as much an indicator as anything on a dashboard, once someone is relying on it.”
The full poster is available from the University’s research repository under an open licence, doi:10.5555/slop.8avp7t.