How do you do....it? Thread, Python IDLE in Technical; We're looking to install Python with the IDLE into some of our ICT suites so the students can do some ...
23rd May 2012, 10:58 AM #1
We're looking to install Python with the IDLE into some of our ICT suites so the students can do some programming. Sounds great but has anyone done this and if so what issues have you have with security policies etc?
My concern is that Python will not obey ntfs permissions/group policies etc correctly and students could write scripts to access system files and so on, not being a Python programmer I've not had a lot to do with it!
I'm all for getting the students programming but I'm conscious of the pitfalls.
IDG Tech News
23rd May 2012, 11:22 AM #2
Python is like any other windows program. It has to obey ntfs permissions. The only problems are if the permissions arn't set properly, or when code is submitted to a teacher. If a teacher (or admin) runs a students program, then it will run with the teachers permissions. Practically I don't think there is much chance of this being a problem, but the risk is there. The best solution to that is if the member of staff reads the code before running it. most stuff should be obvious.
23rd May 2012, 11:59 AM #3
Thats a good start anyway - I had intended to put a windows firewall rule in to block python.exe from any network access as they don't need to do it.
I'm not being deliberately awkward, but we do need to pre-empt any problems that can causes issues. Teachers and students have broadly similar permissions on networked PCs anyway so that shouldn't be too much of an issue.
23rd May 2012, 12:02 PM #4
Yeah you are... but that's your job
Originally Posted by Sheridan
I'm following this with interest as i'm doing some reading try to pre-empt the inevitable. The ICT guys are dabbling with KODU and scratch, but it's only a matter of time!
23rd May 2012, 12:08 PM #5
We already have scratch in use and Kodu is being looked at (althought that seems pretty safe anyway)
We also looked into the Pi's - but availability seems to be an issue!
23rd May 2012, 12:10 PM #6
Indeed... I'm still waiting for my Pi, when it arrives we'll sit down and work out if we can create a scheme of work to use it.
23rd May 2012, 12:35 PM #7
Actually if the python IDE does obey NTFS permissions, and I block python.exe from any network traffic that would probably secure it enough for most users.
Not being a python programmer I haven't got the knowledge to test it, bit of a VB man myself!
23rd May 2012, 12:57 PM #8
I doubt they would be able to do much damage with network stuff. I would be more concerned with running other programs, using the subprocess module or the os module. But this is common to most, if not all, other serious programming languages. It probably depends on your staff and students as to how much you need to secure it. In terms of security, python and vb have fairly similar security issues.
I'm also waiting on my pi.
23rd May 2012, 01:33 PM #9
Yes thats the bit I don't understand. Policy prevents them from running regedit (for example) but does that mean it could be started from python instead?
1st August 2012, 06:24 PM #10
- Rep Power
Hey..just curious on the latest with this? We've been asked to roll out Python...but I'm looking for the security holes too...
2nd August 2012, 01:57 AM #11
Your probably not programmers so I'll explain
If you give people a tool (such as sharp knives or Python) then what you need is for people to take responsibility for using them - trying to restrict their usage (such as anchoring the knives via a piece of chain to a table or restricting permissions on share access) negates the usefulness of the tool.
What you need is social behaviour policies/rules/policing/sanctions not physical restrictions
Thanks to SimpleSi from:
CyberNerd (7th December 2012)
3rd August 2012, 10:18 PM #12
- Rep Power
6th August 2012, 01:15 PM #13
- Rep Power
Cheers SimpleSi...but in a school it is simplier said than done...
10th October 2012, 06:53 PM #14
- Rep Power
We are looking at rolling out python to some areas for same reasons.
I acknowledge SimpleSi's principle and this will apply in 95+% cases at our school. However every so often we get someone who wants to 'experiment' (not a bad thing), but they may also be someone who knows less than they think they do and/or someone who is relatively immature in applying such principles (the nature of [some] school students).
So - just wondering if people have now tried this, before we have a go and reinvent the wheel.
Also if any particular distribution of python is better to deploy on a curriculum network than others ('vanilla', ActiveState, Portable etc) and any pitfalls to avoid ....
[personally prefer PyScripter to IDLE]
Last edited by bede; 10th October 2012 at 07:06 PM.
7th December 2012, 07:24 PM #15
- Rep Power
Hi, "It's only a matter of time...I think you are right.
I have asked our technicians (yes I'm a teacher - just ducking to avoid shrapnel now) to install Python (IDLE) and it is blocked by group policy for everyone except Admin. We were not sure why. Can anyone help us?
Also I was not sure whether the Python IDLE runs an executable if you stay within the IDE.
Up to know we have been doing all our "proper" programming using JAVA so this issue has been avoided.
Any pointers appreciated.
By CyberNerd in forum Scripts
Last Post: 13th August 2009, 01:56 PM
By Quackers in forum Windows
Last Post: 18th October 2007, 03:43 PM
By CyberNerd in forum Coding
Last Post: 14th December 2006, 02:18 PM
By sidewinder in forum Wireless Networks
Last Post: 9th November 2006, 10:37 AM
By nuttygeek in forum Windows
Last Post: 22nd March 2006, 10:51 AM
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)