Hi,
Sorry it has taken me a while to reply to this, but this is the reason we have blocked sparklebox.
We became aware on Monday of a site that is causing concern to other grids around the country – SparkleBox. I took the decision to add this to the blocked list on Monday because of the issues which have been brought to my attention. It appears that there are three key issues with the site:
1. The site is operating illegally in that the company operating the site has no registration with the Data Protection Registrar
2. The site signposts users to an un-trusted social networking site
3. The site offers the download of a toolbox with an unknown 'payload' – for example, the download could be collecting browsing history or initiate an internal attack on school systems immediately, or at some unknown future time.
We are currently investigating the toolbox in detail to see whether we can identify the exact nature of the threat, but there is a difficulty with anything like this in identifying what is buried in the code.
We feel that this threat needs to be taken seriously – and we do so not only with this website, but with any others that we have justifiable concerns about. Clearly, this website has a number of users in the region and I feel that this is an opportunity to re-state our position on threats such as these.
Clearly, teachers can still access the site by using the elevated logon, but we do think that any teachers who are tempted to do so should be made aware of the issues regarding its use – the installation of any ‘toolkit’ or browser toolbar carries a risk and may be a breach of existing acceptable use policies.
It may be an opportunity to point out to schools the existence of our ‘Guidance for creating a school eSafety policy’ and ‘End user AUP guidance’ which are available from
Policies / Schools / eSafety / YHGfL - YHGfL. We are also in the process of reviewing our local authority AUP with the Network and eLearning Groups and should be making detailed proposals to CAB in December.