Jump to content

Recommended Posts

Posted

Well, today my FB account was logged out on my phone and when I went to log in again it wanted me to upload a photocopy of my driving license, well..................I didn't and now I am FB free yeeha!!

 

They can have my account but not my ID sorry FB but this is a bridge too far!!

Posted
Ha! You should have paid the £5.99 instead, then they don't need your driving license. Or you could simply copy and paste the agreement in to your status and tell everyone else to I think.
Posted
Well, today my FB account was logged out on my phone and when I went to log in again it wanted me to upload a photocopy of my driving license, well..................I didn't and now I am FB free yeeha!!

 

They can have my account but not my ID sorry FB but this is a bridge too far!!

 

Am I missing something? Why on earth would they need that? Or at least, what's their excuse?

Posted

Safe Harbor is going to take a hell of a beating over the next year, but it is mainly politics that is going on.

 

The recent pact for law enforcement to share data is one thing but this is going to cause all sorts of problems, especially for the ruling on whether data can be subpoenaed when held overseas Microsoft 'must release' data held on Dublin server - BBC News

 

Advice from experts for a number of years has been to complete some form of risk assessment when using a company via the Safe Harbor scheme. The most basic form of this is to see what they qualify as data in their entry in the register. An example would be a company that covers process of payment data ... doesn't cover data stored in files you host with them.

 

This is why EEA or UK sovereignty is important to a number of organisations.

 

This will run for some time (appeals, etc) but at this point, I would advise people to investigate how much data goes overseas and how much stays with UK and/or EEA. Measure the risk, try to work out what you would do if you *have* to change, and let your SLT know that there *could* be an issue further down the line.

 

As always, make a call to the ICO helpline for initial advice but be prepared for a holding answer as they are unlikely to have a firm grasp on this as it is so new.

  • Thanks 2
Posted (edited)
Well, today my FB account was logged out on my phone and when I went to log in again it wanted me to upload a photocopy of my driving license, well..................I didn't and now I am FB free yeeha!!

 

They can have my account but not my ID sorry FB but this is a bridge too far!!

 

Likely you have been reported for (or automatically suspected of) using a pseudonym. Facebook hate fakes names, do you not recall the massive spat they had with transvestites using their stage names? Had a friend of mine who used a pseudonym in the US get reported for it and she had to provide ID to reclaim her account. She couldn't just put in her name (or any name, really) without having some evidence to back it up. I'm waiting for the day it happens to me, but I refuse to use my real name when I work in a school and have had in the past, children try to add me.

 

I know I can clamp down my privacy settings but they can still see my profile pictures, pictures of me other people have shared (if their privacy settings aren't up to scratch) and my.. I forget it's name. The big picture at the top. All of that is viewable by the public no matter how much I clamp my account down, and I'm not okay with that.

 

Edit: Back on topic, after reading the article, it doesn't come across as "Safe Habour is bad", more "We're okay with Safe Habour, you agree to protect the data and that's okay. But unfortunately your government doesn't agree to it, and they're forcing you to hand over the data. We understand that you have to hand over this data else your company is operating illegally. Because of this, we can't guarantee Safe Harbour is sufficient enough protection any more. So with that in mind, if you suspect your data has been mishandled, courts cannot refuse to investigate based upon the fact that the company in question has signed up to Safe Harbour."

Edited by Garacesh
  • Thanks 1
Posted
not really they have only just announced the ruling today that article is about what they expect to happen not what has happened

 

Yep, the 'opinion' that was released previously was for guidance ... and it has been pretty much taken on completely (including the rephrasing).

 

https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2015/10/ico-response-to-ecj-ruling-on-personal-data-to-us-safe-harbor/ is the latest statement from the ICO and I know that lawyers, etc. are working away on this for the big names.

 

Until I have firm advice on this anything I state will just be opinion, so I will leave it a bit until things are firmed up.

Posted
So does this mean we can't use OneDrive or Google Docs to store or transfer files anymore for fear of them getting slurped?
Posted
So does this mean we can't use OneDrive or Google Docs to store or transfer files anymore for fear of them getting slurped?

 

I think it means you need to re-do risk assessments, and include this new ruling in them. You can not just use "Safe Harbor" as a "yup, they comply" now. Instead, you would have to analyse the specific terms and conditions of the product and ensure they comply with the law. Safe Harbor was supposed to be a way of simplifying this really, but has turned out to be less than ideal.

 

Office 365 for Education is based in the EU, I'm pretty sure, except for shipping specific relevant information out when a support request is made (if I recall correctly, based on the info I was given when our LEA moved to it).

 

Google Docs - that's more of an issue. They do ship info out of the EU, and store it wherever they want to. So, any risk assessment will have to take that into account.

Posted
I don't have O365 Edu, only the home variant attached to an old former MSN Account.

 

Not really related to this issue then, as school business shouldn't be used via such accounts anyway.

Posted
Investigate this, risk assess that, certs smerts woffle poffle. If you really think any data about yourself is safe on-line then you will believe any bloke in a suite bullcrap you blind. If snowdons whistle told you anything its your 5 steps behind.

 

That's just the thing - it was Snowden's revelations that kicked this whole thing off. The complaint, I believe, was about Facebook shipping data to the USA, where it would be subject to NSA spying. In the EU, if our countries intercept the data, they have to comply with the EU laws on it all. If the USA were intercepting EU data without it actually having been sent to the US in the first place (ie. intercepting internationally), then they would be risking an international incident with whichever country they were fiddling with - just look at their phone taps in Germany and Brazil.

 

Sure, in reality things will be a lot of shades of grey, but the law is the law and it means you have recourse to prosecute if things are not done correctly.

Posted
Not really related to this issue then, as school business shouldn't be used via such accounts anyway.

 

What's stopping someone from using it for personal reasons? It's a glorified USB key at the end of the day, Microsoft intended people to use those accounts to take work home with them.

Posted
What's stopping someone from using it for personal reasons? It's a glorified USB key at the end of the day, Microsoft intended people to use those accounts to take work home with them.

 

Your policies. If staff are told "do not use personal accounts for work purposes" and they then do so, they would be breaking those policies and as such should be disciplined accordingly.

Posted
Guess I'd better delete my Edugeek account then since it's a personal account but I use it for networking and getting solutions for work...
Posted
Guess I'd better delete my Edugeek account then since it's a personal account but I use it for networking and getting solutions for work...

 

You're not transferring data protected by EU data protection laws by using Edugeek though, so that would be an odd thing to do.

Posted
...because there is nothing like a policy that protects the farm when horse has has already bolted.

 

Not really sure of your point. The entire concept of policies is the same as laws. Don't follow them and you reap the consequences.

Posted
...because there is nothing like a policy that protects the farm when horse has has already bolted.

 

but arnt those policies more about saying its his fault rather than actually stopping anything?

Posted
but arnt those policies more about saying its his fault rather than actually stopping anything?

 

They would do both. You have a policy saying "You must not use personal accounts, devices or services to transfer any data between school and home, including but not limited to personal email services such as Gmail or Outlook.com, personal file sharing services such as Dropbox and Google Drive, or personal phones".

 

That outlines the rules on how things should be done. You would also have your usual disciplinary procedure which handles non-compliance with any and all policies.

Posted (edited)

I think the keyword behind the policy-centric logic is "deterrant". It only takes one or two staff disciplinaries before the word starts to spread.

 

Essentially, and bearing human nature in mind, it's in the same way that having laws against murder or rape doesn't totally eradicate these problems, but I think it's true to say - however depressingly - that there would be a lot more of those things going on if the deterrant were not present.

Edited by Ephelyon
Posted (edited)
There are loads of threads on here about account/finance packages .. you name it ... and yet you honestly believe a few policies keep you safe and snug.

I don't subscribe to that thanks.

 

They keep you safe from being prosecuted yourself for not making whatever we might wearily describe as "reasonable efforts", yes. But again, it's more about saying these problems would be a lot more rampant without a deterrant in place - essentially it's all relative. At the end of the day, yes, some people will always do their own thing, so the most you can reasonably do is outline clearly what you expect and put consequences in place for those who flout the policies.

 

It's not a 100% foolproof solution, because there's no such thing, but it's still better than not putting such measures in place at all. I don't think anyone here is saying they seriously expect that just because they make a policy, everyone will follow it. It's more about how you deal with events post facto.

Edited by Ephelyon
Posted
Lets recap ...

 

Q) What's stopping someone from using it for personal reasons? It's a glorified USB key at the end of the day, Microsoft intended people to use those accounts to take work home with them.

 

A)Your policies. If staff are told "do not use personal accounts for work purposes" and they then do so, they would be breaking those policies and as such should be disciplined accordingly.

 

So its all trust based. How many times have you walked passed an unattended computer with a staff usb stick wedged in and just shake your head and walked on. How many staff didnt notice, how many people bothered to check, how many staff go around checking and are 'disciplined'? its all waffle.

 

There are loads of threads on here about account/finance packages .. you name it ... and yet you honestly believe a few policies keep you safe and snug.

I don't subscribe to that thanks.

 

Of course it is trust based. We can't go around holding everyone's hands, or watching over their shoulders to make sure they are complying. We can only do what is practical. I do not walk past unattended machines with things plugged in to them. They get locked, and the USB device removed. They then get sent an email.

 

You are arguing against the way our entire judicial system works. (Indeed, not just our system, pretty much every system). It all works by trust. Without that trust you become a fascist dictatorship - and that isn't a good way to run a business.

Posted

Having sat in on staff disciplinary sessions as an Independant Member, I can say that some schools are good at dealing with it.

 

Policies and procedures should be backed up by information and training.

 

Personal accounts are a big no-no for school business as there is no accountability ... for those areas where clear accountability and audit trail is needed!

Your EG account? A very minor risk and policies on professional conduct when 'representing' the school should deal with that.

 

Using personal accounts to share files? A big risk and should be squashed asap. Read my article on Dropbox to understand some of that.

 

Localzuk has covered the questions so far, but I am puzzled why people think that dealing with this is problem.

 

Schools that are rubbishy on data protection ... It will make no difference to them. They are still rubbish. Maybe the high profile story can help change things?

 

Schools that are good will have done due diligence and chosen someone doing more than just relying on Safe Harbor.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...