Jump to content

Recommended Posts

Posted
On a personal note (I know this isn't scalable at an organisational level) I use truecrypt and encrypt my data before it hits dropbox. Its an extra step, but I know my data is safe and secure that way.
Posted

I have asked my LEA several times now, each time no answer other than "Be a little careful with Dropbox "!

 

Okay, I'm being very lax with my quoting, but what alternatives to dropbox are there that give the same freedom and functionality?

Posted
AeroFS. Once it's out of beta, I'm ditching Dropbox for good!

 

Because AeroFS is completely distributed, even if we experience downtime, you won't!

 

So if non of your "friends" computers are on where does it sync to?

 

Are all your "friends" signed up with safe harbour?

 

Not sure I like it for a school

Posted

If you are looking at free (or at least no cost in licence or contract) then at the moment the only thing I can point to that I have not come across any show stopping concerns is SkyDrive. There are UK based firms with UK based data centres which can do commercial offerings (and so fit in with DPA, etc) but I don't have a list of those ... and with my day-job hat on ... I can't recommend any of them anyway.

 

Some VLE / Learning Platform providers will provide storage, but I am not aware of any who will do anything that does automated synchronising, other than Sharepoint-based options with synching document libraries ... again, YMMV on how good the performance is on these.

 

I know of some schools who have been using RSYNC or other synching solutions, but I am not aware of anyone getting these running over the tinterweb in a happy manner ... but I am prepared to be pleasantly surprised (if anyone from Open Source Schools is about they may have examples).

 

LAs are often a tad reluctant to give categoric information, especially if you don't buy advice from their legal service / information management / etc ... and the cost of some teams within an LA getting a definitive answer from legal folk is outside of available budgets (if they still have a budget ... which I don't!).

Posted
AeroFS. Once it's out of beta, I'm ditching Dropbox for good!

 

@GrumbleDook. You may find this useful (slide 16 onwards)...

fak3r » DEFCON 19: Taking your ball and going home

 

I had tried to steer clear of some of these points and purely take items based on DPA as why it is an issue. I like the look of LipSync and can see how it could be good in a school (synching back to school servers) and hope to see what it develops into.

Posted

to paraphrase...

DP - Its a sad, sad situation. And its getting more and more absurd :(

 

and

 

for evil to triumph, all its needs is for good men to stand idle (a bit OTT I realise [like the article :) ] - but I couldn't come up with a good alternative!)

 

Lets worry about important things!

 

Si

Posted (edited)
So if none of your "friends" computers are on where does it sync to?

Nowhere, if you have the cloud backup feature turned off.

 

Are all your "friends" signed up with safe harbour?

The main advantage to AeroFS is that you can sync files between two or more computers without your data being stored (temporarily or permanently) in a random data centre somewhere in the world. It works exactly like Dropbox except you have far more control over where your files are located.

 

The files are transferred directly between computers via an encrypted connection without passing through a middleman. Your friends could simply be "me, myself and I" (there's nothing stopping you from setting up multiple accounts). ;)

Edited by Arthur
  • Thanks 1
Posted (edited)

I don't believe that even SkyDrive meets the criteria, I understand that the US "Patriot Act" trumps all others if the company or subsidiaries are US owned.

This means that any Microsoft owned service can be accessed at any time id the US so desires.

 

I know that the need a good reason to look, but -Nothing- will stop them if the want to see your data.

Search "patriot act data protection uk"

Just one of may links:Data Protection and the Patriot Act

 

I am not concerned for my own rather boring collection of scripts and so on that I store in DropBox, SkyDrive or where-ever, but students, (or even staff), personally identifiabled information should NEVER be stored outside the school without being heavily encrypted.Even things like Sims Learning Gateway, E-portal accessible from the CMIS VLE offering worry me.

 

BoX

Edited by box_l
formatting
Posted

I have asked for clarification re Patriot Act but from what I had previously been told during DPA discussions the reference to accessing data from EU customers is when it is already outside of the EEA, i.e. if the data centres used are in the US. With DropBox we don't know what they are using or where. They say Amazon ... but nothing guaranteed. At least with SkyDrive we know it is within the EEA (Ireland and fail over to the Netherlands IIRC)

 

If the Data Centres are in EEA and are run within the EEA then any seizure of data is the a factual breach of DPA. A company cannot transfer the data from within the EEA to outside of the EEA without your consent, even if the Patriot Act is used. To do so would mean that an individual is being forced by the US authority to breach the laws of another country, ... and if you consider the number of companies who operate on Govt contracts who have US sections (or are US based) then there could be a royal bun fight should it be tried.

 

But, as I have said, I have asked for clarification on that.

Posted (edited)
I know of some schools who have been using RSYNC or other synching solutions

 

Why does a school need to use any kind of syncing solution in the first place? Surely users either want direct access to their file area or, ideally (especially for staff handling pupil data and so on), a remote access solution that lets them edit their files using the school's system. That could be something a bit cludgy like letting them access an RDP desktop, or do it peoperly and make your system web-based. The fewer files containing pupil data you have wandering around outside the school the better.

Edited by dhicks
Posted

@dhicks I am with you on this one. I really don't like the thought of all this data flowing backwards and forwards. Do you ever really know who is accessing it and where it is ending up?

 

For access to data, I'd much rather use something like XenApp that can prevent data being saved and printed over the remote connection. You will never get around the fact that people can steal anything that you need your eyes to read but it does limit opportunities. Plus all your data stays on your systems.

 

Of course, this does then open up the question of cloud-based backup but I imagine 'free' solutions are too limited for this anyway.

Posted
Why does a school need to use any kind of syncing solution in the first place? Surely users either want direct access to their file area or, ideally (especially for staff handling pupil data and so on), a remote access solution that lets them edit their files using the school's system. That could be something a bit cludgy like letting them access an RDP desktop, or do it peoperly and make your system web-based. The fewer files containing pupil data you have wandering around outside the school the better.

 

There is a presumption that people will never work offline, will never work on multiple devices and that people are happy to spend time uploading files in that response ... or am I wrong? Most people like the use of the file sync / file storage tools because it automates a lot of work for them. Being able to share a folder ( and contents) with specific people has its benefits, and being able to automatically distribute changes is something that has a fair bit of precedent. Yes, there are concerns about *what* people put in the folders as well, but that is a user-education piece of work and exists anyway, without having to consider the security implications of any particular tool / technology. I also think you mentioned an important word in your response ... cludgy. Are we still in the age where we think people will accept cludgy or reduced functionality? Every time we make it difficult and overly complex for a user do do something we put back the cause of IT as a ubiquitous tool that simply works. It is one thing to do it for a specific security reason, but when there could be solutions out there to do what is needed that *aren't* a bit Heath-Robinson then it sometimes comes down to the simple matter of time / cost / training ... except that it is never that simple when you introduce those three.

 

File sync tools and online file storage are being pushed as an alternative to all those USB memory devices being moved around (usually unencrypted devices too) ... if you make it awkward then people will just go back to using (and losing) them instead.

  • Thanks 2
Posted

Regarding Patriot Act vs EU Data Protection - look at it from the point of view of a US company. On one hand they have the UK/EU saying 'you've agreed to follow EU data protection rules' and on the other you have the US government saying 'hand over the data else your CEO and board of directors will end up in Guantanamo bay'. I know the example is ridiculous but it highlights my point here - for a US company, the Patriot Act will always trump third party country rules.I have reservations about these services, but have just adopted an already in place google apps installation at my new school. When I get a moment, I will highlight my concerns.However, as an institution it is also a risk management exercise. What is the likelihood that the data held on the US servers will ever be requested under the Patriot Act? I'd estimate 'so low, you're more likely to get hit by lightning 1000 times in a row'...

Posted

@localzuk

I know the risk is likely to be low, but it has to at least be registered as a risk ... something that I can see falling through the gaps in a number of institutes.

 

Also, having spoken with the ICO Helpline and getting advice from the Policy Unit (nothing definitive) it is likely that a company would not release under The Patriot Act, but under Section 35 of the DPA (as part of legal proceedings) ... the same clause that can be invoked when UK authorities required data held overseas.

 

I am still investigating as having spoken to 2 companies who deal with similar services but for other sections of the public sector, they have said that DPA is only one aspect of protecting data. I might see if I can prod @Drummer_Boy for a chat about it.

Posted
@localzuk

I know the risk is likely to be low, but it has to at least be registered as a risk ... something that I can see falling through the gaps in a number of institutes.

 

Also, having spoken with the ICO Helpline and getting advice from the Policy Unit (nothing definitive) it is likely that a company would not release under The Patriot Act, but under Section 35 of the DPA (as part of legal proceedings) ... the same clause that can be invoked when UK authorities required data held overseas.

 

I am still investigating as having spoken to 2 companies who deal with similar services but for other sections of the public sector, they have said that DPA is only one aspect of protecting data. I might see if I can prod @Drummer_Boy for a chat about it.

 

Indeed. There are many other possible issues with external hosting that aren't specific to foreign data centres as well too - such as collateral damage from law enforcement raids. I know of at least 2 raids on data centres which had hundreds of servers confiscated as part of investigations by the FBI and police in 2 different countries - one of which is in the EU.

 

Sure, they were targeting a specific user of those servers, but the knock on effect was hundreds of businesses were effected. In the USA, a raid caused multiple businesses to go out of business.

 

Hence my trepidation at cloud services for file storage. Its also why I use a sync service for my work email, and will be getting everyone else to implement it at some point to ensure data continuity.

 

Risk management, as you say, isn't about ignoring unlikely issues, its about adding them to your risk assessment and planning accordingly - even if the plan is 'do nothing, as the cost of alternative provision is unaffordable'.

  • Thanks 2
Posted

I've seen this argument thrown back and forth with regards to DropBox, this is a simple answer. SugarSync IMO is just as good, and DOES comply with the Safeharbour Frameworkhttps://www.sugarsync.com/privacy.htmlIt allows you so specify which folders to sync (not just the one "DropBox" folder) and also allows you to sync specific with specific multiple computers. I think you may also get more storage as standard.

Posted
I've seen this argument thrown back and forth with regards to DropBox, this is a simple answer. SugarSync IMO is just as good, and DOES comply with the Safeharbour Frameworkhttps://www.sugarsync.com/privacy.htmlIt allows you so specify which folders to sync (not just the one "DropBox" folder) and also allows you to sync specific with specific multiple computers. I think you may also get more storage as standard.

 

Kinda expensive... $299 a year for 3 users.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...