tmcd35 Posted December 19, 2013 Posted December 19, 2013 Of course there are also downsides such as Tracking individual users As mentioned above, we've just moved from central to local filtering. This is the biggest factor for us. Not so much individials (although there's already been a couple of occassions when that level has been handy), but groups. Our box is linked to our AD and we have three/four filtering groups. Staff get full YouTube, Students get YouTube Edu - for instance. I'd take a lot of convincing to allow an ISP control over our filtering ever again.
sparkeh Posted December 19, 2013 Posted December 19, 2013 Just playing devils adovocate here but some things that would be better if it was ISP level - No more problems with SSL web pages, or authentication issues I want people to authenticate, then we can track usage. - More reliable (not relying on a hardware box in your office) Debatable - we have had less filtering downtime from LA solution since switching to SW. No downtime actually. - Less cost (We currently spend about 3k a year on filtering) You can't say that as you have no idea how much this no existent service would cost - Simple to administer via web interface Again, as the service doesn't exist you can't say anthing about its ease of use. Of course there are also downsides such as Tracking individual users Different levels of access such as allowing youtube for staff and not students Firewall capabilities All of which mean its not suitable for use in school.
AngryTechnician Posted December 19, 2013 Posted December 19, 2013 I'm still not getting the resistance from many ICT professionals on filtering. My main concern is simply that I don't trust ISPs to get it right (now or any time soon). Even Smoothwall, as good as they are, sometimes end up with sites on the blocklist that shouldn't be. I suspect a lot of the resistance stems from a similar view.
tom_newton Posted December 19, 2013 Posted December 19, 2013 Just playing devils adovocate here but some things that would be better if it was ISP level - No more problems with SSL web pages, or authentication issues Same issues - just moved further away and harder to resolve. You either filter SSL or you don't. You can do it DNS based, but that gets old fast.
AngryTechnician Posted December 19, 2013 Posted December 19, 2013 You either filter SSL or you don't. You can do it DNS based, but that gets old fast. Right, and if they aren't doing it via DNS then they are MITMing customers, and I definitely do not want my ISP doing that.
zag Posted December 19, 2013 Author Posted December 19, 2013 My main concern is simply that I don't trust ISPs to get it right (now or any time soon). Even Smoothwall, as good as they are, sometimes end up with sites on the blocklist that shouldn't be. I suspect a lot of the resistance stems from a similar view. Wouldn't a manual override (whitelist) solve that issue completely?
tom_newton Posted December 19, 2013 Posted December 19, 2013 Right, and if they aren't doing it via DNS then they are MITMing customers, and I definitely do not want my ISP doing that. Did you know that google have begun effectively MITMing images sent to a gmail account? The Smoothwall Blog: Gmail Users: Google Makes Your Data More Secure, Owns a Bit More of Your Life
psydii Posted December 19, 2013 Posted December 19, 2013 Do we need local proxies? If the ISP can offer filtering differentiated by by user, group, time and host, probably not. LGfL has an astonishingly good network level filter that almost meets the above capabilities. If i were running a site small enough to be manageable on the default subnets they offer I would not bother with running my own. However the 'by user' functionality is lost because we use our own subnets. There is a site configurable 'block for unauthenticated' list, and if you try to access a site on the list you get asked to authenticate via a captive portal, and then the site is re-evaluated against what the site admin has allowed for your group. In general it is very very fast, impressive given the hundreds of thousands of simultaneous users . If I were building a new large LAN, I would be looking for products that could offer me what LGfL do, with a greater degree of access to logs (live and historical) and raw traffic. I'd even ask LGfL if they could add those features I needed for less that the purchase and maintenance price of the competition. That said I am really going to miss TMG.
sted Posted December 19, 2013 Posted December 19, 2013 The "powers that be"? As far as I know the filtering is controlled by the individual via a web interface. i was meaning this govenment one so they start saying you have you opt into catagories that kids shouldnt see but that measn the govenment is then supplying a list of what is/isnt acceptable. Whats to stop them adding to that list over time so say they deem (as a random stupid example) nobody should know about car modification there is already a system in place to block pron why not add it to that? So what starts out as something with vaugely good intentions turns into a way to filter what the populace can see. I also suspect that people who opt in to getting fuilters removed will be on some list which im sure could be used against them
browolf Posted December 19, 2013 Posted December 19, 2013 Ironically looks like the introduction of lightspeed filtering by our LEA will be the death of our own proxies and the LEA ones. As I understand it, lightspeed acts like a transparent proxy so you don't even need proxy settings! I'm not sure ISP filters will be up to the level of school filters, which usually block a lot more than just porn.
zag Posted December 19, 2013 Author Posted December 19, 2013 i was meaning this govenment one so they start saying you have you opt into catagories that kids shouldnt see but that measn the govenment is then supplying a list of what is/isnt acceptable. Whats to stop them adding to that list over time so say they deem (as a random stupid example) nobody should know about car modification there is already a system in place to block pron why not add it to that? So what starts out as something with vaugely good intentions turns into a way to filter what the populace can see. I also suspect that people who opt in to getting fuilters removed will be on some list which im sure could be used against them Assuming the filtering is optional and we can override it with a white list I really don't see the problem?
AngryTechnician Posted December 19, 2013 Posted December 19, 2013 Did you know that google have begun effectively MITMing images sent to a gmail account? The Smoothwall Blog: Gmail Users: Google Makes Your Data More Secure, Owns a Bit More of Your Life Yes, and I'm not thrilled, but to my knowledge I'm not sending any passwords via GET requests for images, so I'm not as concerned as I would be if my ISP was MITMing me while I logged into my online banking.
localzuk Posted December 19, 2013 Posted December 19, 2013 Assuming the filtering is optional and we can override it with a white list I really don't see the problem? The problem is not the filtering itself, its the resulting data of who is opting out. Its already happened in the media, people being referred to as perverts and degenerates for complaining about having to make it known that they want unfiltered access to the internet. When you click that 'leave filters off' button, you've now put your name down as wanting access to stuff that people think is 'bad'. When you combine that with the mission creep of other government censorship projects (Clean Feed was introduced voluntarily after similar demands from the government (do it voluntarily, or we'll force you to - kinda misunderstanding the concept of voluntary), but since that time the system has been used to block copyright infringing sites and is now under discussion to be used to block "extremist" sites (whatever that means, as who defines such things?)), you have a potential for invasive practices by the government with very little recourse in the future. Considering how much of a blunt tool filters are, their universal application to home internet connectivity raises the question of how end users will know if a site is legitimately blocked for being adult content or if it is a mis-categorisation, or even an attempt at censorship. Who will oversee this process? How will sites that are being blocked wrongly be able to appeal? What recourse will they have for loss of business? What legitimate material will get blocked as adult which shouldn't be (for example, sexual health sites, LGBT sites etc... are being blocked by some ISPs as adult)? There's just too many problems with the scheme at the moment. There's even discussion that such systems violate EU law at the moment too.
sted Posted December 20, 2013 Posted December 20, 2013 (edited) thats the thing say extremism if the government control the filters whos to say they dont define that as anything that dosent make them look good? (so in theory the could filter sites that said they were all a bunch of expense fiddling wastes of space (and if they knew their sites would get put on a block list would any big news agency publish it?)) and as above being stigmatised for not wanting filtering for whatever reason Edited December 20, 2013 by sted
pcstru Posted December 20, 2013 Posted December 20, 2013 "Mummy mummy why is the Guardian news site blocked?" USA already an Orwellian police state?
zag Posted December 20, 2013 Author Posted December 20, 2013 thats the thing say extremism if the government control the filters whos to say they dont define that as anything that dosent make them look good? (so in theory the could filter sites that said they were all a bunch of expense fiddling wastes of space (and if they knew their sites would get put on a block list would any big news agency publish it?)) and as above being stigmatised for not wanting filtering for whatever reason The government do not control the filters. They are optional, run by a 3rd party company, and can be whitelisted by anyone.
localzuk Posted December 20, 2013 Posted December 20, 2013 The government do not control the filters. They are optional, run by a 3rd party company, and can be whitelisted by anyone. Really? Is that the same as the way the filters are in place voluntarily, just like Clean Feed is in place voluntarily too? (IE. You WILL volunteer to use this system else we'll be forced to force you to use it).
sparkeh Posted December 20, 2013 Posted December 20, 2013 The government do not control the filters. They are optional, run by a 3rd party company, and can be whitelisted by anyone. You mean like Talk Talk's filter, controlled by Huawei, which is pretty much controlled by the Chinese Government... yeah I feel comfortable with that.
tmcd35 Posted December 20, 2013 Posted December 20, 2013 AFAIK - there's no central "great fireall of UK" (yet), and no legal requirement for any ISP to install any user filtering at all. All we have is the top 4 or 5 ISP kowtowing to David Camerons grandee-ism and then giving you the option to label yourself as a terrorist or pedo by opting out. While other ISP's exist who are not bowing to tabloid pressure without an act of parlament to back it up then there remains consumer choice. In short - switch ISP.
localzuk Posted December 20, 2013 Posted December 20, 2013 In short - switch ISP. Indeed. Something I will be doing when my (far too long!) contract is up with BT.
zag Posted December 20, 2013 Author Posted December 20, 2013 You mean like Talk Talk's filter, controlled by Huawei, which is pretty much controlled by the Chinese Government... yeah I feel comfortable with that. We use Homesafe here and yes, you can override it with 2 clicks
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now