Jump to content

Recommended Posts

Posted

My local LEA are upgrading there web filters to provide SSL intercept in response to Googles decision for force all searches over a secure connection. The only information schools have been given are instructions on installing the additional client certificates required.

 

I don't think most schools will even realise what's happening.

 

Wondered how other schools handle this. I think staff should at least be informed of the intercept and acceptable use policies should also cover its use.

 

Does the use of SSL intercept break the T&Cs for some online services ?

 

Say your bursar uses online banking and doesn't realise they don't have an secure end to end connection to the bank are they breaking the T&Cs for online banking ?

Posted
Say your bursar uses online banking and doesn't realise they don't have an secure end to end connection to the bank are they breaking the T&Cs for online banking ?

 

We make online banking an exception to SSL inspection. Maybe you can do this as well?

Posted

Most organisations will exclude online banking from their ssl mitm attack but this is something you should clarify with your provider.

 

Ben

Posted
We will be looking to 'intercept' search engines only. Is there a need to intercept all other traffic? I don't think there is unless I am missing something?
Posted
By intercepting all sites I'd imagine in some cases there could be a performance hit because the appliance (if onsite) is doing work it doesn't need to.
Posted
SWGfL handle this by excluding online banking and shopping sites. I think, in fact, they only have it set up to intercept Google at the moment.

 

Is there a way to check what's being intercepted, bar going to each site individually?

 

[Ours is the RM intercept.]

Posted (edited)
Is there a way to check what's being intercepted, bar going to each site individually?

 

[Ours is the RM intercept.]

That is explained here.

 

http://www.rm.com/_RMVirtual/Media/Downloads/SSL_Interception_Policy.pdf

 

We are, at this time, only intercepting Google search results, we reserve the right to intercept other secure websites, in order to continue to provide effective filtering of web content.

We will not intercept personal online transactions, including but not limited to:

Internet banking

Online shopping

 

You would need to look at the SSL cert to be sure they're not intercepting.

Edited by Edu-IT
  • Thanks 1
Posted

Being able to intercept ssl gives you enhanced capabilities over things like facebook and twitter, be able to selectively enable parts of facebook can be useful.

 

Ben

Posted
Thanks for all the helpful answers. I have already contacted them to clarify exactly what they are doing. Would have been helpful if they had volunteered the information before rolling the changes out. Seems a major amount of effort to accommodate one search provider.
Posted
Thanks for all the helpful answers. I have already contacted them to clarify exactly what they are doing. Would have been helpful if they had volunteered the information before rolling the changes out. Seems a major amount of effort to accommodate one search provider.

Google are the ones to blame!

 

RM did send a mailing out and there is a dedicated website and support number.

Posted
Ssl interception is a great tool, as has been said not doing banking sites but we had it on for everything else as ssl Cerys are peanuts now a days so you just mirror say a gaming website and bash a cheap £15 cert on it and book games in school and your non the wiser till it gets found and blocked. Re-key the cert to a new url and off you go again. Cheap domains and certs have been great for us but are now a downside everything can be ssl for peanuts.
Posted
Thanks for all the helpful answers. I have already contacted them to clarify exactly what they are doing. Would have been helpful if they had volunteered the information before rolling the changes out. Seems a major amount of effort to accommodate one search provider.

 

It's not just one search provider though it will in time be all of them and more and more sites will go SSL only, by intercepting SSL you can also have a lot more control over SSL content.

 

Ben

Posted

Someone should talk to Google. They were concerned about the privacy of searches using the noSSL option. Now most insitutions are employing SSL intercept so searches are still not private, they are encouraging wider use of SSL intercept technology which can't be a good thing for the internet and wasting a great deal of time and money for all concerned.

 

Seems like a lose/lose outcome for Google and the educational community.

Posted
...they are encouraging wider use of SSL intercept technology which can't be a good thing for the internet...

 

Seems like a lose/lose outcome for Google and the educational community.

 

 

I couldn't agree more. I'm not sure if it's down to google for making themselves more secure, or the filtering companies for the methods they are placing to decrypt the packets.

 

What worries me the most is how this traffic is all being logged due to the new 2014 Telecommunications Data Retention Act.

Are the ISPs proactively upgrading their security to minimise the impact of any breaches? I hope so.

Posted

From Lightspeed's blog:

 

To retain the current level of Google search reporting and restriction, you should use the Lightspeed Systems Web Filter in proxy mode. It is possible to configure this so that only the Google traffic is proxied and does not require you to proxy all of your encrypted web traffic.

 

As mentioned above, it seems likely that it will only be a matter of time before everything is encrypted and thus almost everything is intercepted, so it will be self-defeating......

Posted

@ReBoot - Is this re: E2BN \ SchoolsChoice? ie this - Installing ProtexRootCA certificates

 

If so, they only do it for Google because Google has withdrawn the NoSSL option. No other sites are affected. Data will be encrypted from Google > E2BN, then it will be re-encrypted with another key from E2BN > School\End User. It's basically how CloudFlare does it, only they don't have to encrypt from CloudFlare to the end server.

  • Thanks 1
Posted

It seems most of the SSL intercepts currently focus on Google. Given that Google already has its own SafeSearch option which can be locked onto a network this seems to be allot of effort for a relatively low risk content provider. Google is a reputable company and the SafeSearch option, while not perfect, does cut out the majority of inappropriate and explicit content.

 

The risk from unfiltered SSL from the rest of the Internet would worry me far more than unfiltered Google SafeSearch. Do commercial filters restrict the sites where SSL can be used ?

Posted
It seems most of the SSL intercepts currently focus on Google. Given that Google already has its own SafeSearch option which can be locked onto a network this seems to be allot of effort for a relatively low risk content provider. Google is a reputable company and the SafeSearch option, while not perfect, does cut out the majority of inappropriate and explicit content.

 

The risk from unfiltered SSL from the rest of the Internet would worry me far more than unfiltered Google SafeSearch. Do commercial filters restrict the sites where SSL can be used ?

 

Google's SafeSearch doesn't do everything a school needs. We have a long list of terms that are filtered on top of SafeSearch. Things like self harm and suicide. As it is the main search engine used by everyone, its not that much effort really!

  • Thanks 1
  • 2 weeks later...
Posted
It seems most of the SSL intercepts currently focus on Google. Given that Google already has its own SafeSearch option which can be locked onto a network this seems to be allot of effort for a relatively low risk content provider. Google is a reputable company and the SafeSearch option, while not perfect, does cut out the majority of inappropriate and explicit content.

 

The risk from unfiltered SSL from the rest of the Internet would worry me far more than unfiltered Google SafeSearch. Do commercial filters restrict the sites where SSL can be used ?

 

You've summed it up. Google's safesearch may not be wholly appropriate, but try an unblocked HTTPS search engine without safesearch. They're out there. SSL interception is far more important for these IMHO.

Posted
Our county service apparently is intercepting Google secure searches but I can go to bing and do a secure search with no intercept. Google probably is the most widely used search engine for Schools but I can't see how this really makes much sense if we are really trying to lock things down.
  • 6 months later...
Posted
Bit of a thread resurrection but was wondering what you're all doing about BYOD with SSL intercept? Do you basically say to users that they install the certificate or put up with constant security warnings?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...