Jump to content

Recommended Posts

Posted

We are in the process of amending our BYOD policy, possibly to only allow the sixth fomr students access.

 

I wondered how many schools have actually not even entertained the idea of a BYOD initiative for students...

Posted

There's not a huge amount for us to think about, we got a policy from our academy sponsors. We encourage it anyway; if they're on our guest wireless, they're not going to be getting anything inappropriate (it won't stop them turning it off for their 3G but helps). Some of our departments make use of student smartphone availability for some bits and bobs, surveys, small research etc and we're glad to see that being the case.

No huge risk on it; currently the guest is controlled by UniFi so there's no access to internal systems + VLANd off anyway.

Posted
There's not a huge amount for us to think about, we got a policy from our academy sponsors. We encourage it anyway; if they're on our guest wireless, they're not going to be getting anything inappropriate (it won't stop them turning it off for their 3G but helps). Some of our departments make use of student smartphone availability for some bits and bobs, surveys, small research etc and we're glad to see that being the case.

No huge risk on it; currently the guest is controlled by UniFi so there's no access to internal systems + VLANd off anyway.

 

We thought there was no risk....but found that students were able to get some "apps" to work, all internet traffic is intercepted by our smooth-wall and they had to logon to browse, but I cannot be 100% certain that all apps on all devices are being blocked....

Posted
No one higher up has asked about it so I haven't given it much thought, I don't see the benefits of it anyway tbh

 

some benefits:

 

(not my list!)

 

1.) Students are already familiar and comfortable using their own technology so they can focus on actually learning with them than learning how to use the device.

2.) Students’ personal mobile devices tend to be more cutting-edge, so schools can more easily stay up-to-date with technology..

3.) Students are more likely to have remembered their beloved mobile devices than textbooks or notes.

4.) It’s a cost-effective way to save schools money on technology.

5.) With BYOD students are more likely to continue learning outside of schools hours.

6.) When students use their own devices, they take care of their own ‘training.’

7.) BYOD provides opportunity for teaching respectful/appropriate use, which will be important in properly preparing them for the future.

8.) Students will be more organized with all their notes and assignments all in one place.

9.) Gives the students limitless access to information and resources.

10.) BYOD allows student & teacher to swap roles.

11.) Teachers can use certain apps to be more connected with students and parents than ever before.

12.) Students love technology so BYOD engages students and creates enthusiasm and excitement about learning.

13.) If students bring their own devices to school, schools can concentrate funding on the students who need it, maybe providing an iPad leasing program.

14.) BYOD allows more opportunities for more personalized learning where students can excel at their own pace.

15.) Students take control of ensuring that their device is working, instilling a sense of responsibility.

16.) BYOD offers a way of delivering ebooks.

17.) There are loads of cool and exciting educational apps to get students excited about learning.

18.) The majority of students and adults already own the devices necessary for BYOD.

19.) Students can use the device they have chosen to complete their tasks so they are more likely to do them.

20.) BYOD can be used as a privilege to encourage students to stay on task.

  • Thanks 1
Posted
I'm already looking into this, We have Private access for devices that belong to the school and Public access for BYOD, they are on seperate VLANS so everything is split and doesn't mix. I think it's a good idea, It opens lots of doors to new technology.
Posted
I'm already looking into this, We have Private access for devices that belong to the school and Public access for BYOD, they are on seperate VLANS so everything is split and doesn't mix. I think it's a good idea, It opens lots of doors to new technology.

 

Our BYOD is on a separate VLAN too.

 

Smoothwall advised us the only way to block FaceTime and iMessage was to block the ports on our firewall!

Posted

We have been doing this for three or four years now. Seems to work rather well.

We don't really find many security problems and the biggest difficulty is working with a myriad of systems and you need to make sure your systems are vendor neutral.

At last count our breakdown was 300 IOS devices, 175 androids, 80 windows 7/8 and 117 "others" (OSX, chromebooks, XP).

 

Our approach was to segregate the wireless networks into yeargroups - the students log in using their network username and password and this puts them on the correct network. None of these networks talk to the internal network or to each others network. proxy is transparent but the user is identified using the logon that the used to access the network via radius so we can keep track of individuals without having to give them all different settings. SSL interception is the most difficult thing to do (which we don't) for BYOD in my opinion.

Posted (edited)

We used to have it for Sixth Form only, but the student council wanted it extended.

 

Been online since 26th Jan (for all) and 44% of the school have signed up (They have to opt-in to agree to the policy)

 

Looking at the logs, the most frequent device is "Apple" - le'sigh.

Edited by SovietRussia
Posted

Looking at the logs, the most frequent device is "Apple" - le'sigh.

 

Same.

 

"Oh I can't afford to move out."

"I can't afford driving lessons."

"I can't afford to pay rent to you, my loving parents."

"I can't afford a birthday present for my nan."

"Sir, could you please set up my iShiny 6 on the wireless?"

Posted
I wondered how many schools have actually not even entertained the idea of a BYOD initiative for students...

 

Us.

 

But, we're a primary school in a dodgy area.

 

It's less "network security" and more "I'm not implementing anything that's likely to get kids stabbed".

  • Thanks 2
Posted
Us.

 

But, we're a primary school in a dodgy area.

 

It's less "network security" and more "I'm not implementing anything that's likely to get kids stabbed".

 

has to be said one of my first thoughts as I work in primaries is would you want your 6 year old dragging £100+ of tablet to and from school each day?

Posted
We have been doing this for three or four years now. Seems to work rather well.

We don't really find many security problems and the biggest difficulty is working with a myriad of systems and you need to make sure your systems are vendor neutral.

At last count our breakdown was 300 IOS devices, 175 androids, 80 windows 7/8 and 117 "others" (OSX, chromebooks, XP).

 

Our approach was to segregate the wireless networks into yeargroups - the students log in using their network username and password and this puts them on the correct network. None of these networks talk to the internal network or to each others network. proxy is transparent but the user is identified using the logon that the used to access the network via radius so we can keep track of individuals without having to give them all different settings. SSL interception is the most difficult thing to do (which we don't) for BYOD in my opinion.

 

How do you guarantee that none of the apps on their phones get through your filtering without it being logged or stopped?

Posted
How do you guarantee that none of the apps on their phones get through your filtering without it being logged or stopped?

 

You can't 100% Which is where policy comes into the equation. In the same way as you can ban students bringing in porn mags, but they might still bring them in there bags and might look at them without any one noticing. But when they get caught there is a punishment.

 

If you want 100% control then you need an MDM that will lock down to only specific apps when connected to your wifi, but even then you could disconnect from wifi and use 3\4G.

Posted (edited)
How do you guarantee that none of the apps on their phones get through your filtering without it being logged or stopped?

 

We've recently rolled out ipads to our 3rd year pupils (BYOD style). Our filtering does a reasonable-ish job of blocking most but pupils always seem to find an app or a proxy which isn't blocked. Also, whenever an app is updated there seems to be a chance it suddenly start working again until the filtering catches up. Even failing that they can always setup remote access to their home computers or simply link their devices to a 3G phone if they want to surf unfiltered! Some have already started setting up VPNs and using a variety of similar services to get around the filtering! Again ,we block VPN's in the filtering but they'll always eventually find one that isn't blocked.

 

I'm starting to feel that between personally owned BYOD devices and transparent proxy's that we no longer have the technical means to reliably filter our pupils' internet access....

 

I think that pupils and staff bringing in their own kit is here to stay though regardless of the risks it brings with it.

Edited by flyinghaggis
Posted
If you want 100% control then you need an MDM

 

There is another way, depending what infrastructure you have.

 

For example :-

 

We have a BYOD wireless , everyone knows the WPA key, once on this wireless you are now on the BYOD VLAN.

The BYOD vlan only allows device to talk to the citrix / RDS servers (smoothwall blocks everything and redirects).

The wifi (MERU) segregates the wifi devices from talking to each other.

Posted
My personal feeling is that with BYOD you really need to ask teachers to keep an eye on what the pupils are doing as there simply aren't the technical tools to reliably filter devices. There's simply too many ways they can work around filtering.....!

 

Teachers actually monitoring what the kids are doing? that'll be the day!

 

That's why I don't like the idea of BYOD, I've done enough stuff on my phone when I was younger and on my school/college networks to know that unless there's some REALLY good MDM solution, it's a bad idea (and there isn't a really good MDM solution afaik).

Posted
How do you guarantee that none of the apps on their phones get through your filtering without it being logged or stopped?

 

I don't think you can guarantee it 100%. I think this is the aspect that scares more IT types. You can certainly put in place things to make it more difficult such as firewalls \ filtering solutions \ vlans etc but at the end of the day it's never going to be 100% secure. But then what is?

Posted
You can't 100% Which is where policy comes into the equation. In the same way as you can ban students bringing in porn mags, but they might still bring them in there bags and might look at them without any one noticing. But when they get caught there is a punishment.

 

If you want 100% control then you need an MDM that will lock down to only specific apps when connected to your wifi, but even then you could disconnect from wifi and use 3\4G.

 

True, but bringing in a magazine and sharing it around in lessons is of little consequence compared to the risk of it happening, whereas being able to Skype or equivalent whilst connected to the school network, even if the risks of this happening is small - the consequences could be huge.

 

At least with our school owned devices we know what is on them.

 

I just doubt the benefits outway the risks, I appreciate that students can do a lot more on their own phones 3 & 4G signals and that does not exclude the school from any responsibility of anything happening in school.....but to me allowing it to happen "on the network" CAN only lay more of the blame at my door....and that worries me....

 

Funding for a proper MDM / NAC software will not be possible with the current cuts...

Posted (edited)

The other issue with a MDM solution is that if you're applying these policies to personally owned devices how much control and lockdown can you reasonably exercise over them? Do you start blocking the install or forcing removal of specific apps, installing certificates and locking down their internet to redirect it through a school proxy, applying filtering and blocking certain functions of the device.

 

All might be appropriate on a school owned device but if it's a pupil or staff members own tablet/phone you might be limited in your options even with MDM rolled out to them?

Edited by flyinghaggis
Posted
All might be appropriate on a school owned device but if it's a pupil or staff members own tablet/phone you might be limited in your options?

 

Pretty much.

 

BYOD is more trouble than it's worth.

 

We can't reasonably say we're meeting our safeguarding requirements, when there's very little we can do to stop anything.

Posted

I detest the thought of BYOD in context of my current school. Here there is such a massive digital divide that some students literally have nothing. Why promote inequality in school where the haves and the have nots impact the very core of delivering the curriculum.

 

I would liken it to abolishing school uniform; on one hand it gives freedom of choice but on the other hand it can cause personal grief and a whole new level of peer pressure. Only in this instance it is being promoted by school policy.

 

Not for me thanks (until I'm told to do otherwise or someone here can convince me I'm wrong)

Posted
True, but bringing in a magazine and sharing it around in lessons is of little consequence compared to the risk of it happening, whereas being able to Skype or equivalent whilst connected to the school network, even if the risks of this happening is small - the consequences could be huge.

 

At least with our school owned devices we know what is on them.

 

I just doubt the benefits outway the risks, I appreciate that students can do a lot more on their own phones 3 & 4G signals and that does not exclude the school from any responsibility of anything happening in school.....but to me allowing it to happen "on the network" CAN only lay more of the blame at my door....and that worries me....

 

Funding for a proper MDM / NAC software will not be possible with the current cuts...

 

Please don't get me wrong, its not like our system is wide open, we use an application blocking system that prevents a lot of apps from working, but its only as good as long as the app is on the system. Apps are always going to be ahead of the blocking vendors.

 

We stop Skype/facetime to name a few, but we also spent a lot of time with the solicitors, SMT and the governors going over policies and procedures.

Posted
The other issue with a MDM solution is that if you're applying these policies to personally owned devices how much control and lockdown can you reasonably exercise over them? Do you start blocking the install or forcing removal of specific apps, installing certificates and locking down their internet to redirect it through a school proxy, applying filtering and blocking certain functions of the device.

 

All might be appropriate on a school owned device but if it's a pupil or staff members own tablet/phone you might be limited in your options even with MDM rolled out to them?

 

This is one reason we haven't gone down the full MDM route, we do get them to install a certificate for SSL interception and staff/students have to agree to this for BYOD. We don't make BYOD mandatory, so if you don't like it, then don't use it. We still have school owned facilities to use in classes if mandatory computer use is needed for a lesson.

 

So far no complaints from staff/students.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...