Jump to content

Anyway to monitor internet use at home?


Recommended Posts

Posted

Hey Guys,

 

Is there like a software package that can be installed on staff machines that can log all websites accessed at home and categories them for easy viewing?

 

I've looked about but can't seem to find much!

 

Cheers

:)

Posted

Your best bet would be a global mandatory proxy server. Basically, a proxy server accessible outside of school that all devices communicate back to.

 

The easiest way of doing this would be to use a service such as Sophos Cloud Web Gateway, but you can also do this by setting up your own proxy instead (you'd have to be careful and make sure it is authenticated to prevent it being an open proxy).

Posted
You can record the history, certainly (using scripts or software). Your first job would be to get this sewn into an absolutely watertight AUP, because you're playing with fire here. My advice would be - don't.
Posted
policy central can do it but as above you need to get people to sign an aup saying they agree to have you "spy" on their internet use
Posted

We can do this with Chromebooks and Smoothwall - force the chromebooks to use a global proxy no matter where they are.

We use it as an 'opt in' feature for students/parents. Much more difficult on home owned machines, and staff won't be best pleased!

 

Perhaps your best bet may be to redirect staff to your web/intranet page and use analytics ?

Posted

Cheers peeps.

 

So it sounds as if a global proxy is the way to go? We have a Smoothwall server internal in the building. How would I setup a global proxy server? Bare in mind we also have county's filter on top. :(

Posted
Cheers peeps.

 

So it sounds as if a global proxy is the way to go? We have a Smoothwall server internal in the building. How would I setup a global proxy server? Bare in mind we also have county's filter on top. :(

 

You open an external IP on your Firewall on a specific port and forward traffic to it (IIRC it uses NTLM auth). On the laptops, set a proxyconfig.pac file so that if the machine has a matching ip address as your school network it will use the internal smoothwall and if it doesn't it uses the external smoothwall. You have to assume the RFC1918 addresses of the home networks (usually 192.168.1.0/24) are different to the school ones.

Posted
You open an external IP on your Firewall on a specific port and forward traffic to it (IIRC it uses NTLM auth). On the laptops, set a proxyconfig.pac file so that if the machine has a matching ip address as your school network it will use the internal smoothwall and if it doesn't it uses the external smoothwall. You have to assume the RFC1918 addresses of the home networks (usually 192.168.1.0/24) are different to the school ones.

 

Cheers.

 

Sounds like a lot of work though to get it all setup properly. Policy Central could be something to look into,I don't want to filter them at home I just want something that will record their websites and categorise them so we can go back through their history.

 

The deputy has gone a bit e-safety mad and wants to monitor the staffs use at home, I don't deem it necessary really... What's the law say about this, monitoring use in school is one thing but I'm not sure about monitoring their home internet usage?

Posted (edited)
Cheers.

 

Sounds like a lot of work though to get it all setup properly. Policy Central could be something to look into,I don't want to filter them at home I just want something that will record their websites and categorise them so we can go back through their history.

 

The deputy has gone a bit e-safety mad and wants to monitor the staffs use at home, I don't deem it necessary really... What's the law say about this, monitoring use in school is one thing but I'm not sure about monitoring their home internet usage?

 

if they are using school equipment and they are informed I suspect that you can do it legally as at the end of the day its your equipment not theirs and you are just monitoring how its used

Edited by sted
Posted
+1 for including in a revised AUP - perhaps look at what other changes you'd like to introduce so that the staff aren't bombarded with changes to the AUP. You really need them on board with this one!
Posted
My advice would be - don't.

 

Yer, ditto. If someone here suspects something, it goes via HR. If you're going to do it get HR involved. The tech is easy, its the policy that is the trouble. If you don't get the policy bit right your wasting your time. Give you an example, if you don't have the policy right, a teacher could use their works laptop to upload their homemade porn to some file sharing site - which the newspapers would have a field day with - but if the school did something they would be in trouble for breach of privacy and you would prob end up getting charged under the computer misuse act for "hacking" or spying on them - pretty hard to get a job in IT with that red mark against you.

 

If it was me, I would say you can't do it. Then let them either get someone who its paid a lot more to deal with it (and the policy side) if they think its broken. If anything DOES actually happen, you'd just involve HR - they can then get the police involved if necessary and pull the logs from the ISP if needed, which is what they'll do anyway, they won't trust your logs as they could be altered. Seriously a can of worms you don't want to open.

 

If you want something to throw back at them, ask the question, ok so I've done it, what will you do with it? So you've found something, what now? You'll tell them off, ok, what happens if they repeat it? How is you calling them out any different then saying it in general in all staff meeting?

Posted
+1 for including in a revised AUP - perhaps look at what other changes you'd like to introduce so that the staff aren't bombarded with changes to the AUP. You really need them on board with this one!

 

I'd be inclined to put something insanely restrictive in there to bury "we'll monitor what you do at home" in worse news!

Posted

IIRC, when I used NetSupport DNA many, many, many moons ago it had this facility - logged everything that happended on the machine almost and then would dump it all back to the central database once conntected to the network again.

Not sure if it still does this or what the legal angle these days would be though!

Posted

@abillybob, can I just ask how this came about?

Is it because you suspect, or have evidence of misuse? If so, does your AUP not already cover that?

 

Is it because staff are installing stuff on 'the school' laptop? If so, could you improve your GP...

 

Is it because they are subjecting themselves, inadvertently, to malware? If so, could you improve your AV solution?

 

You're probably beginning to see from our responses that this is such a grey area, especially if the staff don't see the need for why you would want to do that. If they themselves have had the embarassment of knocking on your door, laptop in hand, suggesting the website seemed innocuous but has done something to the laptop, then the staff may have more sympathy for this type of restriction.

 

Summary - what are the symptoms, and is there a better way?

Posted
I'd be inclined to put something insanely restrictive in there to bury "we'll monitor what you do at home" in worse news!

 

I found they throw the laptop back at you if your AUP says your monitor them - even off prem

Posted
I found they throw the laptop back at you if your AUP says your monitor them - even off prem

 

Never had a problem with it here - we have the notice below that displays before login on all domain joined machines:

 

"Use of the Internet and e-mail via this machine is monitored for violations of acceptable use. Somerset County Council monitoring and Minehead Middle School will monitor virus activity, unsuitable language use in e-mail and use of banned applications such as file-sharing software. Somerset's Internet Service Provider the South West Grid for Learning monitors Internet use including attempts to access illegal websites. All users should be aware that this monitoring is taking place., Violation of the Acceptable Use Policy may result In suspension of Internet AND e-mail accounts AND In some cases disciplinary action may be appropriate including In extreme cases dismissal For gross misconduct AND criminal proceedings., The Internet is a wonderful tool For learners but must be used responsibly. Somerset County Council AND the South West Grid For Learning have a duty to ensure that all users of their systems follow rules For acceptable Use. Users are required to act responsibly when using Internet systems so that all can enjoy safe Internet access. By clicking accept below, you agree that you understand monitoring is taking place AND that your Use of this system will be responsible."

 

Terrible from a punctuation and capitalisation POV, but I wasn't involved in its drafting!

 

We don't currently have anything in place which does monitoring when off-site, but that could always change in the future.

Posted
Indeed, it could be a good money saving tactic towards BYOD.

 

That's up there with firing all the staff and asking them to come back and work for free. BYOD will cause more problems. You'll find staff will want more money, which has tax implications like a company car. You then have to treat them has hostile - as you can't control AV etc on them. Everything has to be cross platform - so you'll waste you time converting stuff and trying to debug it - just because its web based doesn't mean its cross platform, something that works in IE or Firefox doesn't mean it works in Chrome. Then still have the problem of well my laptop has a virus and I can't change my wallpaper (so I can't actually use it as I can't project that photo on the projector to a class full of kids) - so you need to fix my laptop, you'll end up having to recommend kit - so what's the difference between BYOD and school owned again? - or worse, they buy there own support then why do they need a IT tech? Cause you just provide a internet connection... oh wait, the ISP does that...

Posted
Never had a problem with it here - we have the notice below that displays before login on all domain joined machines:

 

There is a different between being able to set something up in the future if a event occurs (both legally and technically) and actually proactivity doing something. One sits nicely in the law the other breaks the "innocent until proven guilty"

 

If you do proactivity monitor staff without cause - then I guess we know where you stand with regards to the NSA\GCHQ etc.

Posted
That's up there with firing all the staff and asking them to come back and work for free. BYOD will cause more problems. You'll find staff will want more money, which has tax implications like a company car. You then have to treat them has hostile - as you can't control AV etc on them. Everything has to be cross platform - so you'll waste you time converting stuff and trying to debug it - just because its web based doesn't mean its cross platform, something that works in IE or Firefox doesn't mean it works in Chrome. Then still have the problem of well my laptop has a virus and I can't change my wallpaper (so I can't actually use it as I can't project that photo on the projector to a class full of kids) - so you need to fix my laptop, you'll end up having to recommend kit - so what's the difference between BYOD and school owned again? - or worse, they buy there own support then why do they need a IT tech? Cause you just provide a internet connection... oh wait, the ISP does that...

 

I know BYOD doesn't work, except in places where it does. (looks at management console of 850 student/staff owned devices).

Posted
There is a different between being able to set something up in the future if a event occurs (both legally and technically) and actually proactivity doing something. One sits nicely in the law the other breaks the "innocent until proven guilty"

 

If you do proactivity monitor staff without cause - then I guess we know where you stand with regards to the NSA\GCHQ etc.

 

In school? We have logs of every website visited by every user on our devices, regardless of whether they are owned by us or not.

 

Extending this to cover devices which are owned by us but used off-site isn't a big step, let alone a leap. If we introduce DirectAccess in the future (likely to happen), this would by default route all network traffic back via our internet connection.

 

Also, your use of "proactively monitor" is not correct. Monitoring is watching. Logging is what we do, and what the OP asked about.

 

I have only ever had to go into our logs a couple of times regarding staff whilst I have worked here. It is incredibly rare.

 

Also, the NSA/GCHQ are not schools. They are trawling everyone. We are protecting our devices, owned by the school, used by employees of the school specifically for school business. They are not private machines, and staff have been told they must not use them as personal machines.

 

The "cause" is quite a simple one, as a reason for logging. We have a great many obligations in schools to ensure the protection of children, sensitive data etc... Logging is a tool used to ensure we are compliant with those obligations.

  • Thanks 1
Posted

Monitoring students is one thing. That's a must. But monitoring the staff? That's a whole heap of chaos if not done correctly. That's my issue. If you setup something, who monitors you? Your basically saying hey, I don't trust you. I think @mrwoberts worded it better, but you shouldn't be throwing tech a policy problem. If you need to investigate something, you own the device, you can just grab that device and investigate. Tech isn't the problem.

 

I have only ever had to go into our logs a couple of times regarding staff whilst I have worked here. It is incredibly rare.

 

Did that go via HR? This wasn't the classic school ground argument type thing.

 

(looks at management console of 850 student/staff owned devices).

 

Bit of contradiction here - when talking about BYOD I thought we where talking about true BYOD where you have no control over device. You're talking about managed devices where you can - say - wipe them? Or push out software? Or are you just talking about wifi managed?

Posted
Monitoring students is one thing. That's a must. But monitoring the staff? That's a whole heap of chaos if not done correctly. That's my issue. If you setup something, who monitors you? Your basically saying hey, I don't trust you. I think @mrwoberts worded it better, but you shouldn't be throwing tech a policy problem. If you need to investigate something, you own the device, you can just grab that device and investigate. Tech isn't the problem.

 

Again, please stop using the term "monitoring". It is logging. Monitoring is far more than logging.

 

I am not saying anything like "I don't trust you". Just like applying to the DBS for disclosure isn't saying that. It is saying "we have a legal duty, this is how we discharge that duty". We have a policy in place, staff agree to it and their computer reminds them on login.

 

If the device isn't logging anything, how would having it in your hands make any difference to an investigation?

 

Did that go via HR? This wasn't the classic school ground argument type thing.

 

It went via the head and assistant head (HR), and the governors in one case. As per our policy.

Posted (edited)

I really think the OP needs to come back here. @abillybob

He hasn't told us the full story, which is crucial to this thread.

 

Responsible traffic logging of school owned equipment is absolutely essential, we'd probably all agree on that. If the staff have not been told they can't use the school laptop for non-work use, at home, then there is a huge hole right there, which make the OPs request wander into 'snooping' territory, but where a good AUP is in place, then it follows that the school should have ways to investigate breaches of AUP, enter the logging traffic solution. (I'm starting to lose the plot myself now, I really wish the OP would come back to us...)

 

Edit: A red faced mrwoberts quickly changes the word monitoring to logging, in admission to the difference of those two words.

 

Edit 2: Then wonders if his previous edit was justified {bubble above head - what about the term RMM}

Edited by mrwoberts
Posted

Re logs and monitoring - if a tree falls...

 

There are logs already. You have the internet history, you have av which will normally have http scanning, again more logs, you have backup logs of any files they save as they get saved to the network.

 

You clearly have policy sorted, by the sounds of a random question they have asked in the original post, they dont - or its not as advanced as yours

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...