Jump to content

Recommended Posts

Posted

I am working through a number of projects at the moment and one question that has come up is this - how are those of you who have shared use iPads (or Android etc...) providing usable logs for web usage?

 

So, a pupil uses an iPad - how do you find out what sites that individual pupil has been on?

 

Reason being, even if we take the lighter look at the new requirements for preventing extremism and the like, I can't see any way around a need to be able to track back individual website usage to an individual user?

 

So, what are people doing to log this?

Posted
We have a captive portal that the iPads use. Child signs in using their AD details giving them an hours internet access. The firewall knows that any traffic from that IP in that hour is from that child.
Posted
Ok, so how are you sure that the next person isn't just using the prior person's credentials? If it is done as an hour at a time, then there will definitely be overlap.
Posted
I'm not but it was either that or use shorter time frames which will alloy people. I'm sure you can adjust times to suit. Without having something tying that iPad to that child I'm not sure how else you'll do it.
Posted (edited)
That's my point really - having a system that doesn't reliably log who is using the internet doesn't appear to comply with the law now, so I'm trying to figure out how to do it. Edited by localzuk
Posted
That's my point really - having a system that doesn't reliably log who is using the internet doesn't appear to comply with the law now, so I'm trying to figure out how to do it.

Children share their account passwords all the time. How do you guarantee the same thing on a PC?

  • Thanks 1
Posted (edited)
Children share their account passwords all the time. How do you guarantee the same thing on a PC?

 

Doing so is a breach of their AUP here, which would be dealt with according to our disciplinary policy. ie. sharing a password is there fault, not ours.

 

Whereas, our systems simply not being able to differentiate because of our own technical limitations would not be covered by the law. So, it would be our fault.

 

All this is about ensuring you have proper provision in place. Some of it will be policies, some training, and some technological.

 

If you have useless policies, you're going to be pulled up on it.

If you don't do any training, you're going to be pulled up on it.

If you have poor technological solutions, you're going to be pulled up on it (maybe).

Edited by localzuk
Posted
If you can spring the cash for AirWatch MDM you can setup the devices so you have to log onto them with AD credentials each time. That way you've got a timed log against the device and you could just give the iPads a static ip.
Posted (edited)
Doing so is a breach of their AUP here, which would be dealt with according to our disciplinary policy. ie. sharing a password is there fault, not ours.

 

Whereas, our systems simply not being able to differentiate because of our own technical limitations would not be covered by the law. So, it would be our fault.

 

All this is about ensuring you have proper provision in place. Some of it will be policies, some training, and some technological.

 

If you have useless policies, you're going to be pulled up on it.

If you don't do any training, you're going to be pulled up on it.

If you have poor technological solutions, you're going to be pulled up on it (maybe).

Regardless, you still wouldn't be any wiser on who actually was the person logged in?

 

Joe Bloggs logs in as Sally Smith and accesses XYZ which they shouldn't. You speak with Sally Smith, who says it wasn't her. You may give her a ticking off for not having a decent password but how does that solve your issue that somebody has accessed such material? You're still not able to tell who it is even though you've given Sally a telling off so you'll still be pulled up on it.

 

We use captive portal on our mobile devices. We can't guarantee 100% that the person who is logged in is the person using the computer though. How could you ever be sure? Fingerprint authentication perhaps?

 

I wouldn't consider this to be poor technological solution. There isn't a fool proof solution?

Edited by Edu-IT
Posted
Regardless, you still wouldn't be any wiser on who actually was the person logged in?

 

Joe Bloggs logs in as Sally Smith and accesses XYZ which they shouldn't. You speak with Sally Smith, who says it wasn't her. You may give her a ticking off for not having a decent password but how does that solve your issue that somebody has accessed such material? You're still not able to tell who it is even though you've given Sally a telling off so you'll still be pulled up on it.

 

We use captive portal on our mobile devices. We can't guarantee 100% that the person who is logged in is the person using the computer though. How could you ever be sure? Fingerprint authentication perhaps?

 

I wouldn't consider this to be poor technological solution. There isn't a fool proof solution?

 

That isn't how it works. There won't be things in an Ofsted inspection which will look how we stop children sharing passwords beyond our policies. There will be parts checking we use adequate technological solutions to comply with our legal duties.

 

There is no such thing as a perfect solution, but providing one that simply doesn't work properly isn't complying with the law in the first place that I can see.

Posted
That isn't how it works. There won't be things in an Ofsted inspection which will look how we stop children sharing passwords beyond our policies. There will be parts checking we use adequate technological solutions to comply with our legal duties.

 

There is no such thing as a perfect solution, but providing one that simply doesn't work properly isn't complying with the law in the first place that I can see.

So what you're saying is, Ofsted will be looking for a solution whereby you can guarantee who is logged on and who has been accessing what? I'd very much value their suggestion on what to use that is 100% accurate and fool proof.

 

Define adequate for me?

Posted
So what you're saying is, Ofsted will be looking for a solution whereby you can guarantee who is logged on and who has been accessing what? I'd very much value their suggestion on what to use that is 100% accurate and fool proof.

 

Define adequate for me?

 

That's the question isn't it? A system where people could just be logged on as someone else because sessions don't "end" when the user leaves would not be, in my view, adequate.

 

We'd need some form of "log off" mechanism.

Posted

A question: How do you know that internet for that hour is from that specific child? We use Smoothwall, and if a user logs off, the next user picks up that session, so the whole point of tracking a pupil's usage is lost, because we can never be sure that the correct person was logged on! This is a serious concern I've raised with Smoothwall, and they have no solution. Are you sure your solution actually tracks the correct kids?

 

Smoothwall suggest we tell our pupils to log off at the end of a session, but we all know relying on the user is a lost cause.

Posted
That's the question isn't it? A system where people could just be logged on as someone else because sessions don't "end" when the user leaves would not be, in my view, adequate.

 

We'd need some form of "log off" mechanism.

Most captive portals will have a log out function. Same as leaving a PC logged on, do you log them off automatically after X amount of time?

Posted
Most captive portals will have a log out function. Same as leaving a PC logged on, do you log them off automatically after X amount of time?

 

No. Teachers make sure everyone has logged off at the end of a lesson, or log them off using classroom management tools.

Posted
That's the question isn't it? A system where people could just be logged on as someone else because sessions don't "end" when the user leaves would not be, in my view, adequate.

 

We'd need some form of "log off" mechanism.

 

Our Smoothwall has the same problem. It at least provides a log-off mechanism, but relying on a user to log off is the problem.

Posted
No. Teachers make sure everyone has logged off at the end of a lesson, or log them off using classroom management tools.

So for school owned tablet devices, teachers could make sure they're logged out too?

 

 

Our desktop PC's use an agent to report the logged on user so pretty sure that it's as accurate as it can be and more accurate than Smoothwall by the sounds of it.

Posted
So for school owned tablet devices, teachers could make sure they're logged out too?

 

This is what I'm asking... How do schools do it, and how are they sure it complies with the new rules?

 

Our desktop PC's use an agent to report the logged on user so pretty sure that it's as accurate as it can be and more accurate than Smoothwall by the sounds of it.

 

Ours do too, and the proxy servers log the traffic.

Posted

This isn't something I've seen raised as an issue before, but possible suggestions that spring to mind:

 

1. When ipads are handed out, someone can log the time and who each was handed out to. That way you can link questionable web accesses from a specific ipad at a specific time to the person it was handed to. Obviously this adds a paperwork overhead which teachers may not be happy to have.

2. Captive portal, and have a system to automatically log everyone off at the end of each lesson, possibly with a "quarantine" period between lessons during which no one is allowed to log on to make sure that the "old" user doesn't just relogin if the lesson overruns. Not sure how easy this would be on most systems - our systems don't provide a mechanism for you to do this, but it would be trivial for us to do a custom job for someone if they needed it.

3. Captive portal and an app on each device. The app would run when the device is booted and tell the portal to log off the previous user, that way the user would need to log on every time the device is rebooted - at the end of each lesson, just turn the ipad off and the next time its powered up someone would need to log in. Would require someone to do some development work to put the app together though.

 

(2) would probably be my preference as it's pretty simple and doesn't result in ongoing extra work for the teachers.

 

Also, you can't make anything 100% foolproof because fools are just too ingenious :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...