Jump to content

Recommended Posts

Posted
Does anyone know the general security of RMCC3. How easy is it for a pupil to hack into such a system? I have been told it is very difficult - is that right?
Posted

It depends how the network has been set up - what permissions students have etc and if any additional software has been used or GPOs that have been changed. Generally speaking though, if students are configured as Restricted UserType (red icon in system tray) then yes, they will find it very difficult to reak havoc.

 

Standard and Advanced user types give users increasing amounts of permissions such as certain control panel items. Somewhere in the CC3 handbooks there is a section that details what usertypes have what general permissions.

Posted (edited)

Not being an authority on security I'm not sure how easy it is to hack, but CC3 does allow you to lock things down reasonably tightly. In terms of security, I would imagine you could reproduce most if not all security using vanilla Windows with a few additional tools.

 

An example of where security is possibly lacking is the web-based management console. This is hosted using basic authentication over SSL internally, not ideal as it potentially exposes the risk of a MITM attack with a fake SSL certificate.

Edited by meastaugh1
Posted

As per other threads cc4 as rule standard users can't do much etc. As for web based console in theroy yes but in next version CC4 the RMMC becomes application based again.

 

Russ

Posted
I've been working recently on tightening the security of our CC3 system. I actually find CC3 to be overzealous in terms of locking down student accounts - we had frequent problems with IT students running macros and adding toolbars to Office. Our CC3 setup also has software restrictions set to block everything except what we allow. I'm not sure if that's the default but, combined with http antivirus filtering, that almost eliminates the need for antivirus software. As much as I dislike CC3, it is very secure (unlike 2.4, the pain, the pain!) and we've never had a security breach.
Posted
Does anyone know the general security of RMCC3. How easy is it for a pupil to hack into such a system? I have been told it is very difficult - is that right?

 

if you leave everything as standard then froma security point of view its a very secure system that should prevent any problems.

Thats were the good new ends though, the only way you can get a lot of educational software to run is to customize the the way the system is setup and for some subjects pupils needs much more control over the systems.

 

RM support tend to reccommend that you then make pupils advanced users to enable this software to run.

 

Its secure but only if you don't intend to use most educational software that available on it.

 

I fully expect the RM luddites on here to reply with comments that its not RM's fault that this software requires extra access ( insert other excuse here..) but surely a product such as CC3 that they know is used in schools should be able to run most education software without modification.

 

The school I work at is in the process of ripping this crap out and its quite funny that software that used to have problems running on a CC3 PC now runs fine on a secure vanilla PC.

 

are you primary or secondary ?.

  • Thanks 1
Posted
surely a product such as CC3 that they know is used in schools should be able to run most education software without modification.

 

It does, here at least. I have plenty of apps running on C3 and vanilla desktops with a similar level of security applied.

 

For schools that don't want to bother with locking down desktops, you can switch most of it off (eg software restrictions policies, NTFS permissions on local hdd etc).

Posted

CC3 is pretty secure as standard - yes. Is it just me that's slightly concerned about a person signing up on this board just to ask how easy it is to hack into a network?

 

Jose - getting educational software to run on CC3 is only a chore because most educational software is written in a way that could be bettered by a first year comp-sci student..... I mean - java and command prompts???? In this day and age? If the software was written properly in accordance with Microsoft's MSI best practice - it would work pretty much out of the box.

 

Andrew

Posted
CC3 is pretty secure as standard - yes. Is it just me that's slightly concerned about a person signing up on this board just to ask how easy it is to hack into a network?

 

Jose - getting educational software to run on CC3 is only a chore because most educational software is written in a way that could be bettered by a first year comp-sci student..... I mean - java and command prompts???? In this day and age? If the software was written properly in accordance with Microsoft's MSI best practice - it would work pretty much out of the box.

 

Andrew

 

This is true but surely any system designed to be used in a school would be designed to work with these software products regardless of whose fault it is.

Solutions providers should provide solutions not excuses.

Posted

As said by lot of people had no issues getting software to work on cc3.

 

So maybe if you tell us what problem you are having with what software maybe able to help.

 

Russ

Posted
As said by lot of people had no issues getting software to work on cc3.

 

So maybe if you tell us what problem you are having with what software maybe able to help.

 

Russ

 

are you seriously telling us that with a standard CC3 setup with students as restricted users all of your software runs fault free, I think a quick search on the internet tells us otherwise.

The original poster ask if was secure as standard what it is but not without many important problems. If you have to start changing user types for pupils then its fairly pointless buying a out of the box solution if it does not work out of the box.

Posted (edited)

Yes (fault free with in reason) any issues not down to security settings of cc3. As you can alter settings for each piece of software so if needs access to to folder can give access to that folder.

 

May I ask few questions of you again what software you got an issue with as might be able to help.

 

Second have you done RM Application training course? Your friend in getting software to work is ACL Detective and Software restrictions in RMMC.

 

Russell

Edited by russdev
Posted

I agree with Russ.

 

Our students (Restircted UserType) and staff (Staff UserType) can run all the software we've thrown onto our CC3 network. Some work straight away, some we've create file hash/path rules, some we've created writeAccess.ini files for, and some we've re-done the MSIs for. But atleast everything works while maintiaining the level of security that comes with ease on CC3.

 

Considering 90% of educational software is written by (ex-)teachers with a copy of Dummies Guide to Visual Basic 5 I don't think we do too badly.

Posted
I would second that Russ. Have ran CC3 for 5 years now and most decent applications run straight out of the box. As for the odd pieces of software that are designed badly usually small visual basic progs which really aren't worth the money we have managed to resolve quickly and effectively with the minimum of effort thanks to the tools provided by RM.
Posted (edited)
This is true but surely any system designed to be used in a school would be designed to work with these software products regardless of whose fault it is.

Solutions providers should provide solutions not excuses.

Sorry to jump on the band wagon but have not had problems running decent software. Some I have interesting times with but not had to reject any software for being impossible.

 

Now I will highlight my term, "decent". We have rejected some absolutely crud software. Demanding write access to the whole of c:, not allowing any option of where to install etc etc. Now I could have made these work but I wasn't likely to do that. As for saying that CC3 should magically be able to make any software work with out comprimising security.. Well anyone that can produce that will instantly get my money and eternal adoration.

 

Software vendors should produce decent software not piles of poo but hey, thats life. You may as well say that I should be able to buy a gallon of crude oil & stick it in my car. Should work, engine produces should make it so.

 

& while I am being picky & stroppy you do realise the term RM Luddite is an oxymoron? Be like having a Ford Pedestrian.

 

& WHY AM I STUCK ON CAR ANALOGIES!!!!!!?????

 

I have to go to my cupboard now

 

Ohhh and as for default security, I would agree with the bit over zealous. As with any system though make sure you know what you are doing before you slacken security as you can't blame a system security if you told it to allow something. 5-6 years here without incident (touch wood).

Edited by TechMonkey
  • 5 weeks later...
Posted
Is it just me that's slightly concerned about a person signing up on this board just to ask how easy it is to hack into a network?

 

Andrew

 

No, I am a parent of a child who has been banned from using the school computer system because they think the child might be able to hack it, although they have never done so in the past. I am trying to find out, therefore, how secure the system is so that I can try to persuade the school to change its mind.

 

Many thanks for all the posts.

Posted
No, I am a parent of a child who has been banned from using the school computer system because they think the child might be able to hack it, although they have never done so in the past. I am trying to find out, therefore, how secure the system is so that I can try to persuade the school to change its mind.

 

Many thanks for all the posts.

 

In that case my appologies! So your child has not actually been proven to have hacked the network? If not - I do not see how they could ban your child from the network because of a "percieved / possible threat".

 

Out of the box CC3 is very secure. It can of course be made very insecure by inexperienced / bad managment... but that is the same with any system.

 

Butuz

Posted
This is true but surely any system designed to be used in a school would be designed to work with these software products regardless of whose fault it is.

Solutions providers should provide solutions not excuses.

 

Basically you're saying that if Ford made a new Mondeo that was twice as wide as the old one, so that it no longer fitted on most UK roads - you would expect the Gov't to dig up all of the roads in the UK and make them twice as wide, JUST to fit this one badly designed poorly executed car? Personally - i would blame ford...they should be sensible enough to make cars that actually fit on 99% of UK roads.......

 

Edit - haha another car analogy :D

 

Butuz

Posted
Thanks - I know very little about computers and don't understand a lot of what's in the above posts! However, there does seem to be general agreement that it's a secure system.
Posted

I think it really depends what form the "hack" took. There are entire forums on the net dedicated to "hacking" RM CC3 but it all depends how an individual school has it setup.

 

I personally don't think it is any more or less secure than a vanilla network....

 

Cheers

Jona

Posted

Alice101 - all of us manage our networks with the intention of them being secure; whether they are CC3 or not.

 

If you have been browsing this board in the month you have been a member, you will also see that some of us (particularly those in secondary education) spend a significant amount of time bolting things down, because, no matter what is in place, the little dears will try to get round the network security to run their flash games, get on facebook, or whatever.

 

I am in no way implying that this is what you child has been doing; I'm just trying to explain why school IT staff can get uptight.

 

Do you know in what way your child is supposed to have endangered the school network? It may help us to help you.

Posted
The problem started when some spam emails were sent to the school from an external machine. The content was harmless. The school fears that if the child has access to its email via its website they will be able to get further into the system.
Posted

No - from another computer : I don't know how it was done. It was well over 2 yrs ago and the school ban is still running.

 

The strange thing, to me, is that the child is now allowed to access the school email from their own home computer - because the school is so inconvenienced by the ban. If it's ok to do this from home, why is it unsafe to do it within school? Is there any difference?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...