Jump to content

Recommended Posts

Posted (edited)

They seem to be updating the guidance twice a month at the moment. The word 'Monitor' is the contentious one.

 

Filtering != Monitoring.

 

If we (schools) are required to monitor, then what exactly are we looking for?

 

If it were easy and cheap, the government wouldn't have doubled the SIGINT budget this year.

 

The solution is people and process not additional technology.

Edited by psydii
Posted

It would be nice if impero and smoothwall (along with other esafety / web filters out there) to provide a list or group of words, or sites for us to monitor.

 

Maybe a forum BTRD might be useful for schools running software like impero so it can at least detect when/if someone types in any radicalisation words, possibly like a word / site bank of commonly used phrases.

Posted
What constitutes monitoring is the big question here. Would schools be required to purchase software such as Impero to carry out technological based monitoring and logging alongside their filter, or as common sense tells every one of us, would staff actually watching what their children are doing online "suffice" alongside the reporting services of their filtering systems?
Posted

My view is that we (as the ISP industry for the education sector) should be able to monitor any user and what they are searching for by default anyway (not just by IP address). This should be simple to do and put the power in the hands of those at the school that required it (e-safety officer etc) but also be able to get detailed information for the relevant law enforcement agencies and authorities when required.

 

As a business we should advise on what we deem to be best practise but give our customers the tools to tailor their systems to reflect their individual e-safety policies.

 

What's more I believe all education ISP's (Grids and LA's included) should do all of the above as standard as an absolute minimum and at an inclusive cost. Not have it as an additional extra they should charge for as it should be in by default.

 

Their are some LA's, Grids and ISP's that have fantastic filtering systems that does the above by default but some that don't at all and in my opinion it's dangerous not to be able to do so.

 

We've caught all sorts of stuff (we look after well over 1,000 schools) and if we hadn't have been using the systems we do (Lightspeed and Fortinet) then I know some of it would have been missed.

 

No system is perfect but in my opinion there should at least by a minimum standard. As to who should set this is debatable but it should come top down from government and I suspect we shall see that in the not so distant future.

 

Just my thoughts.

 

Dave

Posted
It would be nice if impero and smoothwall (along with other esafety / web filters out there) to provide a list or group of words, or sites for us to monitor.

 

It would be nice if the _government_ would provide a list of keywords. When we built the "Radicalisation" category for our customers earlier this year we made a lot of enquiries to relevant parts of the government and British security services. However, they appeared to consider that kind of information "sensitive" and therefore not distributable outside of the security services, so we ended up having to do a lot of our own research, which I'm sure was just duplicating what the security services have already done in far higher fidelity.

Posted
Their are some LA's, Grids and ISP's that have fantastic filtering systems that does the above by default but some that don't at all and in my opinion it's dangerous not to be able to do so.

 

We've been in business 10 years and not long ago I was discussing what major changes we've seen over that time - the biggest I can think of is the change in balance between filtering and monitoring. A decade ago, schools had very trigger-happy filters with all the overblocking problems you'd expect; and this was absolutely required because if a child managed to get to porn, etc, that was often considered exclusively the filter's fault, rather than a problem with the child's behaviour/education which needed to be addressed. These days schools have a far more sensible attitude to online safety, which obviously still includes (much less draconian) filters, but now also education and active monitoring to direct not only the curriculum itself, but also the care of individual children.

 

This is certainly a good change - relaxed filtering means less overblocking, education helps keep the kids protected outside of school and monitoring helps pick up on things that even the most overzealous automated filters would have missed.

 

 

Just as a straw poll here: how many of you already install certificates on users' phones/tablets so that you can monitor their HTTPS traffic? I think the vast majority of our customers do for the kids, probably a 50:50 split for the staff (we always promote having _some_ filtering for staff to prevent accidents, but I think decrypting their HTTPS traffic is probably of very questionable value.)

Posted
We direct unauthenticated users to a page where they can download the cert from our server, then a button to continue to log in. There is a disclaimer on the pages on why we need to do this.
Posted

We don't force a root cert onto non-school devices(Yet). We rely on our GfL filtering as a baseline. We have very robust Child Protection and e-Saftey programmes. Borough Police liason has stated 'The school meets its requirements in regard to PREVENT'

 

I'm pretty sure that some of the larger GfLs or at least their national infrastructure partners already have mechanisms for MITM via one or more government sponsored/compromised root certificates authorities already present on *all* devices. I'm not sure why they just don't fess up, and send weekly reports to School CP teams for follow up.

 

 

That said, I expect we'll end up doing something similar to Timbo343 quite soon.

Posted
We direct unauthenticated users to a page where they can download the cert from our server, then a button to continue to log in. There is a disclaimer on the pages on why we need to do this.

 

Does it work on android/ios? Android now contains when a mitm is in use.

Posted
Does it work on android/ios? Android now contains when a mitm is in use.

 

Android is a pain in the backside - you can't install a root certificate unless the device has a lock-screen, and once you have a certificate installed it has a permanent warning about a third party being able to read your communications it in the notification bar. The warning certainly isn't wrong, but it is annoying. (You can get around these problems if the device is rooted, but you're hardly going to root everyone's phone are you?! :))

 

All devices (Android, iOS, Windows, OS X, whatever) also have a myriad of broken apps that don't use the device's trusted certificate store anyway, so the filter has to know about each app and disable interception when necessary. For normal web browsers it works pretty well though.

Posted

I work in primary so, especially with the younger classes, the TA often logs the computers on with a generic class login and then puts it onto the specific website/program that is required

 

What worries me if whether or not we would ever have to produce a list of exactly what web sites 'Child X' has visited in order to comply with regulations

That would be OK in a secondary where every user (child or staff) has their own login but in Primary this isn't true (in most cases that I have seen)

 

Even in secondary there is a problem because the bloke that I saw in the news last night seemed to imply that an site visited WHILE THE KID IS IN SCHOOL needs to be logged. this would include sites visited using a mobile phone via 3G/4G - which we cannot control.

Unless we ban all phones and tablets etc and ALL STAFF enforce it diligently - which can't happen in most schools!

Posted
What worries me if whether or not we would ever have to produce a list of exactly what web sites 'Child X' has visited in order to comply with regulations

That would be OK in a secondary where every user (child or staff) has their own login but in Primary this isn't true (in most cases that I have seen)

 

Certainly sounds like a pain if you would have to radically change the way things are done (i.e. giving every child a separate login). If there is any kind of CCTV I guess a workstation's IP address could be referenced against the video if absolutely necessary, but I imagine very few schools would have CCTV coverage of class rooms. Although maybe it is enough to be able to identify when something concerning has happened, even if you can't pinpoint a specific pupil. And you can probably figure out which class was involved just from the timing, etc. anyway.

 

Even in secondary there is a problem because the bloke that I saw in the news last night seemed to imply that an site visited WHILE THE KID IS IN SCHOOL needs to be logged. this would include sites visited using a mobile phone via 3G/4G - which we cannot control.

 

There has to be a measure of reasonableness considered I think - I don't think its reasonable for schools to be expected to exercise control over devices that are not supplied by the school and don't use any of the school's infrastructure. 3G devices are supplied by the child's parents, so it really should be the parents' responsibility to ensure that the device is being used responsibly. (Not just in regard to radicalisation).

  • Thanks 1
Posted
Android is a pain in the backside - you can't install a root certificate unless the device has a lock-screen, and once you have a certificate installed it has a permanent warning about a third party being able to read your communications it in the notification bar. The warning certainly isn't wrong, but it is annoying. (You can get around these problems if the device is rooted, but you're hardly going to root everyone's phone are you?! :))

 

All devices (Android, iOS, Windows, OS X, whatever) also have a myriad of broken apps that don't use the device's trusted certificate store anyway, so the filter has to know about each app and disable interception when necessary. For normal web browsers it works pretty well though.

 

Annoying but quite right that users are aware of what having a mitm certificate installed entails (many don't know of understand). From my experience (and we aren't in an affluent area etc) most of the kids use 3g and can be watching all the terrorist propaganda they like (most often with contracts in parents names)

 

We need to start asking ourselves what is missing from our teenagers lives that they are likely to be radicalised. I suspect it's a lot easier to stick in a few bits of filtering software.

Posted

I've not read the whole document, but searching for the word "monitor" in the proposed changes document @ https://www.gov.uk/government/consultations/keeping-children-safe-in-education-proposed-changes which seeks views on the changes since the July 2015 document:

 

"The majority of schools and colleges keep their children safe online already. However we believe including the requirement to ensure appropriate filtering and monitoring are in place, in statutory guidance, is proportional and reasonable in order to ensure all schools and colleges are meeting this requirement. We don’t think including this requirement will create addition burdens for the vast majority of schools, as they are already doing this, but we are keen to test this assumption"

 

So intention might not be to expect schools to make radical changes ?

 

The "problem" is going to be what the regional broadband consortium's can do. MITM's are "easy" to do if you own firewall - you can make a choice whether to issue and trust a certificate on your firewall that can implement a MITM attack. However, whether adding a certificate controlled by someone else to every PC in the AD is a good idea... - but as previous poster said - as a country we need to understand what's going on - as trying to block content on the internet if someone wants to find it / get around it is almost impossible...

Posted
I would welcome a public debate about this, including the voice of the technology companies.

 

A few years back BSI spotted that work on standards around this was needed. They pulled together a raft of stakeholders and tried very hard to get things moving on it it.

It fell down due to a few areas.

1 - the DfE would not sponsor or fund it in any way. They allowed 1 meeting to be held in their offices, and support was from ex-Becta staff ... but the response was that if bodies and the industry thought a standard was needed then the market should pay for it.

2 - It is difficult to persuade suppliers to fund and adopt a standard if you can't show competitive edge as a result.

3 - the main direction on public outcry at the time was home use ... and we saw the fun that has been had there.

 

There are also some very interesting legal questions that are raised about the responsibility and liabilities involved in monitoring and the supply of technologies for use by pupils / students. That needs to be fully thought through but it is hard to get the discussion on that going too.

Posted

Do you know, I'd almost forgotten about that...

 

Is there any chance of nudging the DfE again in light of this new push (however "new" and however much of a "push" it turns out to be)? "Well, what you're asking for would be so much easier if ... etc" and all that?

Posted

The 2007 Byron report recommended Filtering in all education establishments - and the government ( Labour) accepted these recommendations but did not legislate them - ie make them law, this document from what I see takes it that step further and makes it a statutory requirement to have filtering and Monitoring in schools.

 

As the report was written in 2007 the big fear was excessive gaming and the negative effective on children and their general well-being - so it was all about filtering, no mention of Monitoring - this is new and part of this gov's Prevent agenda - how times have changed!!

 

Like Steve of Opendium we too banged our heads against various government depts - DfE, Police, Prevent offices themselves etc., to gain access these mythical Radicalisation terms that have been deemed by 'those that know' to need blocking.

 

Eventually like others we did it ourselves, though all the effort from the education focused filtering/monitoring industry will only work with parental engagement as once home most of it stops.

Posted
So, does anyone yet have any clear idea of what "Monitoring" entails? It's been skirted around constantly, rather like it's been mentioned, ratified and required yet noone banding the word around seems to know what it actually means? Leaving us, the schools, rather in the dark as usual.
Posted

Maybe it's like the term "appropriate" in the Seventh Data Protection Principle ("appropriate organisational and technical measures shall be taken etc."), i.e. you need to be doing something that a third party (or courtroom) could look at from an outside perspective and agree fits within the general spirit of the term "monitoring", and which goes about that business effectively. Many, many aspects of written law are codified in such general terms because being overly specific can often lead to legal disasters, with decisions that courts legally have to make - they've got to follow what it says in the book, after all - that fly in the face of all common sense, all because a law that was written prescriptively/proscriptively happens to cover a situation it was never intended to deal with.

 

That being said, this guidance stems from the draft statutory document "Keeping children safe in education 2016" - to apply from next September - and is currently being consulted on. On its third page, it draws a distinction between what schools "should" do and what they "must" do. All the relevant changes on this topic can be found on page 22, and interestingly enough all those sentences seem to be of the "should" variety... although this is further mystified by the occasional use of the word "essential".

 

Either way, this is currently only at the consultation stage, and unless the government has any supporting legislation in the offing, it looks likely to become statutory guidance, not written law. Exactly how much effect it will have - if any - remains to be seen...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...