Guest monkeyx Posted May 18, 2016 Posted May 18, 2016 We are in the process of testing an open source web filtering solution and have been informed that we may possibly need to ensure that we also include the Internet Watch Foundation block list in our list of sites that are blocked. From what I can see the number of domains blocked by the IWF list is less than those on public lists such as Shalla Secure Services. Can anyone confirm it is a definite requirement for UK secondary schools to ensure that their content filters include the sites listed in IWF's list? Are any schools providing their own filtering service without the IWF list. I am aware of the several schools that are not. We currently do as our hosted solution is an IWF partner.
mats Posted May 18, 2016 Posted May 18, 2016 Doesn't your ISP automatically block sites on the IWF list? Which filtering solution are you testing? Does it do reporting, SSL interception & allow different filter levels by AD group?
Guest monkeyx Posted May 18, 2016 Posted May 18, 2016 We are testing pfSense and yes it filters by AD group, with SSO. Does SSL interception and has integrated reporting. So very pleased with it. We have a leased line from an ISP, so will check with them about IWF.
whs1000 Posted May 18, 2016 Posted May 18, 2016 What software are you using with pfsense ? we are testing pfsense + NXFilter at the moment for our backup line
mats Posted May 18, 2016 Posted May 18, 2016 Interesting. But pfsense is a firewall - have you got it doing web filtering or are you using another product for that?
Steve21 Posted May 18, 2016 Posted May 18, 2016 (edited) Interesting. But pfsense is a firewall - have you got it doing web filtering or are you using another product for that? Think the newer versions have SquidGuard built in now (or as a package at least) https://doc.pfsense.org/index.php/SquidGuard_package Was looking at that as an option for our backup line if we get a cheapy net connection in case of main failure yay for cloud! Steve Edited May 18, 2016 by Steve21
Opendium_Steve Posted May 18, 2016 Posted May 18, 2016 We are in the process of testing an open source web filtering solution and have been informed that we may possibly need to ensure that we also include the Internet Watch Foundation block list in our list of sites that are blocked. From what I can see the number of domains blocked by the IWF list is less than those on public lists such as Shalla Secure Services. Can anyone confirm it is a definite requirement for UK secondary schools to ensure that their content filters include the sites listed in IWF's list? The requirements are pretty open to interpretation - I think there are only vague statements about ensuring children are protected from inappropriate or illegal content rather than a specific requirement to use the IWF list. As you've noticed, the IWF list is tiny compared to other block lists - the IWF list only includes (probably-)illegal content, so it is not a substitute for other filters. A lot of ISPs have IWF filters anyway, so you may well already be filtered (but obviously without the ability to generate reports). I don't believe there is any way for individual schools to have access to the IWF block list. At least, you'd probably need to pay a membership fee.
mats Posted May 18, 2016 Posted May 18, 2016 Interesting. Very interesting. Just automated reporting of searches / attempts to get to the naughty bits of the internet left to cover...
Steve21 Posted May 18, 2016 Posted May 18, 2016 Interesting. Very interesting. Just automated reporting of searches / attempts to get to the naughty bits of the internet left to cover... Assuming that was in relation to SG there is built-in reports, but last time I looked they weren't all pretty and GUIish. Just basic text file last time I looked So say you add the IWF library and turn logs on for it, it'll log to that file everytime someone hits one. Steve
tomo1095 Posted May 18, 2016 Posted May 18, 2016 Most ISPs will already block IWF listed sites. Even with the relative short list though, it's probably worth blocking yourself even if it's just for your own peace of mind. Along with the other lists.
Wave9_Lee Posted May 18, 2016 Posted May 18, 2016 [h=4]Illegal Online Content[/h]In considering filtering providers or systems , schools should ensure that access to illegal content is blocked, specifically that the filtering providers: Are IWF members and block access to illegal Child Abuse Images and Content (CAIC) Integrate the ‘the police assessed list of unlawful terrorist content, produced on behalf of the Home Office’ source: Appropriate Filtering - Safer Internet Centre
Opendium_Steve Posted May 18, 2016 Posted May 18, 2016 Illegal Online Content In considering filtering providers or systems , schools should ensure that access to illegal content is blocked, specifically that the filtering providers: Are IWF members and block access to illegal Child Abuse Images and Content (CAIC) Integrate the ‘the police assessed list of unlawful terrorist content, produced on behalf of the Home Office’ source: Appropriate Filtering - Safer Internet Centre Yep, but that's the Safer Internet Centre's interpretation of the requirements, not the requirements themselves. Admittedly if something happened, someone might point at that and expect you to justify why you weren't using the IWF list, but that's not the same as it being mandatory.
Wave9_Lee Posted May 18, 2016 Posted May 18, 2016 I guess from a school's perspective it depends on your appetite for risk. I'm definitely not one for over-regulation or supporting quangos that offer no value, but if government procurement, regional broadband consortia, LEAs all believe that it's good practice, I'm not sure why you wouldn't go with this one.
Guest monkeyx Posted May 19, 2016 Posted May 19, 2016 I guess from a school's perspective it depends on your appetite for risk. I'm definitely not one for over-regulation or supporting quangos that offer no value, but if government procurement, regional broadband consortia, LEAs all believe that it's good practice, I'm not sure why you wouldn't go with this one. I am asking why it is not free to non profit organisations such as schools. Open data etc?
Opendium_Steve Posted May 19, 2016 Posted May 19, 2016 I am asking why it is not free to non profit organisations such as schools. Open data etc? This is something I've always wondered. To be honest, I think it should be free to any organisations with a good reason for needing it and the foundation itself either funded through donations or directly by the government. At least the IWF have clarified their funding model these days - when the IWF was first set up, they advertised that they were funded by "voluntary donations", but what wasn't made quite so obvious was that in order to gain access to the block list, organisations were required to make a "voluntary donation" of a set amount (sometimes tens of thousands of pounds, depending on the size of the organisation). They have at least now started using the term "membership fee" for the mandatory payments instead of "voluntary donations".
RichCowell Posted May 19, 2016 Posted May 19, 2016 It's not available to all members - just the types of members that actually use it like ISPs... there's too much risk of all the info in the various lists falling into the wrong hands... The ANME became a member of the IWF a couple of months ago and it's not something I'd even considered asking about - even though sharing it with the members could potentially be of use - it's not appropriate for all to have access to it...
Opendium_Steve Posted May 19, 2016 Posted May 19, 2016 It's not available to all members - just the types of members that actually use it like ISPs... there's too much risk of all the info in the various lists falling into the wrong hands... The ANME became a member of the IWF a couple of months ago and it's not something I'd even considered asking about - even though sharing it with the members could potentially be of use - it's not appropriate for all to have access to it... The IWF could easily run a DNS based filter similar to the various anti-spam DNS blackhole lists. That would keep the list itself hidden whilst allowing URLs to be checked against it at access-time.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now