Jump to content

Recommended Posts

Posted
FWIW, I think @bmaloney's request was certainly more in line with the spirit of the act, just improperly formatted.

 

Agreed. Use of a webform is the only sensible way to collect data from every school in the country, but the use of no-reply and his own website scuppered him. Perhaps he'll re-submit with an email stating a link, not a button, to a trusted survey site such as Google Forms or Survey Monkey along with a real email address for questions. That, or as I suggested previously, engage a much smaller number of schools willing to have a discussion with him about the policies, practices and differences - that wouldn't give him any statistics to use, but would allow him to come up with a decent recommendation for changes he'd like to see made.

 

I actually have some sympathy for the cause, but think he's gone about it in the wrong way.

Posted

In agreement with most of what has been said - the request and subsequent 'battles' appear to have lost touch with the intended purpose and communication was immediately confrontational in my experience anyway.

 

The motivation was parental rights but seemed to get skewed into him committing a lot of time and effort to proving a point and him 'being right' rather than collating information to support his apparent cause.

 

Ultimately to bring about significant change you need to get large groups of people working with you, not against you.

 

In reflection I wonder if he feels his time could have been better spent as the time spent fighting this wont have improved parental rights much . . .

Posted
Which annoys me. That isn't what FOIA was intended for.

 

You mean like this? 404 FOI requests and counting....

 

Untitled.png

 

- - - Updated - - -

Posted
The only part I'd disagree with in there is this:

 

It is entirely reasonable that a school should maintain a policy of never operating hyperlinks to unknown websites and should instruct staff accordingly.

...

That Mr. Maloney’s website is unquestionably benign and designed for a lawful purpose is neither here nor there. The School cannot know that on receipt of the request Email and cannot sensibly be expected to undertake research to discover whether his website can be safely accessed.

 

If you're going to say it's reasonable to have a policy of never opening links to "unknown" websites then surely it follows that they must be expected to have a means of investigating a website to discover it can be suitably accessed, otherwise they'd never be allowed to stray past their intranet.

I made exactly that point in my first complaint to the ICO, the school were saying we don't click on links that haven't been ratified as safe and secure. OK I said, what's your process for ratifying links as safe and secure? They don't have one, they only click on links from people they "know". So if someone spoofs an email from someone they "know" they'll click on it, despite the fact it's malicious.

Posted
I made exactly that point in my first complaint to the ICO, the school were saying we don't click on links that haven't been ratified as safe and secure. OK I said, what's your process for ratifying links as safe and secure? They don't have one, they only click on links from people they "know". So if someone spoofs an email from someone they "know" they'll click on it, despite the fact it's malicious.

 

Well... Yeah..? I'm not really sure what your point is here...?

 

Hijacking an email account and sending malicious files/links to all entries in the contract book is a ridiculously common attack vector. Which is why we also teach people not to click on links or files they don't expect, too.

  • Thanks 1
Posted (edited)
I made exactly that point in my first complaint to the ICO, the school were saying we don't click on links that haven't been ratified as safe and secure. OK I said, what's your process for ratifying links as safe and secure? They don't have one, they only click on links from people they "know". So if someone spoofs an email from someone they "know" they'll click on it, despite the fact it's malicious.

 

Unfortunately that's a common problem we face when trying to train staff in cyber security. Spoofed or hacked email accounts and convincing phishing emails are a problem and we're trying to train staff in better practices. When we received your request, I was reassured that my colleagues expressed concerns about clicking on the button as they didn't trust it (and not just because they don't know you).

Edited by enjay
  • Thanks 2
Posted
If you say you only click on links which are ratified as safe and secure that implies you have a procedure for ratifying links, it would also suggest there's a list or database somewhere of ratified links. Neither of these is true.
Posted (edited)
If you say you only click on links which are ratified as safe and secure that implies you have a procedure for ratifying links

Dunno about anywhere else, but I do, and occasionally I have staff forward me emails saying something along the lines of "Not sure if this is OK?"

 

It's probably not a policy that's written down anywhere, but every IT tech will have a system to decide whether an email is genuine or not, however you did not include that in a valid FOI request, and therefore we are not obliged to explain our process to you. If someone asked me "Well how do you check if links are legit?" after I refused to click on one they'd emailed me, I would just assume they were being argumentative or stubborn.

 

it would also suggest there's a list or database somewhere of ratified links. Neither of these is true.

No it doesn't. Now you're just being silly.

 

You have to accept that schools get a myriad of spam and a myriad of malicious links and files emailed to us. The Head's PA (by virtue of running Office@) and the Bursar are constantly up to their neck in it, but since they get it so often they're used to it and can pick out what's real and what isn't 99% of the time. You can like it or lump it, but "don't click links from people you don't know and weren't expecting" is advice I'm going to continue to give under the circumstances.

Edited by Garacesh
  • Thanks 4
Posted
If you say you only click on links which are ratified as safe and secure that implies you have a procedure for ratifying links, it would also suggest there's a list or database somewhere of ratified links. Neither of these is true.

 

We do have a procedure in place, or at least staff are given advice which includes staff forwarding emails to IT saying "this looks a bit dodgy, please advise before I click on it". That's why we didn't even click on your link to tell you we were declining (although by the time you sent it to us, we already knew the ICO's initial ruling so knew not to even bother responding with a "no").

 

To be honest Mr Maloney, I really don't think it is worth you still debating whether people should or shouldn't have clicked on your link. That has been ruled on.

  • Thanks 2
Posted
It would have been interesting to hear the explanation surrounding the point 9(ii):

 

Email servers store and forward emails, . Websites are a real time connection which doesn't hang around.

Posted
To be honest Mr Maloney, I really don't think it is worth you still debating whether people should or shouldn't have clicked on your link. That has been ruled on.

Agreed. The ruling is clear and, as far as I know, there is no recourse to challenge the ruling. Endless debate is fruitless.

 

How about we discuss and more constructive path to getting to a point where we are actually addressing the core point behind the FOI request?

  • Thanks 1
Posted
The majority probably would've still filled out the form, but the request would then have fully complied, without all this hassle.

 

There are still concerns with the form, because it was an unknown database on the back of it. One of my colleagues queried how we knew our responses were definitely being recorded against the correct questions.

Posted
How about we discuss and more constructive path to getting to a point where we are actually addressing the core point behind the FOI request?

 

Question 6 of his 13 question request, you mean?

Posted (edited)
There are still concerns with the form, because it was an unknown database on the back of it. One of my colleagues queried how we knew our responses were definitely being recorded against the correct questions.

Yes, but that's what a query email address would've dealt with... The thing is, once the info has been sent over - it isn't any of our concern what unknown database it is put into. Just that it is answered if the request complies, which having a correspondence email address would've resolved.

Edited by localzuk
  • Thanks 1
Posted
There are still concerns with the form, because it was an unknown database on the back of it. One of my colleagues queried how we knew our responses were definitely being recorded against the correct questions.

 

Concerns like this aren't really unique to this format though; you also wouldn't know that was the case if the request came in an email body and you responded likewise, relying on the requester to input the data into their db.

 

However you respond, it'd be important to retain a log of what your response was so you're not relying on the requester accurately recording that.

Posted
Concerns like this aren't really unique to this format though; you also wouldn't know that was the case if the request came in an email body and you responded likewise, relying on the requester to input the data into their db.

 

However you respond, it'd be important to retain a log of what your response was so you're not relying on the requester accurately recording that.

 

I could repeat myself here, but it was in the original request. When you submit your response you get an email confirmation of what you submitted. One of the problems was schools were passing around the emails and then clicking on the link in a request to a different school. They would then enter their information against the wrong school in the database. One school would then get a confirmation of another school's response.

 

That's why the emails had a unique link in them, to make sure the source of the data was properly recorded, but I can't account for school's answering the wrong request.

Posted
Concerns like this aren't really unique to this format though; you also wouldn't know that was the case if the request came in an email body and you responded likewise, relying on the requester to input the data into their db.

 

Fair point. My colleague possibly trusts a human data entry process more than an unknown database form. At least with an emailed response or even Survey Monkey, we would have clear and undeniable record of what we had said even if the response were later garbled by the recipient.

Posted
I could repeat myself here, but it was in the original request. When you submit your response you get an email confirmation of what you submitted. One of the problems was schools were passing around the emails and then clicking on the link in a request to a different school. They would then enter their information against the wrong school in the database. One school would then get a confirmation of another school's response.

 

That's why the emails had a unique link in them, to make sure the source of the data was properly recorded, but I can't account for school's answering the wrong request.

 

An idiot proof system will always find a better idiot.

 

a) Put the school name and postcode or similar in the url, as well as your UID

b) Ask them to confirm the school name and pin code first, so you can reject the wrong ones

Posted
That's why the emails had a unique link in them, to make sure the source of the data was properly recorded, but I can't account for school's answering the wrong request.

 

You can probably trust us to be able to get our school name right when completing your form.

Posted (edited)
I could repeat myself here, but it was in the original request. When you submit your response you get an email confirmation of what you submitted. One of the problems was schools were passing around the emails and then clicking on the link in a request to a different school. They would then enter their information against the wrong school in the database. One school would then get a confirmation of another school's response.

Perhaps that's an issue with you using Google Forms, then?

 

We've been through this. (Please, someone, correct me if I am wrong, but AFAIK:)

You do not have the right to tell us in what format we should be submitting the responses.

You are allowed to say "I want to know about X"

You are not allowed to say "I want to know about X, you may only respond by Y"

 

This is just leading back to the argument of "You're trying to offload your data assessment part onto the schools and that's unfair and not how the FOIA is meant to work" argument but the fact is, you're not within your rights to do that in the first place.

You have to accept that if you're requesting so much data from so many schools there's going to be a significant admin overhead - that's why FOI requests of this scale are usually performed by organisations with lots of people who can chip in to evaluate the responses.

The admin overhead is on you. Stop trying to dodge it.

Edited by Garacesh
  • Thanks 3
Posted
but I can't account for school's answering the wrong request.

 

You could, you just didn't. Multiple ways to do this, from having a cover page that shows the School Name and postcode that is expected and asking the school to contact you if this is incorrect (another reason a valid email is required) to asking the school to enter their postcode and having them select the correct school from a drop down. But all you are doing is adding complexity and time to an all ready over complicated process, all because you did not want to process the data that you were requesting. You would not have hit the issue of the wrong school using the wrong link if you had used WDTK, if you had allowed email submissions or if you had supplied a template. With data collection/questionnaires/surveys etc, you either make the data easy to input (and deal with any issues yourself) or you don't get all the data.

 

As stated before, the main issue is that you have tried to do a massive data collection on the cheap and tried to get everyone else to do all the work for you and stamped your foot if someone hasn't acquiesced to your whims. Most data collectors will bend over backwards to get the data as that is the gold they are willing to spend time and effort to gain. I have had surveyors from major collection projects make multiple repeat appointments to get data from me as I was willing to give them time but I was busy. You can not easily get 20,000 data respondents easily with no work. Well if you can contact MORI or any other data collection company and they will be willing to throw money at you for that technique.

 

I don't think anyone here has been against your implied aim, many have actively supported you or offered advice. I think take that as a positive, that you have active support and build on that, rather than feeling embattled and that everyone is out to get you. This was a grand project that a company would have spent a lot of time and money getting right, so the responses you have got are a great thing for the resources you have had at your disposal.

  • Thanks 4
Posted
You could, you just didn't. Multiple ways to do this, from having a cover page that shows the School Name and postcode that is expected and asking the school to contact you if this is incorrect (another reason a valid email is required)

I did, the school name is on the response form, together with the local authority, the email address the request was sent to, with an option to enter the name of the person responding and their email address. Despite this schools managed to lose the request sent to them and decided to use another school's request email to respond, ignoring what was in front of them as they entered the data.

 

As stated before, the main issue is that you have tried to do a massive data collection on the cheap and tried to get everyone else to do all the work for you and stamped your foot if someone hasn't acquiesced to your whims. Most data collectors will bend over backwards to get the data as that is the gold they are willing to spend time and effort to gain. I have had surveyors from major collection projects make multiple repeat appointments to get data from me as I was willing to give them time but I was busy. You can not easily get 20,000 data respondents easily with no work. Well if you can contact MORI or any other data collection company and they will be willing to throw money at you for that technique.

You seem to be upset that I don't want to be overloaded with work. This decision is a setback, it requires me to make some changes, but I've already got responses from about 20% of schools, I have a solution to avoid the issue of links in emails and it won't require a significant amount of work from me. If it did I would have to abandon the project and the data collected so far would be wasted.

 

I don't think anyone here has been against your implied aim, many have actively supported you or offered advice. I think take that as a positive, that you have active support and build on that, rather than feeling embattled and that everyone is out to get you. This was a grand project that a company would have spent a lot of time and money getting right, so the responses you have got are a great thing for the resources you have had at your disposal.

Thank you. Progress is made when we challenge the assumptions, otherwise we'd all think the world was flat and if you went too far you'd fall off the edge!

Guest
This topic is now closed to further replies.



×
×
  • Create New...