Jump to content

Recommended Posts

Posted (edited)

There's a WordPress hosted website that some members of staff would like access to, as they contain educational resources. However, the video resources are located at videos.files.wordpress.com and it appears that entire domain has been flagged as Radicalisation.

 

Of course, I could allow the (entire) domain but you can all understand immediately my hesitation in doing so! (Safeguarding Alert!!!) or alternatively, allow each and every individual video resource URL etc....

 

Does WordPress do anything of the nature of being able to flag websites / resources as safe / educational? Videopress has been mentioned to me... is that part of WordPress??? or totally different?

 

I suppose the alternative is to get (or see if) the videos (are) hosted on YouTube, and modify the WordPress-based website? Although it's not clear if the website has been created in-house, or by someone the staff know.

 

Thanks.

Edited by MYK-IT
Posted
There's a WordPress hosted website that some members of staff would like access to, as they contain educational resources. However, the video resources are located at videos.files.wordpress.com and it appears that entire domain has been flagged as Radicalisation.

 

Are you doing https interception on your filter? The CTIRU block list contains a number of files hosted on https://videos.files.wordpress.com but it doesn't block the whole domain. These individual files can only be blocked if you do https interception. Our system would take the less restrictive approach of allowing access to the whole domain if HTTPS interception was turned off, but it's possible that other systems would opt to be more restrictive and block everything. It might be a problem to report to your filtering provider, especially if you are doing HTTPS interception.

  • Thanks 1
Posted

Hi @SteveHill,

 

Yes, we do have SSL HTTPS interception enabled for our web-filtering, and appears our filtering provider has taken the stance to block the entire videos.files.wordpress.com domain.

With you (and your own system) also acknowledging that a number of resources located on that domain, are on the CTIRU blocklist I am certainly not going to allow or change access otherwise.

 

i'll just have to advise staff accordingly, and locate alternative resources (or locations for those resources).

 

Thanks for the feedback.

Posted
Yes, we do have SSL HTTPS interception enabled for our web-filtering, and appears our filtering provider has taken the stance to block the entire videos.files.wordpress.com domain.

With you (and your own system) also acknowledging that a number of resources located on that domain, are on the CTIRU blocklist I am certainly not going to allow or change access otherwise.

 

As a filtering supplier, I'm in the unusual position of being able to see specifically what is on the CTIRU list. I can't go into details, but there are about a couple of dozen links listed on that domain. Obviously you need to balance up the risk of someone visiting any of those links against the utility of accessing legitimate resources on the same domain. As a point of comparison, there are a couple of thousand Twitter addresses on the list, but I doubt anyone would block the whole of Twitter for radicalisation reasons (although there are plenty of other very good reasons to block Twitter :).

 

The other thing to consider is that the false positives caused by the whole domain being blocked reduce your ability to meaningfully report on which users may be at risk of radicalisation.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...