Jump to content

Recommended Posts

Posted

Do other schools use this plugin? It allows parents to view and then change their contact details via Firefly.

 

However, Firefly doesn't actually write back to SIMS (or any MIS as far as I know) and I suppose you wouldn't want unchecked data being written back anyway, so all it actually does is take the contents of the form and emails it to an address that has been configured in Firefly (i.e. the email address of the person in school who amends Contact details in SIMS).

 

I'm not sure if sending this data (parent address, phone number and email address) via non-encrypted email is the best way to do this. In reality, parents send much more personal data via email all the time but at least they know they are doing it. Firefly with the green padlock and/or https in the address bar gives the impression that the data is being transmitted securely and of course it is, to Firefly, it's how Firefly gets the data to the school that concerns me.

 

I did email Firefly and they said they had no plans to change this but offered to log it as a feature request.

 

What do people, Firefly users or not, think about this? Am I right to be concerned?

Posted (edited)

I work on a similar system and we also email the amendments at this time. Like you though I have concerns over the security of this as when it gets to email you're essentially sending identifiable information over an unencrypted channel i.e. email. We're looking to change the system so that the changes are securely stored and accessed via an admin tool which can in turn export rather than transmitting anything over email. We've already done this for most other parts of the system that used to email identifiable data and haven't come up against any real opposition so I don't see why Firefly wouldn't be able to do similar. It's in the name of security after all!

 

So in summary, I think you're right to be concerned. I'd say at least ensure it gets logged as a feature request. If it must notify, I'd say it should notify that some user(s) have requested changes but without any identifiable information, with a link to the appropriate page within Firefly where the changes can then be securely handled.

Edited by SimonHooker
Posted
I did email Firefly and they said they had no plans to change this but offered to log it as a feature request.

 

In my experience, Firefly (unusually in the education market) actually seem to have a proper software development methodology behind their product, so if they've logged something as a feature request I'm sure it will actually get considered for implementation at some point. That doesn't necessarily mean that will be any time particularly soon, if they have other work to prioritise. The functionality that makes sense to me would be a parent does a details update online, then an email gets sent informing the admin team to process that change from a secure login of some sort. A Google Form / Google Sheet combination might actually be the simplest way to do this at the moment.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...