Jump to content

Recommended Posts

Posted

My county is moving to a Smoothwall filtering solution.

 

I am running some rudimentary tests on the adult/teacher filter.

 

I am somewhat aghast to find that by checking the SSL certificates that the account logon pages for shops such as M&S and John Lewis, some financial institutions, my doctor's surgery and political parties - sites that might be classed as "sensitive personal data" are having the account name and password decrypted. If shop account logons are decrypted then saved credit card data is also accessible. Am I being paranoid or is this normal? This wasn't the case with the county's previous filtering provider.

 

It seems as though they are intercepting every SSL site with the exception of a few manual exceptions. There has been no formal notification of this policy change.

 

Does anybody know on what legal basis my County might be relying on to intercept these communications?

Posted
Speaking technically, Smoothwall will allow you to exclude certain categories such as online banking etc. Might be worth asking if they can do this for you?
  • Thanks 1
Posted
Yes, but it's County's appliance not ours, so I'm not hopeful. It seems very heavy handed to me, and I'm not convinced it's entirely legal to be intercepting private passwords to personal accounts in this manner.
Posted
Would the school / LA not argue that the school it facilities are for school purposes and not to carry out Christmas shopping?!? As long as the staff are made aware that decryption is taking place then they choose whether they wish to logon such sites moving forward.
  • Thanks 1
Posted

We make it very clear in our AUP that all traffic is monitored and therefore may not be secure. We also make it clear that the internet service at school is to help them do their work, and specifically mention things like personal shopping and banking as stuff they shouldn't be doing.

If after all that, they do it anyway, I don't think they have much room to complain. They can avoid the issue by not doing the things we have told them they shouldn't be doing anyway !

  • Thanks 1
Posted

This seems totally unnecessary to me. SSL intercept is primarily there to safeguard children using encrypted searches such as Google. You don't need SSL intercept to stop staff shopping online and implement your AUP you just block the sites.

 

I don't perform SSL inspection on any staff traffic. For pupils I perform it on to Google, Bing and Youtube all of which have strict safe searches locked.

 

If nothing else doing widespread SSL inspection uses allot of computing resources and does break some services.

  • Thanks 2
Posted
This seems totally unnecessary to me. SSL intercept is primarily there to safeguard children using encrypted searches such as Google. You don't need SSL intercept to stop staff shopping online and implement your AUP you just block the sites.

 

I don't perform SSL inspection on any staff traffic. For pupils I perform it on to Google, Bing and Youtube all of which have strict safe searches locked.

 

If nothing else doing widespread SSL inspection uses allot of computing resources and does break some services.

 

You may as well not bother having a web filter IMO as the amount of stuff you could probably get on get around without decryption will be huge. With appliances like Smoothwall and Lightspeed, you need the inspect and decrypt installed to properly monitor and safeguard students and fully inspect the page, pretty sure the real-time/smart filter won't work on SSL sites without this. Never noticed a drain on resources using this method either, our computers are very old, but still perform well enough.

  • Thanks 2
Posted

We use to make it clear that everything on a computer a student could get access to had SSL inspection on, so all IT suites on vritaully all sites (banking an exception for example)

 

Computers students shoudl never access, main office, staff room etc were still inspected but much reduced, so shopping sites, banking, webmail etc wasn't inspected, the URLs were just logged. Seemed a fair compromise, as when staff are having their lunch why shouldn't they be allowed to do some shopping for example.

  • Thanks 1
Posted

I would suggest everything is decrypted and inspected apart from category SSL/CRL and any websites that fail to work with the inspection.

Financial sites should be set to validate certificate if not inspected, this will give you cover for any spoofed sites and block cert failures.

 

Without https inspection, the smoothwall cannot read the information going through from upstream web server to internal client as it is an encrypted connection, therefore the content filter is unable to categorise web sites, you then have to really on the blocklist. If the url is not within the blocklist then the user gets to the site. Currently there are (according to a quick google search) 70 domains and 571 web sites made every minute of the day. Revealed, what happens in just ONE minute on the internet: 216,000 photos posted, 278,000 Tweets and 1.8m Facebook likes | Daily Mail Online how accurate that is, is questionable.

 

If you have difficulties whilst decrypting, with services erroring then please give us a call at support.

Posted

It's worth pointing out that the default config does exclude banking sites from decryption. If you could check to see if HSBC is decrypted (you'll get a different cert if you are being MITMd) then you can tell if your county kept this default. If that's the case, and you think a site is missing from that category, please let support know. Or post it here.

 

Political sites - I would have though the act of visiting the site would be sufficient. If you're worried about others finding out about your political leanings i'd avoid using a computer in a filtered environment such as a school or public place to access to those sites at all.

 

As for sites with passwords etc - the Smoothwall doesn't store ay data that passes through, so you have nothing to worry about there.

Posted
This seems totally unnecessary to me. SSL intercept is primarily there to safeguard children using encrypted searches such as Google. You don't need SSL intercept to stop staff shopping online and implement your AUP you just block the sites.

 

I don't perform SSL inspection on any staff traffic. For pupils I perform it on to Google, Bing and Youtube all of which have strict safe searches locked.

 

If nothing else doing widespread SSL inspection uses allot of computing resources and does break some services.

 

You corroborate my thoughts.

Posted
I would suggest everything is decrypted and inspected apart from category SSL/CRL and any websites that fail to work with the inspection.

Financial sites should be set to validate certificate if not inspected, this will give you cover for any spoofed sites and block cert failures.

 

Without https inspection, the smoothwall cannot read the information going through from upstream web server to internal client as it is an encrypted connection, therefore the content filter is unable to categorise web sites, you then have to really on the blocklist. If the url is not within the blocklist then the user gets to the site. Currently there are (according to a quick google search) 70 domains and 571 web sites made every minute of the day. Revealed, what happens in just ONE minute on the internet: 216,000 photos posted, 278,000 Tweets and 1.8m Facebook likes | Daily Mail Online how accurate that is, is questionable.

 

If you have difficulties whilst decrypting, with services erroring then please give us a call at support.

 

Thank you, but as stated in my original question, I am not your customer and I don't have a Smoothwall device, the local authority in it's capacity as school broadband provider does, and I am their customer. I was surprised that compared to the previous filtering provider that just about everything was being decrypted for adults when it wasn't previously.

Posted
Isn't good enough on it's own, and puts the responsibility of that entirely on your shoulders. Consider that so much more of the web is being SSL encrypted, not wanting that to safeguard all users in school is hardly advisable. Not filtering staff SSL whatsoever is highly irresponsible IMO and asking for trouble.
  • Thanks 3
Posted
I thought Safeguarding applied to vulnerable adults and young people. I wouldn't have thought staff would be classed as vulnerable and in need of safeguarding.
  • Thanks 1
Posted
I thought Safeguarding applied to vulnerable adults and young people. I wouldn't have thought staff would be classed as vulnerable and in need of safeguarding.
You also have to consider that sometimes dodgy people slip though the net. It's like CCTV. People usually only have an issue with it if they want to hide something.
  • Thanks 1
Posted
Isn't good enough on it's own, and puts the responsibility of that entirely on your shoulders. Consider that so much more of the web is being SSL encrypted, not wanting that to safeguard all users in school is hardly advisable. Not filtering staff SSL whatsoever is highly irresponsible IMO and asking for trouble.

 

I'm not suggesting that there should be no "filtering" of adults, I totally agree that there is a whole plethora of sites that should be "blocked" for the many and various reasons that we all know. Of course everybody's internet in school should be filtered. In addition to those that should rightly (or wrongly sometimes), be blocked by default, I now have access to a portal where I can custom block/unblock. ( I've never had that before. Previously I had to fill in an e-form and my request was validated by the filtering provider and then enacted. I'm not actually sure I want to be solo accountable for blocking/unblocking directly - as you say, too much responsibility. I know some small schools that will just unblock if a lesson has been prepared without considering anything or website T'S and C's or privacy policies, the Data Protection Act - just for expediency, I also recall the KS1 teacher that asked the class to search for "Asian Bears" when filtering was less capable than it is now. but I digress...)

 

My concern is of covert surveillance of adults by the Local Authority, the exposure of Account ID's, passwords, credit card, "sensitive personal data" etc as defined by the DPA/GDPR and and also that of third parties from social media updates on BYOD devices by decryption of HTTPS, and what the legal basis is that is being relied on for doing this.

 

Decryption is not needed to block access to HTTPS.

Posted
It's not covert if you inform them. If you don't do Https inspection you may as well not be doing filtering. URL filtering relies on your filter knowing the content of the site. If it is a new site that has just popped up that serves up some nice pron via Https and a teacher accesses it in front of children then expect lots of crying children.
  • Thanks 1
Posted
You also have to consider that sometimes dodgy people slip though the net. It's like CCTV. People usually only have an issue with it if they want to hide something.

 

So you have glass walls in your bathroom? Nice! :getmecoat:

 

https://www.openrightsgroup.org/blog/2015/responding-to-nothing-to-hide-nothing-to-fear

Debunking a myth: If you have nothing to hide, you have nothing to fear - Identity, Privacy and Trust

https://en.wikipedia.org/wiki/Nothing_to_hide_argument

 

If there are any suspicions about individual adults in schools (or any workplace), the proportionate response is to investigate that individual not the entire school population. Most schools have policies and there are legal processes to do that.

Posted

We have had a situation where a member of non teaching staff has had their contract terminated due to inappropriate internet usage. Nobody would have suspected but smoothwall gave us that visibility and evidence.

 

Sorry but comparing my bathroom to the use of monitoring on a school internet connection isn't the same.

  • Thanks 1
Posted
It's not covert if you inform them. If you don't do Https inspection you may as well not be doing filtering. URL filtering relies on your filter knowing the content of the site. If it is a new site that has just popped up that serves up some nice pron via Https and a teacher accesses it in front of children then expect lots of crying children.

 

Even SSL inspection cannot eliminate this as a possibility as no filter is perfect and none can determine whether an image is safe.

 

SSL is a necessary evil as it breaks many of the internets fundamental principles for end to end security and individual privacy.

 

I think used sparingly for vulnerable groups its acceptable but I question it use as the norm for all internet use including staff.

 

What happens if Smoothwall's private certificates are compromised and your staff are subject to a real MITM attack with financial losses.

  • Thanks 1
Posted
It's not covert if you inform them. If you don't do Https inspection you may as well not be doing filtering. URL filtering relies on your filter knowing the content of the site. If it is a new site that has just popped up that serves up some nice pron via Https and a teacher accesses it in front of children then expect lots of crying children.

 

The url is not encrypted when visiting an HTTPS. The website can still be categorised without decrypting.

Posted
The url is not encrypted when visiting an HTTPS. The website can still be categorised without decrypting.
The URL isn't. But content inside is. If the filter doesn't know what is inside it relies on knowing the category of the site. Consider this example. I register applesapplesapples.co.uk stuff it full of pron and enforce https. If my filter isn't doing mitm and doesn't know that my site has pron on it is open access for all.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...