sigma Posted January 13, 2018 Author Posted January 13, 2018 Sorry but comparing my bathroom to the use of monitoring on a school internet connection isn't the same. It's like CCTV. People usually only have an issue with it if they want to hide something. Sorry, I mentioned your bathroom in the context of your CCTV comment. https://www.theguardian.com/technology/2015/jul/23/panopticon-digital-surveillance-jeremy-bentham https://en.wikipedia.org/wiki/Panopticon
ReBoot Posted January 13, 2018 Posted January 13, 2018 The URL isn't. But content inside is. If the filter doesn't know what is inside it relies on knowing the category of the site. Consider this example. I register applesapplesapples.co.uk stuff it full of pron and enforce https. If my filter isn't doing mitm and doesn't know that my site has pron on it is open access for all. If I create site applesapplesapples.co.uk and only host adult images no filter (mitm or not) could detect this and determine whether to block. Only if I add text to suggest the nature of the content would the filter be able to make a decision. SSL mitm helps but is not foolproof and nothing is 100% reliable at filtering. 1
sigma Posted January 13, 2018 Author Posted January 13, 2018 The URL isn't. But content inside is. If the filter doesn't know what is inside it relies on knowing the category of the site. Consider this example. I register applesapplesapples.co.uk stuff it full of pron and enforce https. If my filter isn't doing mitm and doesn't know that my site has pron on it is open access for all. I take your point, but please excuse me as I'm a newb to Smoothwall, but other devices can replay the base HTTPS url to categorise it?
markwilfan Posted January 13, 2018 Posted January 13, 2018 If I create site applesapplesapples.co.uk and only host adult images no filter (mitm or not) could detect this and determine whether to block. Only if I add text to suggest the nature of the content would the filter be able to make a decision. SSL mitm helps but is not foolproof and nothing is 100% reliable at filtering.No filter at the moment but just think how Google ai works. In the future it may be possible. I should have added to my scenario that there would be text just like most other pron sites 1
markwilfan Posted January 13, 2018 Posted January 13, 2018 I take your point, but please excuse me as I'm a newb to Smoothwall, but other devices can replay the base HTTPS url to categorise it?I assume that smoothwall themselves categorise websites and probably use some other master list too. 1
markwilfan Posted January 13, 2018 Posted January 13, 2018 To be honest guys I would take this to your safeguarding lead. Delegate the decision to somebody who may be more qualified to do so. In our school this has been the outcome of our discussions. We let staff access most categories of site. Anything that may be controversial pulls up a soft block so they can make the adult decision to carry on apart from pron. All sites are SSL decrypted by default apart from banking and manually approved sites that we have risk assessed and only if this is breaking some kind of service. 1
synaesthesia Posted January 14, 2018 Posted January 14, 2018 Noone said staff are vulnerable or anything like that, however the sites they visit should be treated pretty much equally as students. With all the will, training and pleading in the world, teachers will still live search items when on the internet on a projector/whiteboard, they will still click blindly on links without checking first. Then it's not just 1 pupil who could see something inappropriate and damaging, it's 30 odd. 2
markwilfan Posted January 14, 2018 Posted January 14, 2018 Noone said staff are vulnerable or anything like that, however the sites they visit should be treated pretty much equally as students. With all the will, training and pleading in the world, teachers will still live search items when on the internet on a projector/whiteboard, they will still click blindly on links without checking first. Then it's not just 1 pupil who could see something inappropriate and damaging, it's 30 odd.^this... 1
sigma Posted January 14, 2018 Author Posted January 14, 2018 Noone said staff are vulnerable or anything like that, however the sites they visit should be treated pretty much equally as students. With all the will, training and pleading in the world, teachers will still live search items when on the internet on a projector/whiteboard, they will still click blindly on links without checking first. Then it's not just 1 pupil who could see something inappropriate and damaging, it's 30 odd. Consider whether staff using the internet in front of pupils should be using a filter appropriate to the relevant key stage they are teaching in any case?
sigma Posted January 14, 2018 Author Posted January 14, 2018 I would suggest everything is decrypted and inspected apart from category SSL/CRL and any websites that fail to work with the inspection. Financial sites should be set to validate certificate if not inspected, this will give you cover for any spoofed sites and block cert failures. Without https inspection, the smoothwall cannot read the information going through from upstream web server to internal client as it is an encrypted connection, therefore the content filter is unable to categorise web sites, you then have to really on the blocklist. If the url is not within the blocklist then the user gets to the site. Currently there are (according to a quick google search) 70 domains and 571 web sites made every minute of the day. Revealed, what happens in just ONE minute on the internet: 216,000 photos posted, 278,000 Tweets and 1.8m Facebook likes | Daily Mail Online how accurate that is, is questionable. If you have difficulties whilst decrypting, with services erroring then please give us a call at support. Are you suggesting that it is necessary to decrypt the logon account details of Marks and Spencer and John Lewis (for example) every single time because regardless of how many times the (unencrypted) domain name and how many times the same SSL cert is presented that Smoothwall still doesn't know the categories the domains belong to?
sigma Posted January 14, 2018 Author Posted January 14, 2018 It's worth pointing out that the default config does exclude banking sites from decryption. If you could check to see if HSBC is decrypted (you'll get a different cert if you are being MITMd) then you can tell if your county kept this default. If that's the case, and you think a site is missing from that category, please let support know. Or post it here. Political sites - I would have though the act of visiting the site would be sufficient. If you're worried about others finding out about your political leanings i'd avoid using a computer in a filtered environment such as a school or public place to access to those sites at all. As for sites with passwords etc - the Smoothwall doesn't store ay data that passes through, so you have nothing to worry about there. When I checked my system. All bank websites I tested (Coop Bank, Barclays, Nat West) ,were being decrypted with the exception of their login pages. As I don't yet feel confident in your system not to decrypt my bank account details once I'd logged onto my account, I didn't attempt a login. An online savings account from a smaller provider did have its login page decrypted. The login page to the Smoothwall portal was also decryped. Regarding political sites, the Data Protection Act requires certain conditions pertaining to the processing of certain classifications of data. I would think that decrypting the logon pages of "regular" political parties would fall within the scope of the Act. Obviously this doesn't apply to material that falls within the scope of the Prevent Program which I hope would be flagged up by "safeguarding".
markwilfan Posted January 14, 2018 Posted January 14, 2018 It's obvious that this discussion is going in circles now and not benefitting anybody. Speak to your safeguarding lead for advice and then speak to your lea. They will be able to add sites to an exception list. As a bare minimum I would suggest that the certificate is checked for validity instead of being decrypted and checked. My personal feeling is that if a member of staff is using the school network to order stuff from John Lewis they must remember that they are not using their own private internet connection and must remember monitoring is happening. As previously said by somebody else, smoothwall is not actively saving passwords or usernames. 2
sigma Posted January 14, 2018 Author Posted January 14, 2018 It's obvious that this discussion is going in circles now and not benefitting anybody. Speak to your safeguarding lead for advice and then speak to your lea. They will be able to add sites to an exception list. As a bare minimum I would suggest that the certificate is checked for validity instead of being decrypted and checked. My personal feeling is that if a member of staff is using the school network to order stuff from John Lewis they must remember that they are not using their own private internet connection and must remember monitoring is happening. As previously said by somebody else, smoothwall is not actively saving passwords or usernames. Maybe not for you, but I have learned a bit more about how Smoothwall works, and for that I thank you for your contributions. More commonly, its Amazon and educational suppliers of course, but the same applies.
markwilfan Posted January 14, 2018 Posted January 14, 2018 Maybe not for you, but I have learned a bit more about how Smoothwall works, and for that I thank you for your contributions. More commonly, its Amazon and educational suppliers of course, but the same applies.Sorry didn't mean it to sound as harsh as it does. Just meant we are all going over the same points. If I were in your shoes I'd be asking the LA for training. Smoothwall have an accreditation you can do which I found useful to work out what it can and can't do.
EmperorPeng Posted November 29, 2018 Posted November 29, 2018 We have a Smoothwall device and both staff and students have the same policy, same restrictions, same https inspection. I make it clear to our users that they have no expectation of privacy whilst using our network and that we reserve the right to monitor everything that they do whilst they are logged on. 1
DGardiner Posted November 30, 2018 Posted November 30, 2018 (edited) We have a Smoothwall device and both staff and students have the same policy, same restrictions, same https inspection. I make it clear to our users that they have no expectation of privacy whilst using our network and that we reserve the right to monitor everything that they do whilst they are logged on. exactly this. contextual blocking relies on ssl interception to work, if i wasnt going to use it id have got a much cheaper product! end of the day we have to protect the users from themselves, your average teacher will just type a statement into google and click the first thing in the list and believe it as gospel Edited November 30, 2018 by DGardiner
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now