Jump to content

Recommended Posts

Posted
The URL isn't. But content inside is. If the filter doesn't know what is inside it relies on knowing the category of the site. Consider this example. I register applesapplesapples.co.uk stuff it full of pron and enforce https. If my filter isn't doing mitm and doesn't know that my site has pron on it is open access for all.

 

If I create site applesapplesapples.co.uk and only host adult images no filter (mitm or not) could detect this and determine whether to block. Only if I add text to suggest the nature of the content would the filter be able to make a decision. SSL mitm helps but is not foolproof and nothing is 100% reliable at filtering.

  • Thanks 1
Posted
The URL isn't. But content inside is. If the filter doesn't know what is inside it relies on knowing the category of the site. Consider this example. I register applesapplesapples.co.uk stuff it full of pron and enforce https. If my filter isn't doing mitm and doesn't know that my site has pron on it is open access for all.

 

I take your point, but please excuse me as I'm a newb to Smoothwall, but other devices can replay the base HTTPS url to categorise it?

Posted
If I create site applesapplesapples.co.uk and only host adult images no filter (mitm or not) could detect this and determine whether to block. Only if I add text to suggest the nature of the content would the filter be able to make a decision. SSL mitm helps but is not foolproof and nothing is 100% reliable at filtering.
No filter at the moment but just think how Google ai works. In the future it may be possible.

 

I should have added to my scenario that there would be text just like most other pron sites

  • Thanks 1
Posted
I take your point, but please excuse me as I'm a newb to Smoothwall, but other devices can replay the base HTTPS url to categorise it?
I assume that smoothwall themselves categorise websites and probably use some other master list too.
  • Thanks 1
Posted

To be honest guys I would take this to your safeguarding lead. Delegate the decision to somebody who may be more qualified to do so.

 

In our school this has been the outcome of our discussions. We let staff access most categories of site. Anything that may be controversial pulls up a soft block so they can make the adult decision to carry on apart from pron.

 

All sites are SSL decrypted by default apart from banking and manually approved sites that we have risk assessed and only if this is breaking some kind of service.

  • Thanks 1
Posted
Noone said staff are vulnerable or anything like that, however the sites they visit should be treated pretty much equally as students. With all the will, training and pleading in the world, teachers will still live search items when on the internet on a projector/whiteboard, they will still click blindly on links without checking first. Then it's not just 1 pupil who could see something inappropriate and damaging, it's 30 odd.
  • Thanks 2
Posted
Noone said staff are vulnerable or anything like that, however the sites they visit should be treated pretty much equally as students. With all the will, training and pleading in the world, teachers will still live search items when on the internet on a projector/whiteboard, they will still click blindly on links without checking first. Then it's not just 1 pupil who could see something inappropriate and damaging, it's 30 odd.
^this...
  • Thanks 1
Posted
Noone said staff are vulnerable or anything like that, however the sites they visit should be treated pretty much equally as students. With all the will, training and pleading in the world, teachers will still live search items when on the internet on a projector/whiteboard, they will still click blindly on links without checking first. Then it's not just 1 pupil who could see something inappropriate and damaging, it's 30 odd.

 

Consider whether staff using the internet in front of pupils should be using a filter appropriate to the relevant key stage they are teaching in any case?

Posted
I would suggest everything is decrypted and inspected apart from category SSL/CRL and any websites that fail to work with the inspection.

Financial sites should be set to validate certificate if not inspected, this will give you cover for any spoofed sites and block cert failures.

 

Without https inspection, the smoothwall cannot read the information going through from upstream web server to internal client as it is an encrypted connection, therefore the content filter is unable to categorise web sites, you then have to really on the blocklist. If the url is not within the blocklist then the user gets to the site. Currently there are (according to a quick google search) 70 domains and 571 web sites made every minute of the day. Revealed, what happens in just ONE minute on the internet: 216,000 photos posted, 278,000 Tweets and 1.8m Facebook likes | Daily Mail Online how accurate that is, is questionable.

 

If you have difficulties whilst decrypting, with services erroring then please give us a call at support.

 

 

Are you suggesting that it is necessary to decrypt the logon account details of Marks and Spencer and John Lewis (for example) every single time because regardless of how many times the (unencrypted) domain name and how many times the same SSL cert is presented that Smoothwall still doesn't know the categories the domains belong to?

Posted
It's worth pointing out that the default config does exclude banking sites from decryption. If you could check to see if HSBC is decrypted (you'll get a different cert if you are being MITMd) then you can tell if your county kept this default. If that's the case, and you think a site is missing from that category, please let support know. Or post it here.

 

Political sites - I would have though the act of visiting the site would be sufficient. If you're worried about others finding out about your political leanings i'd avoid using a computer in a filtered environment such as a school or public place to access to those sites at all.

 

As for sites with passwords etc - the Smoothwall doesn't store ay data that passes through, so you have nothing to worry about there.

 

When I checked my system. All bank websites I tested (Coop Bank, Barclays, Nat West) ,were being decrypted with the exception of their login pages. As I don't yet feel confident in your system not to decrypt my bank account details once I'd logged onto my account, I didn't attempt a login. An online savings account from a smaller provider did have its login page decrypted. The login page to the Smoothwall portal was also decryped. :ohwell:

 

Regarding political sites, the Data Protection Act requires certain conditions pertaining to the processing of certain classifications of data. I would think that decrypting the logon pages of "regular" political parties would fall within the scope of the Act. Obviously this doesn't apply to material that falls within the scope of the Prevent Program which I hope would be flagged up by "safeguarding".

Posted

It's obvious that this discussion is going in circles now and not benefitting anybody.

 

Speak to your safeguarding lead for advice and then speak to your lea. They will be able to add sites to an exception list. As a bare minimum I would suggest that the certificate is checked for validity instead of being decrypted and checked.

 

My personal feeling is that if a member of staff is using the school network to order stuff from John Lewis they must remember that they are not using their own private internet connection and must remember monitoring is happening. As previously said by somebody else, smoothwall is not actively saving passwords or usernames.

  • Thanks 2
Posted
It's obvious that this discussion is going in circles now and not benefitting anybody.

 

Speak to your safeguarding lead for advice and then speak to your lea. They will be able to add sites to an exception list. As a bare minimum I would suggest that the certificate is checked for validity instead of being decrypted and checked.

 

My personal feeling is that if a member of staff is using the school network to order stuff from John Lewis they must remember that they are not using their own private internet connection and must remember monitoring is happening. As previously said by somebody else, smoothwall is not actively saving passwords or usernames.

 

Maybe not for you, but I have learned a bit more about how Smoothwall works, and for that I thank you for your contributions.

 

More commonly, its Amazon and educational suppliers of course, but the same applies.

Posted
Maybe not for you, but I have learned a bit more about how Smoothwall works, and for that I thank you for your contributions.

 

More commonly, its Amazon and educational suppliers of course, but the same applies.

Sorry didn't mean it to sound as harsh as it does. Just meant we are all going over the same points.

 

If I were in your shoes I'd be asking the LA for training. Smoothwall have an accreditation you can do which I found useful to work out what it can and can't do.

  • 10 months later...
Posted
We have a Smoothwall device and both staff and students have the same policy, same restrictions, same https inspection. I make it clear to our users that they have no expectation of privacy whilst using our network and that we reserve the right to monitor everything that they do whilst they are logged on.
  • Thanks 1
Posted (edited)
We have a Smoothwall device and both staff and students have the same policy, same restrictions, same https inspection. I make it clear to our users that they have no expectation of privacy whilst using our network and that we reserve the right to monitor everything that they do whilst they are logged on.

 

exactly this.

 

contextual blocking relies on ssl interception to work, if i wasnt going to use it id have got a much cheaper product!

 

end of the day we have to protect the users from themselves, your average teacher will just type a statement into google and click the first thing in the list and believe it as gospel

Edited by DGardiner

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...