Jump to content

Recommended Posts

Posted
The push for encryption on systems with personal data is not something new with GDPR.

 

Is it likely/high likely that the school might have been operating in breach of the Data Protection Act?

 

Thanks for your input but Your not exactly contributing to this thread effectively.

 

How about offering a suggestion rather than highlighting everything that is wrong.

 

Let me know if you have any of your own ideas

 

Thanks

Posted
I've put W8.1 on these successfully. Student use, so didn't Bitlocker them - but I can't imagine it wouldn't work as long as you've set the appropriate Group Policy. I'd test, but kinda busy today.

 

They don't run fast, but IIRC 8.1 was better than 7. Of course, if you could afford extra RAM/SSDs it would help.

 

What license agreement do you have ? Did you have problems with activation on your models?

Posted

We use Bitlocker (though there may be some laptops still running truecrypt which we used before it ceased)

 

We use an individual password for each laptop that the teacher chooses. Password must be min of 10 characters and contain lower & upper case, symbol and number(s)

This password is different from their AD login.

 

Staff have a little grumble at first, but I often help them come up with something memorable and it seems to have worked so far.

 

I keep a log of all encryption passwords in case I need to use them.

 

Our new sponsors to be will not allow allow laptops to be taken from school - teachers must provide their own devices to work on anything at home. Waiting to see how that pans out!

  • Thanks 2
Posted
What license agreement do you have ? Did you have problems with activation on your models?

 

Open Value Sub *prays he hasn't been norty by upgrading* and no problems with activation. Like I said, not tried Bitlocker on them, but can't imagine it would be a problem. There tomorrow and will take a look if time.

  • Thanks 1
Posted
Our new sponsors to be will not allow allow laptops to be taken from school - teachers must provide their own devices to work on anything at home. Waiting to see how that pans out!

 

Something like this:

 

torches+pitchforks.jpg

Posted
Our new sponsors to be will not allow allow laptops to be taken from school - teachers must provide their own devices to work on anything at home. Waiting to see how that pans out!

 

 

I hope they:

 

1. subsidise the cost of the laptop

2. don't expect staff or work at home

3. realise the cost of data getting exposed!

  • Thanks 1
Posted
What license agreement do you have ? Did you have problems with activation on your models?

 

Tested one a random 4211C on wireless but plugged in (batteries duff + losing will to get the stopwatch out again).

 

Before BL:

Off to Logon Screen 24s

Logon Screen to Desktop, Student profile 22s

Logon Screen to Desktop, My profile 50s

 

After BL:

Off to BL Password Screen 12s

BL Password Screen to Logon Screen 24s

Logon Screen to Desktop, Student profile 30s

Logon Screen to Desktop, My profile 75s

 

Logon Screen to Desktop seemed to vary a bit, put most common time. Obviously will also vary according to what's happening to your user profiles at logon.

 

It *looks* like BL adds +14 seconds (in total) on that machine to get to the Logon Screen + a variable amount to the logon. Usage doesn't seem any different.

Posted
I hope they:

 

1. subsidise the cost of the laptop

2. don't expect staff or work at home

3. realise the cost of data getting exposed!

 

1. It appears not

2. It appears yes

3. No idea!

Posted
Thanks for your input but Your not exactly contributing to this thread effectively.

 

How about offering a suggestion rather than highlighting everything that is wrong.

 

Let me know if you have any of your own ideas

 

Thanks

 

My suggestion would be to do a proper GDPR data audit etc (or drop the GDPR reference from the thread title; rephrase it as "Another Encryption question - ")

 

You've had these systems out in the field for nigh on 10years without encryption and without any idea what was held on them. After the long overdue encryption is finally put in place, it sounds like you will still have no idea what personal data (if any) is on the systems.

 

Good luck with the rest of your "GDPR" activities.

Posted
Have you considered DesLock from Eset. You do not need the TPM chip for this to work. You can encrypt at Disc/Folder/File level and even encrypt emails on an individual basis. Admin console is used to manage access on a per user basis.
Posted (edited)
We use Bitlocker (though there may be some laptops still running truecrypt which we used before it ceased)

 

We use an individual password for each laptop that the teacher chooses. Password must be min of 10 characters and contain lower & upper case, symbol and number(s)

This password is different from their AD login.

 

Staff have a little grumble at first, but I often help them come up with something memorable and it seems to have worked so far.

 

I keep a log of all encryption passwords in case I need to use them.

 

Our new sponsors to be will not allow allow laptops to be taken from school - teachers must provide their own devices to work on anything at home. Waiting to see how that pans out!

That is a huge security risk as you will have no call on how or what is on this laptops. Under GDPR you need better control of everything that could potentially carry sensitive data including Laptops/Mobiles/Tablets and USB/SD cards. The cost of not providing laptops might pale in to insignificance if you suffer a data breach.

 

The same applies if you expect teachers to use their home computers, you cannot control what is saved to them, too risky by far.

Edited by MrWrighty
  • 5 months later...
Posted

When using Passwords with bitlocker without TPM module, how do you choose a password. Do you set it for the user, or let the user choose their own?

However, if a staff member uses their own password and they bring the laptop in for repair/updates, you would have to ask the user for their own password rather than there being ad admin over-ride or how would you get around this without the user needing to share their password?

Posted
the laptops are not domain joined. they were bought years ago (10years ago maybe) solely for the purpose to aid teachers who didn't have the facility to work on a computer at home were given a staff laptop. so happened that once they new they could get one they suddenly all wanted one

 

Sounds like after 10 years they should be put out to pasture anyway. I'd recall them all, secure wipe them and dispose of the lot.

 

If teachers don't have their own computer then they need to get their hands in their pockets and buy one. Its not the taxpayers responsibility to provide teachers with the basic tools to effectively work in their chosen profession. Every other trade has to buy their own tools, I've never understood why teachers think they are any different.

 

At the end of the day teachers own personal devices are not your concern so I wouldn't lose any sleep over it.

Posted
Sounds like after 10 years they should be put out to pasture anyway. I'd recall them all, secure wipe them and dispose of the lot.

 

If teachers don't have their own computer then they need to get their hands in their pockets and buy one. Its not the taxpayers responsibility to provide teachers with the basic tools to effectively work in their chosen profession. Every other trade has to buy their own tools, I've never understood why teachers think they are any different.

 

At the end of the day teachers own personal devices are not your concern so I wouldn't lose any sleep over it.

 

Have you ever worked in a school??? A school expects only to buy once and never have to renew ever. All equipment must live as long as the person it has been handed to. [emoji12][emoji12][emoji12]

 

I have sent an email to all staff it concerns explaining that they can keep the laptop for what ever purposes they see fit but they aren’t allowed to have any school data on it. If they want to use it for school they must use rds.

Posted
Have you ever worked in a school??? A school expects only to buy once and never have to renew ever. All equipment must live as long as the person it has been handed to. [emoji12][emoji12][emoji12]

 

I have sent an email to all staff it concerns explaining that they can keep the laptop for what ever purposes they see fit but they aren’t allowed to have any school data on it. If they want to use it for school they must use rds.

 

You force SLT's hand by putting a rolling replacement plan in your policies so you don't have to deal with that crap :p

Posted
Have you ever worked in a school??? A school expects only to buy once and never have to renew ever. All equipment must live as long as the person it has been handed to. [emoji12][emoji12][emoji12]

 

I have sent an email to all staff it concerns explaining that they can keep the laptop for what ever purposes they see fit but they aren’t allowed to have any school data on it. If they want to use it for school they must use rds.

 

Yep 13 years in primary and secondary schools. (I should be up for parole soon :))

 

Just explain that they are no longer serviceable and stop supporting them. If staff want to continue using them for personal use at home then let them. It gets them off your hands and saves you the hassle of having to properly dispose of them. You can't be responsible for what data staff decide to copy onto these (or any other) devices. Its beyond your control and staff have to take responsibility for the data they carry around and where they save it. You will never be able to police this whilst the use of portable storage devices is still permitted. Encryption of pen drives is a step in the right direction but it falls short of what is actually required to ensure data is secured.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...