Jump to content

Recommended Posts

Posted

How do people handle HTTPS filtering on BYOD? Particularly in regard to getting the certificate installed? It seems to me that there is a battle going on between companies who provide filtering, and those who provide hardware, browsers etc.. and the filtering is losing.

 

The process to install a certificate to decrypt traffic is so complicated for an end user that I can't bring myself to start writing guides for iOS, Android, Windows, MacOS etc.. as I know our users will not be able to handle the complicated process of getting the certificate in the right place, and trusting it.

 

At the same time, I'm reluctant to turn off HTTPS for BYOD, as we want our students to be able to bring in their own devices and use them safely in school.

 

The fact that HTTPS filtering now seems to break so many apps anyway, even if configured correctly, I can't help but think that filtering HTTPS is going to become impossible very soon, and as most websites are switching to HTTPS, that means that filtering in general is going to become impossible.

 

Am I exaggerating the problem, or do others think this is the way it is going?

Posted

We help anyone in School (6th form/staff) deploy the certificate and it hasn't been an issue really.

For visitors we do not do HTTPS Inspection as its too time consuming to install certificates. They have to get a guest pass from us so its not a free for all. They get student level filtering and we just bypass inspection.

Posted

The fact that HTTPS filtering now seems to break so many apps anyway, even if configured correctly, I can't help but think that filtering HTTPS is going to become impossible very soon, and as most websites are switching to HTTPS, that means that filtering in general is going to become impossible.

 

The apps are a real problem for us, by the time you've either whitelisted or broken WhatsApp, Snapchat, YouTube, Google etc. you've either allowed the data you want to inspect out unfiltered or caused some very unhappy users. School environment you may be wanting to block those anyway but if you're providing the Wi-Fi for leisure as well as learning it's really difficult to implement MITM in an effective way because of certificate pinning :(

  • Thanks 1
Posted
Words of wisdom here...and I concur with them, in That filtering for tablets...android or iOS ....And allowing access to a range of apps...and it’s not just social media ones....is to many practical purposes..impractical. Or at least not if you want to achieve even a basic level of monitoring which it would seem schools are required to do. As gshaw says by the time you have included a long list of exceptions and bypasses including access to potentially unmoderated sites where various apps turn to store their content you may as well not bother with a web filter for mobile devices. And by the time Android 8 arrives which I’m told won’t even allow a MITM certificate...what little visibility sophisticated, lightspeed, and smoothwall provide will be closed off.
  • Thanks 1
Posted

Same issue here.

 

Plan:

6th form byod proposing cert install. Guests no.

Depends on webfilter but allowing the ip range for guests out without ssl filtering is our obstacle but easily achievable.

 

Our biggest challenge will be stopping students using guest.

Posted
And by the time Android 8 arrives which I’m told won’t even allow a MITM certificate...what little visibility sophisticated, lightspeed, and smoothwall provide will be closed off.

 

 

Apple will no doubt follow suit and where does that leave us ? Sounds like we need something new, perhaps just going back to DNS filtering..... I'm not prepared to pay for a product that won't work

Posted

This is the direction things seems to be going in, rather than providing a safe environment we are increasingly being asked to unblock things, reduce previously requested security settings to allows students more freedom. Personally it seems the only way this will end up is with 1:1 devices and practically unfiltered access apart from the core things that would be blocked anywhere.

 

I love to see new technology being introduced and giving more flexibility in the classroom is great but there’s a tipping point where we almost relinquish control to allow it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...