Jump to content

Recommended Posts

Posted

Client-first = "Establish a secure connection with the client first, then connect to the server" This is the way Squid 3.1 did it.

 

Looking through the various wiki's on this and related subjects it seems that more modern methods that will ultimately be highly compatible with TLS 1.2 and 1.3 are varying degrees of not finished/broken/hacky. This supports the assertions from the ISP teams I have spoken to where they say (to paraphrase) "The vendors have code that works, but not sufficiently reliably/efficiently to deploy at the scale required."

Posted

Thanks for the detailed info.

 

If we disable QUIC, TLS 1.3, HTTP 2.0 etc, won't our internet be SLOW? I mean slower than it could be.

 

Apart from iOS, client side agents could be installed I guess.

 

Technology always outpaces the law

Posted

So basically, sooner or later we may as well just have to turn off the internet for students in schools if we are to meet obligations. Definitely no more BYOD from now and no 1:1, seems a step backwards for all the pushing of IT in education.

 

I totally get the need for privacy and I'm all for it, but we have duty of care \ prevent that we will not be able to easily provide in the near future - not sure what the answer is

Posted
If we disable QUIC, TLS 1.3, HTTP 2.0 etc, won't our internet be SLOW? I mean slower than it could be.

 

QUIC and HTTP 2.0 both offer improvements in page loading speeds, so without those you *might* notice things being slightly slower. In reality I'm not convinced it's going to be a big deal. A filter is always going to add a small amount of latency anyway and all of this is likely to be pretty marginal.

 

Apart from iOS, client side agents could be installed I guess.

 

Client side stuff always has the problem that the kids will simply uninstall it (but then the filter can possibly detect that and block access to clients that have it uninstalled). Which is why the Safer Internet Centre's guidelines say that client-side stuff isn't good enough.

Posted
So basically, sooner or later we may as well just have to turn off the internet for students in schools if we are to meet obligations. Definitely no more BYOD from now and no 1:1, seems a step backwards for all the pushing of IT in education.

 

A school is always going to have more control over their own connection than over 4G, etc. You just might not be able to get quite as much control as you'd like. Having the kids on your connection will allow *some* safeguarding, but obviously the school may be liable if someone is using the connection for something they shouldn't. It's certainly not an easy choice.

 

I totally get the need for privacy and I'm all for it, but we have duty of care \ prevent that we will not be able to easily provide in the near future - not sure what the answer is

 

I couldn't agree more, but unfortunately this is going to take engagement from everyone involved - schools and filtering providers are not going to be able to solve all of these problems on their own if the likes of Google and Facebook are actively working against them. If schools want to see this stuff fixed they need to pressure these companies by refusing to buy their services and explaining to them why.

 

Unfortunately I think that any future legislation to force tech companies to help with schools safeguard kids will always end up bundled together with governments snooping on everyone, and quite rightly there would be a lot more push back on those kinds of laws than ones which are specifically aimed at helping to safeguard children in school. You don't need to undermine everyone's security in order to allow schools to safeguard children under their care.

  • Thanks 2
Posted

I've always found that filtering and censorship get in the way of education, the kids should be properly educated first and foremost in usage of the internet - after all they have free reign at home why should it be any different in a school ? If they get blocked now through word of mouth they just install a VPN without any clue on what a VPN does except it gets their snapchats or something

 

I'm a bit loath to renewing contracts on filtering that just almost does the job - it's a fair chunk of my budget

Posted
it's unlikely the students are filtered much a) at home and b) on their phone, so it's probably not worth breaking secure connections to fix it for a few kids in education compared to putting the lives of people in dangerous places at risk.
Posted
I've always found that filtering and censorship get in the way of education, the kids should be properly educated first and foremost in usage of the internet - after all they have free reign at home why should it be any different in a school ? If they get blocked now through word of mouth they just install a VPN without any clue on what a VPN does except it gets their snapchats or something

 

I'm a bit loath to renewing contracts on filtering that just almost does the job - it's a fair chunk of my budget

 

I think you're right... mostly :)

 

There's certainly something to be said for basic filtering to stop people accidentally stumbling across something they don't want to see, but you're not going to stop someone who's determined to get to blocked things. Our focus these days is on the reporting side of things rather than filtering - that way you can relax your filtering rules a bit so they don't get in the way of education and use the reports to give you a heads up when you may need to intervene on a case by case basis. And certainly, kids need to get an education into how to use the internet safely, just as they would be educated on how to cross the road. After all, they will be on their own when they leave school.

Posted
it's unlikely the students are filtered much a) at home and b) on their phone, so it's probably not worth breaking secure connections to fix it for a few kids in education compared to putting the lives of people in dangerous places at risk.

 

To be completely clear: the decryption methods that school filters rely on aren't going to be putting lives at risk. School filters require the users to voluntarily install inspection certificates, which I'm going to assume you're not going to do if an oppressive government asks you to. (And if the OS itself has been backdoored by that government, you're stuffed whatever you do anyway).

Posted
the kids should be properly educated first and foremost in usage of the internet

 

Digital resilience is always better than just saying don't do that. But as with any teaching you don't throw someone in the deep end. You don't give a moped learner a 1000CC superbike, you don't take a dive newbie to the Mariana Trench and you don't give a trainee helicopter pilot the stick, pedals and collective all at once. I think we should be protecting our pupils from some of the real shady areas of the interwebs, do you really want 7 year olds open to beastiality porn? Now maybe we should regulate the internet a bit more and say porn should go on .xxx domains and then schools can just block that but you can guess the likelihood of that happening.

Posted
To be completely clear: the decryption methods that school filters rely on aren't going to be putting lives at risk. School filters require the users to voluntarily install inspection certificates, which I'm going to assume you're not going to do if an oppressive government asks you to. (And if the OS itself has been backdoored by that government, you're stuffed whatever you do anyway).

 

Not putting lives at risk....well, actually I think it does....which is partly why the prevent strategy was put into place. If it’s not under the cover radicisation...it can be self harm..including encitement of suicide...and even sex sites potentially skew their minds ...

 

 

No, sorry...there is serious risk. And I’m not sure that parents understand this...nor governments, despite putting prevent in place.

 

I agree that excessive and intrusive filtering can get in the way of education...but filtering is not at the heart of prevent...but monitoring is.

 

Personally, I’d like to see the age checks being forced on sex sites being extented to social media and or social media being forced to let parents and schools during the school day monitor traffic. It seems bizzare that we allow students a complete invisibility cloak And immunity to bully, commit sexting offences, etc. They don’t have developed minds..and need guidance an supervision. We should not walk our hands of the responsibility.

  • Thanks 1
Posted
Some quick thoughts:

 

QUIC

Not really a big deal since things generally fall back to HTTP if you block QUIC (UDP port 80). But firewalls need to send a rejection rather than just dropping the traffic. HTTP 2.0 is a bigger problem.

 

It shouldn't be a problem but in practice I found apps don't switch neatly when they're open on 4G then connected to Wi-Fi where Quic is blocked. Force closing and reopening tends to do the trick in terms of restarting with a fresh connection but pretty poor end-user experience and many will just think something is "broken"

 

The issues with Quic soon became irrelevant because of the pinning issues you describe afterwards - was either allow YouTube without inspection or have the app not working.

Posted
Digital resilience is always better than just saying don't do that. But as with any teaching you don't throw someone in the deep end. You don't give a moped learner a 1000CC superbike, you don't take a dive newbie to the Mariana Trench and you don't give a trainee helicopter pilot the stick, pedals and collective all at once. I think we should be protecting our pupils from some of the real shady areas of the interwebs, do you really want 7 year olds open to beastiality porn? Now maybe we should regulate the internet a bit more and say porn should go on .xxx domains and then schools can just block that but you can guess the likelihood of that happening.

 

Well, you can force safe search, and block via ip. You can whitelist for primary school if you want.

 

I'd guess than most of the harmful things like bullying and promoting self harm happens at home, better to educate them in how to use facebook/im/etc properly, here's how you block, here's how you report, and actually do it on their accounts, because you've not blocked it all. Also actual lessons in the psychology of why people are attacking them, and how to not be hurt by it

  • Thanks 1
Posted
Now maybe we should regulate the internet a bit more and say porn should go on .xxx domains and then schools can just block that but you can guess the likelihood of that happening.

 

I think the government missed a trick with the whole age verification thing they are pushing. Who's going to want to hand over credit card numbers, etc. to verify their age to a porn site? I think the age verification checks will become such a hurdle for the legitimate business of porn sites that they will start to move overseas to avoid the age verification legislation. It would've been far better to legislate that porn sites must be easy to filter (e.g. inserting appropriate HTTP headers, etc.), which wouldn't have got in the way of their normal business but would've allowed parents to have better control over what their kids can get to.

Posted
Some quick thoughts:

 

 

 

Certificate pinning

When done properly, certificate pinning isn't a problem. e.g. Google's certificates are pinned in Chrome, but that's fine because Chrome also trusts manually installed certificates to override pinning.

 

 

Good summary Steve.

Cert pinning is dead - https://scotthelme.co.uk/the-death-knell-for-hpkp/ - it wasn't a great idea in the first place, as it only provided added toughness for large companies, and done wrong, it was fatal. Certificate Transparency is the "new hotness".

As you say though, apps no longer trust the user cert store by default - I can sorta see why this was done, but it's irritating for filtering. A better solution would have been to let the user choose, and be very explicit about that trusting a cert means. On the other hand, we've seen the carnage "let the user choose" can cause...

  • Thanks 2
Posted
As you say though, apps no longer trust the user cert store by default - I can sorta see why this was done, but it's irritating for filtering. A better solution would have been to let the user choose, and be very explicit about that trusting a cert means. On the other hand, we've seen the carnage "let the user choose" can cause...

 

Well, Android always was pretty explicit (users with a cert installed got a "you're being watched" notification on every boot.) But I think the worst thing is that, as far as I'm aware, there's no way for even school-deployed Android 7 devices to change the "don't trust manually installed certs" default. (You have to rebuild every app package individually to change that, which realistically a school isn't going to be doing.)

Posted
No government should be meddling in the fundamental ways in which the Internet and the Web works (it's inherently impossible to do, the Internet is a global network)

 

A British government can certainly regulate how British companies behave on the internet and that's often a good thing. i.e. "you may not sell illegal drugs through your website" and "you may not use false advertising on the internet". But the government also has to be mindful of the fact that the internet is global and there is a tipping point where regulations become so onerous that businesses start moving overseas in order to avoid that legislation. Its obviously a lot easier to move overseas if your business is entirely electronic (but even where you need to ship physical products to the customer, businesses seem to be doing a pretty good job of flouting false advertising regulations by basing themselves in China).

 

If the government had come along and said that porn sites must embed HTTP headers in their traffic to make it easier for parents to filter the traffic, I can't imagine there would be much push-back from the porn sites. It's easy to do, it doesn't affect the legitimate customers, complying makes the porn industry look more responsible and it doesn't introduce any data protection problems. No one is going to move their business overseas to get out of that. Obviously companies that are already overseas aren't going to be affected, but it would at least help a little bit with filtering the domestic sites. Since it wouldn't be especially controversial, there's a good chance that the rest of Europe and the US could also be convinced to enact similar legislation.

 

On the other hand, introducing measures that will harm the porn producers' legitimate business and introduce a load of data protection problems is going to push producers overseas, and its going to be much harder to convince other countries to do the same.

 

I do agree that the perpetual problem with the government meddling is that they don't understand technology and refuse to listen to anyone who does. I don't expect bosses to understand everything but I do expect them to listen to the people who do.

  • Thanks 1
Posted
Also consider GDPR. EU regulation, but all internet companies are having to adopt compatible policies for EU citizens. When combined with the brouhaha around Facebook at the moment there is an emerging consensus that maybe the web will be a better place because of it.
Posted
Also consider GDPR. EU regulation, but all internet companies are having to adopt compatible policies for EU citizens. When combined with the brouhaha around Facebook at the moment there is an emerging consensus that maybe the web will be a better place because of it.

 

Not convinced that much will change in the long term - GDPR introduces a few nice (as far as the consumer is concerned) new things, but the vast majority of it was already implemented under the Data Protection Act. I think most of the good of GDPR at the moment is that people are worried about the new scary law and are busy implementing things they should have already been doing. Once they realise that it's being enforced by the ICO, who have never been interested in holding anyone but the worst offenders to account, I imagine a lot of stuff will slip back to how it was.

  • 2 years later...
  • 1 month later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...