Jump to content

Recommended Posts

Posted
You do know that if I come to your school I can logon to your school's portal with my school's account and make changes to your school's filtering?

Discovered this as well. I have two logins. One for a secondary school and one for a primary school.

 

If I login with the primary school account while on the secondary school network I get the secondary school filter lists.

Posted
Discovered this as well. I have two logins. One for a secondary school and one for a primary school.

 

If I login with the primary school account while on the secondary school network I get the secondary school filter lists.

 

I reported this plus the inability to change passwords that are shared with County, MLL and Smoothwall (so no accountability) back in November!

Posted (edited)

Hi!

 

With thanks to Sigma for giving me the heads-up about this conversation, I have to say that the transfer from E2BN to MLL/Smoothwall has been and continues to be a rough ride.

 

 

Being a Google school, Westley has been up the proverbial creek for far too long. My teachers think that I have lost it but I am still waiting for some help from Suffolk IT/MLL/Smoothwall. G-Suite is simply not working on mobile devices and it's not much better on PCs. Even though every device has the certificate on it, the issue would sem to be down to Google's use of SSL across the board. E2BN were able to allow it through so why can't Smoothwall?!?

 

 

Our Chromebooks were, initially, expensive placemats until I discovered that wiping them and re-enrolling them onto the domain made them function again. That said, pushed/pinned apps are not appearing.

 

The puritanical filtering on Staff/Admin profiles is yet another matter. Sigma's cucumber simply highlights how ridiculous the situation has become. If, like E2BN, they could add a comment facility to their blocked pages, they could start to turn the tide on such stupidity.Suffolk have closed the mail account that was supposedly our contact with the company so I have had to start afresh with an Schools' Choice helpdesk ticket. I was surprised to find that, even then, simple requests for exceptions to be added to the firewall are no longer dealt with in-house so I am not quite sure what the 'networks team' are doing. Having sent the standard form to the helpdesk, one request is finally, after a couple of months, sorted.

 

 

When chasing it up on the IT helpdesk, I discovered that 'they' had closed the ticket without processing it or informing me of any problems. Finally, when I had a Smoothwall tech on the phone, he had the wrong information - thinking that we had a proper Smoothwall setup. This was clearly a case of Chinese Whispers, where the message changes from one end of the line to the other.

 

 

Leaving the county's broadband provision is fast rising to the top of my list.

 

 

As for the idex client, I have not bothered with that and have no plans to do so in the future. With regards to the contradictory need for monitoring pupils online activities for safeguarding reasons and the oncoming GDPR, I am happy with the Impero system that we have in place. The monitoring is purely in-house and the logs can easily be deleted.

 

 

Finally, for now, with no signs of light or life at the end of the Smoothwall Tunnel, I will wish you all a sunny, good weekend!

Edited by Westley_IT
  • Thanks 1
Posted

I hope that anyone - especially adults - using this service prior to mid-January to access any online accounts has changed their passwords as all those logon pages were being decrypted and inspected at that time. The major bank domain urls were excluded, but not the logon urls. (The padlock showed that it was the installed SSL cert not the "real" SSL cert being used to secure the session).

 

DPA/GDPR anyone?

 

Now it's just searches, Wikipedia, YouTube(?) and all your Social Media (incoming and outgoing) that is being decrypted and inspected. I've not yet finished testing APPS to figure out what's going on there.

Posted
I did'nt make the move to the new proxy until mid March so hopefully I've not been caught in that drag net!!!
Posted
Today's issue:

Teacher does news search (think she mean't to do image search) for "cucumber" and it gets blocked for reason "Core blocked - porn"

 

I do pupil search (KS1/2) for "news for Cucumber" and the first Google search result is:

Why would anyone cleanse their vagina with a cucumber? - BBC Three

https://www.bbc.co.uk/bbcthree/article/ab7a165a-3904-477b-8878-e55833f44e1a

 

This system is seriously failing.

 

Hi @sigma - we've got a blocklist feedback form where you can submit any categorisation issues you come across, or you can send me a message on here and I'll try to resolve any categorisation issues you encounter. Could you expand on the problem above? I've tested a variety of cucumber related search terms but haven't been able to replicate the issue described where the results were blocked.

 

Today a search for:

Can+you+grow+potatoes+inside?

 

Is blocked by the "core block" for *drugs*

 

Who knew?

 

This one should now be resolved :) We provide a list of search terms and one of them was overzealously blocking the phrase potatoes because it contained the word pot. We're usually very careful to make sure this kind of thing doesn't happen, but sometimes problematic search terms slip through the net.

I had the same with Bing searches for "Twinkl" that were being blocked because the word "twink" is a descriptive word for a certain kind of gay man :rolleyes2: this filter is a mess!

 

And I have rolled back the use of the idex client for now until GDPR issues are made clear. Only filtering based on machine IP now.

 

Hi @TomHD - As above, any issues you encounter can be submitted via the blocklist feedback form or by sending me a PM on Edugeek. I've tested the search term but haven't been able to replicate the problem, is this still being blocked on your network? If it is, can you let me know for what reason it's being blocked (I assume it's blocked on content). When I performed some tests, variations on the word "twinkl" did return results that were pornographic and/or inappropriate for young audiences, and these were correctly identified and blocked by Guardian as 'Pornography'.

Posted

Hi CSmith thanks for hopping into the thread.

 

With reference to the above, can you explain in what circumstance a safeguarding record is logged. I've not yet managed to get a safeguarding report to run

 

If a teacher searches for cucumber for example and gets a porn block, how we can get that log record deleted as they were not actually looking for porn? If anyone were later to search the records it could be assumed that somebody at the school was looking for porn when they were not.

Posted

 

 

As for the idex client, I have not bothered with that and have no plans to do so in the future. With regards to the contradictory need for monitoring pupils online activities for safeguarding reasons and the oncoming GDPR, I am happy with the Impero system that we have in place. The monitoring is purely in-house and the logs can easily be deleted.

 

 

 

There wouldn't be quite such a conflict of interest between safeguarding and GDPR if the Smoothwall logs could only be accessed securely by the appropriate schools and deleted as required by the schools' internal processes.

 

Three doesn't seem to have been any forethought as to what is legal and appropriate for adults.

Posted
Hi @sigma - we've got a blocklist feedback form where you can submit any categorisation issues you come across, or you can send me a message on here and I'll try to resolve any categorisation issues you encounter. Could you expand on the problem above? I've tested a variety of cucumber related search terms but haven't been able to replicate the issue described where the results were blocked.

 

 

 

This one should now be resolved :) We provide a list of search terms and one of them was overzealously blocking the phrase potatoes because it contained the word pot. We're usually very careful to make sure this kind of thing doesn't happen, but sometimes problematic search terms slip through the net.

 

 

Hi @TomHD - As above, any issues you encounter can be submitted via the blocklist feedback form or by sending me a PM on Edugeek. I've tested the search term but haven't been able to replicate the problem, is this still being blocked on your network? If it is, can you let me know for what reason it's being blocked (I assume it's blocked on content). When I performed some tests, variations on the word "twinkl" did return results that were pornographic and/or inappropriate for young audiences, and these were correctly identified and blocked by Guardian as 'Pornography'.

 

 

 

We are tenants, we do not have a serial number. Is the only way that we can provide blocklist feedback via a third party community forum?

Posted
Hi CSmith thanks for hopping into the thread.

 

With reference to the above, can you explain in what circumstance a safeguarding record is logged. I've not yet managed to get a safeguarding report to run

 

Hi @sigma, a safeguarding alert should be generated any time a user accesses a webpage which is categorised as one of 'Child Abuse', 'Drugs', 'Intolerance', 'Pornography', 'Alcohol', 'Self Harm', 'Terrorism Violence', 'Sexuality Sites', 'Personal Weapons', 'Criminal Activity', or 'Adult sites'. These are all categories which we provide, and these fit into different rulesets (e.g. the 'Intolerance' and 'Terrorism' categories go into the 'Radicalisation' ruleset etc...) - there's a more indepth description on our knowledge base :)

 

If a teacher searches for cucumber for example and gets a porn block, how we can get that log record deleted as they were not actually looking for porn? If anyone were later to search the records it could be assumed that somebody at the school was looking for porn when they were not.

 

To exclude a domain, URL, or searchterm from the safeguarding reports you need to first find the item in the reports and then select the 'Exclude' button which appears on the right-hand side when you hover over an item. Any item that you exclude from the reports will be sent back to the categorisation team at Smoothwall so we can fix the issue.

Posted
Hi @sigma, a safeguarding alert should be generated any time a user accesses a webpage which is categorised as one of 'Child Abuse', 'Drugs', 'Intolerance', 'Pornography', 'Alcohol', 'Self Harm', 'Terrorism Violence', 'Sexuality Sites', 'Personal Weapons', 'Criminal Activity', or 'Adult sites'. These are all categories which we provide, and these fit into different rulesets (e.g. the 'Intolerance' and 'Terrorism' categories go into the 'Radicalisation' ruleset etc...) - there's a more indepth description on our knowledge base :)

 

 

 

To exclude a domain, URL, or searchterm from the safeguarding reports you need to first find the item in the reports and then select the 'Exclude' button which appears on the right-hand side when you hover over an item. Any item that you exclude from the reports will be sent back to the categorisation team at Smoothwall so we can fix the issue.

 

Many thanks for your reply and for the link.

 

Regarding the report. I don't want to exclude a domain, URL, or search term from the safeguarding reports, I want to remove (or edit?) a record from the log. Even under the old DPA, people are entitled to have incorrect information corrected. There is a log entry that indicates that an image search for "cucumber" generated a "core block" for porn. As we are tenants, these reports can be widely accessed, and as they are not controlled by the school, who can say what they will be used for or accessed by in future?

Posted

@sigma since you aren't a direct customer of Smoothwall you might get further with your issues talking to your provider.

 

In addition I'm not sure that you would have the right to have the have this record removed from the log since it's not incorrect information. The search was carried out using that account and it was blocked. The context around this will be clearly seen in the log and you do need to remember that content analysis is dynamic so certain sites may spontaneously block if their changing content happens to contain something dubious at that point in time.

Posted

@Primus Thank you so much for your insightful reply.

 

GDPR allows a person to have incorrect data about them corrected. Perhaps the best solution would be for that record to be anonymised thus keeping the log of the block but removing an incorrect algorithmic decision against an innocent person as the law will allow.

Posted

@sigma I appreciate what you're saying and I am familiar with the legislation but the log of the block is not incorrect data. The website was blocked and therefore I don't believe this would be covered under the DPA or under GDPR in terms of having incorrect data being corrected.

 

You'd also be talking about an IT Office being inundated with requests from staff and students alike - I tried to get to a site and it was blocked, can I have the record of this removed please? It's not workable. I also don't see how we can anonymise the log as we'd have the same problem again - staff would be inundated with requests both genuine and spurious. Once you get into altering the logs then it's a very slippery slope and their veracity can no longer be relied upon.

Posted
I hear what you say, but if a staff member gets a record of searching for porn against them when they were clearly not, because the Smoothwall algorithm incorrectly decided that they were, it could be a serious safeguarding matter if say, somebody was looking at aggregate data.
Posted (edited)
I'm with Sigma here, the data is clearly not correct. How on God's Earth can a search for cucumber = porn...? It cannot! You do say the context can be seen in the logs but how do we know the viewer of the logs is seeing full context, if the data is aggregated context could easily be lost. Edited by TomHD
  • Thanks 1
Posted

@sigma - it doesn't work like that. The context is always there, on the initial report it lists the website and the category. In the log it always keeps the full browsing history to provide the context.

 

At no point is someone just provided with data that says Fred Bloggs tried to access porn - they're always given much more data than that and the full log provides all the context and protection any member of staff has for any innocent or miscategorised blocks.

 

You'd have more issues if logs were edited because then you really do run the risk of the context being lost.

Posted
I'm with Sigma here, the data is clearly not correct. How on God's Earth can a search for cucumber = porn...? It cannot! You do say the context can be seen in the logs but how do we know the viewer of the logs is seeing full context, if the data is aggregated context could easily be lost.

 

The data is correct because at the time the search resulted in a block.

Posted
So if I made a FOI to asking how many times a school was blocked due to porn searches all the cucumber searches would be part of that data and would make a school look like it's making many searches for porn when it just not? Am I getting this wrong?
  • Thanks 1
Posted

@TomHD I would suggest you would be able to refuse such a request under the DPA because they are asking for information about other people.

 

However you may be able to disclose a raw figure, but it's similar to an FOI for details of members of staff who have been through disciplinary procedures - there's personal data involved that cannot be disclosed.

Posted
I disagree, of course any identifiable data would be redacted but the data, which I'm pretty sure a school would be obliged to provide under FOI, would suggest the school's employees or students are searching for porn when they are absolutely not?
  • Thanks 1
Posted

@TomHD sorry I don't believe this to be the case - I couldn't under FoI request all the records pertaining to staff conduct etc.

 

There is data that the school holds that is exempt from FoI requests - you can absolutely refuse disclosure - you don't need to anonymise since it's exempt from disclosure.

Posted

Oh, dear. This is like one of those REALLY long games at Wimbledon. I reckon that we should agree to disagree with Primus - whoever they are. Forum anonymity is all very well but it can also muddle issues.

 

The world, unlike a computer, is not black and white. If a system is working with an incorrect dataset, it does not make any resultant log correct.

 

Working on that premise, the 'pornography' flag can be misconstrued. A false and potentially harmful log that could result in an allegation against a member of staff should most definitely be amended. Even if the black and white programming cannot amend the flag, the resultant human intervention should, at the very least, mark it up as a 'false positive' and then remove the incorrect word from the dataset.

 

My Impero system marks up the word 'oreo' as racist but our 9-13 year olds are talking about biscuits. It also flags up Raccoon when they are doing a wildlife project. I look at each flagged case objectively and delete or mark each one as a false positive where appropriate. On the odd occasion where a stupid pupil intentionally uses racist/offensive language, the headteacher and I come down on them like the proverbial tonne of bricks.

 

On a final, more pleasant note have a great, IT-free half-term! :cool:

  • Thanks 2
Posted

@Westley_IT I'm not quite sure why you've appointed yourself the voice of this message board - "I reckon we should agree to disagree with Primus - whoever they are".

 

Whoever I am? What on earth do you mean by that - most people on here have usernames that don't directly correlate to their name!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...