Jump to content

Recommended Posts

Posted

Considering swapping my Smoothwall S4 for individual Firewall / Filtering solutions.

 

Can anyone provide any feedback on Relay from Light speed as a filtering solution? The set up looks good from the videos etc...

 

Would like to hear some real word thoughts though.

 

Many thanks

W

Posted

I'm not familiar with Relay, but a quick look suggests that it requires some kind of agent on every device (similar to Securly, etc I guess?). As @SchoolsBroadband says, I can't imagine this working well for BYOD, but also the UK Safer Internet Centre's "Appropriate Filtering" guidelines specifically say "filtering should be applied at ‘network level’ ie, not reliant on any software on user devices".[1] As far as I can tell, this means that it is *not* ok to use the likes of Relay/Securly/etc. as the primary filtering system for your network. By all means, use these systems *in addition* to your normal filtering in order to provide some off-site protection for school owned devices, but not as a replacement to a network level filter. Obviously check with your filtering vendor to make sure that these additional systems are compatible before you make a purchase, of course. :)

 

Another thing that springs to mind from my personal experience in developing online safety stuff is that separating web filtering and firewalling seems a backward step - the trend is more and more integration between web filtering and firewalling, since the world is no longer neatly divided into "the web" and "everything else" - applications frequently mix web traffic with other protocols and there is more and more pressure for online safety systems to stop putting a hard distinction between them. Hence the advent of UTM products from all the major vendors which try and bring these different aspects together.

 

Lightspeed are a very US centric company, and often don't fully appreciate the UK guidelines / requirements.

 

1. https://www.saferinternet.org.uk/advice-centre/teachers-and-school-staff/appropriate-filtering-and-monitoring/appropriate-filtering

Posted (edited)

How do Schools Broadband handle guest/BYOD traffic? Also, how do they handle devices that go off the network? With more and more 1:1 schemes, how would those devices remain protected once off the schools broadband network?

 

And why is the presumption that software isn't able to handle school owned devices?

 

I am rolling out a 1:1 scheme, and have evaluated many products on the market. Relay stood out due to their categorisation, ease of deployment and offsite filtering - It's all so simple to setup!

 

I have a very small BYOD/Guest network, and am dealing with that traffic through the BYOD filter lightspeed provides, and a captive portal through my wireless controller linked to guest AD accounts. I know who is coming onto the network, at which time and who the person is - and all of my staff and student devices has an agent which handles the filtering, wherever that device goes. You can also relax rules out side of school hours.

 

Why would this not meet satisfactory filtering standards? I know that my devices, and students are safe.

Edited by justanittech
Posted

@justanittech

 

We support Captive portal, Radius and IP based filtering for BYOD.

 

For devices offsite it's proxy, chrome plugin and / or captive portal.

 

For onsite school controlled devices we generally use an agent for PC's and MAC, Chrome plugin for Chromebooks and captive portal for anything else. All tie into AD or Google Auth.

 

Thanks

 

Dave

Posted
And why is the presumption that software isn't able to handle school owned devices?

 

I don't think anyone said that. @SchoolsBroadband pointed out that installing extra software on BYOD devices may be problematic, and I pointed out that the Safer Internet Centre specifically say an on-device agent is not good enough. That's not my opinion, it's the opinion of the Safer Internet Centre :).

 

Now, Keeping Children Safe in Education doesn't actually set any hard and fast rules and basically says the school needs to do a risk assessment and make their own decisions; so you can ignore that advice and do your own thing. But in my opinion, if you are going against very specific guidance, you really need to have dotted the "i"s and crossed the "t"s to show that you have assessed the risk and stated the reasons why you think it is acceptable.

 

Why would this not meet satisfactory filtering standards? I know that my devices, and students are safe.

 

As I said, it wasn't based on my opinion, it was based on the guidance published by the Safer Internet Centre.

 

However, if you want my opinion (and I fully accept that I am biassed :)), it is that on-device filtering inherently has a lower level of security than network level filtering - there's more scope for students tampering with on-device software, there's more scope for the software simply breaking and you ending up with a few devices not being filtered without noticing. But since there are no hard rules and you're expected to use a risk based approach, "less security" doesn't necessarily rule it out, it just means you better be damned sure you document why you're accepting less security. :)

  • Thanks 2
Posted

It may well be - that on device filtering will be the only method available in the future.

 

Certificate pining and other techniques deployed by Android and iOS to supposedly to make your apps/browser more private increasingly make https interception and authentication difficult if not impossible to deploy and the list of exceptions and special cases that you need to add to filters such as smoothwall grows by the day (...can never understand why smoothwall doesn't automatically include and update them for the majority of common apps).

 

Under such circumstances - software that sits in the device - and possibly replaces the browser - and checks on what is being typed has the possibility of being more comprehensive (although I agree - its not easy to enforce with BYOD)

 

Still think the government should do more to mandate social media to allow parents and school better monitoring...for 4G and personal devices.

Posted (edited)
It may well be - that on device filtering will be the only method available in the future.

 

Possibly, although it seems more likely to me that hybrid systems will start to become common (network based filtering which gets fed secondary information from on-device agents where possible). I'm sure the guidelines will continue to evolve to accommodate those kinds of changes.

 

Certificate pining and other techniques deployed by Android and iOS to supposedly to make your apps/browser more private increasingly make https interception and authentication difficult if not impossible to deploy and the list of exceptions and special cases that you need to add to filters such as smoothwall grows by the day

 

This came up for discussion at the recent CTIRU safeguarding conference, which was attended by many filtering providers, ISPs, and folks from the home office and police - I have drafted a report on the conference that CTIRU are looking over at the moment to make sure it doesn't say anything we're not supposed to say in public - probably be published in a week or two.

 

The feeling I got at the conference is that this is a problem that everyone knows about but none of the filtering vendors want to talk about because, frankly, who wants to be the first vendor to stand up and say "we can't filter $thing" (the fact that nobody else can either is easily overlooked).

 

I can probably see guidance or legislation being updated in the future to prohibit schools from purchasing devices / using apps that can't be adequately monitored - Android being entirely banned from schools could well make the likes of Google rethink their strategy. Obviously that probably doesn't help with BYOD though.

 

There's also push-back from businesses on the same things, because obviously they often want to be able to do malware scanning at the network border, and also scan data to make sure that confidential business information isn't being leaked. It will be interesting to see where the future takes us, but it's sure to be a bumpy ride. :)

 

One thing often overlooked is that the days of being able to do what you like with your own device are long gone - Apple is ultimately in control of what you can do on iOS, Google is ultimately in control of what you can do on Android, and if those vendors decide they don't want to allow an online safety agent to run on the devices, you're screwed. In that respect, an on-device agent isn't too different from HTTPS interception - it works until the device vendor decides it doesn't, and Apple/Google/Microsoft/Facebook/Twitter, etc are all way too big to be influenced by a couple of schools screaming at them.

 

I was talking to someone at Impero the other day about exactly this - there are some types of device that they have extremely reduced functionality on because the OS simply doesn't let them monitor the things they need to. The same is also true with things like Chrome plugins - you're entirely reliant on the software vendor (Google in the case of Chrome) allowing you to do the monitoring you want to do.

 

Still think the government should do more to mandate social media to allow parents and school better monitoring...for 4G and personal devices.

 

Schools certainly need better guidance on how to handle 4G devices within the school, and also how to handle apps that can't be filtered at all.

Edited by Opendium_Steve
Posted
There's also push-back from businesses on the same things, because obviously they often want to be able to do malware scanning at the network border, and also scan data to make sure that confidential business information isn't being leaked. It will be interesting to see where the future takes us, but it's sure to be a bumpy ride. :)

 

Complete FUD.

 

As some one who consults in education, enterprise and healthcare for iOS I can asure you businesses and the NHS in particular are buying thousands of iOS devices and not pushing back as you say. With the right tools e.g. MAM/MDM and Certs in place they can made very secure and don't need to be locked down from the network border.

 

There are plenty of very good HTTPS Inspection solutions either at the network edge or a software device agent that filter, e.g. Lightspeed Rocket and Relay, Smoothwall Guardian fof education and Cisco/Juniper. Some of them can not do certain HTTPS inspections yet with iOS but these tools are coming.

 

As for Chromebooks you can do full HTTPS Inspection/Decryption now with solutions such as Lightspeed Relay.

Posted
Complete FUD.

 

 

As for Chromebooks you can do full HTTPS Inspection/Decryption now with solutions such as Lightspeed Relay.

 

Yes; you can do full HTTPS inspection/decryption....but loads of apps then fail to work because they detect the presence of the intermediate certificate being used.

 

...perhaps Industry should be pushing back...

Posted
As some one who consults in education, enterprise and healthcare for iOS I can asure you businesses and the NHS in particular are buying thousands of iOS devices and not pushing back as you say. With the right tools e.g. MAM/MDM and Certs in place they can made very secure and don't need to be locked down from the network border.

 

iOS can (currently) be man-in-the-middled without too many problems (some apps use cert pinning and can't be inspected, but at the OS level at least MITM works). However, Android devices are hostile to MITM - apps targetting Android API level 24 and above default to not trusting custom CA certificates, even for MDM managed devices. This isn't a default that the user or network administrator can change, it is a default that only the app developer can change, and of course the majority of apps will not change this default.

 

This is Google's stated policy[1], and increasingly prevents Android devices from being filtered or monitored satisfactorily. This is not FUD, it is fact and backed up by what Google has said publicly.

 

There are plenty of very good HTTPS Inspection solutions either at the network edge or a software device agent that filter, e.g. Lightspeed Rocket and Relay, Smoothwall Guardian fof education and Cisco/Juniper.

 

Yes, and as I said, these "very good HTTPS inspection solutions" do not work on an increasing number of apps and an increasing number of Android devices because of the stated policies of some of the big brands.

 

As for Chromebooks you can do full HTTPS Inspection/Decryption now with solutions such as Lightspeed Relay.

 

Pretty much all the school online safety systems support HTTPS decryption of ChromeOS at the moment. However, Google's stated position on these things is that (a) apps running on Android devices will not be decryptable without each app developer opting into decryption, and (b) they indent to gradually move towards unifying ChromeOS and Android into a single operating system. There is significant concern in the online safety industry that this will lead to ChromeOS following the Android lead and becoming hostile to decryption in the future.

 

[1] https://android-developers.googleblog.com/2016/07/changes-to-trusted-certificate.html

  • Thanks 1
  • 2 weeks later...
Posted
The problem with HTTPS inspection and certificate pinning or apps not using user installed CAs will likely take a long time to get resolved correctly. Apps that do not work with HTTPS inspection in place is a bother to be sure. One workaround will be to use the web service instead of the app, which generally does work. If the service needs to be used and HTTPS inspection is required, then that is currently the only method. Facebook has a web page :) WhatsApp does too - and since these are accessed using a browser, then generally, the HTTPS inspection will be implemented there. It's not an elegant workaround but it does give you the inspection required while maintaining the use of apps.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...