Lone_Rider Posted December 17, 2018 Posted December 17, 2018 I read a very interesting article in the Telegraph on Saturday. Tens of thousands of pupils aged as young as five are at risk of being spied on through their webcams using software designed to tackle extremism in schools. “Classroom management software” is used by schools across the UK to flag up when words linked with terrorism, cyberbullying and self-harm are typed on laptops and tablets. However, an investigation by the Sunday Telegraph has found that one major provider of the software is able to remotely enable webcams on devices to spy on pupils, often without students or their parents ever knowing. NetSupport DNA, which provides its software to more than 1,000 schools in the UK, said the camera on a laptop is enabled if a student types in words such as “bomb” or “suicide”. A screenshot or recording of the student is then captured and sent to a teacher to flag that they are a risk. In some cases, details of the student are also sent to the police. NetSupport DNA was not able to reveal how many webcam images and videos of students are taken each day. “The parents don’t know this software exists,” said Jen Persson director of campaign group Defend Digital Me and a mother of three, who is concerned the technology is being used to take images and video recordings of children in secret. “It’s a huge red flag that companies are so unwilling to speak openly about how the systems work and that there is no documentation about what parents should be told.” Katie Hall, NetSupport DNA’s marketing manager, said that while recordings are currently made on school premises, the company is planning a software update that will allow webcams to be activated in a student’s home. This could happen if, for instance, a school operates a Bring Your Own Device (BYOD) scheme, which allows students to use their own laptop at school. The school could then install the monitoring software onto the child’s device, enabling teachers to remotely activate the webcam 24/7, regardless of location. “I am somewhat shocked to see that this is viewed as acceptable,” said Andy Phippen, Professor of Social Responsibility in IT at Plymouth University. “There are major data protection concerns about an outside agency being able to move from an alert based on keyword matching to viewing the subject in the home. “I would be amazed if school children had given consent for this invasion of privacy and it seems wholly disproportionate based upon something that could be entirely innocuous.” There are also concerns that hackers could gain access to databases created by school monitoring tools, providing them with a “honey pot” of images, videos and recordings of vulnerable children. In 2015, a security flaw was found in Impero classroom monitoring software which is used in 1,400 UK secondary schools. The flaw allowed almost anyone to access computers running Impero software, including files and records stored on the students that had been flagged by the system. Richard Fuller, CEO of Impero is adamant that the company takes security issues seriously. In defence of his software, he claims it can be used as a tool to help spot problems before they become critical. “I know of monitoring software where children have been very depressed and have looked for ways to take their own life online, and that’s a situation in which our software can provide alerts and get someone help,” he said. He is also keen to stress that Impero doesn’t use webcam monitoring. “I would find that concerning,” he said. Schools have been ramping up their use of the monitoring software since 2016 after the government issued its Keeping Children Safe guidance that “obligates schools to introduce appropriate levels of web monitoring”. But Ms Persson fears that they have done so without fully understanding the privacy implications of the technology. “Matt Hancock said that we want to make the UK the safest place to go online,” she said. “We can’t do that by saying our own government’s statutory guidance has allowed some guy in some back room to look at your teenage daughter through her webcam.” I am now bracing myself for a flood of emails from parents about this. GDPR or not, Government Guidelines on Safeguarding, hmm and we are in the middle! 2
synaesthesia Posted December 17, 2018 Posted December 17, 2018 Don't agree with the webcam thing one little bit, that's a step too far IMO. I can't really see the point either; where CCTV will give a wide overall picture, the ability to see the look on someone's face when they're searching for such things isn't likely to shed much light on things like a context for that search. Impero's keywords for us have been excellent, to the point where we believe it may have gotten help given to vulnerable children who needed it. 1
theeggmaster Posted December 17, 2018 Posted December 17, 2018 Don't agree with the webcam thing one little bit, that's a step too far IMO. I can't really see the point either; where CCTV will give a wide overall picture, the ability to see the look on someone's face when they're searching for such things isn't likely to shed much light on things like a context for that search. Impero's keywords for us have been excellent, to the point where we believe it may have gotten help given to vulnerable children who needed it. Impero have a video on exactly that subject.
Oaktech Posted December 17, 2018 Posted December 17, 2018 I understand the intent, but no. Even if I did have that level of monitoring, I would resist very hard any decision to use it.
FishCustard Posted December 17, 2018 Posted December 17, 2018 I understand the intent, but no. Even if I did have that level of monitoring, I would resist very hard any decision to use it. Agreed. We are not Big Brother, nor should we ever become so.
DrCheese Posted December 17, 2018 Posted December 17, 2018 The webcam thingy is when an e-safety alert is triggered, you can tell it to take a capture of the webcam. It's not quite as scary as the article makes out "Staff can watch you any time!!!" But I can see for example, if a school lends a laptop to a student for a weekend, they then trigger an e-safety alert whist at home then when the device reconnects to the school network (Or instantly if the school has VPN/Directaccess) then the screenshot will be sent up. This could be very bad. Whist not netsupports fault per sa (They don't set policies and by default this feature is turned off) they are the easy target for the press.
Popular Post Al_NetSupport Posted December 17, 2018 Popular Post Posted December 17, 2018 (edited) Hi all, We are aware of the article, it is shaped by an organisation Defenddigitalme and is full of inaccuracies, as you will know we are LAN based currently, we don't allow a teacher to remotely change the webcam settings on a child's PC and there is no webcam feed. The rest of it is full of "scare" stories - we don't have a feature to report content to the police and once installed at a school have no control whatsoever over the software. We have a fuller response but below is a quick outline of 2 inaccuracies (there are 6 inaccuracies identified in the article) but I can assure everyone we have no plans in any shape or form to be remotely watching any webcams within the product. “remotely enable webcams on devices to spy on pupils often without student or their parents ever knowing”. This statement is wholly incorrect. The software is locally installed and controlled by the school and only they can control its configuration. By default “out of the box” Webcam capture is disabled, as are video alerts. Webcams cannot be remotely controlled -all of the data is stored on the school network, not in the cloud or on servers managed by NetSupport. Before a child logs onto any school device, they must acknowledge the schools acceptable use policy, and a visual splash box identifies which features are active on each student PC (including the keyword filtering tools). Furthermore, the webcam does not record any video, ever. It can only capture a single photo of the student at the computer which has triggered a critical keyword, for example, suicide or self-harm. The product only currently runs on a LAN (Local Area Network), so this applies within the school, not at home. “Enabling teachers to remotely activate the webcam 24/7 regardless of location”. None of this is in any way possible. A student PC at home has no means of communicating with or from school devices. Teachers do not have the ability to interact with student devices at home, and as repeatedly stated, the product ONLY works on a local School / Trust network. Just for clarity, the feature is disabled by default by DSLs asked if we could add a feature that meant children using shared resources in a library, when searching for a serious term "Suicide" it could be used to capture a picture of the students from the webcam so they knew who they needed to intervene with and support. The school has compete control over the feature, not NetSupport. Hope that clarifies but happy to answer any questions. Al Edited December 17, 2018 by Al_NetSupport 6
Lone_Rider Posted December 17, 2018 Author Posted December 17, 2018 Glad to see that webcam capture is disabled by default, we use NetDNA at our school and have configured it to email alerts, when someone types certain words and the fact that we have a screen capture with a date and time stamp of the user, is a godsend. As that has bee proof of what went on and why its been reported to the DSP etc. At least I can now refer any irate parents to the rebuttal from NetSupport. I also am somewhat surprised that the Telegraph have put such a spin on it. 1
steveg Posted December 17, 2018 Posted December 17, 2018 We recently moved to netsupport, and have enabled this feature. It will only be triggered if certain high priority keywords are typed, and at that point we want to know who was using the computer, as they have either broken the school rules, or we have a serious safeguarding concern. Despite all having individual accounts, our year 6's have started increasingly using someone elses account, when they leave the room for example. Whilst we continue to educate on the risks of leaving a computer unlocked it does happen, and being able to catch who is actually doing it will be very useful. Details of the use of this are shared in our acceptable use policy, which all users sign. Steve 1
synaesthesia Posted December 17, 2018 Posted December 17, 2018 Despite all having individual accounts, our year 6's have started increasingly using someone elses account, when they leave the room for example. Steve There's a good point, something we often stumble across (or multiple kids gathered round one computer mashing things in) 1
IrritableTech Posted December 17, 2018 Posted December 17, 2018 We have a fuller response here - statement | NetSupport Ltd but I can assure everyone we have no plans in any shape or form to be remotely watching any webcams within the product. Al Thanks Al. Just to let you know this is 404ing for me.
Al_NetSupport Posted December 17, 2018 Posted December 17, 2018 Thanks - just added some of our response into my post.
gh5000 Posted December 17, 2018 Posted December 17, 2018 Just getting a page asking for a password when I try to view the statement @Al_NetSupport On the LAN only thing, I'll need to double check what went on but we investigated a flag of the word "weed" which occurred outside of school hours on a Chromebook. I don't know if the tab reloaded inside school to cause the ping but I'm sure the timing of it on DNA was 19:00. It was backed up by the securly extension recording the search from an external IP address outside of school hours. Does the chrome extension cache keywords until back on site?
Al_NetSupport Posted December 18, 2018 Posted December 18, 2018 Just PMd you with password and reply. Al.
gh5000 Posted December 18, 2018 Posted December 18, 2018 Just to confirm on my Chromebook point above. The results are cached until the Chromebook are back on the LAN. Parents are told at multiple times that if they use their daughters @school.org logon on the Chromebook we may be able to see searches and triggered keywords that flag to us (in Securly as well as DNA). Parents have the option to ask us to enable non school logons using the GSfE out of hours rules where no monitoring is enabled. Monitoring of school student accounts is done for safeguarding reasons which parents have been happy with so far. The issues we have are predominately with students phone usage - on this, we can't do anything because they are personal devices but get lumped with the bullying, safeguarding etc issues that stem from them. Seeing this article last night, I'm actually surprised one of our parents hasn't called.
Popular Post Al_NetSupport Posted December 18, 2018 Popular Post Posted December 18, 2018 Just be clear, the Telegraph has retracted the article and removed it from their website and will be publishing an apology, now we have shown it to be wholly inaccurate on most of the key points. Other copies of the article by other publishers are also being retracted. A good example regrettably of poorly informed journalists looking for a scoop. Al. 11
Lone_Rider Posted December 18, 2018 Author Posted December 18, 2018 I'm glad its going to be retracted and publish an apology. We have enough to be concerned about without, being chastised for over monitoring "Spying" on students. Its bad enough at the moment trying to keep ahead of what sites the little darlings try and get to and what they think they can search for, instead of concentrating in class. 1
tmoon-mint Posted December 19, 2018 Posted December 19, 2018 No wonder public trust in the media is at an all time low. Unfortunately the inaccurate information still went out regardless of whether they post an apology or not as not everyone is guaranteed to read the retraction piece. As others have said we have enough to deal with in terms of safeguarding already without the telegraph writing nonsense. 1
synaesthesia Posted December 19, 2018 Posted December 19, 2018 Doesn't help with muppets on other social media channels ranting about privacy in the first place, being adamant the only thing in place in schools should be filtering and nothing more; this sort of article fuels the fire of said trolls. Had quite a lengthy argument on Twitter with one such git yesterday who believes all IT use should be monitored by humans in the classroom at all times and to hell with the cost/feasibility/logistics of such a requirement. All problems that these systems can detect can be dealt with better by humans who should "just talk" to the children involved. No idea how on earth they'd pick them up other than obvious physical/behavioural signs... 1
sted Posted December 19, 2018 Posted December 19, 2018 No wonder public trust in the media is at an all time low. Unfortunately the inaccurate information still went out regardless of whether they post an apology or not as not everyone is guaranteed to read the retraction piece. As others have said we have enough to deal with in terms of safeguarding already without the telegraph writing nonsense. retraction pieces should have to have the same prominence and "page space" as the original article. So if newspaper 1 fills the front page with a story thats exactly where the retraction should be same for websites if its the main story for 2 days the retraction needs to be 1
jmak Posted December 19, 2018 Posted December 19, 2018 Bearing in mind that the Telegraph web site is pay-walled, presumably you would have to be logged in to view the article. Therefore they must know exactly who read it and could make the retraction the first thing the customer sees the next time they log in. 1
Al_NetSupport Posted December 19, 2018 Posted December 19, 2018 Thanks for all the support folks, really appreciated by all the team here. Have a lovely Christmas. ! 1
mavhc Posted December 19, 2018 Posted December 19, 2018 Doesn't help with muppets on other social media channels ranting about privacy in the first place, being adamant the only thing in place in schools should be filtering and nothing more; this sort of article fuels the fire of said trolls. Had quite a lengthy argument on Twitter with one such git yesterday who believes all IT use should be monitored by humans in the classroom at all times and to hell with the cost/feasibility/logistics of such a requirement. All problems that these systems can detect can be dealt with better by humans who should "just talk" to the children involved. No idea how on earth they'd pick them up other than obvious physical/behavioural signs... Did you ask him how much he'd like his taxes to go up to pay for that?
synaesthesia Posted December 19, 2018 Posted December 19, 2018 No, there got to a point with the "discussion" where I decided no amount of work was going to get him to think straight. In an ideal world we'd all like to be able to trust everyone, assume kids will always remain safe online etc. Reality sucks.
jenatddm Posted December 22, 2018 Posted December 22, 2018 Happy Christmas holidays everyone. I'm pleased to say we're meeting [myself and NetSupport] in January to have a chat in detail about this, and the product, as we've already discussed briefly several times in passing previously, at events for example. Regards this comment and article, for obvious reasons, we were concerned when the journalist approached us and reported the NetSupport DNA marketing manager as saying, "the company is planning a software update that will allow webcams to be activated in a student’s home." Al and I exchanged email, and he has subsequently reviewed and approved a statement that we posted on our website, so there are more facts in the public domain how the product works. More generally, we hope the whole area and use of these products will become much more transparent and informed in 2019. We are developing materials for parents and children to better understand it, and to help you in schools meet the fair processing requirements under UK Data Protection law / GDPR consistently. Some places have better policy, practice, and communications than others. The poll of parents we commissioned in February 2018 through Survation, showed poor understanding, and that 86% of parents with children in England’s state education system think that both children and parents should be informed of what the consequences are, if these keywords are searched for and flags created. This should be the bare minimum provided to families under GDPR rules on [risk] profiling, and we're pleased to get more engagement from companies, including NSDNA, to get improved understanding and consistency across the sector, what good should look like -- and put that into your hands for schools to use. Safeguarding-in-schools generated information, can be the trigger for staff to begin a Channel referral for children into the Prevent programme, and reporting statistics. 1 in 3 of all referrals come from the education sector today, yet 70% of referrals into the Channel programme in 2017-18, resulted in no action for the individuals, so improvement is clearly needed somewhere in that process, to reduce over-referrals. We also get concerns from staff (and more rarely young people) usually where they feel it is not possible to speak up on their concerns on use of these software in school; on over blocking of content, on how to delete flags assigned to the wrong child, or flags created without real cause. We work [for free] with companies whose products are in use across the education sector, often going to sites, and we ask only for the coverage of direct travel expenses. Those who do, tell us they find it constructive and helpful. That doesn't mean they always like the answers, or our opinions, pointing out for example if products have not considered their lawful basis for product development, or lack of fair and required communications to families, and action is needed. We work with, and offer confidentiality to schools, MATs, [education] charities and others, willing to share their own issues, map data flows, testing-in-practice of their concerns (using a dummy student or staff profile), privacy policies, and Home-School ICT agreements that relates to these and any other software / personal data related topics. We will comment in confidence if and how to consider anything in your communications/text that may need updated, or any case studies provided. This makes for local improvement, but for us it is useful is to help feed [anonymously or not as preferred] into national improvements, such as input to the DfE GDPR toolkit, and our own wider work. If you want your school to contribute, you can send us your practical experiences, policies or questions which can help make improvements on any issue that can affect similar schools more widely. For example, to include in a new report we will bring out in 2019. Any companies named get to see the text in advance, and can also contribute text and changes. The UK is a large exporter of this kind of products, and with it we export the potential for both the good and bad practice. It has developed with little external scrutiny over the last ten years, and with increasing consciousness of data protection law, it is almost certain to get more scrutiny in 2019, nationally and internationally. So, with that, Happy Christmas holidays from me, all of us at defenddigitalme, and looking forward to the year ahead.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now