Jump to content

Recommended Posts

Posted

I read a very interesting article in the Telegraph on Saturday.

 

Tens of thousands of pupils aged as young as five are at risk of being spied on through their webcams using software designed to tackle extremism in schools.

“Classroom management software” is used by schools across the UK to flag up when words linked with terrorism, cyberbullying and self-harm are typed on laptops and tablets.

However, an investigation by the Sunday Telegraph has found that one major provider of the software is able to remotely enable webcams on devices to spy on pupils, often without students or their parents ever knowing.

NetSupport DNA, which provides its software to more than 1,000 schools in the UK, said the camera on a laptop is enabled if a student types in words such as “bomb” or “suicide”.

A screenshot or recording of the student is then captured and sent to a teacher to flag that they are a risk. In some cases, details of the student are also sent to the police.

NetSupport DNA was not able to reveal how many webcam images and videos of students are taken each day.

“The parents don’t know this software exists,” said Jen Persson director of campaign group Defend Digital Me and a mother of three, who is concerned the technology is being used to take images and video recordings of children in secret.

“It’s a huge red flag that companies are so unwilling to speak openly about how the systems work and that there is no documentation about what parents should be told.”

 

 

Katie Hall, NetSupport DNA’s marketing manager, said that while recordings are currently made on school premises, the company is planning a software update that will allow webcams to be activated in a student’s home.

This could happen if, for instance, a school operates a Bring Your Own Device (BYOD) scheme, which allows students to use their own laptop at school.

The school could then install the monitoring software onto the child’s device, enabling teachers to remotely activate the webcam 24/7, regardless of location.

“I am somewhat shocked to see that this is viewed as acceptable,” said Andy Phippen, Professor of Social Responsibility in IT at Plymouth University.

“There are major data protection concerns about an outside agency being able to move from an alert based on keyword matching to viewing the subject in the home.

“I would be amazed if school children had given consent for this invasion of privacy and it seems wholly disproportionate based upon something that could be entirely innocuous.”

There are also concerns that hackers could gain access to databases created by school monitoring tools, providing them with a “honey pot” of images, videos and recordings of vulnerable children.

In 2015, a security flaw was found in Impero classroom monitoring software which is used in 1,400 UK secondary schools.

The flaw allowed almost anyone to access computers running Impero software, including files and records stored on the students that had been flagged by the system.

Richard Fuller, CEO of Impero is adamant that the company takes security issues seriously. In defence of his software, he claims it can be used as a tool to help spot problems before they become critical.

“I know of monitoring software where children have been very depressed and have looked for ways to take their own life online, and that’s a situation in which our software can provide alerts and get someone help,” he said.

He is also keen to stress that Impero doesn’t use webcam monitoring. “I would find that concerning,” he said.

Schools have been ramping up their use of the monitoring software since 2016 after the government issued its Keeping Children Safe guidance that “obligates schools to introduce appropriate levels of web monitoring”.

But Ms Persson fears that they have done so without fully understanding the privacy implications of the technology.

“Matt Hancock said that we want to make the UK the safest place to go online,” she said.

“We can’t do that by saying our own government’s statutory guidance has allowed some guy in some back room to look at your teenage daughter through her webcam.”

 

I am now bracing myself for a flood of emails from parents about this. GDPR or not, Government Guidelines on Safeguarding, hmm and we are in the middle!

  • Thanks 2
Posted
Don't agree with the webcam thing one little bit, that's a step too far IMO. I can't really see the point either; where CCTV will give a wide overall picture, the ability to see the look on someone's face when they're searching for such things isn't likely to shed much light on things like a context for that search. Impero's keywords for us have been excellent, to the point where we believe it may have gotten help given to vulnerable children who needed it.
  • Thanks 1
Posted
Don't agree with the webcam thing one little bit, that's a step too far IMO. I can't really see the point either; where CCTV will give a wide overall picture, the ability to see the look on someone's face when they're searching for such things isn't likely to shed much light on things like a context for that search. Impero's keywords for us have been excellent, to the point where we believe it may have gotten help given to vulnerable children who needed it.

 

Impero have a video on exactly that subject.

Posted
I understand the intent, but no. Even if I did have that level of monitoring, I would resist very hard any decision to use it.

 

Agreed. We are not Big Brother, nor should we ever become so.

Posted

The webcam thingy is when an e-safety alert is triggered, you can tell it to take a capture of the webcam. It's not quite as scary as the article makes out "Staff can watch you any time!!!"

 

But I can see for example, if a school lends a laptop to a student for a weekend, they then trigger an e-safety alert whist at home then when the device reconnects to the school network (Or instantly if the school has VPN/Directaccess) then the screenshot will be sent up. This could be very bad.

 

Whist not netsupports fault per sa (They don't set policies and by default this feature is turned off) they are the easy target for the press.

Posted

Glad to see that webcam capture is disabled by default, we use NetDNA at our school and have configured it to email alerts, when someone types certain words and the fact that we have a screen capture with a date and time stamp of the user, is a godsend. As that has bee proof of what went on and why its been reported to the DSP etc.

 

At least I can now refer any irate parents to the rebuttal from NetSupport. I also am somewhat surprised that the Telegraph have put such a spin on it.

  • Thanks 1
Posted

We recently moved to netsupport, and have enabled this feature. It will only be triggered if certain high priority keywords are typed, and at that point we want to know who was using the computer, as they have either broken the school rules, or we have a serious safeguarding concern.

 

Despite all having individual accounts, our year 6's have started increasingly using someone elses account, when they leave the room for example. Whilst we continue to educate on the risks of leaving a computer unlocked it does happen, and being able to catch who is actually doing it will be very useful. Details of the use of this are shared in our acceptable use policy, which all users sign.

 

Steve

  • Thanks 1
Posted

 

Despite all having individual accounts, our year 6's have started increasingly using someone elses account, when they leave the room for example.

 

Steve

 

There's a good point, something we often stumble across (or multiple kids gathered round one computer mashing things in)

  • Thanks 1
Posted

Just getting a page asking for a password when I try to view the statement @Al_NetSupport

 

On the LAN only thing, I'll need to double check what went on but we investigated a flag of the word "weed" which occurred outside of school hours on a Chromebook. I don't know if the tab reloaded inside school to cause the ping but I'm sure the timing of it on DNA was 19:00. It was backed up by the securly extension recording the search from an external IP address outside of school hours. Does the chrome extension cache keywords until back on site?

Posted

Just to confirm on my Chromebook point above. The results are cached until the Chromebook are back on the LAN. Parents are told at multiple times that if they use their daughters @school.org logon on the Chromebook we may be able to see searches and triggered keywords that flag to us (in Securly as well as DNA). Parents have the option to ask us to enable non school logons using the GSfE out of hours rules where no monitoring is enabled.

 

Monitoring of school student accounts is done for safeguarding reasons which parents have been happy with so far. The issues we have are predominately with students phone usage - on this, we can't do anything because they are personal devices but get lumped with the bullying, safeguarding etc issues that stem from them.

 

Seeing this article last night, I'm actually surprised one of our parents hasn't called.

Posted
I'm glad its going to be retracted and publish an apology. We have enough to be concerned about without, being chastised for over monitoring "Spying" on students. Its bad enough at the moment trying to keep ahead of what sites the little darlings try and get to and what they think they can search for, instead of concentrating in class.
  • Thanks 1
Posted
No wonder public trust in the media is at an all time low. Unfortunately the inaccurate information still went out regardless of whether they post an apology or not as not everyone is guaranteed to read the retraction piece. As others have said we have enough to deal with in terms of safeguarding already without the telegraph writing nonsense.
  • Thanks 1
Posted
Doesn't help with muppets on other social media channels ranting about privacy in the first place, being adamant the only thing in place in schools should be filtering and nothing more; this sort of article fuels the fire of said trolls. Had quite a lengthy argument on Twitter with one such git yesterday who believes all IT use should be monitored by humans in the classroom at all times and to hell with the cost/feasibility/logistics of such a requirement. All problems that these systems can detect can be dealt with better by humans who should "just talk" to the children involved. No idea how on earth they'd pick them up other than obvious physical/behavioural signs...
  • Thanks 1
Posted
No wonder public trust in the media is at an all time low. Unfortunately the inaccurate information still went out regardless of whether they post an apology or not as not everyone is guaranteed to read the retraction piece. As others have said we have enough to deal with in terms of safeguarding already without the telegraph writing nonsense.

 

retraction pieces should have to have the same prominence and "page space" as the original article. So if newspaper 1 fills the front page with a story thats exactly where the retraction should be same for websites if its the main story for 2 days the retraction needs to be

  • Thanks 1
Posted
Bearing in mind that the Telegraph web site is pay-walled, presumably you would have to be logged in to view the article. Therefore they must know exactly who read it and could make the retraction the first thing the customer sees the next time they log in.
  • Thanks 1
Posted
Doesn't help with muppets on other social media channels ranting about privacy in the first place, being adamant the only thing in place in schools should be filtering and nothing more; this sort of article fuels the fire of said trolls. Had quite a lengthy argument on Twitter with one such git yesterday who believes all IT use should be monitored by humans in the classroom at all times and to hell with the cost/feasibility/logistics of such a requirement. All problems that these systems can detect can be dealt with better by humans who should "just talk" to the children involved. No idea how on earth they'd pick them up other than obvious physical/behavioural signs...

 

Did you ask him how much he'd like his taxes to go up to pay for that?

Posted
No, there got to a point with the "discussion" where I decided no amount of work was going to get him to think straight. In an ideal world we'd all like to be able to trust everyone, assume kids will always remain safe online etc. Reality sucks.
Posted

Happy Christmas holidays everyone.

 

I'm pleased to say we're meeting [myself and NetSupport] in January to have a chat in detail about this, and the product, as we've already discussed briefly several times in passing previously, at events for example.

 

Regards this comment and article, for obvious reasons, we were concerned when the journalist approached us and reported the NetSupport DNA marketing manager as saying, "the company is planning a software update that will allow webcams to be activated in a student’s home." Al and I exchanged email, and he has subsequently reviewed and approved a statement that we posted on our website, so there are more facts in the public domain how the product works.

 

More generally, we hope the whole area and use of these products will become much more transparent and informed in 2019. We are developing materials for parents and children to better understand it, and to help you in schools meet the fair processing requirements under UK Data Protection law / GDPR consistently.

Some places have better policy, practice, and communications than others. The poll of parents we commissioned in February 2018 through Survation, showed poor understanding, and that 86% of parents with children in England’s state education system think that both children and parents should be informed of what the consequences are, if these keywords are searched for and flags created. This should be the bare minimum provided to families under GDPR rules on [risk] profiling, and we're pleased to get more engagement from companies, including NSDNA, to get improved understanding and consistency across the sector, what good should look like -- and put that into your hands for schools to use.

 

Safeguarding-in-schools generated information, can be the trigger for staff to begin a Channel referral for children into the Prevent programme, and reporting statistics. 1 in 3 of all referrals come from the education sector today, yet 70% of referrals into the Channel programme in 2017-18, resulted in no action for the individuals, so improvement is clearly needed somewhere in that process, to reduce over-referrals. We also get concerns from staff (and more rarely young people) usually where they feel it is not possible to speak up on their concerns on use of these software in school; on over blocking of content, on how to delete flags assigned to the wrong child, or flags created without real cause.

We work [for free] with companies whose products are in use across the education sector, often going to sites, and we ask only for the coverage of direct travel expenses. Those who do, tell us they find it constructive and helpful. That doesn't mean they always like the answers, or our opinions, pointing out for example if products have not considered their lawful basis for product development, or lack of fair and required communications to families, and action is needed.

 

We work with, and offer confidentiality to schools, MATs, [education] charities and others, willing to share their own issues, map data flows, testing-in-practice of their concerns (using a dummy student or staff profile), privacy policies, and Home-School ICT agreements that relates to these and any other software / personal data related topics. We will comment in confidence if and how to consider anything in your communications/text that may need updated, or any case studies provided. This makes for local improvement, but for us it is useful is to help feed [anonymously or not as preferred] into national improvements, such as input to the DfE GDPR toolkit, and our own wider work.

 

If you want your school to contribute, you can send us your practical experiences, policies or questions which can help make improvements on any issue that can affect similar schools more widely. For example, to include in a new report we will bring out in 2019. Any companies named get to see the text in advance, and can also contribute text and changes.

 

The UK is a large exporter of this kind of products, and with it we export the potential for both the good and bad practice. It has developed with little external scrutiny over the last ten years, and with increasing consciousness of data protection law, it is almost certain to get more scrutiny in 2019, nationally and internationally.

 

 

So, with that, Happy Christmas holidays from me, all of us at defenddigitalme, and looking forward to the year ahead.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...