TwistedHelixis Posted March 18, 2019 Posted March 18, 2019 (edited) I have had IMAP & POP disabled for many years at my schools as it is not very secure, and if someone is using a third part mail program at home, the schools data is then not on our systems. Also IMAP & POP do not not work with 2FA. Recently I taken over a new school. After disabling IMAP & POP one governor is not very happy as he can no longer use his Mac email client at home to read the emails and wants me to re enable it. I have sent him an email explaining that IMAP & POP are not very secure and that schools should keep any data on the schools supplied systems. The reply I got back was, he does not understand any of that but needs me to help him get the school email in his Mac email client like it always has. I know that IMAP & POP are a security concern, but am I correct in saying the schools data should stay on the schools systems? Basically should he be using the schools supplied email software? If not, how do we make sure he deletes any emails after he has left? BTW we are using G suite. Edited March 18, 2019 by TwistedHelixis
MartinT Posted March 18, 2019 Posted March 18, 2019 I would never enable POP3 for anyone. IMAP is debatable. What do you do for your staff? We use Exchange which can be used in the built-in mail client or via the Outlook app. There must be similar for GMail. 1
Arthur Posted March 18, 2019 Posted March 18, 2019 (edited) Three Two options... Use the Gmail web interface. Don't access school e-mail on personal devices. Edited March 18, 2019 by Arthur 1
TwistedHelixis Posted March 18, 2019 Author Posted March 18, 2019 What do you do for your staff Across all my schools the staff use either Gmail web browser, or the Gmail app. Both of these support all the security features that Google recommend.
FN-GM Posted March 18, 2019 Posted March 18, 2019 Some evidence to support your no stance. http://www.edugeek.net/forums/security/205006-60-office-365-g-suite-tenants-targeted-w-imap-based-password-spraying-attacks.html 1
TwistedHelixis Posted March 18, 2019 Author Posted March 18, 2019 Question about step 2. Setup the Mac mail client to connect via the Google account provider. Does the Mac client download the emails to its software or are the emails still held on Google servers? If we removed his account would any emails still be available on his email client?
TwistedHelixis Posted March 18, 2019 Author Posted March 18, 2019 Sorry, I do not have a Mac to do any testing. All of these do not require POP or IMAP to be enabled and the first two both support 2FA Are you sure, Just read the following https://www.lifewire.com/gmail-os-x-access-1172876 and it mentions IMAP in the tips box.
TwistedHelixis Posted March 18, 2019 Author Posted March 18, 2019 Also found this The concept of creating a Gmail account in Apple Mail is simple enough. Gmail makes use of standard mail protocols, and Apple Mail supports the methods of communicating with the Gmail servers. You can add a Gmail account the same way you'd add any POP or IMAP account you currently use. Most versions of OS X and the newer macOS have an automated system that creates Gmail accounts for you.You can create a Gmail account either directly in Mail or from System Preferences. The System Preferences option is a handy way to keep all your social media and your email accounts together so you can easily make changes that are automatically reflected in any OS X app that makes use of them. The two methods, using Mail and System Preferences, are nearly identical and end up creating the same data in both Mail and System Preferences. The Gmail account makes use of IMAP because Google recommends IMAP over POP.
synaesthesia Posted March 18, 2019 Posted March 18, 2019 Absolutely not, whether he's a governor, head teacher or the leader of OFSTED, you shouldn't compromise your network security for the sake of his convenience. Advice the use of the web client if the above options don't appear available. 1
Arthur Posted March 18, 2019 Posted March 18, 2019 (edited) Does the Mac client download the emails to its software or are the emails still held on Google servers? I think the e-mails would still be cached on his Mac, but they should be deleted when you remove his G Suite account. You may want to try this with a test user account to see if this is the case however. By the way, the Google account provider does support 2FA (not security keys), although I'm not sure if it would connect via IMAP. Edited March 18, 2019 by Arthur
TwistedHelixis Posted March 18, 2019 Author Posted March 18, 2019 Very much appreciate all the help so far. That is good to know it does now support 2FA. So would I still need to enable IMAP on my G Suite domain, as these sites seem suggest? https://www.lifewire.com/gmail-os-x-access-1172876 https://www.lifewire.com/set-up-gmail-account-with-macs-mail-application-2260069 If so, that is still a reason for me to ask this Governor not to use his Mac email client, as I do not want to enable IMAP.
Arthur Posted March 18, 2019 Posted March 18, 2019 (edited) So would I still need to enable IMAP on my G Suite domain, as these sites seem suggest? I did some more testing (with POP/IMAP still disabled on my G Suite domain) and while it appears that you can send e-mails after logging in with your 2FA protected G Suite account, it doesn't let you do much else (see account error in top right of screenshot). I therefore wouldn't recommend using the Apple Mail client. If so, that is still a reason for me to ask this Governor not to use his Mac email client, as I do not want to enable IMAP. Yeah. I would tell him he has to use the Gmail web interface. Anything else would compromise security. Edited March 18, 2019 by Arthur 1
TwistedHelixis Posted March 18, 2019 Author Posted March 18, 2019 Thank you very much. Edugeek to the rescue once again :0)
GrumbleDook Posted March 19, 2019 Posted March 19, 2019 The problem is that sometimes, as a Governor, having access to information quickly is key. I can fully understand his requirements on this ... However, there are things that need to be done to protect you systems. 1 - any data that is sent via email or is linked to within an email can still be downloaded. Don’t confuse protecting one method of access with protecting information. 2 - POP is a big no no, and IMAP is susceptible, but you are going to have to face that if he uses the web app he will need to get notifications ... how about explaining how he can do that. 3 - also face the fact that guidance needs to be given to Governors about securing data on home devices. Whilst Governors rarely have to deal with personal data, when they do it is important to keep it safe ... organisational measures should be there to support that (policies). 4 - Please remember that Governors are volunteers ... generally a dedicated bunch who are not there to be difficult, but to help the school. There are many governors on EG (including yours truly) so please be mindful of not casually dismissing their needs. 2
elsiegee40 Posted March 19, 2019 Posted March 19, 2019 (edited) 4 - Please remember that Governors are volunteers ... generally a dedicated bunch who are not there to be difficult, but to help the school. There are many governors on EG (including yours truly) so please be mindful of not casually dismissing their needs. THIS! #MeToo! Governors are a vital part of the team working hard for the students in your school in their own unpaid time. They come with all levels of skill, expertise and experience in everything and anything. Your school’s governors cannot all have the same levels of GDPR, Safeguarding, IT and governance expertise as Grumbledook or me. Be an enabler. If the thing requested can be done in a better way then present it as that... most governors will be eternally grateful for a solution presented with a smile. Have a chat with your DPO and DSL about what training or guidance could be offered to governors. The offer of a short presentation at the start of a full governors meeting is likely to be eagerly accepted. I will also mention the Clerk to the governors. This person is paid, but likely part time and for very few hours. (Some, but by no means all, will be school employees) Their role is not just taking minutes; they are also the people who have the knowledge of procedure and statute to ensure the GB covers its obligations. Clerks are people to befriend. They are the primary access point to any Governing Board. Get them onside and you will have easy access to getting the message over to the GB! Edited March 19, 2019 by elsiegee40
Arthur Posted March 19, 2019 Posted March 19, 2019 (edited) 1 - any data that is sent via email or is linked to within an email can still be downloaded. For this reason, wouldn't it be better to store files on Google Drive where you get the ability to restrict downloading and printing (if required)? https://gsuiteupdates.googleblog.com/2015/07/disable-downloading-printing-and.html Edited March 19, 2019 by Arthur
GrumbleDook Posted March 19, 2019 Posted March 19, 2019 For this reason, wouldn't it be better to store files on Google Drive where you get the ability to restrict downloading and printing (if required)? https://gsuiteupdates.googleblog.com/2015/07/disable-downloading-printing-and.html Screengabs will be taken, and even people taking photos of the screen. If folk want the data, they will get the data.
TwistedHelixis Posted March 19, 2019 Author Posted March 19, 2019 so please be mindful of not casually dismissing their needs. Have I missed something? I though asking these questions were actually taking the governors needs in to account. This is a fact finding process and all avenues should be discussed. If there was a secure way for me to help him I would, but I do not want to start enabling protocols on our system when they are know to be insecure and the school has a very simple alternative method of working. I am sure he will be fine to use whichever system we suggest but the point of these posts was to check alternatives. BTW, I have only been at this school for a couple of weeks, and prior to my arrival it was another governor that was looking after all the schools G Suite systems.
TwistedHelixis Posted March 19, 2019 Author Posted March 19, 2019 Screengabs will be taken, and even people taking photos of the screen. If folk want the data, they will get the data. I am not sure that is a good reason to lower the security of s system.
GrumbleDook Posted March 21, 2019 Posted March 21, 2019 I am not sure that is a good reason to lower the security of s system. It is mainly there as a comment for those looking to say "do x as it will prevent y", when doing x only makes y difficult, doesn't prevent it. If your justification for x is solely to prevent y then it is faulty.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now