Jump to content

Recommended Posts

Posted
Not that every pupil doesn't know the password of at least 1 person in their class, because it's 123456, or they shouted it, or the teacher shouted it, or they told them because they wanted to be friends.

 

If teachers are shouting passwords then you've got a training issue to be addressed. :)

 

Anyway, no one's pretending that you're going to get 100% accurate user identification, but I think it's disingenuous to say that it's so inaccurate as to be useless. I agree that (ethical concerns aside) biometric logins would be really useful for primaries and a lot of special schools where the kids struggle with typing usernames and passwords though (fingerprint, facial recognition, etc).

  • Thanks 1
Posted (edited)

 

Thanks for this - I hadn't spotted that the draft had been published. From a quick scan through they don't seemed to have made it any less vague, although it does link to the UKCCIS guidance, which is well worth a read:

https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/759010/Guidance_for_School_Governors_-_Question_list.pdf

 

Key notes from that document relevant to this conversation:

 

  • Evidence of monitoring and evaluation processes to ensure understanding of, and adherence to, online safety policies.
  • Auditing of online behaviour and risks which provides base line information from the pupils about the levels and types of online issues prevalent in the school / college.
  • Appendix 1 signposts schools to the UKSIC guidance again.

 

All seems to indicate that schools are expected to regularly review online activity reports.

Edited by Opendium_Steve
Posted
If teachers are shouting passwords then you've got a training issue to be addressed. :)

 

Anyway, no one's pretending that you're going to get 100% accurate user identification, but I think it's disingenuous to say that it's so inaccurate as to be useless. I agree that (ethical concerns aside) biometric logins would be really useful for primaries and a lot of special schools where the kids struggle with typing usernames and passwords though (fingerprint, facial recognition, etc).

 

It'll catch the pupils not smart enough to realise they're being logged anyway.

 

Desktop fingerprint readers are still too expensive. And Windows Hello doesn't scale to the server, so can't log into any machine, just the one you set it up on.

Posted
how does user loggin work with shared devices like ipads? we use EXA Surfprotect and unless they are loged into a domain computer we only have ip addresses we can trace activity by
Posted
If you're not using something like Shared iPad or a captive portal that times out after a short period then iPads that aren't 1:1 are a real issue for logging against users.
Posted
how does user loggin work with shared devices like ipads? we use EXA Surfprotect and unless they are loged into a domain computer we only have ip addresses we can trace activity by

There are various methods, and I think each filter is a bit different in how they can handle them, although none of the methods are perfect.

 

Opendium systems let you connect each shared device to an 802.1x wifi network with a special "device" account and the user then gets a captive portal to sign in to and stays signed in while the device is connected to the wifi. When the wifi is disconnected (e.g. device is rebooted, etc), the user is automatically logged out and the next time the device connects to the wifi the captive portal pops up again.

 

I've seen this used quite effectively in a school which had a set of ipads that were available to be used by any user at any time. They had the ipad charging stations in a metal cabinet: the student goes to the cabinet, opens the door and picks up any of the ipads, logs into the portal and uses it. When they're finished, put it back in the charging cabinet and close the door. Because its a metal cabinet, it's a Faraday cage, so the ipad loses its wifi connection and the student is automatically logged off.

 

I know some other systems let you set short captive portal timeouts, or can be set to automatically log people out at the scheduled end of each lesson.

 

There's obviously also the paperwork method - log each ipad into the network using a unique username ("ipad1", "ipad2", etc.) and label them all. When a member of staff hands out the ipad they record who they handed it to. There's obviously a management overhead with doing that and it makes identifying the users in reports more effort (as previously discussed, this is a bad thing).

 

I'm sure people have come up with other methods of handling this, although this may be a time when you can legitimately fill in a risk assessment that says you have made a concious choice not to identify shared device users because you can't find a solution which doesn't tip the cost:benefit balance the wrong way. My original comment was that having no user identification at all on your entire network is a very bad thing - there may well be restricted situations where you can justify user identification as being too difficult, I just don't think you can reasonably do this for your whole network.

 

1:1 ipads, BYOD, etc. on the other hand, is easy - you just use 802.1x to authenticate them with the "owner's" credentials as they connect to wifi.

Posted (edited)

Reading all that, I think the essential thing to take away are the words: "appropriate filtering"

 

These are junior school children. Allegedly our filtering is quite good enough at this level. I would also call your attention to the fact that Ofsted have never deemed our filtering to be not fit for purpose

 

I did mention that we have user appropriate filtering in that the children have no access of any kind to YouTube or any dodgy content - the list of blocked stuff is extensive and I keep an eye on the edugeek threads for anything new. Even staff have to use a password to gain access to anything other than very basic and bland stuff. Perhaps this is what enables our risk assessment to decide that we do have appropriate filtering.

Edited by witch
Posted
Reading all that, I think the essential thing to take away are the words: "appropriate filtering"

 

These are junior school children. Allegedly our filtering is quite good enough at this level. I would also call your attention to the fact that Ofsted have never deemed our filtering to be not fit for purpose

 

I did mention that we have user appropriate filtering in that the children have no access of any kind to YouTube or any dodgy content - the list of blocked stuff is extensive and I keep an eye on the edugeek threads for anything new. Even staff have to use a password to gain access to anything other than very basic and bland stuff. Perhaps this is what enables our risk assessment to decide that we do have appropriate filtering.

 

Are these legal requirements or just guidlines?

 

I certanly dont run reports atm and if they want me to, a discussion may have to be had about the huge increase in responsibiliy and workload and the pay scale of an entry level tech...

 

The Safer Internet Centre’s guidance on “appropriate filtering” is nationally recognised

https://www.saferinternet.org.uk/advice-centre/teachers-and-school-staff/appropriate-filtering-and-monitoring

 

@esafety_officer wrote about it in her analysis of KCSIE 2016 and I pulled it out in my post in this thread

http://www.edugeek.net/forums/e-safety/171051-online-safety-within-keeping-children-safe-education-2016-published-26-5-16-a.html#post1464382

Posted
RM Safety Net have all sorts of ban lists - much like those mentioned in the Safer Internet Centre document - which was written in conjunction with SWGfL which is who we speak to when we want to change something about the filtering....:)
Posted

Monitoring doesn’t have to be flagging up items from the logs. It can mean a teacher actually keeping an eye on the class. I can certainly see where Witch is coming from within primary schools. Secondary would be much different though I think.

 

That said I do think it’s good practice and an important feature to have used identifiable info and good reporting. As with all things in life there is a balance. Present the user with as much info info as possible in an easy to read and understand manner with minimal fuss.

But a good filtering company should be able to help you dig further into the logs for further analysis - even if that’s behind the scenes.

  • Thanks 1
Posted
Monitoring doesn’t have to be flagging up items from the logs. It can mean a teacher actually keeping an eye on the class. I can certainly see where Witch is coming from within primary schools. Secondary would be much different though I think.

 

That said I do think it’s good practice and an important feature to have used identifiable info and good reporting. As with all things in life there is a balance. Present the user with as much info info as possible in an easy to read and understand manner with minimal fuss.

But a good filtering company should be able to help you dig further into the logs for further analysis - even if that’s behind the scenes.

 

Witch has said they don't log against users.

 

A teacher watching a class is going to miss things - students who are going to go where they shouldn't won't do it whilst the teacher is watching.

 

Filtering and monitoring go hand in hand - the information that our filter has flagged through monitoring has prevented self harm and perhaps even worse - why wouldn't you?

Posted
RM Safety Net have all sorts of ban lists - much like those mentioned in the Safer Internet Centre document - which was written in conjunction with SWGfL which is who we speak to when we want to change something about the filtering....:)

 

 

If you're using RM SafetyNet you can definitely monitor effectively, I'm speaking from experience. If you're talking to SWGfL maybe ask them for a read-only account for SafetyNet so you can view the monitoring information you need. I've previously used read only accounts to give DSL's access without them messing with my filter lists but it sounds like SWGfL could provision you as such if you want it.

Posted
I think we need to be very careful considering Primary age school pupils from a filtering/monitoring perspective. Anyone that's done PREVENT training will know from the outset that based on exterior appearances, it is virtually impossible to spot those pose a risk or those at risk. Whilst I agree in a small primary, where every child (and the whole family) is well known to staff, the risk is general at the lower end of the scale, but we have to be very cautious not to fall in to the trap of 'not at my school'. I know from first hand experience that even at a primary age, filtering/monitoring can show up concerns from most unexpected sources. This can occur through naivety rather than anything more sinister. Just consider the Y5 or Y6 child who is being taken down the wrong path by an older secondary school sibling - that can spill into primary.
  • Thanks 2
Posted
I think we need to be very careful considering Primary age school pupils from a filtering/monitoring perspective. Anyone that's done PREVENT training will know from the outset that based on exterior appearances, it is virtually impossible to spot those pose a risk or those at risk. Whilst I agree in a small primary, where every child (and the whole family) is well known to staff, the risk is general at the lower end of the scale, but we have to be very cautious not to fall in to the trap of 'not at my school'. I know from first hand experience that even at a primary age, filtering/monitoring can show up concerns from most unexpected sources. This can occur through naivety rather than anything more sinister. Just consider the Y5 or Y6 child who is being taken down the wrong path by an older secondary school sibling - that can spill into primary.

 

Hence my concern at many primaries being incredibly blasé about it all.

  • Thanks 2
Posted

I tend to think that getting some kind of regular report that identifies individuals who may be at risk is low hanging fruit - its easy, low cost, so why wouldn't you do it?

 

Certainly the type and quality of the reports you can get will depend on the exact filtering system you're using, but whatever system you've got you should be able to do some level of reporting out of the box.

Posted
Another thing I believe may be compounding this issue is that a lot of primaries use third party ict companies. That is perfectly fine, but many of these companies may not necessarily cover these services and the school thinks they're covered because 'All our IT is handled'. Or, they do offer some E-Safeguarding but it is not near the standard which is required of Prevent and KCSiE .
Posted
Never noticed a proactive 3rd party company, always want to do the minimum required, never increasing security.

 

I work for a third party company. Minimum required is not a way to run a business. I have seen plenty that do. Get in a profit gouge. But I also see many that do a great job. So the sweeping statement is very disrespectful.

Posted
I work for a third party company. Minimum required is not a way to run a business. I have seen plenty that do. Get in a profit gouge. But I also see many that do a great job. So the sweeping statement is very disrespectful.

 

Just said I've never noticed one, the ones that are better need to find a way to get more attention, write some blog posts about how you implemented SRP, Credential Guard, consulted with clients and removed access to data for people who didn't need it, auto update 3rd party software, firewalled photocopiers, added a secure incredibly cheap voip system, have live backups of VMs streaming to your backup system, automated account creation on 3rd party sites, etc etc etc.

Posted

Not sure how primaries need all that (although much of it - found a software company who said they’d consider it a feature request to add smb2/3 support for their file transfer app. Sigh. )

The business side do all of that and more though.

Posted
Monitoring doesn’t have to be flagging up items from the logs. It can mean a teacher actually keeping an eye on the class. I can certainly see where Witch is coming from within primary schools. Secondary would be much different though I think.

 

That said I do think it’s good practice and an important feature to have used identifiable info and good reporting. As with all things in life there is a balance. Present the user with as much info info as possible in an easy to read and understand manner with minimal fuss.

But a good filtering company should be able to help you dig further into the logs for further analysis - even if that’s behind the scenes.

 

RM do dig behind the scenes. We have had meetings with the local Police depts which liaise with such as RM SafetyNet.

Our filtering is draconian - anything and everything is filtered. Perhaps this is why we are as we are.

User-level filtering is not cheap. And who is going to run the reports? Not this bottom-of-the-pile tech

 

BTW some third party companies ARE proactive and do the best they can

  • Thanks 1
Posted
RM do dig behind the scenes. We have had meetings with the local Police depts which liaise with such as RM SafetyNet.

Our filtering is draconian - anything and everything is filtered. Perhaps this is why we are as we are.

User-level filtering is not cheap. And who is going to run the reports? Not this bottom-of-the-pile tech

 

BTW some third party companies ARE proactive and do the best they can

 

Witch as said before draconian filtering isn't good either - filtering should be age appropriate and not over the top at all.

 

KCSiE - "Whilst it is essential that governing bodies and proprietors ensure that appropriate filters and monitoring systems are in place, they should be careful that “over blocking” does not lead to unreasonable restrictions as to what children can be taught with regard to online teaching and safeguarding."

 

If RM are charging a fortune for user level filtering then switch provider - in this day and age user level filtering and regular reporting are the bare minimum. No one should be manually running reports - they should be automated and emailed to the appropriate people.

 

Once again, it's incredibly worrying how blasé primaries are with filtering and monitoring.

Posted

My school is a junior school. I do not think that the level of filtering we have is at all inappropriate for the children.

I'm not arguing any more. It is what it is. Ofsted were happy with our systems. User-level filtering will come, I am sure, but until then I am fine with it as it is.

 

*oh yeah, as if I have any power to switch anything

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...