Jump to content

Recommended Posts

Posted

@witch you called it draconian in one post and now it's all fine in another.

 

The other point is what is acceptable for 1 year group may not be for a younger year group - again with user based filtering you can tailor it so that it is age appropriate which is once again a requirement.

 

Saying Ofsted are fine with it means nothing - half the time Ofsted don't even look at IT provision. It's akin to the kids at school telling me they're allowed to wear trainers because they walked past the head wearing them and he didn't say anything!

 

As with all things, it's all fine until something bad happens and then everyone will blame IT. It sounds like you're covered as you've had stuff back from the MAT in writing but IMHO the people at the MAT are not living up to their obligations to provide monitoring.

Posted
So two people disagreed with you - one got called sarcastic, the other pedantic - nice!

 

I don't like being ranted at. I used the word Draconian as a joke - because I knew that those complaining would think that of my filtering.

 

 

I wasnt aware "pedantic" was an insult but I am sorry for any offence caused

  • Thanks 1
Posted
While keeping this thread completely off course from what the OP originally posted, who is expected to review the monitoring reports @Primus? It's certainly not the remit of IT Support, and even if you do review what sites have been accessed, as most searches are via https, they are virtually impossible to identify via the URL content.
  • Thanks 1
Posted
While keeping this thread completely off course from what the OP originally posted, who is expected to review the monitoring reports @Primus? It's certainly not the remit of IT Support, and even if you do review what sites have been accessed, as most searches are via https, they are virtually impossible to identify via the URL content.

 

It varies from school to school - ideally it should go to the DSL or someone who has received the DSL training.

 

It's not true that searches are impossible to identify provided you do HTTPS interception - if you don't well then yes you have no way of knowing what was searched for but then you'd have to ask yourself why you wouldn't use HTTPS interception since so many sites use HTTPS now that if you don't use it your filter is blind.

 

The reports we receive daily from our Smoothwall are intelligible and relevant. We also received immediate reports if the category is related to self harm, suicide etc - it has certainly helped us safeguard our students and reduce/prevent self harm - helping early interventions and keep our pastoral staff informed.

Posted (edited)
Just said I've never noticed one, the ones that are better need to find a way to get more attention, write some blog posts about how you implemented SRP, Credential Guard, consulted with clients and removed access to data for people who didn't need it, auto update 3rd party software, firewalled photocopiers, added a secure incredibly cheap voip system, have live backups of VMs streaming to your backup system, automated account creation on 3rd party sites, etc etc etc.

I'd just like to echo that (as a director of a 3rd party company) "bare minimum" certainly isn't how I've ever worked. In fact, the whole reason we established the company was because neither of us (the directors) were happy with the level of support being offered by our previous employer. We are, frankly, rubbish at telling people that we're not going to help them, so are always ending up solving problems that really should be someone else's!

 

Also, I often think that people don't realise just how hard it is to both do good work and get attention for it - by definition, the companies who price-gouge and put in the minimum of effort have more resources to throw at their marketing budget, whilst those of us who put the time in to provide good service are spending our time doing exactly that rather than writing regular blog posts about how great we are, or visiting expensive trade shows. I was recently asked by a long-term customer why we didn't exhibit at BETT, and they simply didn't believe me when I explained how much even the pokiest stands at BETT cost - the big companies have huge stands, but smaller businesses have to make tough choices about what they spent their time and money on.

 

We do write blog articles and publish case studies every so often, but ultimately this is limited by the amount of time that we can spend doing that instead of supporting customers and developing products. This is coupled with the fact that customers often consider a lot of what we do to be confidential, and wouldn't want us blogging about them all the time; and attracting attention to the blog articles that do get written is also not trivial.

Edited by Opendium_Steve
  • Thanks 1
Posted

I was specifically referring to companies that exist instead of having an IT Technician, who come in and set up your software/hardware/do phone support.

 

You'd think as they work at a larger scale they'd be better at setting up systems to deploy automatically, have been default security, etc etc. But never have I been to a school who use a 3rd party support company where that is the case.

 

My other job is doing simple security audits. The results are always horrifying.

 

So really need some company to show that they're better than the rest, and cheaper because they've automated so much, so I can recommend them

Posted

Well, I guess they all run windows, so automatic deployment onto new hw, plus all the apps they use, along with security settings so they can't run anything not approved, eg ransomware.

 

Automating the BIOS settings is more of a pain, but at scale that would be less so, there's only so many models of computer.

 

Buy computer, turn on, boot to pxe, pick a name, rest should be automatic, including adding details to inventory, then print out a bar code sticker/inform the deployer of the assigned preprinted sticker.

 

Pretty much the same for servers, switches. VLAN off photocopier, phones, cctv so their terrible security can't be used to hack the rest of the network. Sync AD with phone directory.

 

Automate comparing password hashes with haveibeenpwnd list, auto check that at least admin users have 2fa on internet accounts. Automate adding/removing accounts from lame 3rd party websites that don't support oauth/ldap.

 

There's always a user that's left and their account is still working on some website, and no one ever checks if they get their account password brute forced, because no one notices it gets disabled all the time. Another reason not to have a staff list on your website, archive.org to find out who used to work there, guess their account names.

Posted
:mod: This thread is drifting

 

:focus:

As the OP - it has indeed! I'm none the wiser as how to implement UBF. I do know the NM has now started to look at RM Unify, but this person is off to new ventures shortly so it's all a bit in vain.

  • Thanks 1
Posted (edited)

@Ditto for the SafetynetPlus UBF to work, you have the RM AD Sync tool installed onto your DC's, which picks up your users details based on OU's it is set to scan, and group membership of a RM Unify Users group (there is also an admin group)

 

This information is synchronised with RM Unify, which in turn passes the username and credentials through to the Safetynet filtering, along with which group the user is assigned (be it student, teaching, non teaching, other etc)

Within Safetynet you can then set the different filter lists for each category. Staff might be allowed to access Webmail and chat sites for their own e-mail, while students are not.

We make use of the "Other" group to assign select students to a Walled Garden list where all sites other than the few on the allow list are blocked.

 

We've been running it since it was launched for the SWGfL, and we're just going through the process with 2 other schools in the MAT in getting it setup as they have continued to use the old flat level filtering all this time.

 

Also (coming soonish) is a module within Unify that will enable users via the transparent proxy to signin to the UBF as long as there is not a NAT in the way.

Edited by Boredguy

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...