Jump to content

Safeguarding/Keyword monitoring/etc software and monitoring offsite devices.


Recommended Posts

Posted

Currently we're using Senso, but I'd be lying if I said I was 100% enthused by the software.

 

I'm not keen on being able to remote control any PC from anywhere on earth as long as it's internet connected, as far as I see it, that makes Senso a reasonable-sized hole in our defences. Should it (or an admin) ever be compromised, all of our end-user devices would be compromised, including IT Support PC's.

Plus I don't think the school should be monitoring devices sent home. As far as I'm concerned, if we give little Johnny a laptop and he's going on stuff he shouldn't be doing at home, that's an issue for the parent to be fixing. By us monitoring the device off-site, that could be seen as us accepting liability for its use on a network we have no control over. That being said, do we not already do that by providing the device with certain restrictions (eg no admin account)? What're people's thoughts on this one?

 

So far I've looked at NetSupport DNA and I have to admit I'm reasonably impressed. Customisable severity levels, email alerts, screenshots and an easy to read UI are all a big plus.

 

I can see Impero offer similar with their well:being software, but with no trial I'm not sure I could properly vouch for it. I may look into their demo though.

ABTutor looks to just be classroom management, and not much in the way of behind the scenes safeguarding.

 

What else is out there that people can recommend?

 

Realistically, our needs are:

  • Keyword logging, with a customisable list
  • Customisable email alerts (such as if certain websites or keywords are used)
  • Automated end-of-week reporting is a bonus
  • Cloud-accessible portal, so the safeguarding team can check alerts from outside school
  • Relatively easy to get an overview of what's going on
  • Capability for multiple users

Posted

I'm afraid I have to suggest revisiting your thoughts on "monitoring" devices from home, more specifically that they're not "monitored". If the device belongs to the school and they sign a relevant agreement for it, then there shouldn't be an issue. What they browse on it shouldn't necessarily be down to you to configure (you can keep keyword reporting on but disable any filtering when off-site) BUT with a device provided by you as a school, and they do something they shouldn't could liability shift? Could the school cop some responsibility? You also don't have to have Senso active when it's not on your site.

What if Senso picks up keywords and behaviour, flagging them up to you that would otherwise go unnoticed at home? Perhaps home IS the problem and they are not able to escape it? Perhaps it catches something, the school acts on it and before you know it, you've saved a kids life.

Lots of pros and cons, but a discussion with your senior leadership would go a long way. You may not agree, they may not, perhaps minds will be changed.

  • Thanks 1
Posted

In the past we took the view that if we supplied the device and the connection (eg. a 4G hotspot) then we would filter and report, if we only provided a device on loan then it was up to the parent to ensure filtering etc at home and we had paperwork for this.

 

However when the DfE Covid scheme happened it became clear their expectation was that all devices that were loaned were filtered and reported on when offsite - even if we weren't giving them a 4G hotspot. So we changed our processes to fall in with the DfE's expectations - now any device loaned to a student is filtered and reported on in the same manner whether it's onsite or offsite and our documentation makes this clear.

Posted
I'm afraid I have to suggest revisiting your thoughts on "monitoring" devices from home, more specifically that they're not "monitored". If the device belongs to the school and they sign a relevant agreement for it, then there shouldn't be an issue. What they browse on it shouldn't necessarily be down to you to configure (you can keep keyword reporting on but disable any filtering when off-site) BUT with a device provided by you as a school, and they do something they shouldn't could liability shift? Could the school cop some responsibility? You also don't have to have Senso active when it's not on your site.

What if Senso picks up keywords and behaviour, flagging them up to you that would otherwise go unnoticed at home? Perhaps home IS the problem and they are not able to escape it? Perhaps it catches something, the school acts on it and before you know it, you've saved a kids life.

Lots of pros and cons, but a discussion with your senior leadership would go a long way. You may not agree, they may not, perhaps minds will be changed.

 

I appreciate what you're saying, but there's not really an 'on when on-site, off when off-site' option. It's on or it isn't - Senso sends all of its data over the internet. Plus our loan devices don't really toggle between. They're either at home until they get returned, or here until they're loaned out.

Currently the agreement they sign does state that the device is monitored and Chromebooks do have Senso force-installed on them via G Suite. Part of my concern is that this monitoring could A) give parents a false sense of security through misunderstanding exactly what that means, B) open the school up to liability for things beyond our control, and/or C) potentially capture information it really shouldn't (since it takes screenshots), such as if they're using the device's webcam. The current agreement does stipulate the device is only to be used by the named pupil(s) and only for school work, but we all know folks abiding by that is about as likely as I am to win an olympic gold.

I guess the question is how far does our duty to safeguard the children extend?

 

We have some leeway for now because most of the loaned devices are DfE Windows devices, so they're as-provided with the DfE's settings/filtering/whatever they come with. But the chromebooks we got are enrolled into our domain, so they do run Senso offsite at the moment.

  • Thanks 1
Posted
I appreciate what you're saying, but there's not really an 'on when on-site, off when off-site' option. It's on or it isn't - Senso sends all of its data over the internet. Plus our loan devices don't really toggle between. They're either at home until they get returned, or here until they're loaned out.

Currently the agreement they sign does state that the device is monitored and Chromebooks do have Senso force-installed on them via G Suite. Part of my concern is that this monitoring could A) give parents a false sense of security through misunderstanding exactly what that means, B) open the school up to liability for things beyond our control, and/or C) potentially capture information it really shouldn't (since it takes screenshots), such as if they're using the device's webcam. The current agreement does stipulate the device is only to be used by the named pupil(s) and only for school work, but we all know folks abiding by that is about as likely as I am to win an olympic gold.

I guess the question is how far does our duty to safeguard the children extend?

 

We have some leeway for now because most of the loaned devices are DfE Windows devices, so they're as-provided with the DfE's settings/filtering/whatever they come with. But the chromebooks we got are enrolled into our domain, so they do run Senso offsite at the moment.

 

I'm sure I saw this as a sort of conditional access option - I'll take a look when I've stopped swearing at SIMS and our new LEA ;)

It's an interesting thing to follow hence my interest and hoisting upon thee my opinion as this will certainly become more common, and I suspect other providers may follow suit either by default or as an option.

  • Thanks 1
Posted

Well, I've confirmed that AB Tutor is indeed pretty much just classroom management. Shame.

Emailed Impero asking for a trial of well:being. Let's see where that ends up.

Smoothwall are also offering every school a free 90-day trial of Monitor, so I've sent an email about that. Thank you @Rob_D

  • Thanks 1
Posted

I'm not paid by NetSupport but I'm really going to have to give them a shout out here, the software really is fantastic.

 

It's not an official solution as far as I can tell but what I've done is the following;

 

Set up NetSupport on an Azure VM with a public IP (VM costs around £8 a month)

Install the client on machines configured with the public IP of the NetSupport VM instead of a local one

 

This way the devices are always talking to the cloud VM that doesn't require any on-prem gumph. The official solution is to install gateway servers but I felt this was a more complex solution at greater cost and for not much benefit. You can then set the NetSupport installation to sync with their own cloud service so you can view all the information from a web portal. The software itself provides all the functionality you require and more. The only caveat with my solution is that remote control of a device wont work off-site as NetSupport takes the local IP address of the client to route VNC.

 

However, everything else works; cheap, simple and highly effective.

Posted

I'd thought about that, but in testing, I dropped a chromebook onto my own data and googled a naughty, got no email about it as was to be expected, but 5 mins later when I connected the device back to work wifi, even after a reboot, I still got an email.

Not sure which trumps 'worse', pay £8 a month and don't have the remote control option, or get delayed alerts for off-site devices. Guess that's up to safeguarding to decide.

 

On the plus side, email back and forth with Impero, and they've agreed to let me trial the software so we can get a true side-by-side comparison, so that's nice.

Posted

We use senso and monitor access at home but if I wanted to restrict monitoring to just onsite devices I'd create a group who's membership was determined by IP address, add our school ranges and apply the logging policy to that group.

Devices at home would still show up on the portal but they wouldn't be monitored.

Posted (edited)

Hi,

 

Check out our educational specific Lightspeed Systems Alert (including AI + Human Review) and Lightspeed Systems Filter solutions below:

 

https://www.lightspeedsystems.com/solutions/lightspeed-alert/

 

https://www.lightspeedsystems.com/solutions/lightspeed-filter/

 

Please also see our United Learning Trust case study, they were in a very similar situation prior to moving away from alternative solutions - https://www.lightspeedsystems.com/case-study/united-learning-trust/

 

We would love to help filter and safeguard your students when using their devices remotely or onsite.

 

I’d also be keen to walk you through the solutions and set you up on an evaluation.

 

If this would be something of interest please feel free to email me on [email protected]

 

Thanks,

Shaun Phillips

Lightspeed Systems

https://www.lightspeedsystems.com/

Edited by Lightspeed_Shaun
Posted
at my old place we used esafe, able to download the client and works on stand alone pcs off the network. if anything was flagged hoys are informed
Posted
We currently use Senso and have equal feelings towards it, we used to use e-safe which we found to be a much better piece of software and would pick up device on/offsite also the keyword monitoring was a lot better. I think it costs a bit more but you're getting what you pay for, and when it comes to safeguarding I don't think it's best to cheap out on that.
Posted

Until there is more joined-up advice on this, it is hard to say exactly what works best.

Would people be interested in a short session looking at issues like this? Get a safeguarding expert, an NM and a Privacy Professional together to chat about it?

 

Absolutely - we're moving to a more online world, cloud only schools, 1:1/BYOD and that already wobbly line between privacy and safeguarding is getting hazier ever day. One reason for that is that the device isn't always aware or cares where in the world it is - pretty much only one thing between "on site" and "off site" is the school's wifi & public IP (and then with ipv6/IOT that might be even blurrier!)

 

I don't think anyone has any definitive answers for this, there's a million scenarios so it would be nice to find a reasonable consensus!

Posted
Would people be interested in a short session looking at issues like this? Get a safeguarding expert, an NM and a Privacy Professional together to chat about it?

As always, your input is appreciated :)

I would absolutely be interested, even though I'm not very involved with safeguarding.

 

Absolutely - we're moving to a more online world, cloud only schools, 1:1/BYOD and that already wobbly line between privacy and safeguarding is getting hazier ever day. One reason for that is that the device isn't always aware or cares where in the world it is - pretty much only one thing between "on site" and "off site" is the school's wifi & public IP (and then with ipv6/IOT that might be even blurrier!)

 

I don't think anyone has any definitive answers for this, there's a million scenarios so it would be nice to find a reasonable consensus!

Indeed. For the most part, off-site monitoring seems to be available no matter who you go with (even if NetSupport's offering is delayed or a bit kludgy, due to the server element).

It's a conversation I'm going to leave to the safeguarding bods, as I know I don't know enough about this to come to a decision myself (and also it's outside of my remit, so I wouldn't want to be the guy making the decision anyway). I just wondered what other schools were doing as the question has been asked here.

Posted (edited)

I don't suppose there are safeguarding phrase lists floating around the internet, are there?

Management seem quite keen on the look and functionality of NetSupport, but in testing, Senso seems to be picking up far more stuff (specific examples being 'gun', 'knife' and 'kill my self')

 

A cursory Google doesn't find me much.

 

Edit: I know I can (and have) added custom phrases, but seems pretty whack-a-mole-y. I guess phrase matching always will be, but still, I'm sure there are better organisations than I, probably with more than one dude working there vs me, myself and I, who have been able to curate something significantly more in-depth.

 

Edit2: The IWF say they have a keyword list, but allegedly NetSupport already uses that.

Edited by Garacesh
Posted
I don't suppose there are safeguarding phrase lists floating around the internet, are there?

Management seem quite keen on the look and functionality of NetSupport, but in testing, Senso seems to be picking up far more stuff (specific examples being 'gun', 'knife' and 'kill my self')

 

A cursory Google doesn't find me much.

 

Edit: I know I can (and have) added custom phrases, but seems pretty whack-a-mole-y. I guess phrase matching always will be, but still, I'm sure there are better organisations than I, probably with more than one dude working there vs me, myself and I, who have been able to curate something significantly more in-depth.

 

Edit2: The IWF say they have a keyword list, but allegedly NetSupport already uses that.

 

I know 'kill my self' should have been picked up (sensitivity of matching for variations of words may have been set too low) and I know that 'gun' and 'knife' are regular terms that may have needed additional terms, but I'm sure the team can check on that.

 

And yes, the NetSupport phrase list is the result of working with many resources including the IWF. To say whack-a-mole-y is really putting it politely. Going back 20 years, Symantec bought out URLabs (the creators of iGear and MailGear) just so that they could get the scoring engine and rights to it. I watch conversations in Roblox and it truly scares me how quickly people adapt language now to bypass any filters of moderation!

Posted
I don't suppose there are safeguarding phrase lists floating around the internet, are there?

Management seem quite keen on the look and functionality of NetSupport, but in testing, Senso seems to be picking up far more stuff (specific examples being 'gun', 'knife' and 'kill my self')

 

If you want to run through anything again, happy to do that with you and see how you can get a good balance.

Posted (edited)

Hmm, well it didn't work in testing yesterday (typing things into MS Word)

 

Dropping the detection sensitivity down to 70% (the lowest it can go) has made it catch it with 'myself' as two words.

However, my test user isn't getting phrase matches when typing into a google docs document. Google searches on the same user/chromebook/session pop results, but typing things into google docs doesn't flag anything.

Which is a bummer, as we know kids have used the collaborative editing features as a pseudo-chatroom in the past.

 

Edit: getting a looot of matches that really aren't matches, though.. Will definitely need some further tweaking, if we go with this, but if I had to call it either way, it looks like we'll be sticking with Senso, if NS-DNA doesn't/can't watch Google docs. Smoothwall's offering is waay too expensive, and management think re-educating users to effectively replace CPOMS as Impero's solution is supposed to do would cause too many problems.

Edited by Garacesh
Posted (edited)

Hmm, so I spoke with a NetSupport bod last night, they've confirmed that NS-DNA currently isn't able to track what's being typed into a google docs tab on a chromebook. Nor is it, for some reason, telling the server when it blocks an attempt to access a restricted website (though it does block the request and redirect to the specified url as programmed) on a chromebook. They have confirmed this isn't intentional, though - that bit was working but now is not, so they've passed that on to the relevant folks.

 

However, from further testing, it's looking like safeguarding team need to be able to access a computer with the DNA client on it, because I'm the only person that can log in to the cloud platform (at dnaauthentication-uksouth.azurewebsites.net). Even if I make second operator that's given the Administrator permissions and role, it returns Incorrect email or password. Except, even when I log in, I don't have access to Alerts, only phrases/eSafety, so I can't monitor 'Attempt to access a restricted website' (and the email alert that attempt generates doesn't list the URL, so they'd need to be able to access the Alerts section to see what site). So even if we did get the cloud login working, some of the things they want to check, they can only do when they're on-site via the client.

 

I could load NetSupport DNA onto the Remote Desktop server, but then if all they have is a phone that's going to be such a pain to use.

All in all - and I say this as someone that came from a school that used NetSupport School, and really likes NetSupport - it's really looking like NetSupport DNA is aaaallllmost there, but not quite. There's just those few core niggles that make it unsuitable for our current needs/environment.

 

Which is also a massive shame, because as good as Senso's safeguarding seems to be, the ICT staff (and other rooms where there's high IT capacity, library, technology, etc) genuinely prefer to use our old, klunky, perpetual license of LanSchool from 2016 rather than Senso's classroom management tools - that's just how poorly the website performs. I had to use it as a pseudo-remote-access tool when I first started here and good lord, it was painful.

 

So Senso seems to be giving us the best suited safeguarding, but a poor classroom management, whereas NetSupport offers a great classroom management tool, but has a few issues with the safeguarding.

 

:(

Edited by Garacesh
speeling iz hared
Posted

 

So Senso seems to be giving us the best suited safeguarding, but a poor classroom management, whereas NetSupport offers a great classroom management tool, but has a few issues with the safeguarding.

 

:(

 

Agreed. As much as I'd like to get rid of Impero, we absolutely need it currently as Senso isn't there yet for the management side of things. Our MAT are however working closely with them to improve things, fingers crossed!

Just thankful we have a perpetual license for Impero, so we're OK unless we need to upgrade it!

  • Thanks 1
Posted
Hmm, so I spoke with a NetSupport bod last night, they've confirmed that NS-DNA currently isn't able to track what's being typed into a google docs tab on a chromebook. Nor is it, for some reason, telling the server when it blocks an attempt to access a restricted website (though it does block the request and redirect to the specified url as programmed) on a chromebook. They have confirmed this isn't intentional, though - that bit was working but now is not, so they've passed that on to the relevant folks.

 

However, from further testing, it's looking like safeguarding team need to be able to access a computer with the DNA client on it, because I'm the only person that can log in to the cloud platform (at dnaauthentication-uksouth.azurewebsites.net). Even if I make second operator that's given the Administrator permissions and role, it returns Incorrect email or password. Except, even when I log in, I don't have access to Alerts, only phrases/eSafety, so I can't monitor 'Attempt to access a restricted website' (and the email alert that attempt generates doesn't list the URL, so they'd need to be able to access the Alerts section to see what site). So even if we did get the cloud login working, some of the things they want to check, they can only do when they're on-site via the client.

 

I could load NetSupport DNA onto the Remote Desktop server, but then if all they have is a phone that's going to be such a pain to use.

All in all - and I say this as someone that came from a school that used NetSupport School, and really likes NetSupport - it's really looking like NetSupport DNA is aaaallllmost there, but not quite. There's just those few core niggles that make it unsuitable for our current needs/environment.

 

Which is also a massive shame, because as good as Senso's safeguarding seems to be, the ICT staff (and other rooms where there's high IT capacity, library, technology, etc) genuinely prefer to use our old, klunky, perpetual license of LanSchool from 2016 rather than Senso's classroom management tools - that's just how poorly the website performs. I had to use it as a pseudo-remote-access tool when I first started here and good lord, it was painful.

 

So Senso seems to be giving us the best suited safeguarding, but a poor classroom management, whereas NetSupport offers a great classroom management tool, but has a few issues with the safeguarding.

 

:(

I'm a little sad to hear this opinion of Senso. Have you contacted Support? Poor performance very rarely indicates an issue with Senso and I'd be more than happy to do check over things with you and I'd really like to see the poor performance for myself.

 

We're constantly striving to improve the product and customer feedback is extremely valuable to us. Please reach out to me via the Live Chat in the Portal and I'll personally take a look at everything for you.

 

That also goes for any customer who feels their product is performing poorly, reach out to the companies support teams.

Posted (edited)

I have not, admittedly.

 

It originally struck me that the issue was to do with outdated hardware, a lot of our computers are old i3-3xxx, 4GB DDR3 machines, but even with newer hardware (i5-7xxx, 8GB DDR4, SSD) staff are still complaining it's considerably slow or buggy. I spoke with the head of IT yesterday and he mentioned that sometimes peripheral input is still disabled after unlocking computers, sometimes issuing commands just flat-out doesn't work, and that the web UI is slow and/or unresponsive when trying to control a remote machine (the latter of the 3 which I personally have experience of, as previously mentioned).

 

There's also the issue of having to assign staff to certain rooms. Which seems a bit of a bizarre choice, really. Surely it shouldn't matter who the member of staff is, it should matter where the member of staff is?

Ideally a classroom management solution allows any user of PC X (the staff device) to control the PC's A, B, C, D, [...] because they 'know' they're in the same room, especially when you consider rooms with ICT provision are usually shared, bookable, or available for ad-hoc use.

I appreciate the user front-end is entirely cloud-based, so it's not a 1:1 comparison, and figuring out what device a user is using isn't so simple when your software is built that way, but that's entirely my point, and is why I say your safeguarding is great but your classroom management leaves much to be desired.

Edited by Garacesh
Posted
I have not, admittedly.

 

It originally struck me that the issue was to do with outdated hardware, a lot of our computers are old i3-3xxx, 4GB DDR3 machines, but even with newer hardware (i5-7xxx, 8GB DDR4, SSD) staff are still complaining it's considerably slow or buggy. I spoke with the head of IT yesterday and he mentioned that sometimes peripheral input is still disabled after unlocking computers, sometimes issuing commands just flat-out doesn't work, and that the web UI is slow and unresponsive when trying to control a remote machine the latter of the 3 which I personally have experience of, as previously mentioned.

 

There's also the issue of having to assign staff to certain rooms. Which seems a bit of a bizarre choice, really. Surely it shouldn't matter who the member of staff is, it should matter where the member of staff is?

Ideally a classroom management solution allows any user of PC X (the staff device) to control the PC's A, B, C, D, [...] because they 'know' they're in the same room, especially when you consider rooms with ICT provision are usually shared, bookable, or available for ad-hoc use.

 

Hi Garacesh,

 

I should strongly recommend you contact us.

 

Your first issue mentioned from your IT Staff sounds like either a WebRTC configuration or Firewall/Filter/AV issue, which we can send you articles on how to resolve. Connections should be instant if you are on the same network as the devices you are viewing/controlling, as WebRTC will create a P2P connection over the Local network, this sounds like it isn't, and is instead going through the Relay. This can be confirmed in Thumbnail view, where a little yellow symbol appears in the bottom left corner that says "Indirect Slow Connection".

 

Your second question is also completely doable, we call it Dedicated Teacher PC and you can find the article for that on our Support page.

 

In the portal, if you use the little Live Chat symbol next to your email address in the top right, ask for me and we can arrange a session to go over everything.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...