Jump to content

Recommended Posts

Posted

So...

 

Had a (verbal - I'm awaiting a written one before proceeding) request to ditch logins for pupils at my KS2/Junior School in the suite to save login times as it takes an age to get a class logged in due to forgotten/"forgotten" passwords, lots of kids who are "challenging" or ESL etc, and the time taken to set up a new profile on the ageing machines. Profiles are auto-deleted after a while to save disk space. We already have similar in place for laptop trolleys due to lack of disk space meaning that they soon fill up with profiles, but those machines are allegedly only used in lessons. The suite sees unsupervised (not my decision) use at break times.

 

I'm not keen, as we have had some cases where I've had to track usage. "Those" students have left, but I'm not as sure as the requesters that there won't be more.

 

What do others do? In a way, a single login would be easier - set the machines to autologon - but I'm not happy with how open it would be. I know some places use "Intake Year" accounts or "Class" ones, though I'm not keen on the "Class" idea due to the need for regular updating. Or do people just use "simple" logons? Say, for Steve Rogers in Y3 21SR and a simple password - they're currently e.g. Heck9999. That said, even simple logins wouldn't alleviate the "new profile" setup time.

 

 

 

Am I being overly cautious? If not, has anyone got some "easy for teachers to grasp" reasons to keep individual logons?

Posted

My last school was a primary

When I started I noticed that all computers in the school auto logged in - only exceptions were the Head's laptop and the SENCO

 

I had a discussion about changing this at least once a year - Head would never accept the concept of changing it in any way

 

One argument was to get the Year 6's used to the idea to help then when they go to Secondary

Another was to stop kids having access to all the other kids work

 

None were acceptable based on the 'difficulty' of logging a class in - I even tried with known passwords on a list that the teacher had access to - probably printed

 

They still had a generic login when I left

 

Good Luck

  • Thanks 1
Posted

The way the trust I used to work for used to work things was to create an account for a student as soon as they entered Year 1. The school then had the option of either using it or using a generic Year account. Most of them used generic accounts up to year 3 then started using their personal accounts from year 4. The idea was that account names where generated thusly:

 

{First letter of the school cluster}{Year of Y1 entry}.{First Initial}{Surname}

 

That account then follows them around for as long as they're a member of that school cluster, right through primary school, into secondary then into sixth form.

 

However, the pandemic changed that; once remote learning became a thing all students from Year 1 were issued with their accounts and simple passwords generated using three simple words. I think their parents were given the student's passwords and told to guide them logging into Teams. I don't know how successful that was, but it was what we were told to do.

  • Thanks 1
Posted

We are a primary school, Reception have a generic login, as do year 1 for the first half the year, we introduce individual user accounts for them part way through, then disable the shared year 1 login. Year 2 - 6 have individual logins with increasingly complex passwords.

 

From a safeguarding point of view I don't know how we could manage with shared logins, with keyword monitoring and web filtering it isn't very useful to be able to say one of the 60 kids in year 3 did x.

  • Thanks 1
Posted
I agree from a safeguarding perspective you need individual accounts - I'd get the DPO engaged with the proposal. Do the PC's have cameras? QR login can help - Clever Badges were ideal but support got pulled for UK. Now that the acquisition of Clever by Kahoot is complete (today by coincidence), it would great if the product was brought back to include UK. Wonde I think offer something similar.
  • Thanks 1
Posted
Safeguarding wise, children should have their own individual logins.

 

 

 

That's my gut feeling, but I need concrete examples that will be taken seriously.

 

I agree from a safeguarding perspective you need individual accounts - I'd get the DPO engaged with the proposal. Do the PC's have cameras? QR login can help - Clever Badges were ideal but support got pulled for UK. Now that the acquisition of Clever by Kahoot is complete (today by coincidence), it would great if the product was brought back to include UK. Wonde I think offer something similar.

 

 

I saw mention of Clever in an old thread. No webcams, though (possibly for the best, I guess).

  • Thanks 1
Posted

As a primary our usernames are intake Year+First name+Initial of surname. I wrote a password generator that picks a colour and an animal from a list and adds two numbers to the end, ie redfox22. These are normally pretty easy to remember.

 

Pre-pandemic Year R and Year 1 didn't use passwords, just their username. Since we set up O365 for pupils they now have passwords and it hasn't really be a big deal, in fact I get less hassle from the lower years about passwords then I do from the year 5 and 6 classes.

 

I do have password lists for each class shared with class teachers via teams. Not ideal but better then them printing them out and sticking them to a wall I suppose (though that does occasionally still happen).

 

Even with a pretty good bunch of kids here there have been a few occasions over the years were I have had to verify who did what. If I was running a single login that would have been impossible and would have in at least 1 case had some serious safeguarding consequences attached to it.

  • Thanks 1
Posted (edited)
That's my gut feeling, but I need concrete examples that will be taken seriously.

It's a frustration that it's not easy to find this. Keeping Children Safe In Education 2021 (just refreshed) highlights the need for monitoring. All staff and governors should be familiar and up to date with this document. For me, in the scenario of a safeguarding issue arising due to online activity, if a schools response was 'We are not sure which child as we use shared accounts", I don't think it would pan out well under scrutiny. I have heard some suggest the teacher keeps a log of which child sits at which desk and then track by hardware, but that's quite a faff! I'm less bothered, for the very young, about passwords, but being able to pinpoint activity against an individual is in my mind sufficiently important, that it is worth tackling the overhead of getting every child able to login easily.

 

The KCSIE document links to https://360safe.org.uk/. It's been quite a while since I went through this, but if you can find time, it may be worth doing - I can't recall if it directly addresses generic accounts, but if you were to do the review and plan for incremental improvement, you'd be in a much better position.

Edited by Ditto
  • Thanks 2
Posted

I have to say having taught KS2 that age group are generally more than capable of being taught how to login.

 

It's down to teachers and how much time they want to put in (that isn't a dig, time is precious!).

 

It's all about expectations and I think lots of teachers assume they are going to walk into a lab and they kids are going to login and start working through top end scratch lesson plans which doesn't work and they end up doing a poster about e-safety for a term instead.

 

Realistically it will take a term to orient year 3 kids on logging in/finding there way round/opening and saving files etc. It's all doable it just takes time.

 

My mantra with password was:

 

Y3 first name.lastname easy shared password with handouts to copy if they got stuck

 

Y4 first name.lastname easy shared password

 

Y5 first name.lastname easy made up password but a lesson spent on how to make a good one!

 

Y6 first name.lastname complex password with a lesson how to do it and how to keep your details safe online.

 

 

In an ideal world all the kids would all be MFAd with a super complex password but need to be realistic and teach the importance of passwords.

 

I can't comment on the new profile creation speed but this may be adding to a barrier of entry for the entire use of IT in the school. I would have a talk to head and stress how important it is and not that costly (hopefully) to get everything sped up!

  • Thanks 1
Posted

Again - my last school

I tried all that tracking and DPO stuff - but it made it 'too difficult' for the teachers

 

there was an incident where a 'troubled' kid was accused of 'looking an picture of ladies with no clothes'

 

hmmm - the LEA filters should ..... etc

 

but I chased it up obvoiusly

I traced the physical PB to an IP address and checked it was consistent throughout the day

 

logged a request with the LEA for s report of all websites that IP addres had accesses on that day

 

I had already checked and the history had been deleted - the kids was troubled - not dumb!!

 

anyway - I also went onto a few normal website just so I could know the report from the LEA was OK - probably BBC News and Edugeek knowing me

 

 

LEA came back after about 2 weeks (yes - I know_) to say there was NO ACTIVITY on that ip address that day

 

funny that - I checked the IP address using IPCONFIG myself before I went onto BBC news and edugeek

and there is no activity!!!!!

 

 

now - if it had been a specific userid - it would have need different

 

I would have been looking for maybe something like AB Tutor to log such things on site

 

but even this did not register enough in terms of H&S or Child Protection to allow an enforcement of proper logins

 

because 'Teaching and Learning' migth be affected

 

or - more accurately - teachers might moan

 

 

I had a lot of respect in that school - which is great - but it had limits

 

still

 

you can only log the problem and the possible consequences and make sure it is documented

 

then get on with life

  • Thanks 1
Posted

I won (or was in the lead in an ongoing competition) at my last school when I left. The clincher was that it massively reduced the amount of work lost through failing to save/not knowing where stuff had been saved to/moved to buy another child. We used to use Purple Mash quite a lot and Google Docs. Obviously with Google Docs if they're signed in it's almost impossible to lose work. They wanted the kids to be able to view and edit their work at home. We got the parents to support learning to log on.

 

It wasn't particularly secure in Reception as they had printed cards with their username and password printed on them, but at least you knew who'd been using which computer and what they'd done on it. About half the kids could remember them unprompted by half way through the year. Almost everyone else mastered it by the beginning of year 1.

  • Thanks 1
Posted

It is the teachers and TAs that can't manage

 

same as putting in a new entry card system on the doors - they will moan like mad that it is too $soemthingorother for them to use

 

a good teacher should be able to get the kids to remember a simple password as long as you don;t make the rules too draconian

 

round here - if you have to hack a kids account for some reason - try 'Liverpool' or 'Everton' for boys

 

true story - when I worked in a big business a security company went to the business opposite. The IT deptartment refused to co-operate because the management had called the 'consultant's in without talking to IT

The consultants challenged them - if they could login to 50% of their account with 24 hours then the IT people would co-operate - if not the consultants would declare the security to be good

 

They got onto about 80% of the IT accounts - most by using one of the main football team names - or Everton

the rest by the name on a photo on someone's desk

 

 

This was a long time ago

 

 

and may or may not be true

Posted
Too right, the complaints more likely come from the staff! However, with the right head in charge, I found the problem no longer existed. Sadly, given @LeMarchand 's OP, I suspect there is a battle ahead.
Posted

Guess what? Just been sent the PowerPoint etc from the recent Inset Day, subject: Safeguarding - including the need for checking online activity :frusty:.

 

(This was also more or less the online course I recently had to do, so not sure why both were necessary).

Posted
So...

 

Had a (verbal - I'm awaiting a written one before proceeding) request to ditch logins for pupils at my KS2/Junior School in the suite to save login times as it takes an age to get a class logged in due to forgotten/"forgotten" passwords, lots of kids who are "challenging" or ESL etc, and the time taken to set up a new profile on the ageing machines. Profiles are auto-deleted after a while to save disk space. We already have similar in place for laptop trolleys due to lack of disk space meaning that they soon fill up with profiles, but those machines are allegedly only used in lessons. The suite sees unsupervised (not my decision) use at break times.

 

I'm not keen, as we have had some cases where I've had to track usage. "Those" students have left, but I'm not as sure as the requesters that there won't be more.

 

What do others do? In a way, a single login would be easier - set the machines to autologon - but I'm not happy with how open it would be. I know some places use "Intake Year" accounts or "Class" ones, though I'm not keen on the "Class" idea due to the need for regular updating. Or do people just use "simple" logons? Say, for Steve Rogers in Y3 21SR and a simple password - they're currently e.g. Heck9999. That said, even simple logins wouldn't alleviate the "new profile" setup time.

 

 

 

Am I being overly cautious? If not, has anyone got some "easy for teachers to grasp" reasons to keep individual logons?

 

At my last school every child had a login from Year R up. It’s necessary for tracking never mind everything else. Yes it does take time to learn how to login, but our reception teacher made a game of it and there were rewards for learning how to login quickly. This game meant they were competent long before they got to year 1.

 

The whole of reception class had the same “top secret” password… and it was only 3 letters long. Year 1 had 4 letters, Year2 to 5 letters… so by Year 5 they were on 8 character passwords and in Year 6 they got to pick their own.

 

Login names were the year of admission of the year group to reception followed by their forename and surname initial. Shortened forenames were used where appropriate.

 

eg 21AlexB

 

We were 1 form entry and this system wouldn’t work in a larger school.

 

We only got into trouble once and needed 21AlexBa and 21AlexBe to separate 2 girls with similar names.

 

I know about not having identifying information in login info, etc but seriously these kids couldn’t email until year 4 and even then only within their year group.

 

Regardless of what login name you use, I think a teacher’s enthusiasm for rewarding the kids for learning to login quickly was the best thing… and acceptance that the first few lessons are going to be dominated by learning how to do so.

  • Thanks 2
Posted
We do have 21JBloggs - though that can get to be a pain when it turns out that the child prefers to be called Mickey rather than Joe and/or likes to use a different surname (I remember a change of one of the "barrels" was a regular event with one family). I don't think that WORDNNNN where the number is the school's DfE number should be that difficult,but part of the problem is the login times as these will often be "first time" logins due to the necessity of having to regularly clear out old profiles. Though I guess fixed seating might help there...
Posted

DfE guidance regarding appropriate filtering and monitoring requires web usage to be logged and identifiable as to who visited it. So, without individual logins, I can't see how you would comply with this requirement.

 

We have logins for all users here.

  • Thanks 3
Posted
DfE guidance regarding appropriate filtering and monitoring requires web usage to be logged and identifiable as to who visited it. So, without individual logins, I can't see how you would comply with this requirement.

 

We have logins for all users here.

Do you have a link and reference to that guidance, it will be useful @LeMarchand and others who come to the thread at a later time.

Posted
Do you have a link and reference to that guidance, it will be useful @LeMarchand and others who come to the thread at a later time.

So, the DfE defers to the UK Safer Internet Centre for their filtering guidance in the KCSIE guidance (paragraph 129). This is the up to date page on appropriate filtering - https://www.saferinternet.org.uk/advice-centre/teachers-and-school-staff/appropriate-filtering-and-monitoring/appropriate-filtering

  • Thanks 3
Posted

I wish it was a bit more in depth than

 

The appropriateness of any filters and monitoring systems are a matter for individual schools and colleges

 

Though the second link includes

 

Identification - the filtering system should have the ability to identify users

 

Which it can't unless they are logged in. Mind you, it only identifies them on Windows devices - might have to have a word with the LA...

Posted

My reading of this sort of guidance, with their "should" "up to schools", is that we should read it through the lens of "if Ofsted inspect and ask you why you're not following the guidance, will you be able to satisfactorily answer the question".

 

An answer of "its too complicated for children to log in" won't pass muster, I feel. When there's systems designed to make that easier - eg. Wonde QR logins etc...

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...