garbage46 Posted December 13, 2021 Posted December 13, 2021 This guy https://www.whatdotheyknow.com/user/gareth_jackson?page=1 Spamming the same FOI requests to schools, currently up to around 670 requests sent since May 2021.
Aprice Posted December 13, 2021 Posted December 13, 2021 Wonder if he works for a Managed print service, great sales info if you know when contracts are expiring. Not sure why you would post newly acquired info all over the internet though. 1
6Foot2 Posted December 13, 2021 Posted December 13, 2021 A student who had left a couple of years before placed an FOI request while I was still at work. He was a "difficult" student. He continued to be difficult after leaving, as he was encouraging other former students to make FOI requests with the sole aim of wasting time for staff. Requests were dealt with, and interest in this "sport" died off.
TechMonkey Posted December 13, 2021 Posted December 13, 2021 Does seem to be a very specific area. Blackpool, Wales and the Wirral. In fact, an account manager at Canon has the same name and is based in Wales...
LukeRowberry Posted December 13, 2021 Posted December 13, 2021 Just found this - https://www.whatdotheyknow.com/request/printing_and_photocopying_contra_19#incoming-1812636 1
GrumbleDook Posted December 14, 2021 Posted December 14, 2021 At the risk of sounding like a grumpy old git, it is not spamming. He is using a legitimate method of identifying what printers/copiers/services a school has. Yes, it will then be used for business, but because it is via what do they know, then all their competitors have the same info. 3
enjay Posted December 14, 2021 Posted December 14, 2021 At the risk of sounding like a grumpy old git, it is not spamming. He is using a legitimate method of identifying what printers/copiers/services a school has. I don't think it is what FOIA was introduced for, though. That was to ensure public bodies are kept accountable, it wasn't to save a company from paying some cold-callers. Also, let's take a moment to discuss the security risk of us all posting online saying what systems we have. Why tell someone which platforms we have so people know a route into our network? Especially in the week in which Log4J became known, why would I tell some random on the Internet that we've got Papercut? I'd refuse his request as vexatious. It certainly vexes me! 2
MatthewL Posted December 14, 2021 Posted December 14, 2021 Long and short is they are using it to their advantage and they are not doing anything wrong. Can be a very useful tool to get information as a member of the public.
paulkerton Posted December 14, 2021 Posted December 14, 2021 I don't think it is what FOIA was introduced for, though. That was to ensure public bodies are kept accountable, it wasn't to save a company from paying some cold-callers. Agreed, but it is within the letter of the law, if it isn't in the spirit of it. As much as it vexes me too, we can't make up the law to suit ourselves. The law needs revisiting, but it is what it is currently.
TechMonkey Posted December 14, 2021 Posted December 14, 2021 I was refraining from saying similar, about the spamming. At least he didn't ask everyone to fill in a custom form... 3
LeMarchand Posted December 14, 2021 Posted December 14, 2021 I know that his company would have to have a significantly better AND cheaper offering come renewal time to get a look in if we'd had to fill in one of those.
enjay Posted December 14, 2021 Posted December 14, 2021 Agreed, but it is within the letter of the law, if it isn't in the spirit of it. As much as it vexes me too, we can't make up the law to suit ourselves. The law needs revisiting, but it is what it is currently. I'm not trying to make up the law to suit me. I'm suggesting if it vexes us, we should also follow the letter of the law and refuse vexatious requests - https://ico.org.uk/for-organisations/guide-to-freedom-of-information/refusing-a-request/#:~:text=PDF%20(229.08K)-,When%20can%20we%20refuse%20a%20request%20as%20vexatious%3F,can%20refuse%20to%20comply%20with%20a%20request%20that%20is%20vexatious.,-If%20so%2C%20you
mikeprice Posted December 14, 2021 Posted December 14, 2021 Just to add a different viewpoint There is a proper reason that this sort of thing exists e.g. if someone found out that the Head of an academy has a relative who runs a printer company and suspects that all the schools in the academy are being pressurised to have their contract with this company this is, as far as I know, the reason that such things exists - to allow people to dig out situation where someone working for a publicly funded organisation uses it in a way that benefits themselves. In this case I would agree that this is not the case but limiting the ability of a printer sales person to find out this sort of thing also limits the ability of the other person as well you can't have swings without roundabouts (or something like that) - - - Updated - - - As an extra bit - would it be valid for the school to reply but leave out the bit about the make etc for security reasons?? 1
enjay Posted December 14, 2021 Posted December 14, 2021 There is a proper reason that this sort of thing exists e.g. if someone found out that the Head of an academy has a relative who runs a printer company and suspects that all the schools in the academy are being pressurised to have their contract with this company this is, as far as I know, the reason that such things exists - to allow people to dig out situation where someone working for a publicly funded organisation uses it in a way that benefits themselves. In this case I would agree that this is not the case but limiting the ability of a printer sales person to find out this sort of thing also limits the ability of the other person as well I would be okay with people making FOI requests in those circumstances, but as you say, that isn't what is going on here. This is someone with a commercial interest in the information using the FOIA to save themselves money. I don't see why limiting people with commercial interests also limits the whistleblower/concerned citizen.
TechMonkey Posted December 14, 2021 Posted December 14, 2021 I'm not trying to make up the law to suit me. I'm suggesting if it vexes us, we should also follow the letter of the law and refuse vexatious requests - https://ico.org.uk/for-organisations/guide-to-freedom-of-information/refusing-a-request/#:~:text=PDF%20(229.08K)-,When%20can%20we%20refuse%20a%20request%20as%20vexatious%3F,can%20refuse%20to%20comply%20with%20a%20request%20that%20is%20vexatious.,-If%20so%2C%20you I know it is annoying but from the article you quote: The key question to ask yourself is whether the request is likely to cause a disproportionate or unjustifiable level of distress, disruption or irritation. Answering 4 questions, as long as he hasn't bombarded you before, is not vexatious. The article also says As a general rule, you should not take into account the identity or intentions of a requester when considering whether to comply with a request for information. You cannot refuse a request simply because it does not seem to be of much value.
David44 Posted December 14, 2021 Posted December 14, 2021 I would be okay with people making FOI requests in those circumstances, but as you say, that isn't what is going on here. This is someone with a commercial interest in the information using the FOIA to save themselves money. I don't see why limiting people with commercial interests also limits the whistleblower/concerned citizen. How do you define someone with a commercial interest? Journalists have a commercial interest as they are paid to investigate these things. Should journalists be banned from making FOI requests? If there is a conflict of interest to uncover then someone with a commercial interest is going to be more likely to investigate than someone without. We are all concerned citizens but we all have bills to pay. If schools don't want to respond to requests like this then they should just stick details of all contracts over a certain threshold on their website and refer requesters to that page. It's public money. It's important that the public know how it is spent. At least this guy isn't keeping the information to himself.
paulkerton Posted December 14, 2021 Posted December 14, 2021 I'm not trying to make up the law to suit me. Sorry, didn't mean to suggest you were! More that the law leaves these big gaps that people can take advantage of and we have to follow it, even if it is an a*s.
paulkerton Posted December 14, 2021 Posted December 14, 2021 If schools don't want to respond to requests like this then they should just stick details of all contracts over a certain threshold on their website and refer requesters to that page. We don't have to do that? I thought there were some requirements on this somewhere...
localzuk Posted December 14, 2021 Posted December 14, 2021 (edited) I'm not trying to make up the law to suit me. I'm suggesting if it vexes us, we should also follow the letter of the law and refuse vexatious requests - https://ico.org.uk/for-organisations/guide-to-freedom-of-information/refusing-a-request/#:~:text=PDF%20(229.08K)-,When%20can%20we%20refuse%20a%20request%20as%20vexatious%3F,can%20refuse%20to%20comply%20with%20a%20request%20that%20is%20vexatious.,-If%20so%2C%20you That link is pretty clear, receiving a single request asking for a set of simple information is not vexatious. As an extra bit - would it be valid for the school to reply but leave out the bit about the make etc for security reasons?? Not that I can see, no. Simply knowing what system you have is not a security threat. Everyone needs to remember that the law very much leans on the public interest side of things when determining exemptions for FoI. If you aren't sure, run it past your DPO. There are some exemptions that can only be decided on by a properly qualified person anyway. Edited December 14, 2021 by localzuk
paulkerton Posted December 14, 2021 Posted December 14, 2021 Not that I can see, no. Simply knowing what system you have is not a security threat. See, I kinda disagree with that. It's really dependent on what you've already disclosed. If you've already told people what your edge appliances, firewalls, your ISP, your AV solution, your wifi solution, what CCTV systems you have etc. are then eventually it can become a security threat. How you handle FOIs? Well, That's a whole different kettle of fish, but disclosing everything could easily present a security threat. Not that obfuscation should be your only security tool in your kit, but it should be a part of it.
enjay Posted December 14, 2021 Posted December 14, 2021 Simply knowing what system you have is not a security threat. It is if that system is an unpatched Papercut server... 2
enjay Posted December 14, 2021 Posted December 14, 2021 See, I kinda disagree with that. It's really dependent on what you've already disclosed. If you've already told people what your edge appliances, firewalls, your ISP, your AV solution, your wifi solution, what CCTV systems you have etc. are then eventually it can become a security threat Agreed. We have refused FOI requests about our CCTV system before. How many cameras do you have? Are all points of access covered by CCTV? Do the cameras include night vision? Do they include gait recognition? Answering those might have been all a burglar's Christmases at once.
enjay Posted December 14, 2021 Posted December 14, 2021 How do you define someone with a commercial interest? Journalists have a commercial interest as they are paid to investigate these things. Should journalists be banned from making FOI requests? Yeah, I see where you're coming from and quantifying it could be difficult, but I'm sure you agree a newspaper with a potential story of mismanaged public money is not the same as a sales company who don't want to pay cold-callers. Maybe we need to put up with these misuses of the FOIA to ensure the legitimate uses are still possible.
localzuk Posted December 14, 2021 Posted December 14, 2021 See, I kinda disagree with that. It's really dependent on what you've already disclosed. If you've already told people what your edge appliances, firewalls, your ISP, your AV solution, your wifi solution, what CCTV systems you have etc. are then eventually it can become a security threat. How you handle FOIs? Well, That's a whole different kettle of fish, but disclosing everything could easily present a security threat. Not that obfuscation should be your only security tool in your kit, but it should be a part of it. It is if that system is an unpatched Papercut server... The law makes certain exemptions and that's it. Knowing that you run Ricoh copiers is simply not a security risk. Knowing that you have a certain brand of firewall or cctv camera is not a security risk either. Security by obscurity is not security. This is very much why you should be running things past a properly qualified person when making these determinations. The law has very little wiggle room with this, and the public interest test matters. There is no general exemption for perceived security risks. 1
paulkerton Posted December 14, 2021 Posted December 14, 2021 (edited) The law makes certain exemptions and that's it. Knowing that you run Ricoh copiers is simply not a security risk. Knowing that you have a certain brand of firewall or cctv camera is not a security risk either. Security by obscurity is not security. This is very much why you should be running things past a properly qualified person when making these determinations. The law has very little wiggle room with this, and the public interest test matters. I agree that knowing your brands is not a security risk, but declaring specific models of copiers, firewalls and CCTV cameras IS however, I would argue a security risk. Especially in an education setting where upgrading these security risks isn't always seen by senior leaders as a priority. I agree that security by obscurity is not security - well security by obscurity ALONE is not security, but security by obscurity should be by design part of your process.... but neither is it security to tell everyone exactly where the potential weak spots are in your systems. Again, talk to your legal teams and DPO on this, but if there are specific reasons you believe that disclosure could prejudice the effective conduct of public affairs, then you do have mechanisms to reject it. It's up to your legal teams and DPO to help make that decision as to whether make and models could prejudice your day-to-day operations long term though. Edited December 14, 2021 by paulkerton
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now