Jump to content

Recommended Posts

Posted

Dear all

 

I am looking to hear from other schools that have decided to install the Police Cyber Alarm virtual Appliance in the schools they manage. I decided long ago having read the posts about the security concerns in regards to using the virtual appliance that I would have to install it in order to ensure we are FULLY compliant as I personally would not want to be held responsible in the event we needed to make a claim on our RPA insurance policy. The truth of the matter is that it is very unclear what they would require as evidence of compliance in the event we needed to put in an insurance claim of any sort. Anyways, we have had constant issue with the appliance since we installed in about a year ago and have been in contact with PCYB support a number of times as we kept having issues where we were unable to login to the console frequently with an error "Malicious activity detected" and support could only suggest a rebuild of the server each time. I have now finally pinned down this particular issue to the server having a dynamic MAC address in Hyper-V so the resolution was simply to set it to static MAC however the other issue we have had a number of times now and have still not resolved is that once logged in all the details we inputted into it are greyed out and removed. Can anyone shed any light on this?

 

I really do hate this software with a passion...

Posted

I have followed and support Paul's stance since the start, and the reply above is correct that for RPA you only need to register, not install it.

 

However I've recently attended an ANME meeting where one of the schools was hit and lost the majority of their network including backups to encryption. (Very little data actually exfiltrated, from memory).

 

The issue started on Friday night, the police noticed it on CyberAlarm and immediately tried to contact the school. They couldn't get hold of anyone until they eventually contacted ISP at midnight and had their internet connection switched off; school didn't know anything until Monday morning.

 

On the back of this i've made the decision to activate CyberAlarm and ensure 24/7 contact details for myself and my senior tech are available to the police on the other end of it.

Posted

Hi there

 

I still feel it is a grey area what registering actually constitutes in the event you needed to submit a claim to RPA. If it wasn't for this I myself would have removed it long ago...

Posted
Register with Police Cyber AlarmThe base requirement for this control is just to register with the police “Cyber Alarm” service. It should be noted that this does not require the full installation of their data collection tool on your network unless you are fully comfortable with the security and data protection implications of that additional step.

https://partnership.education/rpa-cyber-security-insurance/

 

This is what we followed, didn't install it

Posted

we have it in writing from RPA / DFE that only registration to the website is required and the virtual appliance is not required.

 

Do not use cyber alarm, if your running it, shut it down asap.

  • Thanks 1
Posted

Hi AAC

 

There are only two locations in CyberAlarm where "Malicious activity detected" is thrown. Rebuilding the server isn't a solution... but without the code, they won't know why it's happening.

 

ca1.png

 

and...

 

ca2.png

 

If it's being thrown at 165, it's because the token (a CSRF token they added after one of my disclosures) isn't valid or present. If it's thrown at 665, it's the same reason... but related to the creation of logs.

 

For both situations, it's a sessions issue. Either the session cookie is expiring/being removed before the session has ended or it's not being created properly.

 

You could check your session.save_path INI setting to make sure it's able to write the session data to storage. If it can't, $_SESSION['token'] won't exist and it'll crash with that error. It could also be an FQDN issue... are you loading the console via IP or have you mapped a domain/subdomain to it? The session cookie will be tied to the FQDN and won't be valid if (when) CA tries to load over a different IP/FQDN.

 

In any event, as others have said, it's not worth running anyway. It's of no appreciable benefit; it's poorly written/insecure and only adds risk where it's not necessary.

Posted
Thankyou for your reply, as I mentioned above I tied this particular issue down to it having a dynamic MAC address in the end. I have noticed that there are always issues with Linux virtual machines in hyper-v when using dynamic MAC addresses. I recall we used to have an Aerohive controller that was Linux based that would not boot correctly if the MAC address changed...
Posted
we have it in writing from RPA / DFE that only registration to the website is required and the virtual appliance is not required.

 

Do not use cyber alarm, if your running it, shut it down asap.

 

Yarp - Turn this trash off & ignore anything they say about it being required - It's absolutely not and it's a trainwreck of a piece of software.

Posted
What's the point in registering thought?

 

because you provide external ips / domains etc they do checks their end to my knowledge, very similar to NCSC early warning service

Posted
It is very amusing how NCSC don't say anything about Cyberalarm

 

Probably because they know it's a security ****show but don't want the political headache of calling it out (As they'd probably end up having to take it on!)

Posted

NCSC have taken the (understandable) stance of saying nothing & not tried to step on anyone's toes; presumably hoping it'll fail and go away quietly before proverbial hits the fan.

 

Behind the scenes, it's a different matter. Many a giggle has been had ;)

Posted

Unfortunately one of our schools was instructed by their trust to install, we strongly advised against but ultimately had to install it.

 

Have to say it's pretty rubbish, even ignoring the 'possible' security risks. Its just a syslog server with a 90's web interface, noticed that my session was still logged in from the last time I connected several months ago!

 

It hasn't uncovered anything ground-breaking as of yet, just that the firewall is blocking ports.

Posted

I installed it and don't have a problem. I'll get rid of it when Cent 7 reaches EOL though. I read through the hysteria about it along with the retort from PCA which addressed the concerns. I'm guessing the same folks who are angry about it are the same ones who hold off updating Windows every time a new one comes out because they are cross about something.

 

No, it never really found anything important and often I wonder if it's even working but it was easy enough to set up and manage, they sent update instructions when needed, support is active and it sits on the edge, doing its thing and keeping the insurance happy.

 

Install it or don't but don't let the tin hat dinosaurs make your decision for you.

Posted
That seems unnecessarily disrespectful @robjduk and makes me wonder why...

 

NPCC has never addressed any concerns; they've refuted them from day one and continue to do so.

I was about to comment something along the same lines, without any 'wondering' beyond that statement. However, I think we need @robjduk address the matter of the security issues highlighted. I know from the second post in this thread from @mavhc, he has strong views on those that suggest installing the software.

  • Thanks 1
Posted

The entire point is they did not address the concerns, they didn't even understand the concerns.

 

Imagine a different police officer, standing on the street, and you walk up to them and explain there's someone around the corner setting fire to a building. But the police officer is actually a small white cat wearing a cute police helmet.

 

The understanding of the cat to your concerns, and the software authors to the concerns raised is of a similar level.

  • Thanks 4
Posted
I installed it and don't have a problem. I'll get rid of it when Cent 7 reaches EOL though. I read through the hysteria about it along with the retort from PCA which addressed the concerns. I'm guessing the same folks who are angry about it are the same ones who hold off updating Windows every time a new one comes out because they are cross about something.

 

No, it never really found anything important and often I wonder if it's even working but it was easy enough to set up and manage, they sent update instructions when needed, support is active and it sits on the edge, doing its thing and keeping the insurance happy.

 

Install it or don't but don't let the tin hat dinosaurs make your decision for you.

 

lol what. I allow Windows updates go out the day they are released. I push new versions of Windows out not long after RTM, heck we run the beta's on our work machines for months before hand.

 

I would never install the police cyber alarm. Calling us "Tin Hat Dinosaurs" for not wanting to install a security nightmare is one of the stupidest things I've read on this forum.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...