Jump to content

Recommended Posts

Posted

First off, we have never had smooth sailing with Inventry so maybe this is skewing my opinion...

 

We have Inventry lesson scans which had a small problem one afternoon so we logged a call. The engineer came back and said "A Windows update must have turned the firewall back on"....

 

I logged a call a few days back asking for clarification, thinking I got the wrong end of the stick however (2-3 days later) someone checked and confirmed it was indeed turned to off. I have written back immediately asking them to turn it back on, given it holds personal data and sits on the network.

 

Am I being odd here? Is this normal? Am I being paranoid?

 

They don't seem to give a **** about security, given its a random Windows box and guessing we all have the same password.

 

Thoughts?

Posted
I agree. It took a fair bit of whinging for me to get them to change the default passwords, likewise for us to add them to our domain and install Sophos AV to ensure they comply with basic security standards. Oh, and get them to remote in to clear up enough space for windows update to work, because frankly the 64gb storage they have is just daft even on win 10 LTSC. It is indeed very lax, and I'd be happy to see the back of it.
  • Like 1
Posted
Thoughts?

It's pretty shoddy for a vendor to not know what ports their application uses and to not bother configuring the firewall rules.

 

On the other hand, I don't expect applications to be responsible for server configuration - that's usually the system administrators role.

It seems unclear who is responsible for the system - you as the sysadmin or inventry as the vendor?

Posted
It's pretty shoddy for a vendor to not know what ports their application uses and to not bother configuring the firewall rules.

 

On the other hand, I don't expect applications to be responsible for server configuration - that's usually the system administrator's role.

It seems unclear who is responsible for the system - you as the sysadmin or inventry as the vendor?

 

They have full management and responsibility of the Invertry hardware and we pay an annual maintenance plan.

 

They just came back to me to say they turned the firewall on as per customer request...... as if its not standard practice. This box holds an awful lot of student and staff data and they seem to make it up as they go!

Posted

Email your DPO with a concice list of the many areas is it not compiant with gdpr and safeguarding etc. Reccomend they remove the system as it's a databreech waiting to happen.

 

Leave it to DPO and SLT as it's their remit to lose sleep over it, not yours!

  • Thanks 1
Posted

I literally just noticed a couple of days ago that defender was turned off at one site, and upon checking the others it was also the case.

 

Turning it back on broke various things so I feel it was turned off for convenience on their part but it clearly needs to be on. I opened a ticket with them asking for the required exceptions to be applied but so far have had no response.

 

I wonder how many other schools have theirs turned off?

 

I feel like Inventry is the SIMS of the sign in systems.

Posted
I think I mentioned before, but if the pin is still XXXX (the worst PIN code in history) and the system password is the name of the product and a date circa 40 years ago then someone needs to have serious words with them.
  • Thanks 1
Posted (edited)

Posted about this sort of thing this morning in another thread.

 

It's simply poor that these sorts of things are still happening in 2024. Default passwords that we all seem to know, Firewall Profile off totally, Concerning RegKeys, Defender real time protection disabled.

 

Windows update also not working as it had run out of space.

 

If schools are paying for this hardware to be maintained, then they need some pro-active monitoring. RMM should be alerting them that the disk is nearly full, or that Windows updates aren't working.

 

https://www.edugeek.net/forums/security/236920-inventry-vulnerability.html

Edited by Aprice
Posted
I think I mentioned before, but if the pin is still XXXX (the worst PIN code in history)

 

"The U.K. is the first country to ban default passwords on smart devices starting April 29, 2024"

 

They changed all PINs about 3 months ago, presumably for this reason.

Posted (edited)

Easy check, see if you can browse the admin share from the local account, usually inv-pc-xxxx\administrator and the daft password :)

 

It's also worth being sure noone is over-reacting - it's good people are taking security this seriously, even when some people who should know better, don't. Just because something has always been a certain way, doesn't mean it should continue being so.

Edited by synaesthesia
Posted (edited)
Inventry are not the best and I have struggled with such changes too. Normally have had to do it myself as they can be unreliable and do not take security into account. Edited by RichFix
Posted
Have you thought about implementing additional security measures, such as regular audits or third-party security assessments, to ensure your systems are adequately protected?
Posted
Have you thought about implementing additional security measures, such as regular audits or third-party security assessments, to ensure your systems are adequately protected?

 

We had an audit from secure schools which somehow didn't flag it up.

Posted
It's as if paying a random company for a security audit just means they run an automatic scanner on the network and email you the results, £1000 for 5 mins work
  • Thanks 1
Posted

The scary thing about this is that there has recently been a ransomware attack as a result of Inventry and their lax approach to setup. They have changed the default passwords on the machine but said it’s the customers responsibility to ensure its secured with antivirus etc!

 

I tried to join one to our domain years ago and it never worked properly so hesitant to do so again! Will definitely be moving away to another solution as soon as our contract is up. Sadly we are only 18 months into a 5 year

  • Thanks 1
Posted (edited)
The scary thing about this is that there has recently been a ransomware attack as a result of Inventry and their lax approach to setup. They have changed the default passwords on the machine but said it’s the customers responsibility to ensure its secured with antivirus etc!

 

I tried to join one to our domain years ago and it never worked properly so hesitant to do so again! Will definitely be moving away to another solution as soon as our contract is up. Sadly we are only 18 months into a 5 year ��

 

 

 

 

Do you have the link or article for that ransomware attack at all?

 

 

Inventry get paid a support fee for THEIR equipment THEY provide for THEM to maintain it. Not the MSP on any onsite IT. To say otherwise is just a cop-out from them, what a surprise.

 

Thing is - their GUI is actually pretty good and easy to use.

 

Just a mighty shame about the rest of their system/platform lets it down.

Edited by DrBeaker
Posted

Inventry get paid a support fee for THEIR equipment THEY provide for THEM to maintain it. Not the MSP on any onsite IT. To say otherwise is just a cop-out from them, what a surprise.

.

 

Glad I went with Entrysign now - their techs are really good anything we've needed they remote in and sort it there and then no nonsense.

Posted
Glad I went with Entrysign now - their techs are really good anything we've needed they remote in and sort it there and then no nonsense.

 

I don't suppose Entrysign have the ability to write back lesson attendance to a MIS does it? The lesson scan is literally the only reason we have Inventry (moved from Sign-in which was great).

 

Thanks

Posted
I don't suppose Entrysign have the ability to write back lesson attendance to a MIS does it? The lesson scan is literally the only reason we have Inventry (moved from Sign-in which was great).

 

Thanks

 

Not sure mate we use Classcharts for lesson attendance just wanted it for the guest/contractor etc signing in and out.

Posted
The scary thing about this is that there has recently been a ransomware attack as a result of Inventry and their lax approach to setup. They have changed the default passwords on the machine but said it’s the customers responsibility to ensure its secured with antivirus etc!

 

I tried to join one to our domain years ago and it never worked properly so hesitant to do so again! Will definitely be moving away to another solution as soon as our contract is up. Sadly we are only 18 months into a 5 year ��

 

I'm going to raise a call with them to clarify. They have never mentioned us having to secure the box and can't find anything on their KB about it. Personally, I'd love to put Action 1 on it and see what happens.

Posted (edited)

We have Entrysign here too and it works fine, their techs basically set it up and secured it, I had very limited involvement with it other than providing network ports. It runs totally separate to our network and has no access to it - unfortunately it means it does not integrate with SIMS or our door fob system in any way which is a shame.

 

So you have to use your fob to enter the doors, then sign in using the Entrysign system, then if you are a pupil get registered with SIMS.

 

But like PotNoodle we primarily use the Entrysign system for staff and guests/contractors anyway - and as doors are usually propped open during the rush periods you can't rely on door fob scans to keep track of who is on site anyway as most people will just walk in if the door is already open due to the morning rush.

 

In an ideal world it would all link into SIMS or the door system but tbh with the Inventry vulnerability, (and the papercut one a while ago), for me the least amount of systems especially web enabled systems attached to our domain the better, so I am happy with how it works - I don't do anything with it really anyway which is how I likes it. They set up the OS, it is totally separated from our domain, on a separate VLAN

Edited by mikes
Posted
We have had issues with Inventry Quick scanners for over a year since they were upgraded, only now to be told that when they stop scanning daily with no barcode light, it is a known problem and a software fix is being worked on. I must say it has been frustrating to get Inventry software to work whether its writing back late students to MIS which also often requires a service restart or just ensuring that staff and students can sign in and out without the hardware failing regularly. Their helpdesk ticket system isn't great and better to just phone them for quick support.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...