Jump to content

Recommended Posts

Posted

Never been particularly happy with Inventry's idea of security.

 

As well as having a unique PIN, ours is isolated using ACLs on the core switch. The head unit is domain joined and has a bespoke firewall policy enforced along with AV and Windows Update settings. We use IPSec to restrict access to the shares to a group of users. AppLocker rules ensure that our users can only run exe's that were signed by inventry ltd. Access to the device's power and data ports are behind lock and key.

 

We've not noticed a problem with the barcode reader, but we use proximity cards for staff and students, and guests tend to use the GUI on the head unit to sign out.

Posted

Hey

 

Depending on which version of lesson scan your site has, means the ports are different, if its the older lesson scan "Mk500" its ports 43001,43002,43010, if its the newer lesson scan "CC600" (Looks like a little android phone and runs on it too) then its port 4816, hope that helps somewhat.

 

-Tech

  • Thanks 1
Posted
The scary thing about this is that there has recently been a ransomware attack as a result of Inventry and their lax approach to setup. They have changed the default passwords on the machine but said it’s the customers responsibility to ensure its secured with antivirus etc!

 

I tried to join one to our domain years ago and it never worked properly so hesitant to do so again! Will definitely be moving away to another solution as soon as our contract is up. Sadly we are only 18 months into a 5 year ��

 

It can be done; I've done it a both the schools I've had it. I just put them in their own OU to allow me to allocate GP needed. The user is a kiosk user set up away from the regular users as well.

 

Thing is - their GUI is actually pretty good and easy to use.

 

It is? You are possibly the only person I have ever seen say that! :)

Posted
if its the newer lesson scan "CC600" (Looks like a little android phone and runs on it too) then its port 4816, hope that helps somewhat.

 

Ah - we've just signed up for an InVentry system, to be installed over the summer. I'm guessing we'll be receiving one of those CC600 units. Does it come with Windows Firewall enabled, or do we need to enable it and add the exception for port 4816 ourselves?

 

We'll probably be installing our management client (Action1) and endpoint/antivirus protection (WithSecure) clients on the device, has anyone had any issues with those that you know of?

 

Does the device come with well-known default passwords/PINs set? Are they simple enough to change?

 

Does the device take care of backing up to an off-site facility, or should we install our own backup client (Veeam) on the device?

 

What version of LTSC IoT Enterprise Win 10 does the InVentry device use? I understand some previous versions were using the 2015 version, which will be out of update support next year, I'd guess newer hardware might be using something newer?

Posted (edited)

They don't seem to give a **** about security, given its a random Windows box and guessing we all have the same password.

No you're not over reacting, but are you entirely surprised considering the general malaise of care when it comes to security and edtech? Let alone Microsoft's general attitude to it too! (Plain text OCR screenshots for everyone!!)

Edited by paulkerton
Posted
No you're not over reacting, but are you entirely surprised considering the general malaise of care when it comes to security and edtech? Let alone Microsoft's general attitude to it too! (Plain text OCR screenshots for everyone!!)

 

Thankfully that got canned quicker than Peckham Spring Water.

Posted (edited)
Ah - we've just signed up for an InVentry system, to be installed over the summer. I'm guessing we'll be receiving one of those CC600 units. Does it come with Windows Firewall enabled, or do we need to enable it and add the exception for port 4816 ourselves?

 

We'll probably be installing our management client (Action1) and endpoint/antivirus protection (WithSecure) clients on the device, has anyone had any issues with those that you know of?

 

Does the device come with well-known default passwords/PINs set? Are they simple enough to change?

 

Does the device take care of backing up to an off-site facility, or should we install our own backup client (Veeam) on the device?

 

What version of LTSC IoT Enterprise Win 10 does the InVentry device use? I understand some previous versions were using the 2015 version, which will be out of update support next year, I'd guess newer hardware might be using something newer?

 

 

It'll be a CC600 then, yes the main system should have the firewall enabled with port rules already in place, so only thing you may need to change is all 4816 communication on your network, as this is used for most of the system (4816 being the InVentry API port)

Can't say I've heard any issues with this so you should be good to go, on that front.

 

 

The passwords out of the box are default ones, but these can be changed providing you let the install engineer know or the support team, as only a few things need amending to change this (Services and login details mostly)

 

It can backup remotely as it's just a SQL backup so as long as it can reach the destination it'll backup to, I know some sites do this to a onedrive, or Google Drive location, as long as Veeam has a location it can backup to that should work, depending on your site you may also get "Cloud" which sends up information so in a catastrophic failure, it can re-parity this data back into your system, it's not everything at the moment but currently does Visitor/Staff/Pupil events and records, so if you have a major issue this can repopulate a lot of the system with this.

 

 

Windows 10 IoT Enterprise LTSC 2021

 

-Tech

Edited by InVentryTechnican
  • Thanks 2
Posted
...yes the main system should have the firewall enabled with port rules already in place...

 

In a problem common across many different platform providers (and not unique to Inventry), just because those at head office have sat down and designed the correct firewall rules think it is so, the field engineers/first line teams often add allow/any/any rules because they don't trust/understand Windows or the app.

 

To re-iterate not just an inventry problem. I find it depressingly illuminating to periodically check the firewalls for unexpected deviations from the standard. (I've got BMS, Access Control, CCTV, Cashless Catering systems that all have gained these rules from time to time).

Posted
It'll be a CC600 then, yes the main system should have the firewall enabled with port rules already in place, ... Windows 10 IoT Enterprise LTSC 2021

 

Thankyou for the comprehensive reply. That does all sound reasonable enough - it sounds like we need to make sure our installer / reseller sorts out changing default passwords/PINS, and we might need to add a backup client, but all sensible enough. From the comments on this and a couple of other threads it sounds like maybe older versions of your hardware are maybe a bit under-resourced, but the new version sounds okay. I'll try and aim to reply back to this thread when we get the system installed and let people know how we get on.

Posted
We have LTSB at one site, I've asked them what's the plan is on this and it looks like there will be a charge to 'upgrade'.

 

I was a bit narked off that the equipment we bought... last year was using a CPU that's not Windows 10 compatible. They assured me that as it's running the IoT version of Windows 10 it will still get security updates for a lot longer (which is true), but it's not good that they are still pushing out equipment that can't be upgraded.

Posted
A private VLAN (ie no computer to computer interaction) for all the 3rd party managed devices is probably best practise

 

Problem being that Inventry runs an executable on client devices using a mapped drive. In an ideal world I'd isolate it completely, however that's not possible.

 

Also annoyed that the setup instructions we've been given instruct us to set registry keys on our client devices to insecure settings.

 

The product hasn't been designed with security really considered.

Posted

Yeah - It does feel like a solution that was originally designed in 2008 ish hasn't really moved with the times. Don't get me wrong, it's a great system but it's starting to feel a bit long in the tooth & a bit of a mess security wise -

 

MSSQLDB running on a local machine? Yuck.

Needing local backup? Yuck.

No auto patching & out of date OS out of the box? Yuck.

Sell knowingly obsolete hardware? Yuck.

Trust management needing routes between schools? Yuck. (Just do it over the cloud!)

Posted
I was a bit narked off that the equipment we bought... last year was using a CPU that's not Windows 10 compatible. They assured me that as it's running the IoT version of Windows 10 it will still get security updates for a lot longer (which is true), but it's not good that they are still pushing out equipment that can't be upgraded.

 

I assume you mean Windows 11, not 10?

 

We got ours last year too. Imagine my surprise when I also discovered probably the same non-supported CPU - a Celeron J3455, couldn't believe it when I saw it. I'm thinking InVentry bulk bought many hundreds of these devices with this CPU and are fully intent to using them up rather than writing them off.

 

I imagine it to be the same scenario with the Geobooks and why so many of their devices have the pretty naff Celeron N4020 CPU!

Posted
A private VLAN (ie no computer to computer interaction) for all the 3rd party managed devices is probably best practise

 

We do this for all endpoint devices as well.

Posted (edited)
I was a bit narked off that the equipment we bought... last year was using a CPU that's not Windows 11 compatible. They assured me that as it's running the IoT version of Windows 10 it will still get security updates for a lot longer (which is true), but it's not good that they are still pushing out equipment that can't be upgraded.

 

Windows 10 IoT LTSB will probably be getting security updates for longer that the embedded Android devices they and others sell, and at least with a full-fat Windows OS you can bring the management and monitoring/compliance in house.

Edited by psydii
Posted
You could, except then all their software would fail because things like firewalls and enabling exploit protection would break their crappy visual basic app written in 1993 by an intern
Posted

It did take me about a day to nail it down, but it can be done.

 

*I'd been poking around for a few months to come up with a vague plan - so perhaps three days would be a more honest estimate if you're coming at it cold with no prior experience of how the system works.

Posted
Problem being that Inventry runs an executable on client devices using a mapped drive. In an ideal world I'd isolate it completely, however that's not possible.

 

Also annoyed that the setup instructions we've been given instruct us to set registry keys on our client devices to insecure settings.

 

The product hasn't been designed with security really considered.

 

Rather than expose our computers and set them to allow insecure devices I just gave those that needed it the password to the inventry box, when they open the shortcut it prompts for username and password and they just plonk the details in there. Ticking remember credentials means its once in a blue moon they are asked for it. The fact that they now have an admin password for about 99% of inventry systems isnt my concern...

Posted
Problem being that Inventry runs an executable on client devices using a mapped drive. In an ideal world I'd isolate it completely, however that's not possible.

 

Also annoyed that the setup instructions we've been given instruct us to set registry keys on our client devices to insecure settings.

 

The product hasn't been designed with security really considered.

 

Is there no way to run the Inventry client locally and then point it to the database? There must be, surely?!

Posted
Problem being that Inventry runs an executable on client devices using a mapped drive. In an ideal world I'd isolate it completely, however that's not possible.

 

Also annoyed that the setup instructions we've been given instruct us to set registry keys on our client devices to insecure settings.

 

The product hasn't been designed with security really considered.

 

 

The registry keys are used in the event you want to be able to UNC path to the share location, ideally you'd map the drive with the admin credentials, or to completely work around the UNC pathing issue, domain join the system but, I would speak with support prior as ideally we'd want the system, put in an OU with no policy inheritance as you may strip local admin rights but doing so would completely bypass the need for the keys changing.

 

-Tech

Posted
Is there no way to run the Inventry client locally and then point it to the database? There must be, surely?!

It is possible but it wasn't officially supported at least it wasn't when we did it a few back before we moved away from InVentry. One of my team setup a VM for the database then pointed the 5 local clients to the VM. I wasn't directly involved so cannot go into details though I remember it went against the instructions from InVentry. Seemed like a better way to do it to me and it payed off when one of the local clients died.

Posted
Is there no way to run the Inventry client locally and then point it to the database? There must be, surely?!

 

 

You can do this, providing you periodically copy the console files from the InVentry touchscreen across to the location, an xcopy would be a good way of doing this, you'd want to do this as periodically, when we push an update to the console files, the touchscreen will be updated but the local ones you're running aren't, so some bits may not show as expected, we certainly have sites doing things such as this, a way to get around this could be simply adding a console onto a VM/File server all staff have access to and then copying then having a task set to copy the files across each night.

 

-Xcopy info:

https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/xcopy

 

-Tech

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...