Jump to content

Recommended Posts

Posted

We need to allow the safeguarding lead to temporarily but regularly unfilter the Internet to investigate the filter alerts they receive.

 

I created an 'Administrator Bypass' block page and a user account for them on Smoothwall. They are presented with a 1 minute/5 minute/30 minute bypass option when they hit a filtered page, but it only seems to unfilter that single web page. Source images etc do not display. we really need a completely unfiltered browsing session for that time period.

 

Any ideas how we can do this?

 

(It is also worth noting that the Smoothwall authentication script runs continually in the background so giving them a different Smoothwall user account (username - 'JOHSMI_Unfilter' or something) to log in with may not be an easy fix as they will be logged into Windows as their usual staff account and the script will be authenticating them as that user.)

Posted
Don't. Period. Your DSL needs to pay more attention to their training. If they need to do it, do it outside of a school or use tools available to investigate context. Just because they are the DSL does not make them above the rules.
  • Thanks 1
Posted (edited)

I’ve come across a question like this in the past and I have had the dsl get headteacher written permission.

So how I have done it in one of my schools is the dsl is unfiltered however audited. Her web logs are published to trustees. Whether they read them is their decision. She knows and has agreed to on the ground to safeguard her.

 

It not as if they have access to the dark web or anything but they are aloud to areas that normally found in the core block. With certain exceptions example things that would harm the network malware sites etc

 

With the auditing I feel more at ease as I have a checker checking the checker.

 

My feelings for this were split but having a headteacher written permission helps.

 

At the end of the day the dsl has to be trusted like we are to not abuse the power we have and remain professional.

 

I’m not saying my way is the right way as there is no written guidance I know of from professional bodies on the requirements of a dsl and how we should facilitate their job but I am open to other suggestions and ideas if anyone else is willing to share

Edited by dapaulio
Posted

Some have begun using the quota action for DSL users. Create a group for the DSL users and then create a policy for them towards the top of the policy list with the action 'Limit to quota'. Set the categories you allow them to override blocks on in the what column.

 

If a DSL goes to a site in one of those categories, they will see a block page with button to override the block for a certain time (set in the quota definition). This gives them the block info and a stop before they decide if they really want to continue.

 

Obviously only add categories you feel are OK for them to see - not categories like malware etc.

  • Thanks 2
Posted

I'm not exactly following my own suggested guidance "yet", but there should not be too many things to check where it involves visiting a blocked url that would not normally be available to staff.

 

The most important thing is to know the route.

 

We can't know what has been blocked by "safesearch" (applied to everyone), by definition, so nothing to investigate.

 

If an item is blocked but the search engine's "safesearch" said yes, but the filter said no, then if the search argument is reasonable/sensible/not a typo, then there is nothing to investigate. Nobody can be accountable for what a search engine decides to return. The system worked as intended.

 

I had a pupil search for "high". That returned some items blocked "marijuana" from urls that didn't need to be checked to know what they were, as well as reasonable results. The search was random, not repeated by any other pupils or seemingly relevant to the lesson. That generated a safeguarding alert, but still no reason to bypass the filter as the investigation would be around the context of the search argument.

 

The main time there needs to be an investigation of a url is if a user gets a blocked request after a deliberate click on a url where the referrer is not a search engine. Then it would need to be validated before proceeding.

 

I work from home so do these.

 

Our filters’ Porn blocks have been 100% false positive, but that relies on a lot of heavy lifting from “safesearch” as our ISP whitelists all Google Image search thumbnails, even from categories that we have blocked!

Posted
Some have begun using the quota action for DSL users. Create a group for the DSL users and then create a policy for them towards the top of the policy list with the action 'Limit to quota'. Set the categories you allow them to override blocks on in the what column.

 

If a DSL goes to a site in one of those categories, they will see a block page with button to override the block for a certain time (set in the quota definition). This gives them the block info and a stop before they decide if they really want to continue.

 

Obviously only add categories you feel are OK for them to see - not categories like malware etc.

 

 

Thanks, I am testing this now, I have setup the quota and created a filter policy with an action to apply to the quota, but the user is still seeing our default block page, do I need to set up something else?

Posted
Thanks, I am testing this now, I have setup the quota and created a filter policy with an action to apply to the quota, but the user is still seeing our default block page, do I need to set up something else?

 

Is the quota policy above the block policy? Did you create a special group or just use the username and the default quota?

Posted
I have this working now. I created a 'Bypass allowed staff' group and created a policy with quota above pretty much everything else.
  • Thanks 1
Posted
I still think you need to raise this with your SLT - all the training I've seen and received specifically says that you shouldn't provide unfiltered access to *anyone* in a school, regardless of who they are and the context. You can mitigate it a little by having them log why and what they've searched for (which you should anyway) but even the DSL and Head are at risk of complications that may arise through this.
Posted
But does the above solution not satisfy that? The DSL will hit the filter, and have it logged, and then use their special powers to access the content, also logged. Their special powers will only work on the categories allowed, so it isn't like they will be able to look at all manner of nasties.
Posted
To a point yes - any DSL worth their salt would be pumping the brakes regardless even if it's for their own protection. Anything properly serious would be above and beyond their remit, and if they need involvement then they'll be able to do so with the proper authorities with them.
  • Thanks 1
Posted
[emoji[emoji6[emoji640][emoji638]][emoji640][emoji6[emoji640][emoji638]]][emoji6[emoji640][emoji637]][emoji638][emoji638][emoji[emoji6[emoji640][emoji638]][emoji640][emoji6[emoji640][emoji638]]][emoji639]]Is the quota policy above the block policy? Did you create a special group or just use the username and the default quota?

 

I like the quota idea as my solution lacks she doesn’t actually know she straying in to uncharted territory.

So giving a soft block or quota will inform her of the boundaries she is about to cross.

 

The decision then is in her court

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...