Jump to content

Recommended Posts

Posted
I've been asked about a way to view what students are typing online which doesn't require any client-side installation. Does anyone know if such a thing exists? We have a student BYOD network, and there has been some inappropriate activity on it, so we'd like to see what we can put in place to prevent future occurrences.
Posted

seems a bit impossible and would capture passwords as well I assume. Only way I can think of is some kind of web based RDP service and keylogger running on that.

https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-web-client#what-youll-need-to-use-the-web-client

 

For us the Smoothwall reports which show browser activity before and after a notification event with search terms through https interception is about as close as you can get. Searching for guns, guns in ww2 makes it more obvious what was happening

Posted
seems a bit impossible and would capture passwords as well I assume.

 

Probably true about the passwords, but that is presumably also the case with client-based things like Smoothwall Managed Monitor.

 

For us the Smoothwall reports which show browser activity before and after a notification event with search terms through https interception is about as close as you can get.

 

Unfortunately that doesn't help in this instance as the entire class were legitimately on the website, one of them chose to use it in a silly way.

Posted
typing online is interesting, if you inspect all the traffic you'd get most of the way there, unless the website/app added a second layer of encryption above TLS in the client, like Whatsapp would
Posted
we use securus it works as being a proxy or gateway (transparent proxy) for our ipads it does requier a certificate on the devices. it takes effectivley screenshots when things are flagged. it creates a lot though

https://www.securus-software.com/

 

That might be a possibility, and would have picked this incident up. Is it on-premise or cloud? If cloud, can you turn it off on a schedule? Students are using personally-owned devices, so we need to make sure we're not monitoring them outside school.

Posted
we use securus it works as being a proxy or gateway (transparent proxy) for our ipads

 

Similarly, you could host a web-based proxy which you then force all pupils to go through. You would need to be able to authenticate pupils so you could identify who was typing the rude words.

Posted
Similarly, you could host a web-based proxy which you then force all pupils to go through. You would need to be able to authenticate pupils so you could identify who was typing the rude words.

 

That would work, we've got a captive portal on the Smoothwall already anyway, so nothing would change from the student viewpoint. Would that also negate the need to get SSL certificates onto all the devices?

Posted
That would work, we've got a captive portal on the Smoothwall already anyway, so nothing would change from the student viewpoint. Would that also negate the need to get SSL certificates onto all the devices?

 

The way I'm thinking of it would - pupils would basically be typing any URLs / search terms into your own-hosted web proxy, for which you have control over. I'd have vaugly thought that would be how the Smoothwall captive portal handles things, though - sorry, we use client-based filtering for pupil ChromeOS devices so I'm not familier with the latest options available for other methods.

Posted

Custom web proxy or wireless packet sniffing seems the only way to do this, but it does sound like weeks of engineering time.

Cost it up, add in some third party developer time (say 2 engineers on £500 per day for 6 weeks). Pass it on to SLT and call it a day.

Posted
I've been asked about a way to view what students are typing online which doesn't require any client-side installation. Does anyone know if such a thing exists? We have a student BYOD network, and there has been some inappropriate activity on it, so we'd like to see what we can put in place to prevent future occurrences.

 

I'd echo what others have said as it feels like you're being asked to do the impossible unfortunately. Every OS/device/app these days is geared to allow devices to connect securely to WiFi networks and specfically prevent exactly what you're wanting to do (ie monitor/control communications between their devices and remote servers)!

 

Plus, morals aside, surely the school would be on dubious ground leagally if they're trying to gain access to decrypt/monitor pupil's personal devices and communications on them?

Posted
I think you've got to ask yourself is this a misue of the schools power to put key logging software on pupil owned devices is a step too far in my moral compass.

 

The keylogging wouldn't be on the pupil-owned devices, it would be on our Internet connection which is provided for educational purposes. If a student uses the Internet in a way which constitutes a safeguarding concern or bullying incident which we can then act on, I don't think that's over-reaching.

Posted
log all urls and post data along with username on your proxy, grep it for the bad words, find your culprit, why would that take weeks?
Posted

Not full coverage, but if you have a product like Lightspeed Alert that can plug into your O365 environment, you can monitor communications on that platform regardless of if the device is managed or BYOD, and without the need for any client side installation. Obviously, this would need to be explicitly stated in the AUP and other communications outside of the O365 environment would be unmonitored.

 

Really, if more oversight than this is needed then BYOD is not the correct solution in the first place, something like a parental contribution devices may be better, where the devices are monitored 24/7, but with the potential of varying levels of filtering inside and outside of school.

Posted (edited)
there has been some inappropriate activity on it, so we'd like to see what we can put in place to prevent future occurrences.

 

Without going into specifics are you able to elaborate on the innapropriate actvity (Email, Social Media, chat apps, etc?) as it might help with providing a solution?

Edited by flyinghaggis
Posted
Tell them its not feasible to do what they are asking.

I'd never say it's not feasible, it's not really IT's place to determine that.

Just call out how much it will cost and let them make the decision.

Posted
Without going into specifics are you able to elaborate on the innapropriate actvity (Email, Social Media, chat apps, etc?) as it might help with providing a solution?

 

The particular incident which brought this to the forefront was a highly offensive username in a Kahoot quiz or similar, but it sits amidst a rising trend of using various platforms to make anonymous libellous, reputation-damaging comments about our staff.

Posted
anonymous

 

I see a quick win there. Block sites that allow anonymous posting. Surely theres a safeguarding issue with allowing this?

Posted

Either you force CA cert install, or you don't allow BYOD, kids can't be trusted otherwise.

 

Even that will break a lot of apps, but too bad for the kids

Posted
I see a quick win there. Block sites that allow anonymous posting. Surely theres a safeguarding issue with allowing this?

 

Telling staff not to use Kahoot or Blooket doesn't feel like the right response.

Posted (edited)

Really, if more oversight than this is needed then BYOD is not the correct solution in the first place, something like a parental contribution devices may be better, where the devices are monitored 24/7, but with the potential of varying levels of filtering inside and outside of school.

 

I'll appreciate it's not what the OP wants to hear but my feeling is that most schools will ultimately move away from BYOD for pupils in favour of school-issued and managed devices. We're already seeing most schools starting to ban pupils using mobiles phones and I think this will ultimately extend to personal laptops/tablets/etc.

 

Primarily due to the fact that it's impossible to adequately monitor pupils for safeguarding purposes without installing software/apps/management on their personally owned devices which is an absolute minefield.

Edited by flyinghaggis
  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...