Jump to content

Recommended Posts

Posted

Hello folks.

 

I'm after some advice really.

 

Our head of ICT wants students to be able to encrypt files and folders on the school network. I think this is a **very** bad idea, as I absolutely don't want 'little Jonny' to be able to stash away his dodgy file collection on my servers.

 

At the moment I've said a big NO to this, that I (Network Manager) need to be able to access all the files on the network, i.e. have copies of any passwords or keys or be able to gain access. But he seems to think that they will fail their course without showing evidence of this.

 

How have others managed to deal with this thorny problem?

 

Advice gratefully received.

 

Ta.

Posted

Not a lot of help But I'm with you on this one!

 

So little Johnny stores his MP3, doggy JPG's etc in an encrypted file that nobody can access eh?

Absolutly not!

 

Steve

Posted
But he seems to think that they will fail their course without showing evidence of this.

How about having a standalone machine which they can use for this purpose?

Posted

I would ask to see where it says that they have to encrypt files, he may have just misunderstood what has been asked of him!

 

I personally cannot see how they can request files and folders be encrypted, what type of encryption method should be used, how do you prove the file is indeed encrypted, where is the evidence.

 

It's non workable

Posted
Umm, if they use the built in Windows EFS encryption and you have your domain setup right then the Administrator account or another account that you specify has rights to decrypt any encrypted files created by EFS as this account is also given an encryption key. This should satisfy their course requirements as they are using encryption of the same kind that would be used in an enterprise setting. It also follows the same rules as an enterprise setting where the administrator has the power to override the lockouts if it is nessisary for the best interests of the company, ie employee leaves, legal stuff etc.
  • Thanks 1
Posted
Isn't this more a case of they need to make a presentation / publisher document where they show (screen-shotted) the process of them encrypting a file for their coursework, rather than actually needing to encrypt something?
Posted

Thanks for the replies so far.

 

Domain EFS, PKI stores, Certificate authorities. That sounds like a lot of work!

 

Can anyone recommend a book or website (I'll try Microsoft in a moment) which goes into these topics?

 

Can the password option in Word/Office be turned off?

 

Muchas gracias!

Posted (edited)

Why should students not be allowed to encrypt their files if they so choose. There is nothing you can do to stop them.

 

If a student uses strong encryption such as truecrypt at home and brings in files for example. You will not be able to open them. The most you could do is try and delete them but then you have the problem of hidden drives / partitions and stenography. Basically there is nothing you can do and it is not your responsibility. If they are doing anything illegal it will be a police matter.

Edited by somabc
Posted

I second the idea of a standalone PC or PCs which are NOT network connected and contain a bunch of files and a bunch of crypto tools.

 

Could network connect the machine as long as you take steps to prevent the files entering or leaving. you definitely don't want encrypted files on your net, it could be anything in there.

Posted (edited)
Thanks for the replies so far.

 

Domain EFS, PKI stores, Certificate authorities. That sounds like a lot of work!

 

Can anyone recommend a book or website (I'll try Microsoft in a moment) which goes into these topics?

 

Can the password option in Word/Office be turned off?

 

Muchas gracias!

 

Here are some sites that may help in understanding the workings of EFS:

Encrypting File System - Wikipedia, the free encyclopedia

http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/distrib/dscj_mcs_cpiz.mspx?mfr=true

Microsoft Corporation

Microsoft Corporation

Encrypting File System (EFS) &middot Tutorial 2000Trainers.com

 

You should be able to turn off the password protected save mode by using the group policy ADM extensions for your version of Office (2007 or 2003)

 

I think this is a bad idea too. Aren't NTFS permissions enough?

 

NTFS permissions are stupidly easy to either take ownership of or simply ignore in most situations if you can get access to the files via an OS which you control. When it comes to file security it is like using a padlock, it will only keep out the honest people, the ones who are out to get the data will find ways around it easily.

Edited by SYNACK
  • Thanks 1
Posted

We had a one last year.... "The pupils need to access hotmail for their coursework"

 

Hotmail, along with 90% of MSN features are blocked. Everyone knows, full stop.

Posted

I am sorry but the criteria is to create a document which is password protected, we have been doing this for a couple of years.

 

I would say a big no to students having encrypted files on the network. :mad:

Posted
Why should students not be allowed to encrypt their files if they so choose. There is nothing you can do to stop them.

 

If a student uses strong encryption such as truecrypt at home and brings in files for example. You will not be able to open them. The most you could do is try and delete them but then you have the problem of hidden drives / partitions and stenography. Basically there is nothing you can do and it is not your responsibility. If they are doing anything illegal it will be a police matter.

 

As a Network Manager or responsible person, it is part of the job to know what is being stored on your network (as far as reasonably practicable) as it can impinge on you. Students can encrypt whatever they like on their own computers, but they will NOT do whatever they like on the school network.

 

If I cannot get into a folder or file, then they won't because it will quickly be an ex-file.

Posted

I encourage students to use trucrypt.

TrueCrypt - Free Open-Source On-The-Fly Disk Encryption Software for Windows Vista/XP, Mac OS X and Linux

It is just good practice and should be encouraged. Great to see you have such a forward thinking head of ICT.

 

If you suspect sutdents are storeing illegal files in their encrypted archives you can report them to the police. It is an offense not to hand over encryption keys if the police ask for them - otherwise whats the problem.

Posted
NTFS permissions are stupidly easy to either take ownership of or simply ignore in most situations if you can get access to the files via an OS which you control. When it comes to file security it is like using a padlock, it will only keep out the honest people, the ones who are out to get the data will find ways around it easily.

 

NTFS does its job very well and I think for the majority of domain networked environments it's sufficient to protect user data. I use NTFS wherever I can and it works. Encryption is only particularly useful for users carrying important data around, like on notebooks. It's easy to extract a hard drive from a workstation, but extracting a hard drive from a server (which is normally well protected physically) is a much greater challenge!

 

I've never had the need to introduce encryption on any of the networks I support.

Posted (edited)

If students use something like Truecrypt how do they un-encrypt it on my network where I don't let them install software or run exe's?

 

Business does not allow users to employ their own encryption they use whatever their IT staff have specified....

 

or if your a government dept they don't bother ;)

 

Steve

Edited by Ex-MGSTech
SP
Posted
I encourage students to use trucrypt.

TrueCrypt - Free Open-Source On-The-Fly Disk Encryption Software for Windows Vista/XP, Mac OS X and Linux

It is just good practice and should be encouraged. Great to see you have such a forward thinking head of ICT.

 

If you suspect sutdents are storeing illegal files in their encrypted archives you can report them to the police. It is an offense not to hand over encryption keys if the police ask for them - otherwise whats the problem.

 

There is a giant loophole here though - kids forget passwords constantly, and as such forgetting your password is an excuse to not hand over a key.

 

Schools should not be storing encrypted files within its networks which it cannot access. I'd possibly go so far as to say it could open up legal problems for the school, data protection-wise.

 

Encryption is a good idea for personal files, and for transmitting information across the internet, but in a school environment, it should be very tightly controlled.

Posted
There is a giant loophole here though - kids forget passwords constantly, and as such forgetting your password is an excuse to not hand over a key.

 

Schools should not be storing encrypted files within its networks which it cannot access. I'd possibly go so far as to say it could open up legal problems for the school, data protection-wise.

 

Encryption is a good idea for personal files, and for transmitting information across the internet, but in a school environment, it should be very tightly controlled.

 

Part of the problem with this society is that students are not encouraged or given any responsibility. A school cannot be held responsible for illegal data on its network if it can prove that it didn't have the keys. Of course the police could just imprison the governors for not handing over keys they do not have.

On one hand, the government say that schools should encrypt their data. on the others that students should not be taught or encouraged to use this good behaviour.

Posted
Letting kids have their own encryped files on a network is like letting kids have lockers with no master key. I'd never allow it on my network and you can imagine the problems when said kid forgets the encryption key for their coursework...
Posted
As a Network Manager or responsible person, it is part of the job to know what is being stored on your network (as far as reasonably practicable) as it can impinge on you. Students can encrypt whatever they like on their own computers, but they will NOT do whatever they like on the school network.

 

If I cannot get into a folder or file, then they won't because it will quickly be an ex-file.

 

But what do you do about encrypted files hidden inside other files - stenography?

 

You are only responsible to a reasonable extent under the law. Do schools have a right to request the key to encrypted files?

 

If a pupil forgets their password then they lose their data simple as that, they take that risk when they encrypt the file.

 

I don't think the courts will actually accept the 'I forgot my password' in serious cases you could be looking at jail time.

Posted
Letting kids have their own encryped files on a network is like letting kids have lockers with no master key.

 

Which rather implies it might be a good idea to start looking at school-sanctioned encryption, i.e. something where the school has a key that can access student's encrypted files. That way students get to get the hang of the whole encryption thing and the school can keep tabs on what files are floating around the network.

 

--

David Hicks

Posted

Basically we have the policy if the anti-virus software can't scan it. It gets quarantined.

 

As a network manager I'm responsible for the safe maintenance of the whole network for all users. If by allowing encryption I let student/staff bring in or produce documents that endanger that I'm not doing my job.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...