Wildebeaste Posted September 5, 2008 Posted September 5, 2008 Hello folks. I'm after some advice really. Our head of ICT wants students to be able to encrypt files and folders on the school network. I think this is a **very** bad idea, as I absolutely don't want 'little Jonny' to be able to stash away his dodgy file collection on my servers. At the moment I've said a big NO to this, that I (Network Manager) need to be able to access all the files on the network, i.e. have copies of any passwords or keys or be able to gain access. But he seems to think that they will fail their course without showing evidence of this. How have others managed to deal with this thorny problem? Advice gratefully received. Ta.
Ex-MGSTech Posted September 5, 2008 Posted September 5, 2008 Not a lot of help But I'm with you on this one! So little Johnny stores his MP3, doggy JPG's etc in an encrypted file that nobody can access eh? Absolutly not! Steve
Edu-IT Posted September 5, 2008 Posted September 5, 2008 But he seems to think that they will fail their course without showing evidence of this. How about having a standalone machine which they can use for this purpose?
ICTNUT Posted September 5, 2008 Posted September 5, 2008 I would ask to see where it says that they have to encrypt files, he may have just misunderstood what has been asked of him! I personally cannot see how they can request files and folders be encrypted, what type of encryption method should be used, how do you prove the file is indeed encrypted, where is the evidence. It's non workable
SYNACK Posted September 5, 2008 Posted September 5, 2008 Umm, if they use the built in Windows EFS encryption and you have your domain setup right then the Administrator account or another account that you specify has rights to decrypt any encrypted files created by EFS as this account is also given an encryption key. This should satisfy their course requirements as they are using encryption of the same kind that would be used in an enterprise setting. It also follows the same rules as an enterprise setting where the administrator has the power to override the lockouts if it is nessisary for the best interests of the company, ie employee leaves, legal stuff etc. 1
pete Posted September 5, 2008 Posted September 5, 2008 Isn't this more a case of they need to make a presentation / publisher document where they show (screen-shotted) the process of them encrypting a file for their coursework, rather than actually needing to encrypt something?
Wildebeaste Posted September 5, 2008 Author Posted September 5, 2008 Thanks for the replies so far. Domain EFS, PKI stores, Certificate authorities. That sounds like a lot of work! Can anyone recommend a book or website (I'll try Microsoft in a moment) which goes into these topics? Can the password option in Word/Office be turned off? Muchas gracias!
Heebeejeebee Posted September 5, 2008 Posted September 5, 2008 Some backup programs used to have difficulty with encrypted files. Not sure on the state of play with EFS though. HBJB
somabc Posted September 5, 2008 Posted September 5, 2008 (edited) Why should students not be allowed to encrypt their files if they so choose. There is nothing you can do to stop them. If a student uses strong encryption such as truecrypt at home and brings in files for example. You will not be able to open them. The most you could do is try and delete them but then you have the problem of hidden drives / partitions and stenography. Basically there is nothing you can do and it is not your responsibility. If they are doing anything illegal it will be a police matter. Edited September 5, 2008 by somabc
tom_newton Posted September 5, 2008 Posted September 5, 2008 I second the idea of a standalone PC or PCs which are NOT network connected and contain a bunch of files and a bunch of crypto tools. Could network connect the machine as long as you take steps to prevent the files entering or leaving. you definitely don't want encrypted files on your net, it could be anything in there.
Michael Posted September 5, 2008 Posted September 5, 2008 I think this is a bad idea too. Aren't NTFS permissions enough?
SYNACK Posted September 5, 2008 Posted September 5, 2008 (edited) Thanks for the replies so far. Domain EFS, PKI stores, Certificate authorities. That sounds like a lot of work! Can anyone recommend a book or website (I'll try Microsoft in a moment) which goes into these topics? Can the password option in Word/Office be turned off? Muchas gracias! Here are some sites that may help in understanding the workings of EFS: Encrypting File System - Wikipedia, the free encyclopedia http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/distrib/dscj_mcs_cpiz.mspx?mfr=true Microsoft Corporation Microsoft Corporation Encrypting File System (EFS) · Tutorial 2000Trainers.com You should be able to turn off the password protected save mode by using the group policy ADM extensions for your version of Office (2007 or 2003) I think this is a bad idea too. Aren't NTFS permissions enough? NTFS permissions are stupidly easy to either take ownership of or simply ignore in most situations if you can get access to the files via an OS which you control. When it comes to file security it is like using a padlock, it will only keep out the honest people, the ones who are out to get the data will find ways around it easily. Edited September 5, 2008 by SYNACK 1
Hightower Posted September 5, 2008 Posted September 5, 2008 We had a one last year.... "The pupils need to access hotmail for their coursework" Hotmail, along with 90% of MSN features are blocked. Everyone knows, full stop.
bossman Posted September 5, 2008 Posted September 5, 2008 I am sorry but the criteria is to create a document which is password protected, we have been doing this for a couple of years. I would say a big no to students having encrypted files on the network.
Wildebeaste Posted September 5, 2008 Author Posted September 5, 2008 Why should students not be allowed to encrypt their files if they so choose. There is nothing you can do to stop them. If a student uses strong encryption such as truecrypt at home and brings in files for example. You will not be able to open them. The most you could do is try and delete them but then you have the problem of hidden drives / partitions and stenography. Basically there is nothing you can do and it is not your responsibility. If they are doing anything illegal it will be a police matter. As a Network Manager or responsible person, it is part of the job to know what is being stored on your network (as far as reasonably practicable) as it can impinge on you. Students can encrypt whatever they like on their own computers, but they will NOT do whatever they like on the school network. If I cannot get into a folder or file, then they won't because it will quickly be an ex-file.
localzuk Posted September 5, 2008 Posted September 5, 2008 I have never heard of a school subject which requires encryption! I think your teacher is getting encryption and password protecting mixed up.
CyberNerd Posted September 5, 2008 Posted September 5, 2008 I encourage students to use trucrypt. TrueCrypt - Free Open-Source On-The-Fly Disk Encryption Software for Windows Vista/XP, Mac OS X and Linux It is just good practice and should be encouraged. Great to see you have such a forward thinking head of ICT. If you suspect sutdents are storeing illegal files in their encrypted archives you can report them to the police. It is an offense not to hand over encryption keys if the police ask for them - otherwise whats the problem.
Michael Posted September 5, 2008 Posted September 5, 2008 NTFS permissions are stupidly easy to either take ownership of or simply ignore in most situations if you can get access to the files via an OS which you control. When it comes to file security it is like using a padlock, it will only keep out the honest people, the ones who are out to get the data will find ways around it easily. NTFS does its job very well and I think for the majority of domain networked environments it's sufficient to protect user data. I use NTFS wherever I can and it works. Encryption is only particularly useful for users carrying important data around, like on notebooks. It's easy to extract a hard drive from a workstation, but extracting a hard drive from a server (which is normally well protected physically) is a much greater challenge! I've never had the need to introduce encryption on any of the networks I support.
Ex-MGSTech Posted September 5, 2008 Posted September 5, 2008 (edited) If students use something like Truecrypt how do they un-encrypt it on my network where I don't let them install software or run exe's? Business does not allow users to employ their own encryption they use whatever their IT staff have specified.... or if your a government dept they don't bother Steve Edited September 5, 2008 by Ex-MGSTech SP
localzuk Posted September 5, 2008 Posted September 5, 2008 I encourage students to use trucrypt. TrueCrypt - Free Open-Source On-The-Fly Disk Encryption Software for Windows Vista/XP, Mac OS X and Linux It is just good practice and should be encouraged. Great to see you have such a forward thinking head of ICT. If you suspect sutdents are storeing illegal files in their encrypted archives you can report them to the police. It is an offense not to hand over encryption keys if the police ask for them - otherwise whats the problem. There is a giant loophole here though - kids forget passwords constantly, and as such forgetting your password is an excuse to not hand over a key. Schools should not be storing encrypted files within its networks which it cannot access. I'd possibly go so far as to say it could open up legal problems for the school, data protection-wise. Encryption is a good idea for personal files, and for transmitting information across the internet, but in a school environment, it should be very tightly controlled.
CyberNerd Posted September 5, 2008 Posted September 5, 2008 There is a giant loophole here though - kids forget passwords constantly, and as such forgetting your password is an excuse to not hand over a key. Schools should not be storing encrypted files within its networks which it cannot access. I'd possibly go so far as to say it could open up legal problems for the school, data protection-wise. Encryption is a good idea for personal files, and for transmitting information across the internet, but in a school environment, it should be very tightly controlled. Part of the problem with this society is that students are not encouraged or given any responsibility. A school cannot be held responsible for illegal data on its network if it can prove that it didn't have the keys. Of course the police could just imprison the governors for not handing over keys they do not have. On one hand, the government say that schools should encrypt their data. on the others that students should not be taught or encouraged to use this good behaviour.
rhyds Posted September 5, 2008 Posted September 5, 2008 Letting kids have their own encryped files on a network is like letting kids have lockers with no master key. I'd never allow it on my network and you can imagine the problems when said kid forgets the encryption key for their coursework...
somabc Posted September 5, 2008 Posted September 5, 2008 As a Network Manager or responsible person, it is part of the job to know what is being stored on your network (as far as reasonably practicable) as it can impinge on you. Students can encrypt whatever they like on their own computers, but they will NOT do whatever they like on the school network. If I cannot get into a folder or file, then they won't because it will quickly be an ex-file. But what do you do about encrypted files hidden inside other files - stenography? You are only responsible to a reasonable extent under the law. Do schools have a right to request the key to encrypted files? If a pupil forgets their password then they lose their data simple as that, they take that risk when they encrypt the file. I don't think the courts will actually accept the 'I forgot my password' in serious cases you could be looking at jail time.
dhicks Posted September 8, 2008 Posted September 8, 2008 Letting kids have their own encryped files on a network is like letting kids have lockers with no master key. Which rather implies it might be a good idea to start looking at school-sanctioned encryption, i.e. something where the school has a key that can access student's encrypted files. That way students get to get the hang of the whole encryption thing and the school can keep tabs on what files are floating around the network. -- David Hicks
Face-Man Posted September 8, 2008 Posted September 8, 2008 Basically we have the policy if the anti-virus software can't scan it. It gets quarantined. As a network manager I'm responsible for the safe maintenance of the whole network for all users. If by allowing encryption I let student/staff bring in or produce documents that endanger that I'm not doing my job.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now