Jump to content

Recommended Posts

Posted

On some occasions there's a need to share slightly more security sensitive information with others but generally speaking this can't be done on an open forum platform like EduGeek, due to students and 'others' sniffing around.

 

Nothing wrong with an open platform, I fully support EduGeek and what it aims to promote for EduTech's but what do people think about a forum set for "verified" Network Manager's and ICT Technicians?

 

This could be achieved by an email from your work email address with some basic information:

 

- Full Name;

- EduGeek Username;

- Role;

- School Name;

- School Telephone Number.

 

Obviously this would required some management and time behind it which is something to look at later on but for now the question is:

 

Do you feel that a forum set for more sensitive issues, not publicly visible to non-members or "standard registered" members, would be of benefit?

 

If people felt this would be a good idea obviously I'd be happy to work with the EduGeek Admin's. I'm not suggesting that the workload for you should be increased if this idea is felt as a potential future addition.

Posted
What sort of things would be posted in this board?

 

On occasion security flaws/proxy sites/"observations" of various natures get noted.

 

- We don't really need students or end users surfing the board to find the latest unfiltered proxy site/security flaw before we have a chance to check EduGeek ourselves.

 

- We don't always say what we think due to how "public" forums are.

 

I'm not suggesting the forums should be used for "bitching" or anything "more adult" but simply host slightly more "verified, secure, honest" discussions.

Posted

I suppose Students could have school e-mail addresses. Do you see the school being rang up to confirm that x member of staff works in that establishment.

 

We have close to 10,000 and I know that the majority are not regular visitors, but the need to ring them all who wish to be part of the additional forum would cost a lot in time and money.

 

I think something similar may have been discussed before and due to the time constraints it was felt that it was a non-starter.

Posted (edited)

I understand that there's certain identity verification issues and a time/cost one too.

 

However, we have some of the best Techs on this forum and I'm sure one way or another (as a team) we could pull something together which could produce a successful outcome.

 

On the other hand maybe something simple as a web page upload to the schools web server like:

 

http://school.com/edugeekconfirmid-user.html

 

Either way it's more finer tuned "How do we do it" stuff.

Edited by DG01
Posted
Im a student and have FTP access to a folder on my schools website for my ICT course so that may prevent the file uploading idea.

 

But I'm sure they don't give you root FTP access...

 

i.e. public_html relative to http://www.site.com/_______

 

So a carefully placed file like /edugeekverify-user.html or /edugeek/verify-user.html would eliminate the element of students with FTP access.

Posted
But I'm sure they don't give you root FTP access...

 

i.e. public_html relative to http://www.site.com/_______

 

So a carefully placed file like /edugeekverify-user.html or /edugeek/verify-user.html would eliminate the element of students with FTP access.

 

Yeah they don't give me public_html relative, so your idea of carefully placed files would work, even though I am a student I still think this would be a pretty good idea as I think NM and Techs need a private area to discuss things such as vulnerabilities and such.

Posted
But I'm sure they don't give you root FTP access...

 

i.e. public_html relative to http://www.site.com/_______

 

So a carefully placed file like /edugeekverify-user.html or /edugeek/verify-user.html would eliminate the element of students with FTP access.

Some of us have websites managed by third parties too. Ours points directly to our VLE solution so I wouldn't be able to do what you propose.

Posted

But an alternative could be:

 

- 30 second call to the school?;

- emailing the default office@ (or other email listed on website) to verify your ID?

 

But a finely tuned list of methods to verify someone's identity could be drawn up. Question is if we found a method suitable do you feel that this would be a good idea?

Posted (edited)

Who would pay for the calls?

 

Yes it's a nice idea if it could work.

 

Edit: Not sure if this would be possible but how about when you register you have to use the office@ email address in order to be placed into the group. Then after that you can change your email. You would need access to the office@ email to validate the registration so nobody would get through?

Edited by Edu-IT
Posted

I tend to know the people I want to talk to when it comes to things like those you outlined so I take mine to a multi user pm as Edugeek by default allows 5 recipients. This is useful enough for me.

 

I've worked on forums with private subforums with eligibility issues etc and it's even more of a manglement nightmare to contain.

 

Everyone has suggested viable means of vetting status but each one has its own caveats and workarounds.

 

Just my view ofc.

Posted
Who would pay for the calls?

 

Yes it's a nice idea if it could work.

 

Well being as it's my idea I'd be happy to work in with the EduGeek Admins and any few volunteers that there may be in defining verification methods and managing the project.

 

I personally have a tonne of contract minutes left at the end of the month so to me this idea would be a good cause to use those minutes on.

 

It's not something I can obviously say the volunteers would pay for because that's their decision but others may find themselves in similar positions to me who are able to free up 30 minutes to make some quick calls.

 

I feel that the potential benefit to the community/professional base here could be rewarding which is why I'm so open to spending time towards seeing the idea through.

Posted

I would not share any sensitive information with anyone no matter if they are verified or not. And I dont wish to give anyone my place of work name, school number and full name.

 

If I have to go through that prosess to discuss problems and find solutions I will just go elsewhere that requires no more hassle than registering.

 

My opinion

Posted (edited)

This isn't about completely revamping the EduGeek registration system or loosing half the excellent technical support in the existing forums.

 

It's simply a proposal to have more "sensitive" stuff in a "secure" forum.

 

This is one of the good features about the RM Communities - cutting off access to non-technical support personnel, however, the issue there regularly is the Communities Charter which prevents discussions with regards to filtering and non-RMish or forum covered issues.

 

EduGeek has the perfect platform for both an excellent general technical resource and also a more sensitive forum set-up to verified technical personnel.

 

I'm surprised you would respond so lightly to the topic and say: "I will just go elsewhere". The point is to pull together the professionals that care about their networks and end users without compromising integrity.

 

What cost do you place on the possible benefits of this idea going ahead?

 

- The one minute to send an email or upload a html page, or via some other simple secure verification method.

 

Again verification methods would need to be talked about but we're talking very simple quick verification methods.

 

The key has to be simple and easy for all.

Edited by DG01
Posted

I suppose another verification option would be to send letters to schools with the applicants job title included and a verification code inside to be emailed back.

 

Again it'd cost but maybe it could be funded by sponsored ad's - also I assume theres some way to get discounted postage, maybe some of the sponsors can send at reduced rates?

Posted

I said I will go elsewhere for the reasons I stated, I dont want to share any information about where exactly I work or my name. Ill practice what we preach to kids about internet safety.

 

The exsisting forums cover pretty much everything, a good example would be a post I made yesterday asking about exchange. I asked a question, walked away to return later to find the answers I was looking for. I thanked the person for his time. And when I have time of my own I try to help others with their questions.

Posted (edited)

All I'm going to say is that's absolutely fine.

 

Reiterating the idea is to discuss more "sensitive" issues in a more "secure" format. If you chose not to go through verification then it would make no difference at all compared to your current EduGeek experience - you just wouldn't be privy to any discussions within the "secure" format.

Edited by DG01
Spelling Correction
Posted
An example of when a person in a position of trust within a school would share sensitive information with relative strangers would be?

 

On occasion security flaws/proxy sites/"observations" of various natures get noted.

 

- We don't really need students or end users surfing the board to find the latest unfiltered proxy site/security flaw before we have a chance to check EduGeek ourselves.

 

- We don't always say what we think due to how "public" forums are.

 

I'm not suggesting the forums should be used for "bitching" or anything "more adult" but simply host slightly more "verified, secure, honest" discussions.

 

No mention of sensitive information (with respect to data or students) anywhere because that would be in breach of the Data Protection Act.

 

In this case "sensitive" is stuff that we understand the potential security/safety risks of but don't want students or other end users necessarily exploiting them before a solution is found or it is addressed.

Posted
Hummm nice idea but I think this a soution to problem that doesn't really exisist. For a start the surity forums are not, AFAIK, trawled by Google. Also if you have concerns that pupils may be viewing sensitive information then filter it via the schools proxy.

 

Can I just point out that we have students actively registering to EduGeek in attempt to find out the latest flaws and proxy sites which are not filtered etc...

 

This is what the idea is trying to achieve to protect.

Posted

The conversation about security via obscurity has been had before and Geoff has covered why it doesn't really achieve much (shouldn't take long to go through all Geoff's posts ... )

 

We have thought about verification and so far decided against it for a number of reasons, including the sheer amount of time it takes to verify it all. And what happens when you have commercial companies that want to take part in the discussions such as security vendors (eg smoothwall and sophos), solutions providers (eg RM), etc?

 

I am not saying that it shouldn't be thought about ... but just that it has been and we haven't been able to come up with a cast iron reason to put the effort in.

 

Majority of the sensitive discussions would be available elsewhere anyway. i have yet to find anything that would not be found elsewhere ... merely more difficult to find.

Guest
This topic is now closed to further replies.



×
×
  • Create New...