ajbritton Posted June 17, 2006 Posted June 17, 2006 I would also point out that if you need to give your students a 'sandbox' to play in, you could install Virtual Server (free) on XP Pro machines and give them an XP guest PC (not sure of licensing implications) whith as little or as much network access as you want. The guest could use an Undo disk which is automatically discarded on reboot.
RoyG Posted June 18, 2006 Posted June 18, 2006 If you use cards that protect your PCs, what protects any laptops on the network? A software version called EZBack RoyG
MkII Posted June 18, 2006 Posted June 18, 2006 Very interesting RoyG. I dissalow firefox at the moment because I can't audit the kids activities as I do with IE. A weakness in the logoff script perhaps. I also never have to rebuild PCs because they're destroyed by the users, so I'm in the same happy position yourself on that score. I don't see the odd tweaking of Group Policies as any big deal. Your security issue i find very worrying. The work done that day, between backups was lost then. That alone really condemns your practice I think. Seeing how others are implementing virtual machines, I would like to try that method. Or arrange a small isolated network for those interested to experiment. Of course we're singing from the same songsheet really. I too would really like the kids to have as much and as wide an oportunity as possible.
RoyG Posted June 18, 2006 Posted June 18, 2006 Very interesting RoyG. I dissalow firefox at the moment because I can't audit the kids activities as I do with IE. A weakness in the logoff script perhaps. Not a problem, Novell BorderManager logs all webpages visited by users, regardless of whether it's via IE or Firefox. I also never have to rebuild PCs because they're destroyed by the users, so I'm in the same happy position yourself on that score. I don't see the odd tweaking of Group Policies as any big deal. It's still tedious! Your security issue i find very worrying. The work done that day, between backups was lost then. That alone really condemns your practice I think. Also not a problem, Netware Admin has a very effective salvage facility which can recover anything deleted in the past few days. I've very, very rarely had to use it. Seeing how others are implementing virtual machines, I would like to try that method. Or arrange a small isolated network for those interested to experiment. Of course we're singing from the same songsheet really. I too would really like the kids to have as much and as wide an oportunity as possible. I believe it's a question of culture - the more you restrict, the more the kids will fight. I've tried the heavy restriction option which drove me & the kids barmy, but very much prefer the "try what you like, it doesn't bother me" approach. This doesn't imply total freedom for the kids, obviously effective web filtering is essential. It's also essential to ensure that data is 100% secure, with backup & restore systems on servers, workstations & laptops. I can only repeat that in my school's particular situation the policies we have adopted have been really effective. The main benefit has been that all but a minute handful of the kids really appreciate the relative freedoms we've given them, with students, teaching staff & technical staff working with, rather than against each other. RoyG
ITWombat Posted June 18, 2006 Posted June 18, 2006 Ok the PCs are protected from damage, enforced restart between logon gets rid of phish-ware and security best practice on servers as a given. Job done? What happens during lesson time. Do you still run NetOp/NetSupport? Why should a student bother with a tedious database assigment when they can hone their coding skills or play 3D snooker.Are your teaching colleagues quite so happy that kids can do anything and hit the boss key when teacher draws near. Also what about the situation when the school is not the target of cracking activity but a remote site. I take it that BorderMangager is the Novell equivalent of ISA/Censornet. Do you block all protocols apart from HTTP, FTP and RTSP/MMS?
RoyG Posted June 19, 2006 Posted June 19, 2006 Job done? What happens during lesson time. Do you still run NetOp/NetSupport? Why should a student bother with a tedious database assigment when they can hone their coding skills or play 3D snooker.Are your teaching colleagues quite so happy that kids can do anything and hit the boss key when teacher draws near. How does a teacher ensure in a classroom that little Jimmy is doing his geography assignment not reading a comic? Does he get support staff to prevent any comic getting into any classroom?! Again a question of culture - it's the teacher's problem. OK, we help - the layout of the Computer Rooms means that all student screens are visible and even a teacher(!!) can spot 3d snooker from 10 paces! If the teacher is one of the lazy variety that just sits at the front & lets the kids get on with it, I don't see why I should be the one to enforce discipline! Also what about the situation when the school is not the target of cracking activity but a remote site. I take it that BorderManager is the Novell equivalent of ISA/Censornet. Do you block all protocols apart from HTTP, FTP and RTSP/MMS? Combination of County firewalls plus BorderManager takes care of that. I'm sorry if I gave the impression that we don't bother with ANY security in the school, it's just the workstations that are open access with the Reborn cards taking care of them. The servers are locked down as securely as we can manage!!!
NetworkGeezer Posted June 19, 2006 Posted June 19, 2006 How does a teacher ensure in a classroom that little Jimmy is doing his geography assignment not reading a comic? Does he get support staff to prevent any comic getting into any classroom?! Again a question of culture - it's the teacher's problem. OK, we help - the layout of the Computer Rooms means that all student screens are visible and even a teacher(!!) can spot 3d snooker from 10 paces! If the teacher is one of the lazy variety that just sits at the front & lets the kids get on with it, I don't see why I should be the one to enforce discipline! You make a good point. Unfortunately those of us without a teaching background wouldn't have the clout to make such a statement without being accused of insubordination. I'm sorry if I gave the impression that we don't bother with ANY security in the school, it's just the workstations that are open access with the Reborn cards taking care of them. The servers are locked down as securely as we can manage!!! What you have said is all very reasonable and thought out but on eduGeek you have to expect you case to be tested thoroughly when it appears to challenge the status quo. Didn't think you still be a rebel at this age eh Roy
RoyG Posted June 19, 2006 Posted June 19, 2006 What you have said is all very reasonable and thought out but on eduGeek you have to expect you case to be tested thoroughly when it appears to challenge the status quo. Didn't think you still be a rebel at this age eh Roy I'm very happy to be challenged - happier still to be a geriatric rebel!! RoyG
MkII Posted June 19, 2006 Posted June 19, 2006 The only example of problems was when some bright spark dumped a file called something like "the best game in the universe.exe" into a shared area. Anyone daft enough to run it found their home directory blitzed (easily restored from backup)! Your security issue i find very worrying. The work done that day, between backups was lost then. That alone really condemns your practice I think. Also not a problem, Netware Admin has a very effective salvage facility which can recover anything deleted in the past few days. I've very, very rarely had to use it. Not so fast old fogie rebel! ...So you're saying there is or there isn't the possibility of permanent data loss??
RoyG Posted June 19, 2006 Posted June 19, 2006 The only example of problems was when some bright spark dumped a file called something like "the best game in the universe.exe" into a shared area. Anyone daft enough to run it found their home directory blitzed (easily restored from backup)! Your security issue i find very worrying. The work done that day, between backups was lost then. That alone really condemns your practice I think. Also not a problem, Netware Admin has a very effective salvage facility which can recover anything deleted in the past few days. I've very, very rarely had to use it. Not so fast old fogie rebel! ...So you're saying there is or there isn't the possibility of permanent data loss?? I wouldn't be rash enough to say that there was zero chance of losing data (multiple server HDD failure, nuclear attack.....) but it's as near zero as makes no odds. RoyG
NetworkGeezer Posted June 19, 2006 Posted June 19, 2006 I wouldn't be rash enough to say that there was zero chance of losing data (multiple server HDD failure, nuclear attack.....) Oh Miaow
MkII Posted June 19, 2006 Posted June 19, 2006 The honourable gentleman has still not answered my question So for the rest of us ONLY the said natural disasters would cause data loss. At your place Roy - any scrote uploading a fun little vbs can wipe out a days work of some little darlings GCSE coursework?? [/Paxman]
MkII Posted June 19, 2006 Posted June 19, 2006 We had a similar thing - we let kids run vbs files, and had an open share. Kids abused it so much - swapping porn, games and nasty tricks like you said. Teachers couldn't control it so we now have to turn off the open share until requested open for a specific class. It's a lot less work/ hassle.
RoyG Posted June 19, 2006 Posted June 19, 2006 The honourable gentleman has still not answered my question So for the rest of us ONLY the said natural disasters would cause data loss. At your place Roy - any scrote uploading a fun little vbs can wipe out a days work of some little darlings GCSE coursework?? [/Paxman] Not so! Netware Salvage will recover any file recently deleted (recently is usually about a week, dependent on spare HDD space on the user volume). Conceivably if a kid only noticed that he'd lost his home directory weeks later, the files modified on the day he ran the scrote's vbs so not on tape via the daily backup would not be recoverable. It hasn't happened in the 7 years we've been operating our present policy. RoyG
MkII Posted June 19, 2006 Posted June 19, 2006 Sorry - misread You backup to tape daily, then have this Netware Salvage running on top - holding a weeks worth of deleted files???
NetworkGeezer Posted June 19, 2006 Posted June 19, 2006 Sounds a bit like shadow copy on Windows 2003. Maybe that's where Microsoft got the idea from.
RoyG Posted June 19, 2006 Posted June 19, 2006 Sorry - misread You backup to tape daily, then have this Netware Salvage running on top - holding a weeks worth of deleted files??? It's just a glorified Recycle Bin that works really well. Part of Netware. RoyG
bossman Posted June 19, 2006 Posted June 19, 2006 I agree that it sounds like a marvelous piece of kit for the price but i have striven for 5 years to strike a balance with the pupils and the teachers. In all i have tried the softly softly let them have what they want approach this just led to the teachers cocking everything they touched up and ended up running around after them. The Pupils thought it was great cos they could play games and the like whenever the teacher wasn't looking so this in turn upset the teachers. Back to an enforced environment where the kids are restricted by policy to what they are allowed by the teachers to do and also the teachers are given a code of practise enforced again by policy. This has been in force for nearly 5 years now and works very effectively. I am also looking at providing a web based games room which can be accessed at whatever time is stipulated by the teacher for the pupils. I can have a workstation turned around within fifteen minutes, not exactly instant but quick enough for our needs. A total rebuild only takes 1hour fourty five minutes to 2and a half hours depending on the amount of applications needed on said workstation. So at a cost of £30 per machine that works out pretty expensive for your piece of kit. In all i can have pupils running vb code in a custom mode which takes minutes to set up and they are not restricted in the content they have access to in terms of usage. Children need also boundries i know this from experience (i also have two of my own teenagers with attitude) if not they quickly learn to take short cuts and there are no shortcuts in life my friend. Thank you for sharing your experiences with me and i don't condem your approach but have found one that works for me. Regards
E1uSiV3 Posted June 19, 2006 Posted June 19, 2006 Sounds a bit like shadow copy on Windows 2003. Maybe that's where Microsoft got the idea from. Probably. My stance on this is (just to throw the cat amongst the pigeons) is to lock the workstations down, make all resoures the kids need available and lock out the rest. I see what your school is managing to do, but i think its quite a rare situation, the kids at my old place would have tore down the network within a week if we gave them rights similar to yours. also, you must have a great confidence in your ability to secure your servers, personally i wouldnt want to risk it, every (and i mean every) system is crackable, you just have to find the weakest link. The other thing i would be concerned about is the ability for a "guest" to attempt to attack the network. If the kids have such restriction free accounts, it means a wouldbe hacker would only need to obtain access to a kids account to give him relative freedom, compared to a locked down system that would need a key account operators account to attempt to do any real damage. I like the idea, but im too paranoid im afraid. Would you leave your car unlocked because you trust your neighbours? Its not he neighbours im worried about...
RoyG Posted June 19, 2006 Posted June 19, 2006 I see what your school is managing to do, but i think its quite a rare situation, the kids at my old place would have tore down the network within a week if we gave them rights similar to yours. They can't bring the network down, the only total freedom they have is on the workstations, which I can restore in the time it takes to reboot a PC. also, you must have a great confidence in your ability to secure your servers, personally i wouldnt want to risk it, every (and i mean every) system is crackable, you just have to find the weakest link. If I did have any real concerns about that, I wouldn't try & fix it by restricting the workstations! I've encouraged some of my very brightest kids (including several finalists in the British Informatics Olympiad) to try and hack the Netware servers and hack the Reborn Card system. They have never succeeded. The other thing i would be concerned about is the ability for a "guest" to attempt to attack the network. If the kids have such restriction free accounts, it means a wouldbe hacker would only need to obtain access to a kids account to give him relative freedom, compared to a locked down system that would need a key account operators account to attempt to do any real damage. The Guest account has exactly the same profile as Student! I like the idea, but im too paranoid im afraid. Would you leave your car unlocked because you trust your neighbours? Using your analogy, I would be more than happy to leave my car unlocked, with a big sign on it saying, "Please help yourself", if I had a magic wand to restore the car to its original position and condition in 30 seconds flat! RoyG
webman Posted June 19, 2006 Posted June 19, 2006 What about these unrestricted users launching viruses spreading throughout the network? What about these unrestricted users running brute-force apps attempting to crack the security implemented on the server?
MkII Posted June 19, 2006 Posted June 19, 2006 Setting the kids a challenge no where near simulates a real world attack. I've done similar with kids - they just aren't inspired the same.
E1uSiV3 Posted June 19, 2006 Posted June 19, 2006 Using your analogy, I would be more than happy to leave my car unlocked, with a big sign on it saying, "Please help yourself", if I had a magic wand to restore the car to its original position and condition in 30 seconds flat! RoyG Are your servers running the reborn cards then? As for not being able to take down the servers, the kids could load some DDoS tools and attack them, run NetWare specific exploit code looking for holes etc etc, so in all fairness they can at least cause outages as a direct result of letting them run what they want. The odds of this happening however seem to be very low at your school. My old school was a different kettle of fish. The kids used to find every way possible to break things. One of the biggest issues was them running (or trying to run) P2P apps and install games. I think the point i was trying to make is the workstations are great, one reboot fixes all hence the need for no restrictions, but id be more worried about them using the workstations and their freedoms to attack the network infrastructure itself, not knowing netware i cant comment on its security, but i would still be paranoid about allowing them to try. For the bright kids i would have liked to have set up a lab for them to use.
ajbritton Posted June 19, 2006 Posted June 19, 2006 @RoyG: When a student logs on and has local admin rights, does this also give them implied admin rights on all the other PCs? This would certainly be the case on a Windows network if the students were using domain based user accounts. Would this not mean that a student could remotely cause havoc on any other PC, presumably including those used by teachers.
NetworkGeezer Posted June 19, 2006 Posted June 19, 2006 It is possible to limit admin priviligies to spefic clusters student only clusters. Thoug you do have a good point there if they can logon remotely to the Head Teachers PC let's say, they could casue all manner of havoc.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now