Jump to content

Recommended Posts

Posted

Hi all,

 

My principal raised a valid point the other morning when i went to a meeting regarding an incident on our network. She was quite shocked that we could easily monitor any computer screen in the school and that my junior technicians had free access to this.

 

Her main point was that she could be writing up a confidential letter on her PC and we could view it without her knowing! Fair enough i suppose.

 

Do any other schools have policies regarding the use of VNC?

 

Cheers

 

Mike

Posted
We use Impero at our school for access to machines. The curriculum machines are unrestricted which staff are aware of. If we want access to admin machines, the user is prompted if it is OK for us to do so. This was after someone raised a similar issue with our old system which was completely unrestricted. It is a bit of a pain if no-one is actually at the machine!
Posted
Hi all,

 

My principal raised a valid point the other morning when i went to a meeting regarding an incident on our network. She was quite shocked that we could easily monitor any computer screen in the school and that my junior technicians had free access to this.

 

Her main point was that she could be writing up a confidential letter on her PC and we could view it without her knowing! Fair enough i suppose.

 

Do any other schools have policies regarding the use of VNC?

 

Cheers

 

Mike

 

We just generally ask the user first, I know who I can connect to if they don't answer the phone and I generally tell them, normally because they had a document open and i had to tell them where i saved. But thats only when they've requested we fix something. Our VNC is pass word protected and only me and the technician know the password.

Posted
Just been readin up on VNC has an option to prompt the user to accept the connection. But we use TightVNC but i cant find any option like this, real VNC does. Looks like i'll have to change again!
Posted

We generally ask the user to take control or are asked by them.

 

For me it's simply a matter of trust though - I expect my techies to have the highest professional integrity and they don't randomly remotely view screens in the same way they don't randomly trawl people's My Documents folder.

Posted
We only have VNC installed on the student curriculum machines - I decided against installing it on office / headteachers PC for this very reason.
Posted

We use Dameware for support which can be setup to notify users and when we remember to add the correct ini file it does. The problem is that in reality I could replace the ini file restart the service then view without the warning. I could also use Gencontrol which is free and can be installed then uninstalled remotely without trace.

If your techs have admin rights then they can do this, yes you probably need a policy to make it a sackable offence.

 

You could also use GPO to manage local admins on certain groups so only the IT manager can remote support office PC's. At the end of the day the IT manager will have access to all data as it's their job to be guardian of that data. This is a member of staff that SMT have to trust and have faith in if they don't then they have the wrong person.

Posted

Do you have encrypted MyDocuments with a randomly generated backup password stored in a safe which you dont have access to? If not then whats to stop you looking through her documents folder, or even taking a copy of the whole lot and publishing it on the net (for arguements sake)?

 

As said its a matter of trust, and thats one of the reasons IT professionals in industry are payed a wage which reflects this.

Posted
As said its a matter of trust, and thats one of the reasons IT professionals in industry are payed a wage which reflects this.

 

Or as stated some sort of tiered access where lower level techs wouldn't have access to managers data or computers, this would be left to higher level staff who are paid more or a lower level tech might get a look while the manager is present.

Posted

I think the documents comparison is a red herring - you'd generally find that permissions lock people out of places they shouldn't be, and that actions like taking ownership are logged. So, while you can't prevent people snooping, you can make sure you can find they've done it.

 

The problem with VNC is that snooping without detection is possible.

 

It's been a while since I've used VNC, but at the last place we had it run automatically for all students, but staff had to start the server manually (there was a shortcut on the desktop too, so we could describe it easily on the phone!).

Posted
I think the documents comparison is a red herring - you'd generally find that permissions lock people out of places they shouldn't be, and that actions like taking ownership are logged.

 

Theres plenty of ways round it. MSs freely available SubinACL for example.

 

The point is if the school wants me to be able to do my job effectively there is very little they can do to stop me getting at anyones files.

Posted

If we want to snoop we could. That goes for the majority here. Most would not get close to being caught doing so unless there were really tight security in place for monitoring this. We don't because most of us are professional enough to know right from wrong and understand the implications of doing such a thing.

 

You may get a trigger happy junior tech who wants to have a peek at some teachers screen when they first see something like VNC in use. Secure it with passwords and such and wait till the tech is mature enough to handle the responsibility. I think in this day and age a policy is a good idea so that you have some protection should accusations start to fly. Most of us will have a simple understanding in place however, that says we ask before we view and assist.

 

You can even edit remote desktop to allow unsolicited access if you wish with a few tweaks to GPO's as i have played with this on a test network.

 

We tend to email the teacher or update the helpdesk requesting access at a certain time with their permission if we feel the job is quicker done this way. If the staff are unhappy with this there are no hard feelings and we will do it in person instead. Never had anyone say no yet.

 

I understand the principle worrying about such access but i would explain that as an administrator i have full access to all of the files on the system at any time. Junior techs would obviously not have those same rights.

 

(bet your principle is typing out the BSF plans to remove you all!! Load VNC quick!!!):D:D

Posted

If the 'sensitive document' is being saved onto the network, or even onto the teacher's school laptop, then our policies cover us to look at it anyway. The key is, only when it is deemed necessary. Perhaps a line in the AUP for technical staff to cover the use of remote viewing is needed, but that is about all.

I am fairly shocked that a teacher appears to think that another member of the school - a techie - is likely to be randomly roaming about looking for things he shouldn't be. After all, any member of staff could go through another teachers locker or desk or whatever, but that doesn't immediately occur to them, does it?

Posted
I imagine a lot of us have better things to be doing than going through peoples documents/looking at their machines.

Unless they do something to draw attention.e.g. complaining about something "not working" or doing things they most definitly shouldn't be doing. (Possibly complaining about being unable to do something they shouldn't be attempting in the first place.)

Posted
I dont install on the office PCs. It's a pain but it means I get some much needed exercise every now and again!

You can use RDP in then which you can easily tell because it locks their local screen.

 

 

VNC also by default changes the system tray icon when someone connects unless you disable it.

Posted (edited)
If the 'sensitive document' is being saved onto the network, or even onto the teacher's school laptop, then our policies cover us to look at it anyway. The key is, only when it is deemed necessary. Perhaps a line in the AUP for technical staff to cover the use of remote viewing is needed, but that is about all.

I am fairly shocked that a teacher appears to think that another member of the school - a techie - is likely to be randomly roaming about looking for things he shouldn't be. After all, any member of staff could go through another teachers locker or desk or whatever, but that doesn't immediately occur to them, does it?

 

 

I had a member of staff come in an try to drag me down to their room at the other end of school, I said we can view their desktop from here (as they were with me) so I did. They immediatly commented "Oh you can see my screen and my personal email". I replied well yes remote support is mentioned in the AUP that you of course read and signed and you really shouldn't be using personal email in work time on a public terminal if you're bothere about people seeing.

 

 

@theriver

The problem with VNC is that snooping without detection is possible.

 

The problem is that almost all can be setup to allow this. Net Support, VNC, RRC, ABTutor and Dameware are ones we use and all can be setup this way. Dameware is specifically a bussiness tool with FIPS compliance and you can still do this.

 

 

 

As for document access if your staff have DA rights then they can do everything, the only way around this is to have a third party company that sets up the system and doesn't give site staff DA access.

Edited by cookie_monster
Posted

The problem with VNC is that snooping without detection is possible

We have access to all machines, but it prompts for mslogon credentials every time. It is also logged in the event viewer so you can see who looked, when, and for how long (by seeing the connection/disconnection times).

There needs to be a trust of the IT Staff, i could if i wanted access any files anywhere on the network. I have better things to do and know that unless i have been asked/have good reason i shouldn't be accessing other peoples areas. Without trust we can't do our job efficiently!

Posted
Do you have encrypted MyDocuments with a randomly generated backup password stored in a safe which you dont have access to? If not then whats to stop you looking through her documents folder, or even taking a copy of the whole lot and publishing it on the net (for arguements sake)?

 

As said its a matter of trust, and thats one of the reasons IT professionals in industry are payed a wage which reflects this.

 

I agree totally. :)

Posted

To quote a rather awesome "Top 10 Tips ICT Support would like you to know" list, number 10 is:

And finally, yes, I can read your email, I can see what web pages you look at while you are at work, yes, I can access every file on your work computer, and I can tell if you are chatting with people on an instant messenger or chat room (and can also read what you are typing). But no, I don’t do it. It’s unethical, I’m busy, and in all reality you aren’t all that interesting. So unless I am instructed to specifically monitor or investigate your actions, I don’t. There really are much more interesting things on the internet than you.
  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...