Jump to content

Recommended Posts

Posted
Anybody else been taken by surprise as Google applications (Gmail, Picasa, Docs etc.) failed to work this morning? Found the article on the website explaining why they've done it (SSL searches on Google bypassing the filters) so appreciate why they've done it, but why do we only seem to find these things are happening afterwards, or is it just me?!
Posted

We should have been sent the email notifying of this last week, but only received it today after complaining that our Google Apps services had all been filtered. Even if I had seen the email I wouldn't have realised that 443 would be blocked for every Google service.

 

I'm a bit stuck now, I've spent the last our testing squid rules, there doesn't seem to be a way to stop Google SSL searches without also stopping Google Apps. The both use the same domain name and the same port number.

 

Are there any options to work around this?

Posted

Hi Folks. I've heard similar rumblings from E2BN and elsewhere in the country. Google have really put the cat amongst the flying rats here...

 

As we see it, there are 3 methods to remedy the filtering concerns:

 

1. Block google.com HTTP&HTTPS.

2. Block google.com HTTPS only.

3. Full HTTPS interception.

 

Methods 1 and 2 will break any web app that requires a Google Accounts logon and kill google.com in general. Boo :-(

Option 2 is lesser impact - it still allows search, toolbars, and custom search etc. to work properly over HTTP.

Option 3 is the most comprehensive - it allows your filter to work "as normal" with Google - just like 2 weeks ago :-)

 

We will be publishing a white paper on this topic Very Soon TM, but our current best practice advice for those of you with in-house smoothies is Option 3 - HTTPS interception.

Posted
Cheers all, have received copy of email via unofficial channels. Looks like the good old Smartcache is flummoxed again, bless it. Definitely looking like a secondary solution will be needed at some point (naming no alternatives (cof smoothwall cof)), or a serious clampdown on anybody found using https to access Google which at least I can do at moment...
Posted
Looks like the good old Smartcache is flummoxed again, bless it.

 

Have you tried poking it, it's a simple being without aggression, which in my book makes it an idea candidate for poking.

Posted

I had notification of this during half term, with the 'public' notification (to the headteachers) happening last Tuesday along with the confirmation that it was going to happen.

 

It's a bit of a pita, but all the same it had to be done.

Posted
Anybody else been taken by surprise as Google applications (Gmail, Picasa, Docs etc.) failed to work this morning? Found the article on the website explaining why they've done it (SSL searches on Google bypassing the filters) so appreciate why they've done it, but why do we only seem to find these things are happening afterwards, or is it just me?!

 

In B&NES we knew about last week BUT what SWGfL didn't tell us was that the filter is at the top most level so even our unfiltered 'net feed is filtered from Google applications that use https! :-|

Posted
In B&NES we knew about last week BUT what SWGfL didn't tell us was that the filter is at the top most level so even our unfiltered 'net feed is filtered from Google applications that use https! :-|

 

That was the only reason I noticed it (I'm a B&NES Chap myself), as Staff complained that they couldn't get to there personal emails at lunch.

 

I'm not quite sure what to say to them on that, apart from 'tough' and you'll have to wait!

Posted
Is it just google.com that's running on https? We redirect google.com to google.co.uk

 

Yes, but a redirect won't work on https - to varying degrees.

Either the redirect won't apply to the encrypted traffic, or if it does, you'll get an HTTP certificate mismatch. You can't reliably redirect HTTPS->HTTP, except perhaps via MITM, which obviates the need for such tricks in the first place.

Posted

OK, starting to get updates through on email now; they did manage to link to a blocked site the first attempt, though - say no more...! Text of Google blog below...

-------------------------

 

An update on encrypted web search in schools

 

Monday, June 14, 2010 at 8:59 AM

 

We recently launched a beta version of encrypted (SSL) search at https://www.google.com to prevent people from intercepting our users’ search terms and results. However, because encrypted search creates an obscured channel between a user’s computer and Google, users who go to https://www.google.com can bypass some schools’ content filters. This can make it hard for schools to stop students from accessing adult content.

 

One option is for schools to use our SafeSearch lock feature, which is designed to help keep adult content out of our search results. But given how many computers some institutions have this is proving impractical in many cases. So to prevent students from bypassing their filters, some schools are blocking encrypted search. However, a side effect of this action is that it also blocks other services hosted at Google’s secure URL, including Google Apps for Education, and many of our other services which require authentication to keep information safe.

 

We’re working hard to address this issue as quickly as possible and in a few weeks we will move encrypted search to a new hostname – so schools can limit access to SSL search without disrupting other Google services, like Google Apps for Education. Longer term, we are exploring other options like moving authentication to its own hostname so that we can return encrypted search to https://www.google.com.

 

Safety and security matter to Google, and we are committed to working with our partners in education so that we help keep students safe and secure on the Internet.

 

Posted by Dave Girouard, President, Google Enterprise

-----------------------------

  • Thanks 1
Posted (edited)

Lost without gmail and apps here.

 

I have applied for it to be unblocked, as it is unlikely to be a major problem here with less tech savy junior school kids. If they were caught using ssl and searching for stuff that was less than savoury then they would loose their internet privileges.

 

As an interesting aside, there have been rumblings about Ofsted wanting unfiltered access to the net for all kids. We should be teaching them what to do to avoid harmful content and what to do when they find it rather than trying make a pretend "safe" internet. With upwards of 90% of the net dedicated to pr0n and freaky stuff its always going to be easier to teach kids to avoid that to try to block every objectionable site.

Edited by ICT_GUY
Posted

Just got this.

 

This message gives an update on the 'Google ssl searching' issue I informed

you of last week.

 

Google have acknowledge the problem and this link explains how they are

going to deal with the issue:

Official Google Enterprise Blog: An update on encrypted web search in schools

 

Put simply, Gmail & Gdocs will remain on https://www.google.com but Google

will move their 'encrypted search' service to a new URL. At that point

SWGfL will be able to remove the block on https://www.google.com

 

However, the Google statement says this will be "in a few weeks".

Posted

I've just had this via email from SWGfL:

 

Good News - You can now control access to Google SSL pages yourself

 

As you may be aware Google have recently released a beta version secure search engine. This new search engine allows users to search the internet, with their search terms and results encrypted. This encryption bypasses the filtering system in place and is affecting many of the mainstream filtering suppliers to education. This means Google Secure Search will return results for ALL search terms, including video/picture thumbnails. Users who attempt to click through to inappropriate sites will find these pages subject to normal filtering policies. For more information click here. To ensure the continued online safety of all users, the South West Grid for Learning has taken the decision to block ALL traffic to secure Google sites. The knock-on effect of this is that access to other secure Google sites, such as Gmail, Google Apps and YouTube will also be blocked.

 

The South West Grid for Learning are aware a number of customers use these Google services, and as a result have added a new filter list to your SWGfL Filtering service. This gives schools the ability to quickly unblock access to these sites. The new filter list is called “Google Secure Services (Inc GMail and Calendar)”. To grant access to these sites again, your SWGfL Filtering administrator will need to un-check this filter list in the admin interface - https://admin.filtering.swgfl.org.uk. If you are unsure of the process to unblock these sites, please contact your normal support provider. Remember, you can also reset your password for the admin interface in the latest version of SWGfL filtering by going to the Settings page.

 

NOTE: By granting access to GMail, Google apps and other secure Google services such as YouTube users will gain access to the Google Secure Search. As explained above, this will give users access to an unfiltered search engine. Any attempt to view an inappropriate site from these search results will be subject to normal filtering rules.

 

The SWGfL and RM are working with Google to find a longer term solution and will update all customers once a more permanent resolution is found. You can find the latest update from Google here.

Posted
Anyone else just being informed by their LEA that they might be fined £500,000 if Google Apps data is found to be outside the EU?

 

I seriously doubt that is true, as the US and the EU have the 'Safe Harbor' agreement, which Google is registered with. US Safe Harbor

Posted
If it transpires that the data is hosted external to the European Community I am advised that this would not be considered acceptable practise by Cornwall Council.

 

That's what the email says. I think Live@Edu would be out too as the same restrictions apply.

Posted
We had a discussion over this at our last IT Managers meeting in N Yorks, and it was said that Google Mail for schools etc was out as Google store data outside the EU which isn't allowed, but Microsoft Live@Edu stores it in a new data-centre they have just got within the EU so that is a good possibility for N Yorks Schools to replace the existing Scalix E-mail platform.
Posted

Live@edu is hosted in Dublin, with fail-over to Amsterdam.

Google do abide by and have a safe harbor agreement which is accepted by Becta and ICO. The fine of £500k would be from the ICO ... who don't have a problem with the Safe harbor agreement?

 

A council not accepting this as acceptable practice is very different to the ICO issuing a massive fine. I would advise whoever you spoke with at the council to contact the ICO to get clarification as other LAs have no issue with this.

Posted
Google has 12 european datacentres, but how can anyone give a guarantee that data isn't backed up / load balanced back to the US? The Microsoft data centers will be part of a global infrastructure so can they guarantee where the data will be at all times? It makes sense to sync changes worldwide if you can so that while the US is asleep if you can use the idle capacity.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...