hudzen76 Posted June 14, 2010 Posted June 14, 2010 Anybody else been taken by surprise as Google applications (Gmail, Picasa, Docs etc.) failed to work this morning? Found the article on the website explaining why they've done it (SSL searches on Google bypassing the filters) so appreciate why they've done it, but why do we only seem to find these things are happening afterwards, or is it just me?!
Mcshammer_dj Posted June 14, 2010 Posted June 14, 2010 there is guidance that has been sent out by SWGFL regarding this, together with advise on what do regarding getting the block removed if required
morganw Posted June 14, 2010 Posted June 14, 2010 We should have been sent the email notifying of this last week, but only received it today after complaining that our Google Apps services had all been filtered. Even if I had seen the email I wouldn't have realised that 443 would be blocked for every Google service. I'm a bit stuck now, I've spent the last our testing squid rules, there doesn't seem to be a way to stop Google SSL searches without also stopping Google Apps. The both use the same domain name and the same port number. Are there any options to work around this?
K.C.Leblanc Posted June 14, 2010 Posted June 14, 2010 We got an email from Gloucestershire CC about it, but it was sent to the school's admin email adderess so it took a while to cross our desk.
localzuk Posted June 14, 2010 Posted June 14, 2010 Somerset CC sent out information about it this morning in their weekly bulletin (which I don't get, but someone in the office down here does).
nile_c Posted June 14, 2010 Posted June 14, 2010 Hi Folks. I've heard similar rumblings from E2BN and elsewhere in the country. Google have really put the cat amongst the flying rats here... As we see it, there are 3 methods to remedy the filtering concerns: 1. Block google.com HTTP&HTTPS. 2. Block google.com HTTPS only. 3. Full HTTPS interception. Methods 1 and 2 will break any web app that requires a Google Accounts logon and kill google.com in general. Boo :-( Option 2 is lesser impact - it still allows search, toolbars, and custom search etc. to work properly over HTTP. Option 3 is the most comprehensive - it allows your filter to work "as normal" with Google - just like 2 weeks ago :-) We will be publishing a white paper on this topic Very Soon TM, but our current best practice advice for those of you with in-house smoothies is Option 3 - HTTPS interception.
hudzen76 Posted June 14, 2010 Author Posted June 14, 2010 Cheers all, have received copy of email via unofficial channels. Looks like the good old Smartcache is flummoxed again, bless it. Definitely looking like a secondary solution will be needed at some point (naming no alternatives (cof smoothwall cof)), or a serious clampdown on anybody found using https to access Google which at least I can do at moment...
Devontechie Posted June 14, 2010 Posted June 14, 2010 Found this on the SWGfL website. South West Grid for Learning Trust - GoogleSSL 1
K.C.Leblanc Posted June 14, 2010 Posted June 14, 2010 Looks like the good old Smartcache is flummoxed again, bless it. Have you tried poking it, it's a simple being without aggression, which in my book makes it an idea candidate for poking.
Mr.Ben Posted June 14, 2010 Posted June 14, 2010 I had notification of this during half term, with the 'public' notification (to the headteachers) happening last Tuesday along with the confirmation that it was going to happen. It's a bit of a pita, but all the same it had to be done.
bgarston Posted June 14, 2010 Posted June 14, 2010 Anybody else been taken by surprise as Google applications (Gmail, Picasa, Docs etc.) failed to work this morning? Found the article on the website explaining why they've done it (SSL searches on Google bypassing the filters) so appreciate why they've done it, but why do we only seem to find these things are happening afterwards, or is it just me?! In B&NES we knew about last week BUT what SWGfL didn't tell us was that the filter is at the top most level so even our unfiltered 'net feed is filtered from Google applications that use https! :-|
clareq Posted June 14, 2010 Posted June 14, 2010 Is it just google.com that's running on https? We redirect google.com to google.co.uk
Mr.Ben Posted June 14, 2010 Posted June 14, 2010 In B&NES we knew about last week BUT what SWGfL didn't tell us was that the filter is at the top most level so even our unfiltered 'net feed is filtered from Google applications that use https! :-| That was the only reason I noticed it (I'm a B&NES Chap myself), as Staff complained that they couldn't get to there personal emails at lunch. I'm not quite sure what to say to them on that, apart from 'tough' and you'll have to wait!
tom_newton Posted June 14, 2010 Posted June 14, 2010 Is it just google.com that's running on https? We redirect google.com to google.co.uk Yes, but a redirect won't work on https - to varying degrees. Either the redirect won't apply to the encrypted traffic, or if it does, you'll get an HTTP certificate mismatch. You can't reliably redirect HTTPS->HTTP, except perhaps via MITM, which obviates the need for such tricks in the first place.
hudzen76 Posted June 15, 2010 Author Posted June 15, 2010 OK, starting to get updates through on email now; they did manage to link to a blocked site the first attempt, though - say no more...! Text of Google blog below... ------------------------- An update on encrypted web search in schools Monday, June 14, 2010 at 8:59 AM We recently launched a beta version of encrypted (SSL) search at https://www.google.com to prevent people from intercepting our users’ search terms and results. However, because encrypted search creates an obscured channel between a user’s computer and Google, users who go to https://www.google.com can bypass some schools’ content filters. This can make it hard for schools to stop students from accessing adult content. One option is for schools to use our SafeSearch lock feature, which is designed to help keep adult content out of our search results. But given how many computers some institutions have this is proving impractical in many cases. So to prevent students from bypassing their filters, some schools are blocking encrypted search. However, a side effect of this action is that it also blocks other services hosted at Google’s secure URL, including Google Apps for Education, and many of our other services which require authentication to keep information safe. We’re working hard to address this issue as quickly as possible and in a few weeks we will move encrypted search to a new hostname – so schools can limit access to SSL search without disrupting other Google services, like Google Apps for Education. Longer term, we are exploring other options like moving authentication to its own hostname so that we can return encrypted search to https://www.google.com. Safety and security matter to Google, and we are committed to working with our partners in education so that we help keep students safe and secure on the Internet. Posted by Dave Girouard, President, Google Enterprise ----------------------------- 1
ICT_GUY Posted June 16, 2010 Posted June 16, 2010 (edited) Lost without gmail and apps here. I have applied for it to be unblocked, as it is unlikely to be a major problem here with less tech savy junior school kids. If they were caught using ssl and searching for stuff that was less than savoury then they would loose their internet privileges. As an interesting aside, there have been rumblings about Ofsted wanting unfiltered access to the net for all kids. We should be teaching them what to do to avoid harmful content and what to do when they find it rather than trying make a pretend "safe" internet. With upwards of 90% of the net dedicated to pr0n and freaky stuff its always going to be easier to teach kids to avoid that to try to block every objectionable site. Edited June 17, 2010 by ICT_GUY
ICT_GUY Posted June 16, 2010 Posted June 16, 2010 Just got this. This message gives an update on the 'Google ssl searching' issue I informed you of last week. Google have acknowledge the problem and this link explains how they are going to deal with the issue: Official Google Enterprise Blog: An update on encrypted web search in schools Put simply, Gmail & Gdocs will remain on https://www.google.com but Google will move their 'encrypted search' service to a new URL. At that point SWGfL will be able to remove the block on https://www.google.com However, the Google statement says this will be "in a few weeks".
Devontechie Posted June 17, 2010 Posted June 17, 2010 I've just had this via email from SWGfL: Good News - You can now control access to Google SSL pages yourself As you may be aware Google have recently released a beta version secure search engine. This new search engine allows users to search the internet, with their search terms and results encrypted. This encryption bypasses the filtering system in place and is affecting many of the mainstream filtering suppliers to education. This means Google Secure Search will return results for ALL search terms, including video/picture thumbnails. Users who attempt to click through to inappropriate sites will find these pages subject to normal filtering policies. For more information click here. To ensure the continued online safety of all users, the South West Grid for Learning has taken the decision to block ALL traffic to secure Google sites. The knock-on effect of this is that access to other secure Google sites, such as Gmail, Google Apps and YouTube will also be blocked. The South West Grid for Learning are aware a number of customers use these Google services, and as a result have added a new filter list to your SWGfL Filtering service. This gives schools the ability to quickly unblock access to these sites. The new filter list is called “Google Secure Services (Inc GMail and Calendar)”. To grant access to these sites again, your SWGfL Filtering administrator will need to un-check this filter list in the admin interface - https://admin.filtering.swgfl.org.uk. If you are unsure of the process to unblock these sites, please contact your normal support provider. Remember, you can also reset your password for the admin interface in the latest version of SWGfL filtering by going to the Settings page. NOTE: By granting access to GMail, Google apps and other secure Google services such as YouTube users will gain access to the Google Secure Search. As explained above, this will give users access to an unfiltered search engine. Any attempt to view an inappropriate site from these search results will be subject to normal filtering rules. The SWGfL and RM are working with Google to find a longer term solution and will update all customers once a more permanent resolution is found. You can find the latest update from Google here.
morganw Posted June 21, 2010 Posted June 21, 2010 Anyone else just being informed by their LEA that they might be fined £500,000 if Google Apps data is found to be outside the EU?
localzuk Posted June 21, 2010 Posted June 21, 2010 Anyone else just being informed by their LEA that they might be fined £500,000 if Google Apps data is found to be outside the EU? I seriously doubt that is true, as the US and the EU have the 'Safe Harbor' agreement, which Google is registered with. US Safe Harbor
morganw Posted June 21, 2010 Posted June 21, 2010 If it transpires that the data is hosted external to the European Community I am advised that this would not be considered acceptable practise by Cornwall Council. That's what the email says. I think Live@Edu would be out too as the same restrictions apply.
john Posted June 21, 2010 Posted June 21, 2010 We had a discussion over this at our last IT Managers meeting in N Yorks, and it was said that Google Mail for schools etc was out as Google store data outside the EU which isn't allowed, but Microsoft Live@Edu stores it in a new data-centre they have just got within the EU so that is a good possibility for N Yorks Schools to replace the existing Scalix E-mail platform.
GrumbleDook Posted June 21, 2010 Posted June 21, 2010 Live@edu is hosted in Dublin, with fail-over to Amsterdam. Google do abide by and have a safe harbor agreement which is accepted by Becta and ICO. The fine of £500k would be from the ICO ... who don't have a problem with the Safe harbor agreement? A council not accepting this as acceptable practice is very different to the ICO issuing a massive fine. I would advise whoever you spoke with at the council to contact the ICO to get clarification as other LAs have no issue with this.
morganw Posted June 21, 2010 Posted June 21, 2010 Google has 12 european datacentres, but how can anyone give a guarantee that data isn't backed up / load balanced back to the US? The Microsoft data centers will be part of a global infrastructure so can they guarantee where the data will be at all times? It makes sense to sync changes worldwide if you can so that while the US is asleep if you can use the idle capacity.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now