Jump to content

Recommended Posts

Posted

Out-of-box solution would be setup Windows Server 2008 firewall, it's picked up as a separate nic. Each SQL instance locks to a TCP port, so you've instancely limited to SIMS2008 instance. Not difficult to do, I would have SQL setup to log successful logins as well.

 

I'm not a security expert, so I can't comment. I'm sure Capita would have consulted a security expert when they were developing it to ensure it's the best, most secure solution.

 

Personally, this discussion needs to go on SupportNet, at least people are checked, so it's not other companys poking Capita. Anyway, IMHO.

Posted (edited)
Personally, this discussion needs to go on SupportNet, at least people are checked, so it's not other companys poking Capita.

Well spotted matt40k! I wasn't going to say anything but its been a long day!

 

ROFL.

Ask a few simple security questions that should be of interest to anyone allowing any incoming to their LAN, reference something I just read in another thread and:

Duh.. lemme see..

oh yeah, 2 + 2 = 22 so

::lightbulb::

You can only be some undercover secret agent working for the Capita opposition!!

 

How extraordinarily Kafka-eqsue... my, I will cherish this one!

 

Or maybe not ::sob:: - are you perhaps, talking about the first post matt40K replied to? But even so you've sucked me in without so much as a.. I'm currently directly on the public pay-roll like most everyone else. I do however have some security in my past and present, thus would like people to care about these kind of issues... y'know as in security of their sensitive data.. that pesky thing the Cabinet Office downwards started getting very fretful about the other year.

 

PS:

I'm sure Capita would have consulted a security expert when they were developing it to ensure it's the best, most secure solution.

 

Good for you. Meanwhile people like Ross Anderson seem to have managed to find security issues in big public sector projects run by other folk who can get some decent consultants, if not the spooks in. It seems highly unlikely Capita wouldn't have done this "nicely", but it really shouldn't hurt to ask or answer.

Edited by PiqueABoo
PS:
  • Thanks 1
Posted (edited)

Oh dear Mr Neal! You can hide behind "who might be bashing Capita" if you like, but a serious question has been asked here and YOU have not provided ANY substantial detail to answer it!

 

The level of technical understanding to properly configure a firewall is considerable and if done badly, will be disastrous! Tying down access using a Firewall doesn't prevent people from probing other TCP ports for example, so it needs doing properly. Who at Primary school level will be doing this, and if it's being done by an outside body (even the Local Authority), how much are they telling the school in terms of what the precise level of access will be?

 

I wonder also as to "who" will now be held responsible for the safety of personal data given there is 3rd party access (and risk)?

 

I think 'PiqueABoo's points about authentication need answering .... not palming away as being paranoid.

 

For myself, I would not sanction a permanent VPN connection unless I was in charge of setting it up personally. I fear that this will not be the case for lots of schools!

 

Lastly, and this will not be received well by some; I'm really tired every time someone challenges Mr Neal (or Capita generally) with a reasonable question or concern, that they get accused of being an anti Capita agent! It is perfectly reasonable to ask questions for goodness sake - but more importantly to GET ANSWERS!

Edited by Nuttyprof
Posted

I'm failing to understand what your problem is. VPN stuff was orginally used by Capita for centrally hosted SLG (SIMS learning gateway), why are you now complaining? Only thing I can think of is you have something to with a certain SIMS > SMS company (quiet rightly so that they are narked off), thus my SupportNet comment.

 

The way it works in Suffolk, is the school contacts Capita, they agree to purchase, School signs CSD's code of connection, Capita signs CSD's code of connection, CSD opens VPN connection to Capita's VPN, Capita installs VPN (+ SLG\InTouch (or school does), school confirms ok (or contacts CSD to confirm). By Capita signing the code of connection, if the data is leaked via the VPN (or such), it's Capita fault and they are liable.

 

Doing it this way, you are 1. sure you are connecting to capita, 2. the data is encrypted, 3. capita can only access what they are suppose to, 4. anything they do is logged against a capita user\ip, 5. It's there problem if something happens.

 

Does that make sense or have I missed something?

Posted
So, does the config you get by default limit it just talking SQL protocols from Capita-land (and how would that be limited to a specific SQL instance)? And if not where/how do you configure what's allowed to pop out of it at your end? Apparently doesn't use certs for mutual auth. either so how good is that shared secret and how widely is it shared i.e. are they unique per site and what's the entropy like?

 

Not got inTouch installed yet, biggest issue has been the direct debit requirements rather than the VPN. The vpn is openvpn and appears to be using a site specific certificate.

Posted (edited)
I'm failing to understand what your problem is. VPN stuff was orginally used by Capita for centrally hosted SLG (SIMS learning gateway), why are you now complaining? Only thing I can think of is you have something to with a certain SIMS > SMS company (quiet rightly so that they are narked off), thus my SupportNet comment.

 

What gives you the right to make comments like this! Just because someone dares to ask a reasonable question from Capita, or god forbid even criticises! Sounds to me matt40k (looking through your posts) that you either work for Capita or are on the payroll given how quickly you jump to defend every comment or question made against Capita! I'm afraid to burst your bubble but I do not work for an SMS company or an MIS competitor! You keep guessing, because thats all you're doing at the moment. And BTW we don't use SLG so why would we be used to a VPN connection already! What an arrogant ignorant attitude.

 

The way it works in Suffolk, is the school contacts Capita, they agree to purchase, School signs CSD's code of connection, Capita signs CSD's code of connection, CSD opens VPN connection to Capita's VPN, Capita installs VPN (+ SLG\InTouch (or school does), school confirms ok (or contacts CSD to confirm). By Capita signing the code of connection, if the data is leaked via the VPN (or such), it's Capita fault and they are liable.

 

This information is at least useful.

 

Doing it this way, you are 1. sure you are connecting to capita, 2. the data is encrypted, 3. capita can only access what they are suppose to, 4. anything they do is logged against a capita user\ip, 5. It's there problem if something happens.

 

Does that make sense or have I missed something?

 

Yes, I'd have quite liked some kind of apology for being tarred with the same brush as your troll (you're not that distinguishable BTW).

I agree you deserve an apology but if you're referring to me as a TROLL, then perhaps you owe one to me also!

 

 

 

Like I said previously, I'm beginning to think this forum is a closed shop and that any comments/question against Capita (however justified or in the public interest) are not wanted.

Edited by Nuttyprof
Posted

The only argument I'm hearing people saying on here is VPN is insecure\not an ideal solution and the whole Capita holding data.

 

VPN being insecure is silly

VPN is an existing method (used for SLG) - cost savings, why reinvent the wheel

And Capita holding data is no different to your ISP holding copies of your emails etc - there still subject to the data protection etc

 

At least if you going to claim capita to be the spawn of Satan make a good argument, like the re-licensing of academies, or the high cost of the "extras", or the fact they've just stuck to two fingers up at companies like schoolscomms. I hate it when people moan without good reason, it's like me saying your network rubbish because of your server, then not explaining it's because your server has a rubbish raid controller. Especially when that server is your career\business.

 

Bah, brick wall.

Posted
if you're referring to me as a TROLL, then perhaps you owe one to me also!

 

::sigh:: I'm not going to spell it out, but there is a clear difference between these two: a) "the troll", b) "your troll"

Posted (edited)
VPN being insecure is silly.

 

This is very frustrating and this is the most diplomatic way I can say it: You're not unique by any means, but you sound out of your depth.

 

Some VPNs have been inherently insecure e.g. PPTP back when I was energetic enough to actually start XORing ciphertext excrypted with reused keystreams etc. AFAIK there are no such concerns with OpenVPN, but that is perfectly capable of being worthless unless it is configured appropriately. If you want an analogy Windows passwords can be OK, if you turn off LANMAN hashes and if they are are reasonably "complex" (I prefer to talk about entropy because a good password doesn't have to follow the MS rules).

 

To put my reasonable questions in simple terms: What has been configured to stop someone hostile sitting on a beach on the other side of the world from getting into a system via that VPN? What stops some theoretical bad apple at Capita getting into more than your SIMS?

 

It's really interesting that you feel some kind of contractual blame-shifting i.e. anything bad happens to part of a school network then it's OK because Capita get the blame, is the end of the story. Perhaps I'm weird, but I would feel 100% responsible if anything bad happened to my network that could have been avoided had I pulled my finger out and asked a few questions. The answers to the questions may well be perfectly good, reassuring ones, but lacking any I automatically assume the worst - I've seen more than enough reasons not to fold because [insert Big-Company-Name or Security-Celebrity Here] says "hey, it's secure, don't worry!".

Edited by PiqueABoo
  • Thanks 1
Posted

If you want to have an indepth discussion about details of the VPN link, phone them up. They're not going to publically post detail as that would be a security hole. They may give more details out on SupportNet then a public form having said that.

 

PS: Yes, I know it'll be a pain to get hold of someone who actually knows the system inside out

Posted

(To avoid doubt, I am a Capita employee, posting a personal view)

 

A colleague and I presented at the EduGeek conference earlier this year on the subject of centralisation and virtualisation of the general IT estate in the public and private sectors and I picked up on your comment;

 

"Mr Neal seems to think it will all end up in shipping containers sooner or later. Personally I think there still a few cost of bandwidth vs. increasing data bloat issues to contend with. Plus with a lot of business critical eggs in a basket the very first outage longer than say 36 hours i.e. hitting Day 2, will put a lot of folk into reverse. "

 

and would like to explore this a little.

 

Its my opinion, as expressed at the conference, that industrialisation of the data centre will drive very large cost savings for end users. Technologically the missing link has been stable and ubiquitous internet connectivity, but there seems to be a general acceptance that internet connectivity is no longer luxurious but essential to businesses in the UK. Google, Amazon and more recently Microsoft I believe have shown the way industrial levels of computing power can be placed at the disposal of end-users at a predictible and relatively low cost.

 

I made the point at the conference that owning a server within a school (or any other SME) might seem idiosyncratic within a medium term timescale, as performance, security, uptime and scalability could be more cheaply and more dependably provided by a industrial computing "power company" off-site. There may be special circumstances where this formula did not work - for instance in defence, healthcare and other critical national functions. Even then, distributed computing might not provide a better service than a centralised node (the RNLI currently host their SAR IT on Microsoft Azure).

 

Having made a case for centralisation, I am interested in the opinions of within the forum to understand the opposite point of view.

 

Since the internet is a routed protocol, and was designed partially to give a high availability in spite of network degredation, what would be the major concerns of a school or educator in off-siting (note: not neccessarily outsouring to my Company - such an arrangement might be provided within the Public Sector) their school MIS ?

 

I realise there are a number of schools where physical internet infrastructure provision is not yet capable of providing a good service - and assume for the purpose of future-gazing that the "provision will follow the demand" and these blackspots will be filled in much like they were in cellular phone coverage a couple of decades ago. Other than this hurdle, what would an educators general concerns be about off-siting ?

 

Thanks in advance.

 

Phillip

  • Thanks 1
Posted

Just my 2penneth.

 

We signed up for SchoolPost this summer. it doesn't bolt onto Sims like others but rather is a online version where you securely upload the contact info to their website.

 

little rough around the edged but I am very impressed with it so far.

Posted (edited)
Since the internet is a routed protocol, and was designed partially to give a high availability in spite of network degredation,

 

It's better nowadays, but I haven't noticed the Internet actually being all that good at "routing around trouble" and as you get out towards the Internet users there are often no alternative routes to take.

 

But it's the application layer that concerns me most. Imagine some web-fronted service in the cloud & this is what you might depend on right now: target DNS server, local DNS server, RBC[1] DNS server, proxy/filter, RBC proxy/filter, RBC firewall, target firewalls, load balancing gizmos, complex multi-tier service (with truckloads of disks at the bottom). YMMV but one or more of the first few have had sustained outages around here in recent years.

 

If you envisage (it's not clear) most everything in in school being some fancy 21st century terminal you still have most of those, but it's not obvious to me that anyone could put together a service that meets all the current requirements in a school, just some of them. Perhaps those apparent requirements can be massaged into a more achievable set, I don't know.

 

The many BSF debates seem relevant - compare and contrast a) local resources with people who can (admittedly not always) go do something about an issue, with b) the very well-established fun and games you have trying to battle your way through support desks and actually get something done this week if you're lucky. Add enough extra money and the latter can get quicker but then we're chipping away at those very large cost savings.

 

I'm a life-trained cynic - and costs that initially look smaller have a nasty habit of turning much bigger. What might look reasonable from a stratospheric viewpoint, can turn out to be rather complicated and much more expensive than expected when you do start drilling down into that devilish detail.

Edited by PiqueABoo
inevitable typos!
Posted
Some interesting comments here, I particularly interested in the potential conflict of interest between Schoolcomms and Capita. Now working on the periphery of SIMS and school, I had a very good working relationship with both last year, and interested to now how this development of inTouch has come about.
Posted (edited)
Some interesting comments here, I particularly interested in the potential conflict of interest between Schoolcomms and Capita. Now working on the periphery of SIMS and school, I had a very good working relationship with both last year, and interested to now how this development of inTouch has come about.

 

Hi Greed,

 

It isn't just about schoolcomms! this decision to enter the comms spaces should sound warning bells to EVERY CAPITA PARTNER!

 

Other Capita partners in this space alone are Truancy Call, ParentMail, Keepkidssafe, Teachers2parents, Groupcall and so on. All of these companies are paying Capita for the right to be 'partners', and they have all been stitched up.

 

This isn't a one off either as Capita have a track record of doing this. (look at parentpay and pass - both of them had the same treatment when SIMS introduced lesson monitor and the dinner money module)!

 

Why - take a guess ... Money, profit and most importantly .... To control the market. Capita don't want any companies getting too big a foothold in the education space so as soon as a company starts to do well and get a good number of schools using their product/s .... You've guessed it .... In come Capita with a 'built into SIMS' option thats easier and cheaper!

 

I had the MD of ParentMail at my school recently, and he told me that he has personally contacted the CEO of Capita (Paul Pindar) to try to persuade Capita to consider producing a 'partner charter' which would grant partners a guaranteed amount of notice if they intend to enter a partners space. Guess what ... He didn't even get a reply! He also told me that he was given only one terms notice that Capita were planning on entering the comms market!

 

To my mind this type of behaviour by Capita is despicable and I've said before schools should act with their feet and refuse to use InTouch.

Edited by marshharrier
  • 2 weeks later...
Posted
Anyone interested in InTouch\SLG, Capita will charge for re-installation (VPN etc). Just something worth thinking about when your getting a new server\InTouch.
Posted
Hi Greed,

 

It isn't just about schoolcomms! this decision to enter the comms spaces should sound warning bells to EVERY CAPITA PARTNER!

 

Other Capita partners in this space alone are Truancy Call, ParentMail, Keepkidssafe, Teachers2parents, Groupcall and so on. All of these companies are paying Capita for the right to be 'partners', and they have all been stitched up.

 

This isn't a one off either as Capita have a track record of doing this. (look at parentpay and pass - both of them had the same treatment when SIMS introduced lesson monitor and the dinner money module)!

 

Why - take a guess ... Money, profit and most importantly .... To control the market. Capita don't want any companies getting too big a foothold in the education space so as soon as a company starts to do well and get a good number of schools using their product/s .... You've guessed it .... In come Capita with a 'built into SIMS' option thats easier and cheaper!

 

I had the MD of ParentMail at my school recently, and he told me that he has personally contacted the CEO of Capita (Paul Pindar) to try to persuade Capita to consider producing a 'partner charter' which would grant partners a guaranteed amount of notice if they intend to enter a partners space. Guess what ... He didn't even get a reply! He also told me that he was given only one terms notice that Capita were planning on entering the comms market!

 

To my mind this type of behaviour by Capita is despicable and I've said before schools should act with their feet and refuse to use InTouch.

 

Fully aware Marshharrier that Schoolcomms is not the only one by a long shot (but the only one I have dealt with!), but agree 100% it appears to be an unstable relationship being a Capita partner, not being one of trust, but merely convenience for a time... I suppose a stark warning to all would be partners to patent ideas, intellectual rights and all that other stuff quickly!

  • 3 months later...
Posted
Have there been any developments in this discussion recently? we are looking for an SMS solution, but with some of the solutions requiring 3 year buy-ins, we are nervous about whether these partner products will still be operational/supported in three years?
  • 2 weeks later...
Posted

The solution is in your own hands? The more schools that stay away from InTouch and support the small guys, the better the chance they will all still be around in 3 years time :-) and the less likely Capita is to keep treading all over their supposed partners!

 

Or you can just play straight into Capita's hands and take the safe option. Should be an easy decision for you - I hope.

  • 1 month later...
Posted

I had the MD of ParentMail at my school recently, and he told me that he has personally contacted the CEO of Capita (Paul Pindar) to try to persuade Capita to consider producing a 'partner charter' which would grant partners a guaranteed amount of notice if they intend to enter a partners space. Guess what ... He didn't even get a reply! He also told me that he was given only one terms notice that Capita were planning on entering the comms market!

 

Marshharrier - We are grateful for your support. To update members here, I never did hear back from Mr Pindar which is a shame as I had a 'partner charter' suggestion whereby Capita would give 12 months notice (perhaps longer) before entering a partners space. This would give the partner time to take evasive action or diversify their products to ensure their commercial survival.

 

More worryingly I received a letter on Thursday last week (7th April) from Phil Neal, informing me that Capita would once again be entering our space by offering payment functionality for parents. He gave no idea as to when exactly this would happen nor has he responded to my request for more information. I know he is a member of this forum so it will be interesting if he is prepared to debate Capita tactics in public?

 

As a small company employing 50 staff, it is very worrying that Capita seem intent on ruling the world. It really does feel like we (and other partners) are now paying thousands of pounds per year (partner charges) for the privilege of doing Capita's Research & Development.

 

I would be interested to know what members here feel about this action from Capita which will of course affect other partners too such as Tucasi, WisePay and ParentPay.

 

Paul

  • 1 year later...
Posted

Hi Guys

 

Still on the same topic of InTouch but with less Capita bashing!!

 

Has anyone got a clue how to move InTouch onto a new server? I have moved SIMS and FMS no problem at all but don't have ac lue how InTouch is setup and so therefore don't know how to move it?

 

Any clues would be useful please!

 

Cheers!

Posted
Has anyone got a clue how to move InTouch onto a new server? I have moved SIMS and FMS no problem at all but don't have ac lue how InTouch is setup and so therefore don't know how to move it?

 

 

Last time I checked, you can't you have to pay Capita to reinstall it, it was £260 + vat last time I heard. Give them a ring, I could be wrong.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...