Jump to content

Recommended Posts

Posted (edited)

I really dont care for these privacy issues. You could debate them until the sky falls in and be no closer to getting a definitive answer.

 

What I do care about is the technology :) Now is there any way to map skydrive/dropbox to a drive letter? Or maybe have a shortcut in their current my documents automatically? We already have skydrive icon on student desktops but it tends to take ages to log in and upload something.

 

Would be awesome to allow students to keep their work on their skydrive accounts, since they all have live@edu already.

Edited by zag
  • Thanks 1
Posted
Really great timing with this as we are re-doing our Web Sense policies and have internal flack from IT tutors regarding Dropbox and the like. Think we will need to dig deeper into the SafeHarbour stuff and see where we really stand.
Posted
I really dont care for these privacy issues. You could debate them until the sky falls in and be no closer to getting a definitive answer.

 

If you work in education then you should care, or you will when you get sued up the yazoo for breaching the DPA where kids are involved

Posted
Now is there any way to map skydrive/dropbox to a drive letter? Or maybe have a shortcut in their current my documents automatically? We already have skydrive icon on student desktops but it tends to take ages to log in and upload something.

 

 

Gladinet maps

""Mezeo Amazon S3 FTP WebDav AT&T Synaptic Storage Internap XIPCloud Storage Google Docs Google Storage EMC Atmos Online Box.net KT ucloud storage Open Stack Nirvanix Peer1 CloudOne Rackspace CloudFiles Windows Azure Windows Live SkyDrive CIFS/SMB Caringo CAStor"""

to Drive letters

 

GLADINET - Cloud Storage Access Platform & Solutions

Posted
If you work in education then you should care, or you will when you get sued up the yazoo for breaching the DPA where kids are involved

 

Has that ever happened?

Posted
Has that ever happened?

 

There are a growing number of examples of schools being tackled for breaches of the DPA. At the moment this has resulted in them signing Undertakings so no fines (consider it a suspended fine ... not quite right but it should give an idea about what would happen next if anything goes wrong) but we don't know yet if this will have any impact on the next time OFSTED come to visit either ... and, unfortunately, that is likely to have more of an impact than the threat of a fine with some senior leaders.

Posted
Has that ever happened?

 

Also, kind of an irrelevant point - it doesn't matter if it has or hasn't happened. A geneticist has never created a hybrid human/lizard but the law is there to stop them before they do it. Whether or not a school has been prosecuted or sued for breaking a law is against the point.

 

Not to mention, as a school it is kind of the institution's job to teach moral strength. Breaking random laws because they aren't always efficiently enforced kind of teaches the wrong thing to our kids 'its ok to break the law if you can get away with it'. Not a lesson I'm a big fan of.

Posted
Has that ever happened?

 

Nope!

 

Even the most serious breaches ended up with just a little paperwork.

 

Pointless discussion in my opinion.

Posted
Nope!

 

Even the most serious breaches ended up with just a little paperwork.

 

Pointless discussion in my opinion.

 

A little paperwork?

Taking Action - Undertakings, Enforcement and Monetary Penalties - ICO

How about you consider an undertaking as the equivalent of a caution?

 

But I have sent a formal request to OFSTED to get their take on whether it would have any impact on an inspection as well. I do know, from talking with a few companies, that they would hesitate to deal with schools who have signed an undertaking in case there is another issue and it drags them down too.

Posted
I don't think many/any ofsted inspectors have much of a clue about IT infrastructure, policies, procedures and how it impacts T+L at least thats why we as network managers never seem to meet Ofsted. Ofsted are teachers after all, and if SLT don't understand DPA you wouldn't expect Ofsted to.
Posted
I don't think many/any ofsted inspectors have much of a clue about IT infrastructure, policies, procedures and how it impacts T+L at least thats why we as network managers never seem to meet Ofsted. Ofsted are teachers after all, and if SLT don't understand DPA you wouldn't expect Ofsted to.

 

It isn't just a DPA issue, its also a Child Protection issue, and that is something that as far as I'm aware, all Ofsted inspectors are supposed to look out for.

Posted
It isn't just a DPA issue, its also a Child Protection issue, and that is something that as far as I'm aware, all Ofsted inspectors are supposed to look out for.

 

bet they don't though. We've consistently received 'outstanding' management, without a clear DPA policy in sight.

Posted

Yeh same, we got outstanding last year and Ofsted didn't even talk to me.

 

Its a non issue in my book.

 

Both dropbox and Skydrive are perfectly safe to use in schools as far as I'm concerned.

Posted
It really is something that Ofsted should do though; In the past we got a lot of information from Becta. We still get information, and the occasional audit from the LA. I bet new academies and Free schools don't get any of this at all. Ofsted should up their game.
Posted
Yeh same, we got outstanding last year and Ofsted didn't even talk to me.

 

Its a non issue in my book.

 

Both dropbox and Skydrive are perfectly safe to use in schools as far as I'm concerned.

 

You think running a system where you know it is quite easy for staff to breach DPA is perfectly safe (i.e. dropbox) and you think it is a non-issue? In which case why don't you just stick up your home address, bank details, any interesting medical facts about yourself if you care so little for the DPA? Or is it that you just don't care because you don't think anything bad will happen to you personally if the people you work with get collared for it?

 

Do you not care about safeguarding?

Do you not care about protecting children?

Do you not care about protecting your colleagues?

 

If not ... then fine, we can happily ignore your contribution to the discussion.

 

If trolling ... then Meh! Considering the amount of hard work some people are doing to try and get this sorted in schools it is poor taste.

  • Thanks 3
Posted

What I don't understand is why Dropbox or Skydrive are any less safe than our VLE, My document shares, USB sticks, hard disks in a server room ect.

 

I have all kinds of confidential stuff on my personal drop box. But its protected with a username and password just like our other IT systems.

 

Just to explain where im coming from we use Skydrive everyday in a large secondary school. In the future I hope to move all our storage into the cloud just like I have our email systems which has already been a great success.

Posted
What I don't understand is why Dropbox or Skydrive are any less safe than our VLE, My document shares, USB sticks, hard disks in a server room ect.

 

You have the admin password or at least know the people who do, the cloud services don't have that luxury so unless you are encrypting all of your stuff again before uploading it you have less knowlege about the conditions of its storage.

 

Personally its up to you what you want to do with your own data but when that data is the schools it is up to the school to take that into consideration.

 

You also have local speed access to it on a locally hosted VLE when at school, with a cloud service you are limited to internet speed all the time.

Posted
What I don't understand is why Dropbox or Skydrive are any less safe than our VLE, My document shares, USB sticks, hard disks in a server room ect.

 

I have all kinds of confidential stuff on my personal drop box. But its protected with a username and password just like our other IT systems.

 

Just to explain where im coming from we use Skydrive everyday in a large secondary school. In the future I hope to move all our storage into the cloud just like I have our email systems which has already been a great success.

 

It comes down to this - UK and EU laws are directly controlled by our own government and representatives. Countries outside the EU are not. They can do whatever they want with their own laws, and therefore do whatever they want with your data.

 

If you don't have the protections of the EU data protection laws when you host your data in the USA, what is to stop them from exploiting a weak state's data protection law there and selling your data? Or making it public? You'd have no recourse in the UK/EU, and you'd have no recourse in the USA as they would be abiding by the state law...

 

We are legally required to ensure the integrity and security of our data, it isn't that difficult. Skydrive is covered by SafeHarbour as Microsoft are a certified provider. Not only that, but the data is stored on servers within the EU. So whichever way they handle it, it is covered by the law.

 

Dropbox isn't.

  • Thanks 2
Posted

That's actually the first good explanation I've seen about this.

 

I still think the likelihood of dropbox selling my users data is remote though. Especially as its stored most probably in the USA who you would imagine have similar laws and moral values.

Posted
That's actually the first good explanation I've seen about this.

 

I still think the likelihood of dropbox selling my users data is remote though. Especially as its stored most probably in the USA who you would imagine have similar laws and moral values.

 

It isn't just about selling etc... though. Its also about protections from, say, hackers etc... The company say they're using encryption but they could simply be lying. If someone managed to circumvent their security and get in and steal your data, in the UK they would be subject to various DPA related crimes. In the USA? Likely not...

Posted (edited)
What I don't understand is why Dropbox or Skydrive are any less safe than our VLE, My document shares, USB sticks, hard disks in a server room ect.

 

I have all kinds of confidential stuff on my personal drop box. But its protected with a username and password just like our other IT systems.

 

Just to explain where im coming from we use Skydrive everyday in a large secondary school. In the future I hope to move all our storage into the cloud just like I have our email systems which has already been a great success.

 

This could almost be a separate article all on its own.

 

A quick summary then ... and this is almost a stand-alone post so trying not to refer back to lots of previous posts.

 

1) There is a law in the UK (and equivalent laws within the EU which are compatible with it) called the Data Protection Act. This is a very clear law as to what people can and can't do with data and information of belonging to others, how you let others know you are going to use / handle their data and supported by 8 clear principles.

 

What this means : The 8 principles are pretty simple to follow and the key areas of concern with cloud based systems is where the data is stored, how it gets there and how access to it is controlled. This is not about risk management where you can be willing to accept the risk, as the law says you *must* comply with all aspects of it.

 

2) When you provide access to, manage or create a tool which may hold such data you have to apply all aspects of the law. This includes remote access to MIS, WebDAV based storage, cloud-based file sync solutions, IdPs, etc. If you have a contract with a system provider (e.g. VLE provider) they have a responsibility to also be within the law, but you ... as the purchaser of the system ... are also responsible to ensure they are doing.

 

What this means : If you provide a VLE then you are solely responsible for making sure you follow the law. If you buy a product in then you have to be happy that you know the vendor will also follow the law. If there is a breach then you are both at fault. If you don't know what they are doing and it is pointed out that there is the possibility of a problem (even if there hasn't been yet) then you are also at fault. An example would be that CEOP have had to sign an undertaking because their online forms did not transit over https ... they should have checked the creators of the tools did the job properly. You cannot pass the buck by claiming you didn't know any better.

3) Some systems are aimed at particular groups of people and will have contracts / T&Cs to reflect this. Although the T&Cs will have to operate within the laws of the land, you may be asking them to do more than can be expected to fit in with laws you also have to adhere to.

 

What this means : If you sign up for Dropbox it is expected that you know what you are doing, that you know that if you are using it for 'business' use that you are happy it fits within the laws you have to follow and that they are not held responsible for when things go wrong (and so begins a long discussion about whether companies can get away with this!) ... because you should have known better. It also expects that you are signing up for it as an individual and that you are not using it to provide a heap of other stuff to others ... If you want that then you go into a different contract and that is why they have Teams. In short ... as tempting as it is just to click 'I Accept' you really do need to read the T&Cs.

 

I know there are some generalisations in the above points but it should give enough of a background.

 

Discussion about whether the law is appropriate, will be enforced to the full extent, whether the guidance available (including previous stuff from Becta) covers everything it should do ... these are almost moot points. The law says "do X ... don't do Y!"

Edited by GrumbleDook
Some formatting for easier reading
Posted

OK, all makes sense :)

 

Simple question then.....

 

Assuming A Cloud Service doesn't loose/sell/hack our data: Do I have to worry about anything?

Posted
OK, all makes sense :)

 

Simple question then.....

 

Assuming A Cloud Service doesn't loose/sell/hack our data: Do I have to worry about anything?

 

Scatter gun police raids on data centers taking all the servers and with it your data?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...