Jump to content

paulkerton

Members
  • Posts

    3,344
  • Joined

  • Last visited

Everything posted by paulkerton

  1. Are you all on the same ISP? 429 is rate limiting, it could be that multiple schools sharing the same external IP (via a proxy or carrier-grade NAT) are collectively triggering the limit, rather than it being a Bromcom infrastructure problem per se. We've seen similar in the last few weeks with Google Admin Console.
  2. We can't be the only ones scratching our heads over this one! Supply staff. Schools can't run without them but from an IT and safeguarding perspective, they sit in this really awkward middle ground. They need enough access to actually do their job on the day, but they're in and out so fast that proper account management often goes out the window. So what are you all actually doing? I know a lot of schools are still handing out a shared "supply" login at the front desk. I get why as it's quick and easy when someone rocks up at 8:15am, and need to be teaching within 30 minutes. But then MFA comes along and suddenly nobody can agree whether it should be on a phone, whether it should be a hardware key, what kinda device they get to access, do you just generate one-time passcodes... and then the password gets written on a Post-it, and before you know it you've got no idea who's actually been logging in and whether the account has been reset nightly. Most of this has just grown organically because schools are busy and people are just trying to get through the day. But I think it's worth trying to figure out what a sensible approach actually looks like, especially as Cyber Essentials and general expectations around account security keep moving the goalposts. Are you using named accounts for supply? If so, how are you turning those around quickly enough when someone's booked last minute? Have you found a way to make MFA work that isn't a complete nightmare in practice? Or are you still in the "we know it's not ideal but here we are" camp? Not here to judge anyone, cause I know this is a constantly moving target. I'm genuinely curious what's working (or not) for people, and how we can work this out as a sector.
  3. But we know how successful that will be (They will transmit personal info, let's be honest) so for the cost, you may as well get an encryption standard that isn't already popped wide open, surely?
  4. I wouldn't assess the likelihood of it happening first. I'd start with the likelihood of success if an attempt were made. The success rate is basically 100% because RC4 is broken and SDR hardware is cheap. They wouldn't even need to be within 10 miles since high-gain aerials can capture radio traffic from way further away. That instantly rules out RC4 and XOR. I wouldn't even bother with the rest of the assessment as it fails at the first hurdle. My insurer isn't going to cover me if I leave my front door unlocked because I thought the likelihood of someone trying the handle was low. Or if they find out I kept a key under the mat.
  5. Episode 5 is an absolute tonal whiplash, and back to what you'd more likely expect from the parent shows. Probably my favourite episode of the lot so far, mind!
  6. Yes it is. Almost the textbook definition of it. You're undertaking a risk management exercise but you're relying on: 1. The attacker would need to be within a 10 mile radius of the school 2. They'd have to be scanning the same frequencies you're using 3. They'd have to have the technical ability to break XOR or RC4. That is literally security through obscurity. You're suggesting weaker encryption is fine, based on the likelihood it'll be found. Plus, using known broken encryption to transmit PII would absolutely not be considered as an appropriate technical measure under the DPA. Low likelihood is not a security control. If someone wanted to do it, a RPi and an SDR aerial would have them listening in minutes. Once encryption is broken, there is no "technical knowhow" needed at that point. Theres like 100,000 amateur radio operators licensed in the UK. That's plenty of people who are bored, can't listen to the police radios anymore, and could be looking around for conversations. My answer would be to go with AES-256. If you can't do it properly, you don't do it at all.
  7. That's security through obscurity though, which probably isn't the best route. 🫣
  8. Well the guy that film was based on has bought options against Nvidia and Palantir. 🫣
  9. So the AI companies now have all the GPUs, RAM, SSDs and HDDs. ... whose now going to buy their products, if we can't buy a device to run them on? I cannot wait for this ridiculous bubble to finally burst. Nvidia, Oracle and OpenAI in particular will be in big, big trouble with all this circular financing they've done.
  10. https://schoolsweek.co.uk/reports-of-data-breach-on-class-charts-platform/ and I think this is all we have to say, really.
  11. I've started to notice a lot of Shadow jobs in schools all of a sudden. They've got to advertise them, but they send out communications about them really kinda too quickly for them to have done a proper assessment of the applicants, and must have someone in mind already.
  12. I would go the exact opposite way. Get screens with no OS on them and put an OPS in them instead. Android on these screens will never be supported for the length of time you'll be expected to keep them up and running and working. Schools are going to want 10 years out of those screens, and you're just not going to get that length of support.
  13. There is a restart the device option I believe? Then it says that the user is still logged in etc, and they use that. It's been a while since it was configured tbh, and I don't use Windows day-to-day.
  14. It's the eventual replacement to ChromeOS, and looks like ChromeOS to me - just with Android as the code base, rather than grafting Android onto the system later. I don't think there's much to see yet. Education devices won't see it until 2028 at the earliest, and most of the machines in students hands in particular will not be running this at all. We've got a long way before ChromeOS is phased out entirely. You're looking at 8 to 10 years.
  15. I've had some wild arguments about fast user switching. We allow students to lock their screens, but we don't allow fast user switching for all the various reasons already stated here. "But someone locked their computer and walked away" was my favourite. They were horrified when I said "Well, log them out then" as they feared the student losing their work. I pointed out that everything we do should autosave, and if it doesn't the child gets to learn an important life lesson. 🤣
  16. Nice little touch of copyright infringement there!
  17. I mean, logically it's potentially safe - but have they done any form of due diligence regarding Data Protection screening?
  18. Isn't this mostly down to the idea that child protection records must be kept separately from a child's main file? Now, I know this is technically true with permissions etc, but I'd imagine a lot of schools take that to mean a completely separate third party system, ie CPOMS or a MyConcern.
  19. I’ve always considered these organisations to be the IT equivalent of the Freemasons, really. Only they have the added bonus that membership doesn't grease the palms or open doors in quite the same way. You pay the fees, but the 'inner circle' perks never seem to materialise. But you get some letters after your name that no one will pay attention to, and everyone will cringe at if you use em, so there is that.
  20. So which are schools in this example? Non-enterprise or Enterprise? Logically as we have access to the Adobe Admin Console, and can use federation etc, we're Enterprise yeah?
  21. No. It isn't. I would suggest using an exam compliant platform like ExamWritePad, Orbitnote or Trelson. Trying to fudge your existing tools to work is a fast route to compliance issues.
  22. The only way to do this is to use WhatsApp for Business. You really cannot be using every day WhatsApp, it's a complete GDPR nightmare. Those parents did not give you permission to take their number an upload their details to WhatsApp servers. Instant breach. If school business is discussed on a personal WhatsApp account they're disclosable under SARs and FOIA requests. There are no eDiscovery solutions available for business use. If a staff member deletes a message that should've been audited and be in a trail, that's a breach of duty to maintain the records. A WhatsApp group exposes everyone's number to everyone else - That's a direct data breach Meta acts as the data controller, not a data processor. The ICO has ruled before now that if school business is conducted on WhatsApp, the messages must be produced for an FOI and not having access to it is not a valid legal excuse. It is not GDPR complaint for school use.
  23. They're a cyber essentials breach, so they either get isolated on the network so they really can't do much - or they go into the WEEE bin. Doesn't matter what staff want, frankly. If it's a security problem, it'll come back on you for allowing it once the poop hits the fan, despite staff protestations.
  24. Setting a precedent where schools manage personal property is a massive overreach. The idea that schools believe they can mandate it is also pretty wild. I guess the strategy is hoping 95% of parents just give up and stop sending devices in or switch to feature phones. Who is liable if the MDM bricks a £1000 phone? Blackout also requires location services to enable the geofencing. They recommend schools don't use the tracking feature but that's just ignoring privacy by design. There is a massive difference between a school's right to confiscate a device or asking staff to use MFA, versus managing and altering a personal device just because the user attends a specific school. The school didn't pay for it, they don't own it, and it essentially encourages parents to abdicate all responsibility for their child's digital behaviours to the school's IT department. Anyone monitoring it 24/7? Also, those magnetically locked pouches sound like a win until the kids inevitably organise a "set an alarm for every 10 minutes" protest. I can't believe anyone thinks any of these are a good idea, but that's just me.
×
×
  • Create New...