Jump to content

paulkerton

Members
  • Posts

    3,344
  • Joined

  • Last visited

Everything posted by paulkerton

  1. British tourists to be banned from France amid rise in Omicron cases https://news.sky.com/story/covid-19-british-tourists-to-be-banned-from-france-amid-rise-in-omicron-cases-12497105
  2. The hardware in the 100e Chromebook is the same as the hardware in the 100e Windows machine. However, I definitely wouldn't do it. ChromeOS will run smoothly on the hardware, Windows certainly won't.
  3. I'm guessing the free, 30-day auto expiring on-domain only version of recording proved impossible to implement?
  4. If I was an LA, or an IPS or however LAs and Schools are organised now, I would absolutely be trying to diversify and provide & support multiple systems rather than going all in on one. Personally.
  5. I guess you haven't seen them recently. Big conspiracy theory antivaxx whoppers.
  6. Speak to a Google Education Partner. It is entirely possible. I did it at a Google training session. Married them up nicely, and used 365 to login to the Chromebooks. You will still need an account on the Google side to match to the account on the AzureAD side, but it doesn't need to be used. Vitalize, C-Learning, GeTech (not the vaccuum people) are good ones to reach out to.
  7. There is this: https://www.givemesport.com/1801044-abu-dhabi-gp-lewis-hamilton-has-max-verstappen-conspiracy-theory https://www.youtube.com/watch?v=pFu7VcU_FXs "Interesting that they like locked up in Turn 1 and all that kind of stuff. I'm a conspirac... no one locks up in Turn 1 so and even if you do it's not a big lock up anyways. So they obviously deliberately chose to go onto the soft in my opinion. I might be wrong but err..." The leaps of logic he makes are astounding. They could just change, they didn't need to flat spot their tyre deliberately to make the change. And this: https://www.reuters.com/article/us-motor-f1-malaysia-hamilton-idUSKCN1220NI And this: https://www.glasgowtimes.co.uk/sport/18754603.lewis-hamilton-park-fia-conspiracy-theories/ And otherwise there's this: https://www.bbc.co.uk/news/uk-53559934 He's got some crazy good marketing, I'll give him that.
  8. I think that depends on the size of the school and how actively it is used.
  9. It's almost certainly them, based on my experiences with them.
  10. Our LA connection fell over less than this, and that was dependent on far too old SQUID boxes and connectivity via the nearest High School as a node. Our office based staff are using their phones to tether to get anything done now.
  11. Our Primary will be moving.
  12. The most successful, most decorated, richest F1 driver of all time and knight of the realm. It's clearly a conspiracy. I saw someone claim it was "systemic racism", but I guess that only kicks in when you've equalled the number of most Championships ever claimed and earn $250,000 a day. I mean, did you see the video where he suggested that RedBull flat spotted their mediums on purpose so they had to change to the soft? They could change at any time, they didn't need to waste a set of tyres to swap. The guy is constantly spouting conspiracy theories and fueling his fans to go with them. He's Trumping the Championship. I wouldn't be surprised if he's got Right Said Fred and Van Morrison on his playlist.
  13. https://csrc.nist.gov/publications/detail/sp/800-160/vol-2-rev-1/final I dunno, I think the half a million per year, per copier might make that obvious - regardless. Might just be me mind you. Nonsense. Open security is completely different to relying on the goodwill of a vendor to make sure their security issues are patched.
  14. And now we have the same problem again... EDIT: SLT are now on the warpath. They're furious that this keeps happening. It's pretty disgraceful really.
  15. and do you know what a good way to penetrate your network would be? To know the exact make and model of hardware on your network and use a known exploit for that device to penetrate your systems... Because famously, being told you can't buy a replacement for a device that is out of support, but needs to be kept up and running because people use it never happens in the EDU sector does it? Because exploits always get disclosed and patched instantly, and are never taken advantage of, before even the manufacturers and developers know and patches never fail to do the job...
  16. Likewise, I could say the same of your judgement. You seem to think the law says you must disclose everything. It doesn't. At all. By any grounds. It explicitly has clauses that allow you not to disclose things that may be a security concern. I would argue with my DPO, or anyone else that disclosing information of this kind is a massive security concern and the last thing anyone should do is open up your infrastructure by basically doing the IT equivalent of saying to people "Well I'm not going to give you the keys, but I'll tell you the barrel code so you can go get one yourself and let yourself in" I would have real concerns with anyone who thinks disclosing this information isn't a potential problem.
  17. Absolutely completely not true! They're absolutely compatible to the point that NIST suggest that both are part of your strategy. As they should be. I'm not going to make "secret can't tell you" the lynchpin of my security systems, just as much as I'm not about to go "Well I'm fully patched so I'm totally safe, so I'll just advertise my public facing IP for remote desktop on my website and let everyone know exact the model of my Firewall, CCTV DVR and Copiers on WDTK and trust that Sophos, Microsoft, Hikvision and Canon haven't got exploits they've failed to patch or disclose" OK, so please tell me when looking at your CCTV and copiers without going near them anything other than the manufacturer? Generally, you can't. But please continue to ignore the fact that I've said disclosing manufacturers isn't an issue, but disclosing makes and models is, especially when it comes to equipment and systems behind. There is absolutely no public interest in knowing I have a particular model of a device, but there is to people who might want to attempt to use that device as a backdoor. It's not about hoping no one can find that information, its about not openly disclosing information that could be useful whilst using security by design practices to try and lock it down. Even segmenting your network wouldn't be enough if your hardware is still vulnerable. If you're basing your security by design principle on being able to close all attack vectors and hoping you don't have a huge security hole in a device that you've just disclosed is on your network publicy, then you're being naive at the very, very best. Having blind faith and trust in companies that produce your hardware such as OS's, copiers, firewalls to keep you secure without using all vectors available to you is absolutely wild.
  18. it works for ChromeOS sign on, so I've assumed that it should do Windows too, but you're probably best to ask them!
  19. We're still looking at Wonde's badges now we're able to set SSO at the OU level. Still a few things to iron out here mind you (Cheers ESS!)
  20. And I would argue, reasonably, that making each and every make and model of every piece of hardware you have freely shared in the public sphere is also indeed a security risk.
  21. Absolutely fundamentally disagree with you on the most basic of levels I'm afraid. It should not be the only layer, a dependent layer, nor should it be a main layer - but it should absolutely be a layer. A good system uses security by design, open security and security by obscurity in tandem. Witholding knowledge of what makes up your systems behind the scenes is different to camoflague. For those of you that don't think obscurity should be a part of it, if I put a freedom of information request in and I ask for "every email address and for each one, whether they are using two factor authentication for their cloud email account" how are you going to respond?
  22. Yes. I agree regarding public interest, but I would argue until Section 31 (Disclosure would be likely to prejudice the prevention of crime) and Section 36 (Disclosure would prejudice the effective conduct of public affairs) of the Act that detailed disclosure of models of equipment used could and should apply here as it could easily be used to launch attacks against your institution, just as it would if you were asked by FOI to disclose every single email address on your system. And these are the decisions people have to take in different organisations. Different DPOs and lawyers would argue differently for different organisations. I'm not saying I'm right and you're wrong. I'm saying I disagree that the detail is required and that the law requires you to disclose it and that it should be discussed throughly with your DPO and legal representation before you disclose anything. Ironically, just because you would disclose it, doesn't mean that all organisations would disclose it, and saying your organisation did so, so mine must is not and hasn't ever been considered a valid argument either. The company whose devices you use: Yeah, sure The number of devices : Yeah, fine. How much the cost of the contract is : OK. Fine. The individual make and model of each device : No need and no public benefit.
  23. Well perhaps it would be, but is that really the mechanism you want to do that with? I do not see where the public interest is in whether you're running a Fortigate FG/FWF-40F or FG/FWF-60F, personally. Fortigate or Sophos XG, yes.
  24. Strange how it changes for so many people in so many different ways isn't it? Jab 1 (AZ) left me with an aching arm for 4 days Jab 2 (AZ) nothing Jab 3 (Pfizer) 2 days into a aching arm, worse than jab 1!
×
×
  • Create New...