Jump to content

filteringtech

Members
  • Posts

    93
  • Joined

  • Last visited

Everything posted by filteringtech

  1. We use Net-Crtl.
  2. 2 things. 1. How are you complying with https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/cyber-security-standards-for-schools-and-colleges ? 2. As someone always reminds me, in Sex Ed we require pupils to understand certain things about making babies, they don't have a practical class for this where they get to try it out. The same is true for some aspects of Computer Science, understanding how exploits work for example, is in the course syllabus, it doesn't mean they to get to practice on the school's "live" network.
  3. I was invited to book for a flu jab. When I got there (a couple of weeks ago), I was asked if I was having both flu and Covid. I opted for just the Covid vax as I sometimes get a reaction from the flu jab, which I still want, but not at the same time, so I'm back again this week for flu. It all seems a bit random as to who gets what.
  4. Well, I've never installed any school SSL certs on or ever attached any of MY personal devices onto a school network in over 20 years and will never do so, or login to personal accounts on a school network. We do have an opportunity to use filtering for other good reasons, and that is to block not just the ads (KCSIE), but as much as possible of the tracking and profiling ecosystem which can give our users a much better and actually more private web experience than they would normally get.
  5. Over 8.5 hours later, well after the end of the school day, the ticket gets an update that "that" problem is fixed, and it is.
  6. I have been trying to make some Netsweeper filtering changes, but its taking over 30 mins for the changes to take effect (both from seeing a result in a Trace Request, and even longer for the actual filter), which is problematic. Is anyone else seeing this? For anyone with Netsweeper not on Schools Broadband, how long does it normally take for a change such as an allow or deny to take place? Thanks.
  7. Now 5 hours, and its still sitting there unresponded to/unopened.
  8. Support ticket (as is our usual experience from Schools Broadband), remains still unopened/unresponded to after over 3 hours.
  9. We haven't for months. The "Recent News" in the Hub hasn't been updated since 4th August 2022. We even have support tickets that go unresponded to for months. Asking for Twitter images not to be whitelisted for everyone is one such example. (Now blocked by us for pupils, but for staff, I don't want them blocked but to be category processed so that at least the porn gets filtered out). On this one, I can't see how the "other schools" reason which we are always given, works as I cannot see any schools wanting even accidental, but predictable, access to porn.
  10. I'm getting a Connection Error when I access this. Anyone having the same problem? If you do a Trace Request, the Policy Server Log0 and Log1 are still down from yesterday evening.
  11. You will also need some commitment/contract review from ISPs and filtering providers where they supply the filtering and firewall. They "should" be on the asset side of the equation, but they seem to be more appropriate placed on the risk side. A firewall with no logging for example is practically useless. They also need to get up to speed with Cloud Architecture, specifically the difference between the cloud provider's platform architecture and the mass of user content hosted in the platform's cloud. I am truly AMAZED at the number of ISPs and filtering providers who when recently asked, just whitelist everything Microsoft for example "because its Microsoft" regardless that some is just phishing, malware and other regular crapware uploaded to Microsoft Cloud by any bad actor. The same is true for user content on Google, Amazon et al. You might not even know this "if the whitelist settings are hidden from you". Don't even think of getting me started on why they whitelist infected ad networks. Yes I know we have virus guards and the like, but a proper multi-layered approach needs each layer to be configured appropriately.
  12. I've discovered that it does work as intended "mostly". I was trying to force duckduckgo.com to safe.duckduckgo.com. That fails with too many redirects. Startpage for example now seems fine.
  13. And another thing. SBB hide some of the Shared Lists they apply to your Policy Groups. We tracked these down because some category blocks were failing. These involve the whitelistng of YouTube and a number of Ad serving domains amongst others.
  14. Schools Broadband whitelist twimg.com (all twitter images) "for everyone". I've had a support ticket open about it since 2/8/23 and no update since 7/8/23. Twitter images should at the very minimum get decrypted and category processed.
  15. Schools Broadband supply a Keyword Filtering list that they confirmed to us: The list contains words such as "adult", "teen", "lesbian", "gay", "bomb","breast" and others that really have no place being totally blocked in a modern system with contextual filtering such that History, PSHE, food tech and Biology can be delivered safely online, but that porn, and extreme content are not. The problem, as I know others are also aware of, is that the way that Schools Broadband have chosen to configure this, is if we allow the word "adult" in the manner suggested, any search including the word adult will bypass filtering. This also applies to urls, with adult delimited if it is added as a "Wholeword" or anywhere in the url if added as a "Keyword". All further filtering is bypassed, such that searches for "adult fetish", "adult porn", "adult beheading" go sailing straight through. For us, initially Schools Broadband denied that it worked like this until we presented irrefutable evidence a couple of months ago. The reason I am posting this is that I was offered the same solution yet again yesterday by an apparently senior person who "has an excellent understanding of the platform". Most schools, and indeed ourselves until last December take the advice of our ISP unquestioningly and expect them to provide the expertise on the tools they provide, and it is frankly astonishing that Schools Broadband are still providing advice to schools to unblock their Keywords in such a dangerous manner that totally disregards user safety and our own filtering obligations. If you are a customer of theirs, please check that you have not added any words as an "allow" to any Local or Shared lists in Netsweeper.
  16. If you have Netsweeper hosted by your ISP, you ought to check that your category settings are really being honoured. You may think you have Social Networking blocked for pupils, but, it might be that your ISP has already whitelisted Twitter images for you, for all users. There's some really unpleasant stuff in there, so its just a heads up that as part of your KCSIE checking that your pupils can't do search with a non-safe search search engine, or find another way to access them. This especilly applies to pbs.twimg.com which is the domain that hosts uploaded user images. Note: Everything that you or your ISP adds as an allow, bypasses content filtering and everything that is added as decrypt://site.com "allow"bypasses decryption.
  17. Yep, I'd already tried all the obvious combinations. Instead of trying to do a helpful redirect, I'll just carry on wielding the ban hammer.
  18. Rather than blocking them, I'm trying to replace search engines that don't have or enforce Safe Search back to Google as described here: https://helpdesk.netsweeper.com/docs/Flare/Netsweeper_Documentation/Content/WebAdmin_Content/Lists/List_Entries/Actions_in_List_Entries.htm Using startpage.com as the "New Entry" and Replace with google com. It looks fine in Trace Request, but the end result is https://startpage.com/google.com and the chrome browser error "startpage.com redirected you too many times" Does anyone else used this and has got it working?
  19. Just to say that there's a jumbo jet full of "things that pupils shouldn't be accessing" because of "a specific KCSIE" reason hosted there. We have it blocked with the items required for the Computing Science GCSE curriculum whitelisted. Ditto herokuapp, vercel and railway, which host "the same things".
  20. Just for the record, another (not Tom), filtering provider actually advises customers to override search words by adding an "allow" - including it in their online help.
  21. Both 4chan.org and 8kun.top are currently cagegorised by Netsweeper as the realtively innocuous "web chat" and "adult mixed content". They should probably both be in a category such as "extreme" "child abuse" or whatever that hits a safeguarding alert category. I have put in a recategorization request. Don't know now other filters are managing this. https://en.wikipedia.org/wiki/8chan
  22. I don't have an answer, but I am completely conflated that if/when pupils (particularly older ones), get to know that when certain things are typed - they will be approached by school staff, that it will actually have a chilling effect on them seeking information on Childline or other reputable organisation before they are ready to talk to a member of staff. We also have noticed quite a few what turn out to be "lean-overs" which is usually a "p***hub" search which in our case never turns out to be the pupil signed in but a "prank" by another pupil.
  23. TOTALLY with you on the use of "Keywords", and I wouldn't let the 99% garbage reports we get anywhere near our very busy DSL lead. To quote my provider's email: Our local theme park is Pleasure Wood Hills. "Pleasure" is on their banned word list. That crops up quite a lot. They also ban - Biological names of parts of the body, key terms in the history syllabus, some Computer Science terms, anyone called "Dick" or "Karim" and the names of a handful of 40+ year old women amongst other things. The filter is context aware, which should make the words safe to search for. The list is on a take-it or leave-it basis as it can't have anything removed. If they don't get with the program (KCSIE 2023), it will be a leave-it.
  24. Impero will do it too.
  25. I get your reasoning, and indeed ran the test myself at a couple of schools months ago. There are things that concern me. The first is, that we "have to test". I think its reasonable to assume that the "well known sites" will be blocked, and you are only really going to know that your filtering is working if you can find and try to access some "new" and or obscure ones, not just adult sites either. An image search using any search engine that isn't blocked and doesn't support "safe search" (if you or your provider allow such a thing for pupils), will suggest if your filtering is working or not. You need a process that logs that you are going to do this, that somebody else knows, and what the outcome is. I am actually more worried that by testing the obvious (well known sites), we are lulled into a false sense of complacency. It may be that a governor or DSL does the SWgfL test to see if we are really checking the logs? I get concerned by things like finding thngs such various "online 1 to 1 adult video chats with strangers" were being accessed by a student teacher. Admittedly on their own device, but going through our proxy as the sites were classified as "Social Networking" which is allowed for staff. Looking at logs for things that are blocked is much about about looking for FP's as it is about behaviour issues and trends. Only by sampling the "allowed" (which I do by dropping the user field for privacy), to look for "unusual things" will you find the real problems.
×
×
  • Create New...