Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

pcstru

Members
  • Posts

    5,998
  • Joined

Everything posted by pcstru

  1. You didn't mention wireless, does that mean it is all OK or that you don't have any?
  2. I've had moletrap.co.uk since 1999. I quite like it as being short and easy to remember. It was originally chosen to annoy some people and it has continued to annoy people since then, most recently a deluded Australian inventor of free energy devices who keeps sending me threats of legal action and before that an Irish company called S t e o r n, now in receivership, were sending me legal threats. It does seem to occasionally be on spam lists (as spammers have in the past spoofed it into the From: ) but I think that is a problem for anyone with a domain.
  3. 4. is Sublogic, FS1, (I thought 2 was too).
  4. Done. Good luck.
  5. IMO, it depends - mostly on the risk of theft, but not all. Servers should generally have good physical security such that it is only possible for authorised people to access them. Those people generally have enough logical access that they essentially have access to the data and that is a trust based relationship (they are trusted with that level of access). So in that case the risk of theft is largely mitigated by trust in the people who do access the equipment and physically denying access to those without that trust. At the end of the equipment life is the risk of disposal - ensuring discs are properly wiped is essential. Which may highlight the biggest single risk - many people have policy and procedure which exists in document form only (i.e. it is written down that people should do X, but few know about it and fewer actually do it). Here, we do not encrypt server discs; we have reasonable physical security and disposal procedure is fair (discs always removed from equipment and handled separately). It does occur to me thinking about it that we need to be tighter on upgrades which can leave discs kicking about (which need to be wiped) and failed discs (which should be physically destroyed).
  6. We encrypt laptop hard drives using Bitlocker. We have policy that, if followed, would prevent staff from using unencrypted USB as data storage. I think I'll extend encryption to admin desktops, to cover break-ins. Overall if we lost data, it would be failure of the "organisational measures" (policy/procedure) that would kill us! (ETA - next May of course, what will kill us is management spending 2017 doing the Ostrich thing )
  7. I'd say the ICO is the best place to start. The GDPR seems to be similar to DPR in that respect. It is very unlikely that legislation will dictate what in any detail constitutes "appropriate technical means" (or even appropriate organisational means) - it would be very difficult to do so without either hobbling organisations or ending up in a few years time with out of date techniques specified. However, if you look at the actual judgements the ICO has made against organisations it is quite clear that NOT encrypting data is seen as a failure to provide "appropriate technical means". Subtle, 'eh?
  8. We loan laptops, netbooks and chromebooks out as part of a library loan scheme. We have separate student and parent agreements which need to be completed before a loan can be made. Loans are 24 hours or over weekends. We have been running this for 5-6 years and it seems to be popular and works quite well (a few instances of damage over the years which is to be expected).
  9. When you did it, you manually injected a mail and got a 250 (Requested mail action okay, completed) response? Did you telnet from the machine that is trying to relay (i.e. did you have the same IP etc). In the absence of good logs, I think to make progress I'd either packet sniff the outgoing connection from the relay (assuming mail is getting into the relay, is it trying to get out) or use a proxy to capture traffic and look at those conversations.
  10. You can telnet to an SMTP port and inject mail via a terminal. That may help diagnose what the issue is (and where it is occurring).
  11. Yes, we use them. I've not had any issues with them but we don't use them on anything particularly critical.
  12. IMO the powerful tools lack curation (i.e. they connect to the raw database, so are difficult for MIS users to learn and drive (reverse engineer a schema and learn a new tool while trying to do that!)), while the curated tools like the Bromcom API tend to be highly constrained and clunky (which means they get slow as soon as things become complex). Somewhere between the two is where I think there is an opportunity being missed.
  13. Auditors should be open and transparent about what they think constitutes proof of compliance, so if you are in any doubt, it is worth asking them. In my experience, 'compliance' (to almost any standard) is usually more about process and procedure, not just the certification/approval of a product. Where product certifications are required to demonstrate compliance, they would be asked for but it is usually the case that certified products are quite capable of being abused or ignored (so overall compliance would fail) in everyday working, hence why audits tend to focus on process and procedure (are people aware of it, if they are, are they following it and documenting that (filling in the paperwork)).
  14. I'm curious as to how many people you will roll this out to? We are a fairly large secondary (1800 students) and it is on one users PC (our Data Manager). There is very limited security over the information you can access (the add in uses it's own API login so permissions are global to that) so you need to ensure that whoever does have access, is OK to access all of the data in the scope of the API. IMO it is also clunky and not terribly useful - it basically saves a couple of clicks that you would need to run a report and export to csv. A shame really as anyone who can conquer integration between the MIS and Excel will have a killer product.
  15. I'd say no. You have no agreement with them or their parents to abide by any school rules and you have no way to enforce those rules. If they were being bullied or groomed via that account (or using it to bully students at your school), the school would be at risk of financial (they would be liable) or reputational damage. The best way to manage that risk is simply avoid it in the first place.
  16. How? Persuaded them that by the time they have sorted monitors, keyboards and mice, the saving over a cheap PC is actually not good value especially when considering the support overheads of an additional platform to learn, configure, secure and manage. Unless they are doing stuff with GPIO pins, a linux VM is likely to be a better solution (but ultimately it does depend exactly what they intend to do). If the requirement is to accessing them over a remote console (so no physical access to GPIO), a PI like VM might just be suitable as a real PI.
  17. This thread may be of some help. Actually, it might have been This one.
  18. There seems to be some competition going on here. I thought a days notice for an exam was a bit short but we have a new record holder : "Support for your exam at, did you say 3pm? Err, 3pm today? That's ... in 7 minutes? No, of course, we will be delighted - you know we have just been sitting around waiting, wondering what we can be getting on with. Thank you so much for saving us from what would otherwise have been another tedious, empty hour."
  19. I worry I might be beyond that - EduCrack. But no, m.u.s.t ... b.e ... p.o.s.i.t.i.v.e .... "At least they asked AND before the exam too!"
  20. Heh, you can ignore this then. Personally, unless you know you need some feature that a particular body provides, I'd invest in glass. One idea; a nice prime lens will force you to think a bit more about composition and position and should produce extremely good quality images.
  21. "You have an exam scheduled for tomorrow and you have had everything prepared for over a week. Colour me impressed!"
  22. We use : Sharepoint - where collaboration between/to staff is required. Google Apps (Sites) - Where collaboration with/between students is required. Wordpress - To communicate to parents and the public.
  23. Sirloin Salad (My take on a Thai styled salad - the steak makes this a substantial salad with the lime and coriander dressing cutting through any fattiness of the meat to keep this feeling quite fresh and light ). Approx 10 Mins to make : Steak rubbed with garlic and seasoned, cooked as you like it (Med Rare for me). Add some chopped spring onion about 30 seconds before it is done. Set aside to rest. The salad is mixed leaves, cucumber, grated carrot, red pepper (capsicum), vine tomatoes. I drizzle a little mayonnaise on (more for looks than texture or taste). Finally, squeeze juice of a lime into a bowl, add salt, pepper and some chopped fresh coriander leaf. Slice the steak into thin(ish) strips toss in the dressing and then place on top of salad. Drizzle any remaining dressing onto salad. (Poor photo).
  24. I agree that this should not cause a problem and I'd not give access to an ex member of staff on the basis that they are not contracted to follow any of our policies relating to safeguarding, data protection etc. If I was feeling particularly co-operative (helping someone falsify their theory that another account matters), I might enable it but change the password (i.e. we have access and could run any 'tests' etc for them). You might also suggest that if they think a particular account username is causing an issue - use a different one!
×
×
  • Create New...