Hi,
New here and maybe in a minority as a Parent - but this site seemed to be a good place to start outside of the vendor!
My kids Primary school are using Uniservity cLc and pushing the kids hard to use the platform. Now as a self proclaimed geek (been in IT probably too long) and working on both private sector and government contracts I though I would check out this "Amazing portal that the children can use at school and at home!".
I was first a bit startled to find the link on the schools homepage took us to an external site - but thought hey it will be secure as it is outside access right! WRONG!
I was shocked to see as my son logged in that firstly he had been given a highly insecure password, then that the security certificate fails (due to their use of front end load balancers) and then once he is logged in all actions and access is not secured - only during logon do you go via https and port 443 - then default takes you back to port 80 and http! So all further interaction with the site, including any messages sent etc are all via a non secure connection.
Is this the standard configuration? Is there a setting the school should be changing to force use of https (if I force use of https via browser then all connections go via this route)?
When a member of staff/School Admin login are they forced to use secure passwords and/or have token authentication in addition to username/password and inline with BECTA guidance for teacher access to VLE portals?
Has anyone here had a conversation with Uniservity on data security and the BECTA guidance on il2/il3 data and how the data is stored in the backed Database? Is the different schools data held in a federated way to provide data security?
Any and all comments would be gratefully received - of course I will also be taking this up with the school but this appeared to be a good forum with which to hopefully get some background information.
Many thanks in advance
Richard