Jump to content

Roberto

Members
  • Posts

    2,735
  • Joined

  • Last visited

Everything posted by Roberto

  1. So either the folder isn't being created with the right permissions or the root of the C drive (which I'd expect the folder to inherit from if no explicit permissions are set) isn't quite right. I'd agree with the people who don't hide the C:\ drive. Not that there's anything wrong with you doing so if your aim is to make things "look tidy" in explorer if you want to, but it's impossible to do so in an utterly reliable way, so if any part of your security or operational reliability relies on your users not finding a way to get into the drive and have a play then you're on a losing bet, so to speak.
  2. Should be fine. Do you have any vendors you frequently work with that are Microsoft partners? For example, Stone computers comes to mind but I’m sure there will be many others. Speak to them and they’ll be able to help.
  3. You can probably guess from my earlier comment what my position would be if I was asked, but I think examining all the options is an entirely reasonable thing to do.
  4. That no one's done a DPIA about where and how the data gathered by this device will be stored and used by the vendor. You hereby grant Ring and its licensees an unlimited, irrevocable, fee free and royalty-free, perpetual, worldwide right to use, distribute, store, delete, translate, copy, modify, display, and create derivative works from such Content that you share through Services including, without limitation, the Ring Neighbors feature or application, the Ring Community, or via a share link, for any purpose and in any media format -- https://en-uk.ring.com/pages/terms Yup, CCTV + Door entry system with intercom. Works whether this is an internal or external door imo.
  5. If they're schools in the same MAT and their data protection policy is written in such a way as to allow sharing across the MAT then this might be ok depending on how they go about it. But my immediate instinct would be to say "no" to be honest because I'm thinking if they had that structure in place already then they'd already have an answer to this in place alongside it. This sounds more like one person wanting to do something "a bit odd" which to me is exactly the sort of thing that should be refused.
  6. Define 'access the global address list'. What exactly are they/you trying to do? Also, what info do you have in the GAL and would any of it be considered sensitive data? Do your students have mailboxes that would then mean they'd have access to any info about children from an email address you do not manage and cannot guaratee the security of. You can use GALSync type tools to pull email addresses from one org to another as contacts. You could give their account guest access to your org, that might work. Or a shared mailbox they can log into, which would then be able to interrogate the GAL.
  7. You've got to f:\ight the powers that be.
  8. Develop some proper requirements. Off the top of my head: Passwords for what? Is this is personal use? Do you need to share passwords within a team? And if so you’ll presumably need audit info on use & changes? Do you need something that will rotate passwords for you? How will you backup and recover this password store? And keep your backup secure?
  9. I'd say everyone should be doing this - keep 'daily driver' account and admin account separate. And also give minimum access based on the jobs they're doing. Good advice for apprentices but also for all IT support types - if someone doesn't need full admin they shouldn't have it.
  10. If you're looking to replace file servers, have you considered Azure Storage - https://learn.microsoft.com/en-us/azure/storage/common/storage-introduction This is handy if you have an app (or people) who insist on having a drive letter to store things on.
  11. I'd absolutely echo localzuk's point - moving to the cloud by lifting and shifting VMs or physical servers 'as is' is inefficient and ineffective. It may make sense in some circumstances (e.g. if you have no choice but to vacate a server room and no capital to buy/convert space for a new one) but it's a poor use of cloud. I'd look to use SaaS if I could ahead of running my own VMs. For example of why SaaS is often better, consider email. Using O365 is almost certainly more cost effective than creating your own Exchange server in Azure. Especially once you start to consider redundancy, patch management, etc. Taking that thinking back to your servers, instead of moving your papercut server to the cloud you might look at Papercut Hive. You might speak to your cashless vendor about what options they have for a cloud navite or a hosted service, or if at least they'll support Azure SQL instead of forcing you to lift and shift a SQL server, which could well be costly (I'm assuming that's how they store data). In addition, if you do need to build servers in the cloud, your servers on prem are probably specced for your anticipated growth during the expected lifetime of the server. You don't do that in the cloud because if you build a cloud server today with 'spare capacity' for what you anticipate needing in year 5, that's a long time to pay for capacity you might need one day, when its trivial to just wait until you need it and add that capacity. This includes changing the machine type to upgrade CPU and RAM, as well as storage btw.
  12. I'd say point #1 is key here (though fwiw, also did point #2 with some success myself) - do they really have documented permission from everyone in the photos from 2010 to use their likeness indefinately? Is there any old PII from former staff or students from 2010 or earlier in this data? Do you not have a policy on data retention?
  13. It really does feel like a physical layer issue with the device itself to me, not a switch issue, so this wouldn't surprise me at all. I can well imagine a doorbell installer only installing the wires they need - it may be that's all they have the terminals for, depending on the device! I'd be looking at using the dumbest least "intelligent" switch I could find to test with and see if it magically kicks in to life when connected to that. If so, then I guess it might have to stay that way. IIRC I think I did something similar for a gate control at my old college.
  14. Is the script on the usb drive being mounted? If so, look at $MyInvocation? https://www.tutorialspoint.com/how-to-get-the-path-of-the-currently-executing-script-in-powershell
  15. That is all kinds of worrying. I'd think most if not all of us would agree that Tate and the like are extremely dangerous for young males to be exposed to.
  16. Do they not have a hate speech category?
  17. Oh, a bit of both, primarily poor design/implementation. Absolutely no doubt. But even if I had wanted to keep Unifi (and I should clarify, I did investiage this idea with our internal network specialists) the age of the kit and the state of the design would have meant a full rip and replace either way. Yep. Couldn't agree more. A bad implementation of top-of-the-line equipment can easily be worse than a spotless implementation of "average" equipment I think.
  18. I’d absolutely buy unifi for my home. Or my church. And if a local school asked me for advice I’d tell them to consider it as well. I’d start having doubts about recommending it for a site the size and complexity of my former employer however. I’m looking at a new office location/refit today where unifi is deployed throughout already and I’ve already recommended replacing it with Cisco Meraki because they’re unhappy with unifi and their WiFi has absolutely positively got to work for anything from running a teams meeting for 3 people through to handling the throughput necessary for the backstage /after party for a music festival (no, really!) or my reputation is on the line. I know Meraki isn’t infallible, but their customer support is very good, they’re able to offer a level of guaranteed quality if I follow their model design, and they’re regarded as something of an industry standard so if there is a problem, no-one is going to say “what was Roberto thinking, selecting them for this deployment?”
  19. Indeed. The costs are the costs, which is why I hope the fine is minimal.
  20. One would hope that any fine imposed by the court would be minor. As much as I've strongly advocated for "this is why edu orgs need to get better at procurement" in this thread, and I still stand by that view, there is nothing good to be gained in punitive fines here, esepcially when the issue is down to process errors rather than any kind of malicious intent.
  21. I wonder if someone confused windows domain name lengths from the NT4 days (e.g. Netbios name), which IIRC was limited to something like 15 or 16 characters, with the length of the FQDN. Or was working with some beastly legacy software that had limits imposed on it.
  22. But not shame on the people who actually lost that money by running their bid processes badly? After all, the rules have been in place for more than 10 years, actually probably more like 15 years by now since I had to follow them for bids for services in a new college campus. If you get caught speeding by a traffic policeman is it their fault they caught you because they were running a speed trap on a dangerous road or is it your fault for speeding?
  23. And can you show your due dilligence that other potential bidders absolutely wouldn't do the same if you were running your bid process improperly? Because with all due respect, your response is a little childish. You can absolutely disagree with how a vendor operates. But I don't think its unreasonable to expect a bid process to be run properly. Let me put it another way - how would you react if you put together a RFP for a complete computer refurbishment across a large MAT in the expectation that a competetive bid contest would be run and you'd end up with a variety of keenly priced proposals to pick from, only to subsequently discover that suppliers were operating a complex monopoly and colluding to carve up the market between themselves based on type of org or geographic location or something, and therefore the prices and service you were getting were not competetive or not as good value as you would reasonably suspect. I think most MATs, large schools and colleges would take a dim view of that. I suspect they'd be expecting the suppliers involved to be excluded from frameworks if the RFPs went through a framework and they'd probably also be looking at their other options including legal ones.
  24. Lots of people have it in their heads that their employer putting MFA tokens on their device allows the employer to spy on them somehow. Or, they resent the idea that an employer is trying to dictate how they use their personal device. I actually have some sympathy for the latter perspective - I see why people might feel that way even if it's a view I personally disagree with. As such, I think that it isn't that unusual for staff to balk at a request to put MFA apps on their personal device - I don't think you can dictate to people that they have to put your software on their device. As such, the school has to have an alternative plan in place - either issuing tokens such as YubiKeys, or simply making it clear to people that access to organisation resources and data without MFA is not going to happen and both the organisation and the employee recognising this may present issues with, e.g., being able to WFH.
  25. So, not unlocking when you’re not looking, then?
×
×
  • Create New...