Jump to content

Roberto

Members
  • Posts

    2,735
  • Joined

  • Last visited

Everything posted by Roberto

  1. We have already invested in SCCM for managing our windows environment, and it made sense for us to therefore use the Parallels SCCM extensions to turn our macs into full "citizens" of our SCCM infrastructure. It's absolutely top-notch for deploying OS images over the network, controlling package installation, stuff like that. http://www.parallels.com/uk/products/mac-management/
  2. The more things change...
  3. Hear hear. Not someone I always agreed with but someone I respected and enjoyed talking with back in the day. This is sad news indeed. ahem!
  4. Exactly - this is a safeguarding issue regarding the use of recording devices around children, not a 'this month's gadget du jour' issue.
  5. I took in 'A Royal Night Out.' with my partner and her mother on Saturday. I don't know if anyone else here listens to the Radio 5 movie review show on Fridays but I have to agree with Mark Kermode - in a lot of ways its an awful film but it's also a lot of fun. It isn't the sort of film I would have chose to watch myself (sadly our schedule meant that my partner and I couldn't fit Spooks in as well as that's much more my thing) but on the whole I enjoyed 'Royal Night' and I'm glad I watched it. We also watched Far From The Madding crowd the other week and that was just great.
  6. Fair enough - And they are generally using mickey mouse network commands to get some practical experience of networks, so things like ping, tracert, etc. These are all examples of not locking things down correctly (though some of it is down to more lax defaults from Microsoft back in the day). Students used telnet to access our exchange server to spoof emails from teaching staff (very amusing, but potentially disastrous). -- Ouch. But either they were authenticating as the teachers concerned or someone had configured the Exchange server to allow anon spoofing. Not good either way. Students enabled the net send service and sent random explicit messages to other pc's on the LAN. -- By default, users should not be able to enable a disabled service. Microsoft were a bit lax on this back in the day so it might be on them. They created different .bat files and saved them in the "all users/startup" folder. The script rebooted the pc after 5 mins etc --Again, incorrect permissions - they should never have been allowed to do anything more than read/execute from that area. Now, don't misunderstand me: I do think there's a case for saying "I have no business / learning requirement to enable something here, so I won't. Perfectly reasonable choice. There is also be one for saying "I don't have the resources to check this is secure and on balance the school has decided it doesn't want to take the risk". But nothing you describe above is a fundamental flaw in the command prompt itself.
  7. Luton Sixth Form College are looking for a Data Analyst. Full time and permanent, salary range £24,722 to £27,291. We have more information, including how to apply, on fejobs.com.
  8. Are your SLT all drunk or high? That's appalling.
  9. Sorry I didn't reply to this sooner - didn't get notifications. Simply put - nothing magically bad happens just because someone opened the command prompt. It respects the permissions the user has been given anyway. If you don't want students (who I assume would be normal users on a workstation) to be able to view other people's user areas or delete system32 then don't give them permissions to do so (as is the case by default). If you don't want them to be able to alter the system from the command line, e.g. changing the IP address, then again, don't give them permission to do so (as is the case by default, again). This relies on locking things down properly (e.g. securing the c: drive with ACLs rather than hiding it and pretending it doesn't exist) but this is a more robust solution than hiding but not securing settings and files and hoping someone doesn't discover a route to access them that you haven't thought about. As for the network - yet again, by default, normal users shouldn't have permission to change anything just by having access to the command prompt. If your network is so insecure that a random user can reconfigure a server just by having access to the command prompt then you need to fix the security on that server, not pray that no one finds a route to the command prompt you haven't thought of. We have several thousand 16-19 yr old students with access to the command prompt here, for several years now. We've had no issues caused to either individual workstations or the network at large by allowing them access to the command prompt or to tools like visual studio. Without wanting to sound like I'm attacking you on a personal level Bertie, this is the kind of attitude that annoyed me in the last thread on this - talking about "exposing all sorts of potential issues" is trading on technobabble and fear of the unknown and it's poor customer service to deny a learning opportunity with a reply like that (if anyone is, not suggesting you or anyone actually does do that). Let's talk about specific threats and we can then talk specifically about how to counter these threats and have a balanced discussion of the potential risk vs. reward of enabling access to something. After all, if we can't expose the network to students because of the threat of "exposing all sorts of potential issues" then why do we even allow students to use computers in schools and colleges at all? There are always all sorts of potential for all kinds of issues, after all.
  10. Why ever not? If your systems are configured correctly then this shouldn't result in a serious risk to your security. If your systems are not configured correctly then the risks that can be realised via the command prompt are equally vulnerable in other ways and so should be fixed by methods other than pretending the command prompt is where the devil lives.
  11. Agreed. They're like the diet coke 'one calorie' version of the BNP in my book. They claim otherwise but I simply don't trust them.
  12. Well done - And I hear you on the wardrobe issues - it's an expensive issue this getting fit lark!
  13. I'll say. Pentium 4s? Never mind buying a few desktops, why doesn't the head of IT see if anyone has an ipad or a samsung phone they're not using or something if he really needs that much computing power.
  14. Isn't this something you should normally make a point of talking about. It's as well to remember (and to remind the occasional supplier who thinks all educational establishments are run by cletus the slack-jawed yokel clones) that you're the customer and as such you get to set the terms of a deal by ultimately taking your money elsewhere if they don't give you what you want. These sound like fairly standard business terms for a service contract.
  15. They may have set up something that requires a CISCO-specific implementation of something. That's always possible, but we have an entirely HP Procurve based network connected to a CISCO router for our JANET internet connection and we always have done. The idea that HP and CISCO based networks can't talk to one another is a nonsense. The possibility that they've done something specific in their config that restricts your choices in this particular case does exist. I would be asking them for specific technical details of what the issue is and why it was configured like that. And I would be very sceptical of any answer that sounded like they were trying to fudge the issue.
  16. Just been reading some of the other stories here, very inspiring. Congrats on hitting your target Bossman When I last posted in October I had lost 2 and a half stones, down from 17 to 14 and a half. I'm now down to 13 stone. Probably still need to lose about another half to 3/4 of a stone and work on upper body condition but I'm feeling so much better than I was. July 2014 Feb 2015 (I've lost about 3 lb since this photo). I've seen someone else mention fitbit here - I've been using a fitbit band and logging my foods, exercise, etc. and I can't recommend it highly enough. I've not been on any kind of particular diet, just watching what I eat and thinking "sure you can have a treat now, but that's it for the day and you're going to need to make sure you don't miss your exercise routine too". Probably been walking about 30 miles in an average week according to the tracker - trying to do some big walks at least 4 times a week but always getting in a couple of miles a day.
  17. "Something like an AUP" but for a business - So a contract, then? Does their contract with you for this support not specify something of this kind? If not, the obvious answer is to amend it so it does.
  18. Well it's a news aggregation site - Just because nothing 'unsuitable' is news today...
  19. Not sure what is happening with Digg these days - it used to be much the same as Reddit, and I'd be wary about letting students of that age range having unrestricted access to all of Reddit.
  20. I have to say I'm much more of a fan of O365 than G'Apps, but I do think running both isn't going to help you in the long run. If you're investing heavily in chromebooks then I would agree that it makes sense to ditch O365.
  21. Hadn't seen an option to get a linx with Pro installed - clearly this would fix the domain issue. Yes, we use SCCM but we don't regard deployment from USB memory stick as a viable model.
  22. Sometimes, yes. Maybe even the majority of the time. But just like any other technology platform, it's a tool, no more and no less, not a magic bullet. And sometimes a tool might be a superb tool in its own right, but still not the tool you need to do the job you're faced with.
  23. As far as I know, that's not the case. Properly licensing 2012r2 DataCentre for the host, say, allows you to deploy 2012 r2 guests with impunity.
  24. Depends on how you want to use them - they can't join a domain IIRC, which negates a big advantage of Windows, they don't support booting from an Ethernet socket plugged into the USB OTG port which limits your ability to manage deployments... Wonderful budget home tablet. Woeful 'business-class' choice (and I should say in their defence, I don't see the manufacturer positioning them as anything other than a home device).
  25. We use Printer Installer from Printerlogic (Printer Installer | PrinterLogic) - it's absolutely wonderful.
×
×
  • Create New...