-
Posts
16,316 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Garacesh
-
Freedom of Information request
Garacesh replied to Jobos's topic in Data Protection & Information Handling
I'm quite certain they do take it seriously, however, they are not answerable to you, nor do they have to prove to you that they take it seriously. -
Deeeeerrrrrrp. Stopped being techie about it (searching error messages) and started being an end-user about it (phrases like "not showing in list") Application properties/Deployment Types/Deployment type properties/User Experience Logon requirement: Only when a user is logged on Changed that to "Whether or not a user is logged on" and it shows up.
-
Psst.. What people usually call 'Barrel rolls' are actually 'Aileron rolls', an actual 'Barrel roll' is something different
-
I haven't had to generate mine either. The Office setup comes with that lot bundled in. It's just "Here's the install exe, here's the config file, go." Alas it's besides the point. There are more applications than Office that need to be installed during imaging. As much as I could do them all with command line tasks, I'd rather have them in as actual applications if possible. Just makes things easier to see what's going on, what we do and don't have getting deployed, etc.
-
Compared to your umpteen lines of code that has to check for OS architecture etc, mine seems complicated? I could just add a Run Command Line step to run the batch, which would probably work, but there's more than Office that needs installing so I might as well do it 'properly'. Yeah, that's ticked on all 4.
-
We're barrelling along with these puns, aren't we? (Top marks to anyone that understands the pun and why )
-
Punctuation: The difference between "Let's eat grandma!" and "Let's eat, grandma!"
-
I've added the Office installer scripts into (what I assume is) the Applications pool (Application Management, Applications) but I'm trying to add them as a step in the Task Sequence but it doesn't show them? The scripts themselves are nothing fancy, just batch files with START /WAIT "Office 2016 Setup" "\\Server\Share$\Path\Setup.exe" /config "\\Server\Share$\Path\Config.xml" I can't really find any information about this because it appears Microsoft use the same "There are no items to show in this view." error message across a bunch of other applications.
-
Freedom of Information request
Garacesh replied to Jobos's topic in Data Protection & Information Handling
Yes, please do. Except this time, make it compliant with the FOIA. And I would suggest that you consider requesting less information so that 1) You don't have the administrative overhead you're so keen to avoid and 2) It doesn't break the £450/18-hour limit. -
[SCCM 1710] Setting up for Windows deployment. .WIM's?
Garacesh replied to Garacesh's topic in O/S Deployment
That's my thinking too, which is why I didn't want to faff about with capturing images because (at least, AFAIK) they're a to edit once you've done it. I'd rather have the task sequence have steps to run certain commands (like disabling the recovery environment, or USB Selective Suspend) than to capture an image where those things were applied, since it lets me add/remove/modify so much easier. Thanks a lot, you two! I'll give install.wim a bash! -
Freedom of Information request
Garacesh replied to Jobos's topic in Data Protection & Information Handling
Slightly off topic but, actually, yes, they do. Just for the record They have automated vulnerability scanners that check sites and look for potential security issues, site forgeries (eg phishing attempts) etc. Edit to be a bit more helpful: Nobody is claiming your Google Form hosts malware. We're pointing out that we specifically make a point of not clicking links emailed to you by people you don't know that you weren't expecting. If a Cover agency emails our Cover Supervisor and it has a link in it, that's a bit more OK in context, because it comes from somebody they know and external resources are expected (eg CV links) An email from someone you're not expecting any correspondence with, containing links, is a bit more suspicious. Those are the links we encourage users not to click. -
So I'm used to WDS/MDT where I set up an .iso, a bunch of driver packages and a task sequence and boom, it installs a clean OS from scratch and then does drivers. No need to sysprep, it's just like popping in a CD-ROM. Fantastic. I'm looking at moving to deployment via SCCM and it doesn't appear there's an option for using .ISO's, only to give it .WIM files. I can't find much beyond a tool called ImageX, which appears to have been discontinued around W8/8.1 times, apparently replaced with DISM? The stock W10 LTSB 2016 ISO from VLSC contains boot.wim and install.wim, but I don't think these are the files I need. Something about WAIK? After finding lots of different forum posts I'm trying to follow this guide by Microsoft and I've got MDT set up on the SCCM server and imported the O/S and made a task sequence as explained, but now I'm up to booting into it and capturing an image? Why do I need to capture an image if I already provided it with a W10 iso? This sounds an awful lot like SysPrep and that's really not a route I want to go down. I really don't get this.
-
Freedom of Information request
Garacesh replied to Jobos's topic in Data Protection & Information Handling
Quite simply, and I'm aware I may be construed as rude here, you have no idea what you're talking about. You cannot compare home-grade equipment with enterprise-grade equipment. Guest networks are easy to set up with a commercial unit because your switch, router, wireless access point and DHCP client are all one unit. This is not the case with enterprise environments. Most enterprise environments will not have a guest network because it brings with it a plethora of security concerns. Let me make this as clear as I possibly can. There is a reason we do this for a living. We know what we're talking about. When we say something isn't feasible, chances are high that it's because it isn't feasible. Not impossible, mind you, just not feasible. We have limited budgets, limited staff, limited time. We're sure as hell not going to buy the new infrastructure and introduce the required downtime that it would take to create the secure1 Guest/BYOD network you're recommending just so we can fulfil some kind of weird criteria to reply to your (invalid, may I remind you?) FOI request. 1: Quick tip, on the house: those guest networks on your home router are insecure as all hell. Don't use them. Like, ever. -
Freedom of Information request
Garacesh replied to Jobos's topic in Data Protection & Information Handling
I too am interested in this. In principle I agree with the idea that there is a huge discrepancy in mothers/fathers ratio and where there may be instances where a parent wants to be part of their child's life but are unable to do so in full due to the actions of the other partner (such as not giving contact information), but I think @elsiegee40's response was more of a "You can ask, just be aware that @bmaloney is not required to actually give an answer." -
Freedom of Information request
Garacesh replied to Jobos's topic in Data Protection & Information Handling
No it isn't. It's necessary to reduce your labour as much as possible. May I remind you that we are under no obligation to reduce your labour, only to respond to the questions that you have asked (if the request is deemed valid, which so far, it has not been). The fact that you have requested so much from so many schools is your problem. If you wanted less labour, you should have asked for less data. The burden of processing the data lies with you. You are trying to offload that burden. Please stop trying to dress it up as anything else. With all due respect, the ICO have declared your request as invalid because a web form is not a method of correspondence. Therefore, a web form is not (and will remain 'is not' until the conclusion of your appeal) a valid method of correspondence. We do not have to respond because your request is invalid. End of story. Even if the appeal is upheld, and the FOI request is deemed valid at a later date, schools are still (and will still have been) doing the correct thing by not responding at present. It's like if your driving license was revoked. You can appeal it, but you must still abide by the original ruling until the appeal has concluded. -
Freedom of Information request
Garacesh replied to Jobos's topic in Data Protection & Information Handling
I get your point, but forms.google could be categorised as a known url for a lot of people. You have a valid point, it's generally best practice not to click emailed urls from unknown sources - I fully expect there have been malware aggressions pretending to be FOI requests - but that's generally. You can't say 'never' because that's just not feasible with the way people communicate online. Consider also that FOI doesn't (or shouldn't) go to regular teachers, but to someone who is a bit more educated about this sort of thing, and that as always, you can encourage staff to request your opinion if they are uncertain. Then again, the point is pretty moot until we hear back from the appeal against the ICO's decision. I would, personally, recommend that anybody submitting an FOI request should do so in a plaintext format avoiding any need for external references (files, websites, etc) but I accept there probably aren't hard rules around it. -
Freedom of Information request
Garacesh replied to Jobos's topic in Data Protection & Information Handling
I'm not sure there's a problem with teaching people to hover over links and see where the link goes. We have staff here that forward me an e-mail if they feel it's a bit suspish (I'm under no illusion that all of them would do it, but some do) and I let them know if it's OK or not. Edit: I appreciate that if you're doing an FOI request properly it shouldn't require any external input at all. They should be able to access all of the request, and return all of the information, by the medium you first used to communicate (eg email, snail mail), but I don't think it's fair to reject anything that contains a hyperlink on security grounds. It's overkill. We're supposed to educate our users so they can function on the wider internet as a whole too, not bubblewrap them from every potential threat ever. -
Freedom of Information request
Garacesh replied to Jobos's topic in Data Protection & Information Handling
I wonder, perhaps, would it be acceptable to say, for example: "For security reasons, links using URL shorteners (e.g. goo.gl) are rejected, as we cannot see their destination. Please submit your FOI request without using these services and we will respond in due course." I think that would be a fair compromise. goo.gl/etc could lead anywhere, but forms.google.com/etc is pretty clear. I just have a very limited knowledge of FOI laws so I'm not certain if that would be acceptable. -
@witch Do witches make good Ghostbusters? I wouldn't think so.. Hogwarts had a fair few and was full of them!
-
I use steel-toe'd Groundwork boots. I tend to buy a new pair every 6-8 months but at £30 per and I'm wearing them 5 days a week, 9 hours a day, I can't complain.
-
Yeah, I considered doing the same, but I wouldn't get much else out of it. I have enough games to play already, I'll do without for now.
-
I'm keeping an eye on it. The beta was fun but it's not something I could see myself playing a lot of in its current state. There just isn't enough content. The framework is all there, but a clever framework doesn't necessarily translate into a long-lasting game and I'll be surprised if there's still a player base in three months when this next big update is supposed to come out.
-
If I might, as someone that's set up G Suite for the school, this is unfortunately a necessary evil. One assumes that if you're using it for work, it's going to have access to sensitive information. That might be pupil medical information, information about home issues, potential safeguarding stuff, etc. The admin permissions allow for the account to be removed from the device remotely, or, should the worst be feared, the device wiped entirely. The admin permissions also mean you can force some kind of lockscreen, which just adds another layer of security between any potential miscreant and the data. I would agree that the all-or-nothing approach is a little bit excessive, though. I think the permissions for a full wipe and for account removal ought to be separate, personally, but there isn't an option for anything more granular. Because it's all-or-nothing their end, we have no choice. We have to go with the 'all' choice.
-
Freedom of Information request
Garacesh replied to Jobos's topic in Data Protection & Information Handling
Could do, yeah. Physical addresses are considerably less likely to change than email addresses, no? You can even go signed for, if you like (sure, email can do read receipts, but most email handlers will reject/ignore that these days.) Of course, depending on how deep your pockets are, that probably stops you being able to send it to every school in the country. But on such a grand scale like this you've got to except a few hiccoughs. When you're sending the same thing to >20,000 recipients with I-don't-know-how-old data that's susceptible to change, you cannot reasonably expect every single one will be received. You're not getting this. Yes you can because you haven't followed the rules (namely provide a method of correspondence). The ICO were asked for their input, if they say it's invalid, it's invalid. No but's! Your appeal means nothing until a decision has been made. The ICO has said it's invalid, it's invalid until someone above them says otherwise. They have not said otherwise yet. They may not say otherwise at all. It doesn't matter how any of us, or you, feel about the legitimacy of the request. Even someone that feels your request is legitimate is overruled by the ICO. -
Freedom of Information request
Garacesh replied to Jobos's topic in Data Protection & Information Handling
If the e-mail address you've used is the one they publish, I don't understand why you would want to FOI them for contact details. You already have contact details. If you FOI a school to confirm their contact details are correct and they are, you've wasted their time and yours. If you FOI a school to confirm their contact details are correct and they aren't, they won't receive the request in the first place. It doesn't achieve anything, and you're just wasting more time (thus, money)
