Jump to content

TechMonkey

Members
  • Posts

    7,550
  • Joined

Everything posted by TechMonkey

  1. Ha ha ha ha, no, of course not... Why who has been saying what?! Still have one suite of 4:3 LCDs and a few more dotted around. Nearly there, should be gone by next academic year or soon after. Generally gone for 24".
  2. Migrated October to 3CX hosted with Clarion and not had any issues so far. SBC is a virtual appliance at the main site and T46U router phones on the smaller sites (max of 10 devices). The hosting is something like £450 a year. As mentioned elsewhere, the alternative I have seen banded about is the Yeastar CloudPBX hosted. I have not used it so can't comment.
  3. Can you get into the Web interface for that copier and one that works? This sounds like a setup issue, but you would need to compare two devices.
  4. I buy FreshService direct from FreshWorks. With their new Business Agents I downgraded a whole heap of admin staff, with the intention of only keeping IT staff and management on the full license. This removed all discounts from our quote as I was told you need a minimum of 15 licenses to get a discount. I was also told that Education and non-profits no longer get discounts.
  5. I looked at Teams through our licensing and a collective version of the licensing. The issue was the price vs flexibility. If I limited the Teams licenses to just what we have now, staff using phones and shared devices, then we could either keep the price the same or make a small saving. 3CX basically gave me a massive saving and the opportunity for anyone in the organisation to have a phone extension at no extra cost. Add on to that new hardware to get the features to make it worth the money, and professional fees charged to set it up, I just couldn't justify it, even at educational rates. I've not used it yet, but Yeastar Cloud-PBX seems to be causing some waves and grabbing interest. Can't quite work out if it is just unrest from 3CX partners/suppliers or if it is actually a similar/better product. Only heard about it after we installed our new 3CX system (isn't that always the case) so haven't looked into it too hard.
  6. We do the different display name, we have "(Pupil)" at the end. We have the school logo as the display picture for pupils with staff either having their staff picture or a white circle with STAFF in a horrible font. Pupil usernames are nothing like staff usernames. BUT it still happens. It is a staff issue, they need to make sure they are sending to the right people and no amount of "We are really busy and don't have the luxury of time" should be taken as mitigation I have had a member of staff lament to me after sending some very sensitive information to pupils, how they had been late at parents evening then night before and then in early that morning to get ready and they'd worked a full day and how could I expect them not to make mistakes. My reply was, because it is your job and you should check, if you are not able to carry out your duties then speak to your head of department or the Headteacher, but do not send sensitive data if you cannot ensure it is going to the right place. It may have been harsh, but they would be the first to complain if their data had been sent to pupils. I'd have more sympathy if they'd held up their hands and claimed mea culpa with their excuses, but as the whole woe is them was purely about why it wasn't their fault I had no time for them.
  7. I haven't used it but apparently iSAMS is starting to partner with Untis from Gruber & Peters. They have an online version/facility. I want our timetabler to get a demo and report back. I have used KJ Timetabler in the past and it is a comprehensive tool and does a good job, but hasn't been modernised in far too long. I know the argument is that the looks don't matter as long as it does the job, but there is only so long that can be used, with resolutions and desktops bigger than ever and odd glitches happening due to how things are expected to work.
  8. We use Intune to lock various tablets down. In the past have used the Google Admin console, if that is more your jam.
  9. Does your filtering have a log or reporting? A live view? Filter by IP of the device and visit, then look at all the filtered results. Otherwise as dmj said, developer tools.
  10. Ok, you tell me who owns the IPs in question? And reassure me that the owner will never change. If I knew all the exfiltration possibilities for a compromised network I'm pretty sure would not be working in a school. But I'll play along. 1) Laptop comes in and it is already compromised. From your network it dials home to the command-and-control server, which just happens to reside on the same cloud server as the provider, and from there sets up a connection to start trying lateral movement to other devices to take over the network. Using a zero-day exploit gets on to your servers and encrypts them. 2) As the provider is shown to be lax about security, they could be compromised and used as forwarder for compromised systems, using the open ports to setup communication. 3) A compromised system on your network floods any ports it can on any IPs it knows or can find. The provider has an IDS system and spots your floods, blacklisting your IP. You now have no phone system. I imagine what you are getting at is that it would take a massive coincidence for any security breach to happen, but I be the majority of security breaches are a mix of the right circumstances at the right (wrong?) time. Why risk it? Let's flip this round. Why would you want to leave all ports open on a massive range that you don't need? Do you feel you should just follow instructions from an external third party who has no interest or need to have your system secure? Do you feel questioning external parties about security is not part of your role? Where do you draw the line of what is worth securing and what is too much trouble? If you can secure something that is proven to help, why wouldn't you?
  11. My first thought was a Raspberry Pi or Arduino with one of the kits you can get to have lots of things to do with it. One of the books that give projects and ideas for them to work through (Evil Genius one is pretty good)
  12. We do not know if the IPs are owned by the company or part of a shared cloud computing pot. Are you saying you whitelist all Azure/AWS/GCS IPs as standard? I'm not sure why someone being secure and mindful of their security is such a sticking point when we also have threads regularly on the front page about whole schools taken down through cyber security incidents. Standardisation and having known and limited exposure is a thing in this day and age and should be applauded and strived for. I mean what are we going to question next? Having proper licensing for Office, or entering in keys manually?
  13. Not sure I get the argument here, we are now arguing to be slap dash about our boundary and security? Things should not be opened unless needed, and least privileges permitted, in or out. Outgoing allows nefarious players to establish a connection. It is why we lock down DNS connections to only selected services or internal. As snagrat said, there would be no control over who the IP addresses are used by. Potentially that could be the range of a hosted service or cloud service (AWS, Azure, Google Cloud) which would mean anyone on those services would have the ability to setup a communication channel. Just let everything through is quite an outdated practice.
  14. My interpretation, which may be wildly wrong, is that you are not storing facial biometric data for each person. For the systems I have dealt with so far, you are picking an image and saying find more of these. It doesn't then reference a DB and tell you who the person is. It is just shape recognition. I agree with enjay, the natural language searches is different from facial recognition and not a DPA issue as it isn't using personal data. There is a Code of Practice for surveillance cameras that was updated in 2022 to cover facial recognition, but geared towards automated facial-recognition: • Use of a surveillance camera system must always be for a specified purpose which is in pursuit of a legitimate aim and necessary to meet an identified pressing need. • The user of a surveillance camera system must take into account its effect on individuals and their privacy, with regular reviews to ensure its use remains justified. • There must be as much transparency in the use of a surveillance camera system as possible, including a published contact point for access to information and complaints. • There must be clear responsibility and accountability for all surveillance camera system activities including images and information collected, held and used. • Clear rules, policies and procedures must be in place before a surveillance camera system is used, and these must be communicated to all who need to comply with them. • No more images and information should be stored than that which is strictly required for the stated purpose of a surveillance camera system, and such images and information should be deleted once their purposes have been discharged. • Access to retained images and information should be restricted and there must be clearly defined rules on who can gain access and for what purpose such access is granted; the disclosure of images and information should only take place when it is necessary for such a purpose or for law enforcement purposes. • Surveillance camera system operators should consider any approved operational, technical and competency standards relevant to a system and its purpose and work to meet and maintain those standards. • Surveillance camera system images and information should be subject to appropriate security measures to safeguard against unauthorised access and use. • There should be effective review and audit mechanisms to ensure legal requirements, policies and standards are complied with in practice, and regular reports should be published. • When the use of a surveillance camera system is in pursuit of a legitimate aim, and there is a pressing need for its use, it should then be used in the most effective way to support public safety and law enforcement with the aim of processing images and information of evidential value. • Any information used to support a surveillance camera system which compares against a reference database for matching purposes should be accurate and kept up to date.
  15. Couple of days ago
  16. We use iSAMS and iFinance (AccountsIQ). iSAMS is a funny one in that they did a bit of a SIMS on a smaller scale, were the market leader and didn't really move forward, partly as I think because they were so far ahead to start with. They are making up for that now and the future looks good, but they aren't there yet so we will have to see. It is not a bad option, just that there are some niggly bits that don't satisfy. They seem to flip flop between "we offer the data store and management and you should get a third party to do anything else if you aren't happy", and "we are a one stop shop for what you need". If I have understood properly, they are doing a big migration to a new platform but doing it in such a way you don't have to do anything or notice, except you get a new interface. This is bit by bit with new modules. The other option I know of is WCBS HUBmis, but no idea about it. Was with WCBS on their older product and it was a pain and they did some really funny (odd, not ha ha) things.
  17. I think our team use Safety Culture. I've not really had anything to do with it, I'm down to look at integrations with our ticket system, so that may indicate how easy it is to use.
  18. I bet legacy shared credentials. Such a menace but very hard sometimes to get away from. Think of your switches? Do you put a separate user on each of them?
  19. In the Single Sign On section of the app registration you can edit the Attributes & Claims section (2) and "Add new claim". I called mine Role. I created 2 claim conditions. User types were Members, Source is Attribute and one has a value of "Teacher" and the other has a value of "Administrator". I assigned groups to each claim, so any teaching groups to the Teacher claim and the IT Services group to the Administrator. If there is no claim they go in as a standard pupil. Hope that helps.
  20. What Youtube mode have you got in your Content Modification rules?
  21. Don't know if they will suit you, probably not if you already have a full compliment of screens, but we are getting the Dell Hub screens. Cheaper than a hub and screen and can daisy chain 2 screens. P2425HE I think, but don't take the price on the website (as ever with Dell). EDIT: Typical, I get distracted and delayed posting and now I look like a muppet
  22. It may be a step too far at the moment but I would also try, or have an eye on, making whatever you do expandable or shareable. If you get a new teammate (however unlikely you may think that is) you don't have to completely re-engineer your solution or if the worse happens to you your current departmental situation is laid out to whoever has to pick up the pieces. If you are on your own, maybe look at something like FreshDesk that gives 2 free licenses, to allow you to get on the Ticket bandwagon. This would also enable you to better document what you are doing and how you are spending your time/resources to manglement
  23. I like using MS Planner, as you can group and label items and keep notes to yourself about where you are at.
  24. We popped along yesterday and felt very welcome. Great to see you!
  25. But is this the usual coding problem of it takes longer to setup but then every use after saves time? The old XKCD is it worth the time matrix
×
×
  • Create New...