Jump to content

TechMonkey

Members
  • Posts

    7,551
  • Joined

Everything posted by TechMonkey

  1. Sounds like a fire risk to me. Want to get that looked at
  2. I've heard of it being requested. Never heard of it implemented. I would find out what particular concerns he has about it being on. Is it power consumption, fire risk, too many Blinkenlights? Just hearing this, my concerns would be: - how will backups be done, especially getting offsite backups offsite - how will after hour updates be done? - what times would he want as would this clash with after school events? And would it all be up for those early starters? - If the timer fails what is the back up plan? - Is he going to go around at clock change time and set them correctly? Basically an uneducated request that needs killing with objections rather than just being told how stupid it really is. -
  3. Not wanting to be that person but most schools want unobstructed views into offices and classes for safeguarding. One way film may fall foul of that. The film works well though, had it on external facing windows on some small IT suites as they got to hot. Even face pressed against the glass it is hard to see in.
  4. I did have similar back in the mists of time and we eventually tracked it down to a network card causing a broadcast storm, we had been looking for loopbacks as that is what it looked like. It seems odd that it is only happening every now and then though, so could someone be plugging in a device? Would it be worth unpatching any port not in use?
  5. As others have commented, technically you can, but why would you? From ease of troubleshooting, to just ease of use and managing. Seeing a xx.xx.10.xx IP range and know that is a particular area or type of device, or how ever you organise, is such a benefit, even over flat networks I feel.
  6. There is AIQ which have a school specific solution. I'm pretty sure iFinance from iSAMS is this rebadged and tweaked to fit in with iSAMS. I've not used the unbadged version, our Accounts team seemed to get on with the iSAMS version with very little input from the IT Department.
  7. Isn't Enterprise Roaming Profiles the replacement? https://docs.microsoft.com/en-us/azure/active-directory/devices/enterprise-state-roaming-overview
  8. If you are adding security cameras I'm presuming you have VLANs to segregate them off? Cameras can be very chatty so a VLAN will stop them annoying everyone else. As for your software, a network monitoring suite will do this. So for free you could try NAGIOS, or Cacti, semi free there is PRTG (up to 100 sensors). Yuu query your switches or router with SNMP and get all teh data you could possibly want, speeds, throughput, errors, etc.
  9. Powershell would be my port of call. Either export a list of all users or loop through all of them. If you are really keen make it loop through a chosen group and set for each of the members. Set-UserPhoto seems to be the main command and then that propagates it to Azure AD.
  10. Depending on how quickly you need it Smoothwall are apparently comin gout with a Classroom Management solution. Possibly from their new Parent Company.
  11. I'd like to be proved wrong but I think you will find you are completely out of luck. With HTTPS, rightly, in widespread usage you will not be able to see keywords with out a Man In The Middle certificate or a browser extension. Without that you will be able to see the top URL they have gone to but not search terms, in page content or anything else of the URL.
  12. Not found this? https://www.codetwo.com/admins-blog/prevent-users-from-changing-profile-photos-microsoft-365/
  13. I added an "Except if..." rule that checked if the subject or body includes a large, unique part of our signature. That way if it is already in the message, from the first time, it won't be applied again.
  14. Ohhhh. I'm about to join a school that is implementing this...
  15. Sorry, being dense, can't find a single mention of security through obscurity in that document. Could you give me a section or page number? If the half a mill per copier isn't published, it isn't obvious. That is what FOI is about, bringing these things to light. And sorry, I thought it was fairly obvious they were exaggerated figures to make the example clear. I will try and be more literal from now on. Where did I say Open Security is about relying on the vendor? It is nothing of the sort. In fact I quite clearly wrote, with no exaggerations or sarcasm to obfuscate, that: So I am confused where your comment came from. Could you enlighten me? Maybe there is a difference in understanding of security terms here. Could you define what you understand to be security through obscurity, Security by design and open security? What you are arguing does not align with my understanding of the definitions of these terms.
  16. Could you point me to the guidance by NIST to use security through obscurity? I'd be very interested to read up on it. It's also interesting that in all my studies and all the articles I've read about security directly say that security through obscurity is the direct opposite of security by design and open security. Public interest is that if you are spending £5,000,000 on 3 MX3405 copiers on a three year lease from your uncle Bob when market value is actually £3,000 then either there is fraud, incompetence or malevolence. Schools are spending public money so the public interest is that it is being spent properly. Hence why the ICO specifically say you don't get choose what is and isn't relevant. You say follow the tenants of security by design, which I have agreed with, then say I trust all those companies blindly. At no point have I said this. I will repeat again slowly. Security. Through. Obscurity. Is. Not. A. Security. Vector. Security. Through. Obscurity. Is. Not. A. Security. Layer. If you are following security through design or open security then you would never trust anything blindly, you use the layers to protect your self. Considering open security is based on open source philosophies, your scorn over publishing security details publicly is in contrast with your trumpeting open security. Open security was in response to traditional application security that relied on STO. If you know any information can be found out, STO is completely pointless considering for even a second. It would be like using a zip tie to secure a door, with more security behind. Yes it is a layer but what is the point?
  17. But it doesn't make it stronger, it does nothing. If you think hackers are not scanning your public IPs, looking for servers or services that could be compromised then you should keep hoping that obscurity covers you, right up until the point you are receiving a ransom request. If you think a hacker that has penetrated your network isn't scanning every IP range possible and then every port on every device it finds looking for servers and services to compromise then I'll repeat the above. If you did not patch your Papercut server ASAP then you will have problems. There was a thread recently where people were unhappy that management don't take security seriously but how do they take it serious when we are more worried about if someone finds out what model copier we have, or if they find out what printing solution we have, rather than actually fixing the issue.
  18. I agree with the fundamentally disagreement. If obscurity is any part of your security plan you are relying on smoke and mirrors. If it you are not making it a dependent layer, what is the point? Feel free to put an FOI in and find out. But a list of emails and how they are configured is very different to what kit you have. And to be honest it isn't like working out that information isn't that hard. So relying on people not knowing your email is, again, security through obscurity and completely pointless. Pretending people can't find out easy information is not security by design. In fact, I would go as far as to say security by design and STO are opposite ends of the spectrum so incompatible. The former, you make things secure so anything that can happen will be anticipated by design, the later you cross your fingers and hope. You are also pulling away from talking about types of copiers and CCTV cameras, when there is no obscurity around them. Unless you are using shape camouflage, like car manufacturers do, or putting sheets over them, then they are easily spotted and easily identifiable. Yes it is sensible not to stand out on the road yelling out the network specs, IP ranges, and what patches you are missing. I will give you that. But hoping no one can find that information out is naïve at best. And if you are going to base your security design on people being able to find out that information anyway, then what is the point in even considering that information hidden anyway?
  19. Sorry but no. Security through obscurity is just not a thing that should be used. It should not be a layer, it shouldn't be even thought of as a part of a design. Attacker walks past your school, looks at camera, can tell what it is. Layer is gone. Looks through a window or pops in or gets a tour, sees a copier, layer gone. If by knowing what you have compromises your security plan, then you have lost already. It's not as if it isn't too hard to find out and if you are relying on that at all, even slightly, then you are lost. You can do much more by segregating your network, keeping things updated and following standard security guidelines then by trying to hide what equipment you have, especially equipment that is out on show.
  20. I think that is why the first few were great and then I think they started doing it for the lols and conflict. I've seen comments that the cliched puffery statements they make are either given to them or they are asked to say some and just have the cameras recording until they get enough that they want. Be nice to just have a pared back people doing business. I quite like the beer brewing program on Amazon at the moment where there isn't any eliminations, just work through the weeks and the judges pick a winner each week for the task and then an over all winner from the week winners. Not sure if that would translate but it is a bit less aggressive
  21. I know it is annoying but from the article you quote: Answering 4 questions, as long as he hasn't bombarded you before, is not vexatious. The article also says
  22. I was refraining from saying similar, about the spamming. At least he didn't ask everyone to fill in a custom form...
  23. Does seem to be a very specific area. Blackpool, Wales and the Wirral. In fact, an account manager at Canon has the same name and is based in Wales...
  24. Surely if, as some have pointed out, current contracts end. New contract is sourced through G-Cloud, 2 years instead of 3. Profit. Must get them in deep doo doo if they offer something on the Gov portal but switch to other terms when signing?
  25. I can put you in touch with our Chief Accountant if it helps. We have only been using iFinance since September (training and install happened before hand though) so it wouldn't be a long term review.
×
×
  • Create New...