Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

JSchlackman

Members
  • Posts

    69
  • Joined

  • Last visited

Everything posted by JSchlackman

  1. Just spotted that this was made available by Jisc this week - have had a quick look through and while Jisc obviously focuses on FE settings, there's some good stuff in there for all schools regarding the legal position of BYOD and the aspects you need to consider. BYOD Toolkit (1 May 2013)
      • 6
      • Thanks
  2. Well, I would have lost my tenner, but I was close: another Java 7 update is due out on Tuesday. Ars Technica are reporting that it is Java 7 Update 21, but don't explain what happened to update 18, 19 and 20 (update 17 is the latest one available for download). So technically maybe I was right? Who even knows any more.
  3. Well, we all knew it was coming. Security Alert CVE-2013-1493 - update here. By my count that's the 4th one this year. I have a tenner that says we'll make 5 by Easter.
  4. This Heath & Safety Executive alert has been doing the rounds on Twitter today, and although its actually a few years old and has been posted about before, I think it's worth a read for those who weren't here when it came out in 2009: Guidance - Laptop computer charging trolleys safety alert If your laptop trolley does not have a written Declaration of Conformity and a valid CE mark, you need to take action. The guidance the HSE lay out for non-CE marked trolleys is important because even if you think some of the steps they recommend are over the top, anyone investigating an incident in future will lay the blame squarely with the school if the guidance has not been followed. Trolleys with a valid CE mark should need no further action (note the HSE wording before the action items: "The following recommendations are for situations where laptop computer charging trolleys remain in use where there is no Declaration of Conformity and CE marking"). That said, some of the advice is good practice even for those that conform with the regulations. So, anyone got a trolley that isn't CE marked? Just checked our Bretford again and looks like we're in the clear.
  5. The ICO has recently issued guidance on secure disposal of IT equipment, the full details of which can be found here: IT disposal - Data Protection Guidance for Organisations - ICO There were a couple of points in the overview that stood out for me though. Here's all their points, but the last two are interesting... I've always erased hard disks before handing them over, but the company we use do their own erasure, which suggests not everyone does. However, we've never entered into a written contract with them, and according to the ICO, this is required under the DPA if they are doing the erasing for you. I wonder how many schools do this?
      • 1
      • Thanks
  6. I don't run anything off a network share unless I have to, but that's mostly a principle thing on account of me not wanting to buy full desktops and then treat them like thin clients As such, I have an MSI for VLC, but all it really does is copy the files, make a shortcut, and set up a small number of file associations for the file types that Windows Media Player won't open (.flv in particular). I would think the only thing a 'portable' version does differently is save the preferences in a different place, and you probably want those to be per-user in AppData anyway.
  7. Posted an update to this earlier in the week with some new functionality - somewhat different from the original, but addressing another limitation in the options Windows provides. Session Arbiter can now be used to configure a laptop to log off the current user when the lid is closed (an option not natively available in Windows), as well as optionally placing the laptop into Sleep or Hibernate once the logoff has finished. We are using this with our loan pool laptops, as we frequently found that pupils would start logging off and then immediately close the lid (causing roaming profile sync problems), or forget to log off entirely (causing account hijacking problems). Now closing the lid will log off the user, and then put the laptop to sleep, and we've had far fewer problems since. This functionality can be used independently of the time limit functionality, so if you don't want time limits, you can simply not configure that part and just use the program to do the lid-close logoffs.
  8. Do you use Google Apps for your pupil email? Do you use Objectionable Content or Content Compliance filters to copy you into messages with bad language, or to messages from certain senders such as Facebook? Did you know that in certain circumstances those messages won't actually be copied to you? No, neither did I. It seems that Google did, but hadn't really told anyone, and it took 5 weeks of back and forth with support before someone figured out that was what was happening in our case. Here's how it can fail: You have a compliance filter set up that when triggered, adds an extra recipient to the email (i.e. copies it to you or someone else tasked with monitoring). The filter also has the Prepend custom subject option enabled, (e.g. adding "Email misuse" to the subject). A message is sent from a sender that uses DKIM (DomainKeys Identified Mail) on their outgoing mail server. The sender's DMARC TXT record in DNS is set to instruct mail servers to reject any message for which DKIM fails. In these circumstances, there is a very high chance that the message will not be delivered to the additional recipient. This is because DKIM indicates that the message is a forgery if the subject field is modified, so it is rejected as spam. For those unfamiliar, DKIM adds a digitial signature to the email based on the message body and some of the headers. The list of headers that is signed almost always includes the subject (as well as from, to, and any others the sender specifies). The sender can then add a TXT record in DNS that tells receiving mail servers what to do if the signature verification fails. In many cases, such as with Facebook, this is set to reject. When Google Apps modifies the subject, the digital signature is no longer valid, and Gmail will then automatically reject the message when it tries to deliver it to the additional recipient. So, guess who found out 5 weeks ago that he wasn't getting notifications that a load of under-13 pupils had registered for Facebook with their school email addresses? Workaround The workaround is simple once you know what is going on: don't use the Prepend custom subject option. Google are working on a fix, but it's not ready yet. The following is from the support engineer that dealt with our case, from whom I have permission to share this: In the meantime, check your filters and remove the custom subject option if you're using it.
  9. Hello all, long time lurker here on EduGeek, and for my first post I'd like to share with you a program I've written to deal with a problem we had with multiple logons on our Windows 7 domain. We have Fast User Switching enabled to allow people to share workstations without sharing login details, but I found that we would end up with stale logons where someone would switch user, then the original user would forget they didn't log off. The logon would then sit there for weeks on end, consuming resources and preventing Windows Update from automatically restarting after updates were applied. I thought about having a scheduled restart in the evenings or weekends, but that would annoy the few people who lock their workstation at night instead of logging off (me included), when I really only cared about the forgotten logons in the background. Looking around in Group Policy, I found that Remote Desktop Services allows you to automatically log off unused sessions after a set time has elapsed, but even though FUS is based on RDS, the limits don't apply to workstations. So, I wrote a program to make them apply. http://sessionarbiter.codeplex.com/ Now any session that is in the Disconnected state (i.e. someone else has clicked Switch User) will now be logged off after 18 hours. Logons that are merely locked do not fall into this category, as they are still treated as an active session. The time limit is completely configurable, and you can even use the RDS group policy settings to configure it (just don't install the program on your RDS servers as it might do something horrible, like how putting 'google' in to Google will break the Internet). I've had this deployed on all our workstations since March with no side-effects, so I'm pretty sure it's stable. Notably, I have also not had a single user complain that their account was logged off without their consent, so I'm pretty sure no-one was leaving their account logged on intentionally. It runs as a service and has an .msi that works for GPO deployment or via SCUP/LUP. Hope this is of some use to someone!
  10. Your timing in asking this question is perfect, as I'm about to post about a program I wrote that might help with this sort of problem. We don't restrict the number of concurrent logons, but we do keep track of them and automatically log off the oenes that have been left in the Disconnected state to long. I gather I can't post a URL on my first post so look for a thread about Session Arbiter in the Windows 7 forum in a few minutes.
×
×
  • Create New...