Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

CyberNerd

Members
  • Posts

    9,169
  • Joined

  • Last visited

Everything posted by CyberNerd

  1. Any particular bits? There is an API for Google Classroom and I know it already will sync SIMS classes (either via script or 3rd party support).
  2. I absolutely agree with these points: Having no system is better than a mixed bag. A H/W system REALLY needs fully management buy in - even the "write it in your planner" method. With our use of Google Classroom it is the only way staff are allowed to set homework (even if the H/W is non-IT related).
  3. I don't think it's a good idea to open anything directly into the internal network, but I don't think its good to put SIMS database into the DMZ either. At the end of the day you need to do what the vendor (capita) support and if they say it is the best thing to do then go for it. With web services you can run a reverse proxy on your webserver and just open that up to the specific port on the SIMS. I don't know enough about security to say either way whether it would really help in a practical sense - but it's very easy to do if you have a web server in the DMZ already. Absolutely agree with this. We moved most to Google and it must be more secure (overall) than school technicians (me!) randomly letting the internet in without 24/7 support, pen testers and recognised security protocols.
  4. If it isn't avoidable you should at least proxy these connections via apache or something
  5. We sometimes use Google hangouts to project video (usually from phones, tablets, chromebooks) onto projector screens. You can add multiple clients (classrooms) but I think need addons to record.
  6. I do apologise. Neither IPS nor DMZ will stop everything - only unpluugging the cable will do that. All you are trying to do is mitigate risk. IDS/IPS and DMZ will help so are worth doing.
  7. Sorry, I was being facetious again. I'll try to stop. The point of a DMZ is that you put servers in it that could become compromised because they have holes opened to the internet. If that server becomes compromised, it is very difficult to use that server to gain access to other servers on your interlan lan (your most precious databases etc). The advantage of the DMZ is that you don't need to mess about with FW rules internally and it avoids the situation where your compromised webserver is running on the same internal network as your sims. It makes things more difficult for an attacker and hence is best practice.
  8. Yes, you can do this using the API. There are some third party tools developed for it (integrated into other products). The simplest is to use GAM by ditto https://github.com/jay0lee/GAM and utilise shell scripts to do the heavy lifting. You can see all files, folders etc as an admin and change their permissions. You can also see these in Vault (and share access with teachers if you want), but as you eluded to vault doesn't snapshot deleted files like oit does email.
  9. Do you guys do consultancy work?
  10. You need to think of drive files and folders more as ID's in a database structure than a hierarchical structure. Some of the things you say (in red) are incorrect Nobody can override an admins permission - you can always get the file back using the API but you DO need to know the ID. Only the OWNER can permanently destroy a file. In the scenario above (creating shared folders) this would never happen as the admin is moving the shared folders to drive.
  11. Just hit "restore data" and you can go back 30 days. It will find anything deleted, even if it's deleted from the bin.
  12. All our homework goes into Google Classroom. It's school policy. It does calendar, Drive and email integration and it is free. When I spoke to Google at BETT they said new in the pipeline is parent access to allow parents view permission over classroom and drive files; like an exercise book. Not sure how or when it will happen: - but I certainly wouldn't spend any money on a service like this.
  13. I've also noticed this problem. A decent workaround is to put a link either on your old shared drive, or in a learning platform. A shared drive is a nice method because people think it's accessed from the same location as old. There are some methods of automatically adding the files to individuals drives but it requires scripting and I've never done it with folders.
  14. Thanks- I wasn't sure if I had dreamed it. So nothing to do with ultrasonic - subsonic in this case.
  15. Swear I heard on the radio a recent study saying ultrasonic noise can damage hearing, even if we can't hear it. Can't find any reference to it now.
  16. Have a look at Chromebooks, they are much better suited and many now work as tablets with touchscreens and can run some android apps.
  17. I saw a good presentation from Arbour at BETT: Arbor Education Partners
  18. yes I see that now. If it is on a network then nmap will find it, given the correct options. * caveat being the management interface has to be plugged into the same network!
  19. If you get the portscanner to just check the port that you are looking for it will speed things up immensely. nmap will do this.
  20. There is a tendency to overspec things. Our fileserver (2000 users) still runs fine with 1GB ram, it doesn't de-duplicate files and is a similar spec to my phone*. No gui, just runs samba and it does a pretty good job. It is a virtual machine so I could up-spec it if it needed it. Much of the load is now outsourced to Google so I can see that running for a few years yet; never needs a reboot and is rock solid, linux severs FTW! * should mention it has a FC SAN with SSD for the regularly used files.
  21. What he said. scan a whole subnet if it's your network.
  22. I'd like to qualify my earlier "read the HP manual" comment: Vendor documentation is probably the best resource you can find. The manufacturers really, really want you to implement their technologies and the good ones (HP networking, Cisco, IBM etc) make some fantastic resources available for free. They often include their own terminology and emphasise their proprietary protocols/services (not to the extent that MS try and re-write things). The important 'concept' stuff is open standards which are implemented by all vendors; so go get yourself some manuals as they are all readily available.
  23. I was meaning historic applications in a backwards thinking, locally installed way, not that they are actually old. It's good that your network is secure and nobody can get to your gata. I have a team of Google engineers constantly monitoring our school network looking for problems, applying patches, fixing hardware - so I didn't need to invest quite so heavily in the infrastructure. We spent the money on teaching and learning instead. @flyinghaggis I couldn't agree more with your last post. I think it really hit the nail on the head. Next year will be the year of the windows mobile!
  24. Read the HP manuals.
×
×
  • Create New...