Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

CyberNerd

Members
  • Posts

    9,169
  • Joined

  • Last visited

Everything posted by CyberNerd

  1. Is it uploaded in Drive? I know video plays and shares fine in drive but wasn't aware that it went via youtube.
  2. Do they have network access though?
  3. You can sync AD groups into GAFE using GADS...
  4. probably stacks of copyrighted material owned by the previous school. personally I'd just stick it on GAFE but failing that go for the dropbox method. No point in downloading it.
  5. It seems to be how a few local authorities negotiate these things. I don't know how they manage to purchase a service without an SLA. It's either corruption or incompetence. I once went on a LA course about procurement and how we needed to test against different metrics for value for money. When I mentioned the (awful) broadband service I was told that I didn't need to go through a procurement exercise because "they did it". I went through the exercise anyway and the LA didn't even get shortlisted.
  6. They tend to change their behaviour when you give them a workaround; ie to use chrome.
  7. or use chrome which also includes flash updates.
  8. Have you done all of the 'usual' things like clear the browser cache? Check there are no broken extensions running in the chrome task manager (shift-esc), delete them and try again.
  9. When we reset passwords through active directory the sync is instant, so I would guess it is to do with the VLE, a token or similar.
  10. We found that on Chrome/Chromebooks it will sync the username/password for the VLE on login, so on a large scale chrome rollout it makes little difference.
  11. I think we can safely say it would meet the definition!
  12. We had the same issue. We used to SSO to GAFE via the VLE but when we tested the chromebooks we found this wasn't workable. We removed the SSO for the VLE and auth directly to Google. If the VLE provider could allow auth via google your SSO will work. Doing this also fixed a bunch of problems with drive on ipads as a side note.
  13. Just HTTPS inspection *disabled* (IE DO NOT INSPECT) for the sites I posted above. ie we create a "chromebook login" group and choose not to intercept the https for those sites. Which makes sense from a load point of view too, I don't want to load my proxies with random login info.
  14. We still inspect Google et al. (smoothwall) Our "do not HTTPS inspect" list is: gstatic.com lh1.googleusercontent.com lh2.googleusercontent.com clients3.google.com lh4.googleusercontent.com clients4.google.com accounts.youtube.com talk.google.com accounts.google.co.uk clients2.google.com lh3.googleusercontent.com clients1.google.com mtalk.google.com google-analytics.com r17---sn-aigllnll.c.pack.google.com m.google.com accounts.google.com cache.pack.google.com ssl.gstatic.com googleapis.com 'safe-search' is still applied.
  15. Google is used as an Office system and it's used for admin too. Even our admissions are processed through it.
  16. It's ok, it was tongue in cheek - I've not used windows on the desktop since around 2007.
  17. Yes, using a virtual machine in linux, that I wipe daily.
  18. Go for the model contract clause then, it is a reasonable thing to do. To be honest the risk is entirely theoretical . I've come to the conclusion that US government already own my data, even if it was on a server I do control. It would be interesting to see ICO prosecute a school because of this!
  19. Depends who you speak to. We opted in years ago but others would say delete all of your data. You choose.
  20. 4. re-image it every 6-12 months to keep it running smooth
  21. https://www.google.com/work/apps/terms/dpa_terms.html https://www.google.com/work/apps/terms/mcc_terms.html
  22. Sure, I guess they must be using different auth methods? We have one SSID that serves 6 vlans and another SSID for a different auth method.
  23. If you can you want to keep them all on the same SSID and then segregate them by vlan: your radius will do this.
  24. I've had good success with splunk in a previous life.
  25. a good opportunity to do both increase the scopes and segregate groups using 802.1x !
×
×
  • Create New...