-
Posts
2,151 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by flyinghaggis
-
We also suggested, if a VM wasn't an option, that computing staff could run programming apps on laptops connected to an isolated (Guest/BYOD type) network but they're unwilling to consider it since it means they'd require separately managed devices/logins, pupils wouldn't have access to their network home drives/etc. Basically, they've cited several other similar/nearby schools who do run programming/development apps on the school's networked computers. The argument being that if other schools are doing it then why can't you? They've also bolstered their argument with a list of requirements from the exam board to suggest that running applications directly on school computers is the only viable solution. Tellingly, I suspect, none of those schools were willing to discuss with me what steps they'd taken to secure the computers on the domain running programming IDEs though? They all replied along the lines of "we don't discuss network security/config" or "The 'school' felt the risk was low/tolerable". The problem being, as things stand, I'm not convinced there actually is a way to adequately mitigate the risk of allowing pupils to freely run code on the domain connected Windows computers and the computing department aren't willing to move on their demand for it. That's why we're looking for suggestions to secure the above scenario......
-
Virtualbox + image for programming classes
flyinghaggis replied to mwbutler's topic in How do you do....it?
It's becoming a real frustration that exam boards keep insisting on requirements which mandate programming/coding apps have to be run on computers rather than using sandboxed/secure or online development environments. IMO we need a way to make representation to these exam boards that allowing pupils to run programming IDE's on school computers is utterly reckless and putting schools in a dangerous position. -
No. Unfortunately at the moment they're demanding exactly that and aren't prepared to negotiate Our Virtualbox image is setup the exact same way using shared folders mapped to the user's home drive. Allegedly, having to use a VM and copy a file back/forth is too complicated for the younger (11-13 y/o) pupils when learning programming. That's why we're trying to investigate if there are viable methods to reliably secure the school's business network if we’re forced to allow users to run/compile their own code and apps using locally installed programming IDE's like Visual Studio.........
-
Their argument was that whatever VM solution we implement use it'll be more awkward for the pupils to login, save work, print, access the internet, etc than it otherwise would be if the apps were directly installed on domain connected workstations. We currently use VirtualBox VMs for coding/web/database/development which can't be covered using Replit and the computing staff aren't happy with it as a solution for the above reasons. Plus, any hosted solution will potentially be expensive whereas installing the software onto client PCs is a no-cost option in terms of their departmental budget. Essentially they've refused to consider it as they want the software installed on client devices now that Replit is no longer usable.
-
I agree that ideally those things should already be in place. The Challenge is most of them cost money to implement which may not be on offer. Even the ones which technically don't (like amending network switch configurations) require in-house expertise/training/time which also may not be readily available.
-
Our computing department have been unable to find a suitable cloud/online ODE replacement and aren't prepared to use any kind of VM (local or hosted) to replace it. Has anyone reverted back to locally installing IDE's (Python, Visual Studio, etc) on AD networked Windows computers following the demise of Replit for Education? If so what steps have you implemented to secure domain connected AD Windows computers. We've been trying to put together a list of options above the usual Group policy and user account ones already in place :- Tightening up networking switch config (ACLs, VLANs, open accessible ports, etc) Tweaking locally install Firewalls/Antivirus/Security software to restrict network/internet access for specific apps. Adding an IPS / NDR solution to report suspicious network traffic and behaviour. Providing staff with a monitoring tool along the lines of Impero/ABTutor to allow them to better supervise pupils in labs Any other suggestions?
-
https://arstechnica.com/gadgets/2023/12/hp-misreads-room-awkwardly-brags-about-its-less-hated-printers/
- 1 reply
-
- 1
-
-
Yeah, guess maybe they felt the educational sector wasn't a market they wanted to focus on anymore. Seemed a bit odd for them as it looks like education was their primary market when they first start out.
-
Does anyone know why Replit removed the "Teams for Education" feature having made it free last year? https://blog.replit.com/teamsforedu_free It seems like an odd business decision to make something they previously charged for free then to remove it completely? Especially as there are clearly plenty of schools/customers who would have happily paid them for it given the functionality it offers and will now have to go elsewhere
-
The issue is that Windows/Domain security alone isn't really enough IME. We actually had a security company in and they literally demonstrated that with just a Windows AD account (which all pupils have [or possibly a "friends" AD credentials]) and the ability to run scripts/code and or hacking/cracking applications unrestricted you can literally wreck havoc on a fully patched Active Directory / File server and the local Windows install even assuming restricted network access to just the AD/SMB ports/protocols alone. Like you mention Microsoft couldn't even properly secure the root of the Windows system drive on clients! As others have said if pupils want to experiment with scripts and applications the school's live academic/business network isn't the place. Best options seem to be :- 1) Off-network Virtual Machines running on the client PCs 2) Remote/Hosted apps like Replit or cloud/hosted VMs's 3) Computers/laptops specifically for coding/development connected to a segregated network (VLAN'd / Wifi-Internet Only)
-
Are you suggesting there should be no restrictions in place on what applications/code pupils should be allowed to run and access on a school network beyond basic Windows ACL file permissions....?
-
That's essentially the question to discuss. There needs to be a level of segregation between the live network and computers where pupils have the ability to freely run their scripts, code and applications. To me that either needs to be done with offline VM's running on the live network or you have separate "programming/development" computers (VLAN'd etc) so they're unable to communicate with other devices and computers on the network. Or you look into somekind of cloud/hosted/remote based solution like Replit/etc. I guess it's a discussion to be had at SLT level as generally IT Teachers will continually push for more and more pupil freedom/access on the live network and there has to be a clear line drawn somewhere. If you have pupils able to run python encryption scripts and code/hacking tools designed to harvest AD/user information, scan systems and probe the live network (with evidence this is happening) clearly things can't be left as is. We currently use VM's but our computing staff aren't really happy with the solution (lack of internet access on the VM's being the main point of contention) and keep pressing for dev/coding apps to be locally installed on computers.
-
My school is planning on loaning iPads to an entire year group of pupils to use at home. We've been asked to look into options/costs for filtering these devices when they're used offsite. The devices are owned by the school (DEP'd ) and we have an MDM solution to manage them. However our current MDM doesn't offer category based web filtering and the only options in it are an allow/block URL list and setting a proxy so we'd need another solution to provide web filtering. I'm not really sure what options are available for iPads/IOS. I don't think we'd want to change our MDM provider so I'd assume some kind of proxy based solution would be preferable? Or are there any iPad/IOS specific filtering apps/solutions we could install directly on the devices? Are there any solutions folk on here are currently using and would recommend?
-
+1 Experiencing the same issue. We initially thought it was staff changing settings but, as others have suggested, I'm convinced it's a recent Windows/Driver update that's caused this as the problem is too widespread.
-
IIRC the Apple silicon Macbook Air's can only support a single external display. I believe you need to Macbook Pro to connect multiple external monitors. https://www.macworld.com/article/675869/how-to-connect-two-or-more-external-displays-to-apple-silicon-m1-macs.html I'm kind of on the fence whether MacOS/Windows is the better OS overall. However, Apple's laptop chips are so far ahead of the game in terms of CPU/GPU performace, thermals and battery life that I wouldn't buy a laptop with anything else in it right now.
-
Not GPS based but would an Apple Air Tag (or similar) be an option? I use them on my bicycles for security and keep one in my car (can be handy for finding it when parking as well!). https://www.apple.com/uk/airtag/
-
Just heard back from Casio Support. Apparently they're no longer offer the existing Classwiz emulator for Scientific calculators and have replaced it with an online web-based app/service called Classpad? https://education.casio.co.uk/classpad/
-
Yeah, I recall receiving a batch of codes last time. The page seems to imply it's only available free to teachers and not institutions however the "Not based in the UK? Purchase an emulator" link implies this is only for school's outside of the UK suggesting it is still free for us? I've emailed Casio support to check!
-
Is this software still available for free to schools as our licence has expired? I'm sure it used to be free for educational institutions but now the page seems to imply it's only standalone licences for teachers and doesn't offer the option to request a batch of licences? https://education.casio.co.uk/emulators-landing-page/
-
Default c:\ Perms allows auth users to make folders.
flyinghaggis replied to DrCheese's topic in Windows 7
We've noticed this still seems to be the default setting even on our newly installed Windows 10 computers. I presume it's like this for legacy support reasons but it seems hugely insecure and outright dangerous that *any* authenticated user on a computer can create files/folders on the root of a system drive which everyone else can access? Has anyone changed this setting and if so did it have any negative impact? I feel like it's something that really should be restricted but I'm apprehensive about making widespread changes like that to all computers on our domain if it's the expected default setting! https://learn.microsoft.com/en-us/answers/questions/952516/closing-ntfs-security-holes-in-windows-10 -
So having spent most of this thread questioning the point of gravel bikes I've gone and bought one .....sort of.... https://whytebikes.com/products/portobello-my23?variant=43938638758163# I don't know if you'd call it a flat bar gravel bike, hybrid, rigid fork mountain bike or something else! Regadless of category I finally got round to selling my road bike and wanted something a bit more commuter focused than my mountain bike for getting to work. This seemed to offer exactly what I wanted in a commuter bike (flat bars, rack/mudguard mounts, wider road tyres, 1x drivetrain, hydraulic disc brakes). Perfect for my daily trek to work!
-
@penfold Just curious if you decided to purchase another bike in the end and if so which option you went for?
-
We use ManageEngine Endpoint Central MDM installed on an onsite server. Quite competitive on cost and convenient since we use if for managing Windows devices however I suspect there are probably better cloud/hosted options out there these days. Do any of you use MDM's with offsite filtering to prevent pupil's accessing inappropriate websites on school issued devices when at home/etc? We're currently looking at providing school issued devices to some pupils next year, but I don't think the ManageEngine MDM has any kind of integrated web filtering to block specific categories (VPNS, Adult content, etc)? Are there any standalone products which would do this if we don't want to change our MDM?
-
How are you finding the Datto solution? I'm a bit wary as we're moving away from Spanning due them losing/corrupting all of our Google Workspace backup data and they don't seem able to resolve the problem a month later. I noticed that Kaseya also own Datto. After being utterly let down by Spanning frankly I don't want to touch another Kaseya product!
