Jump to content

jthompson

Members
  • Posts

    5,685
  • Joined

  • Last visited

Everything posted by jthompson

  1. For me, using LTSC for general deployment across a school is one of those 'swimming against the tide' decisions. I've found that aligning myself with the general direction and intent of Google/Microsoft's design makes for an easier time, but we'll all be predisposed to that instinct to a greater or lesser extent. But it's not like there's any particular downside to using LTSC: nobody has ended up snookered or in some wildly different place as the years have passed.
  2. Back when Windows 10 was less mature, I suppose there was more of an argument for it. With end users so much more familiar nowadays with cloudy SaaS for their goto productivity, I think they're more accustomed to sudden UI and feature changes, so less need to protect everyone from software changes. Personally, having stuck with W7 for so long, the jump up to Win10 was a fair chunk of work so I wasnted to get off that big-change-every-few-years cycle and smooth it all out with incremental changes every 6 months. The number of changes where we've actually had to suddenly configure something following a feature update for W10 has been tiny, though. The only ones I can think of off the top of my head are when search processing got baked into the Start menu (previously we were blocking searching in the Start menu) and that dumb weather & news widget.
  3. My obligatory recommendation for Checkmk Raw Edition. The colours are pretty.
  4. I don't know, I kinda like that SIMS 7 doesn't have the latest fancy graphics. I like the old-school look and feel of it, and it's refreshing to have to think and take your time to accomplish things in the game.
  5. We also prohibit writing to removable media, so all these jobs come via us in conjunction with the exams office. That's fine, because it provides a much needed element of quality control. We also have a stockpile of older USB sticks that will only ever see use for this kind of thing. We make a point of archiving in a Google shared drive (away from teaching staff) a copy of anything sent off on USB, in case we're asked to resend anything.
  6. AQA prescribe a couple of encryption passwords each exam season for work being submitted on USB. One for A-Level and one for GCSE. They also list the subjects that the passwords should be used for, which I believe is those where candidates are necessarily visually identifiable (Dance, Drama, etc). We've sent off DT work on USB to AQA, for instance, which they didn't want encrypted. We encryptted it anyway, because the students' portfolio work may well include a photo of them. The assessor emailed us to say that the files wouldn't open: they hadn't been briefed by AQA to expect 7-Zip/BitLocker encrypted material. It's all very well bemoaning the use of USB sticks, but honestly, the number of idiosyncratic systems that our exams officer has to deal with when uploading students' work via the web... it creates a lot of work from a support perspective. Some systems only allow files to be uploaded one at a time, some don't want zip archives, some just fail mysteriously. One even uses the web versions of SecureAssess, with the exam officer essentially having to 'sit' X number of exams one after the other, where there is one file submission 'question'. Naffo. In contrast, slinging files through 7-Zip onto a USB stick with no confusion as to what password should be used is a piece of cake. I believe AQA have a good system at the moment: in previous years, I seem to remember each qualification having a different password to use, and the assessor ultimately taking delivery of the USB stick would often be confused about any mention of encryption tools. It seems to work pretty well at the moment, touch wood.
  7. My previous Mac was a 2011 MBP. Doubling the RAM and then installing an SSD extended it's life considerably, although by the end the battery needed replacing. That said, upgrading a laptop so that it still feels fast is of limited advantage if it's stuck running an out-of-date OS version. I wasn't able to run Google Drive for Desktop any more on the old Mac, because it stopped supporting the OS. I'm therefore not expecting as many years out of the non-upgradable MBA anyway.
  8. Recently splashed out on a MacBook Air M2. Yes, it's expensive and no, the hardware can't be upgraded, but I love it to bits. Very thin but still sturdy, great display, great sound, fanless (!) charging lead is actually good. No USB-A for the money, but it is an Air model after all. If you like Macs I think the current models are particularly good designs.
  9. It amuses me that whenever 'widgets' are a touted feature of a device, the obligatory sports results and stocks widgets get rolled out. Surely anyone who cares about a sports result will either already know it directly, or want to actively avoid knowing it right away. And stocks I'm assuming are just a very widgetable data source that nobody actually has any interest in: least of all someone opting for a free television set.
  10. Free, ad-supported television. Literally. https://www.freetelly.com/ A free (as in £0) television set which includes a secondary screen below it that constantly displays advertisments. Adverts mights also be shown on the main screen when nothing in particular is being watched. Oh, and it has a built-in camera and microphone, because it has Zoom.
  11. When I first saw some of them I couldn't really see why they were winners particularly, but then you look a bit closer and notice some of the textures being achieved... whoa! Not a huge fan of the non-metallic metals look which seems in vogue at the moment, particularly when it's dialled up to 11.
  12. We're still seeing more Hotmail mailboxes of parents bouncing back as over quota. I get that it's the recipeint's responsibilty if their mailbox isn't accepting new messages, but I would suggest that schools take a look at how many NDRs they're receiving off the back of school comms and attempt to notify parents about the issue if there's a significant number.
  13. We use AppLocker to block access to Calculator, Office apps etc as required for the conditions of each exam.
  14. EduLink One will let you take registers and log both achievements and behaviour. They have a live demo that you can poke around at without needing to express interest or anything: https://www.edulinkone.com/#!/ then click the DEMO button. The site is responsive so suitable for mobile. Achivements can be found in the Behaviour section.
  15. Perhaps deploy an additional new SSID, keeping the original in service for a period of time that's suitably long enough for clients to use it to be able to pull down the new SSID details.
  16. I can only assume that Lord Flashheart will be getting a special set dedicated just to him.
  17. This fascinating article goes into detail about underpainting, which is basically some nice straightforward steps between undercoating and adding colour. https://www.goonhammer.com/how-to-paint-everything-underpainting/
  18. Painting Warhammer [40k] miniatures. Not very wife-friendly, though: for some reason she's not that bothered about my hand-painted space monsters. We have an allotment now, too, which is mainly my OH's hobby that I help out with. We'll shortly be taking up parenting, so I think that's probably my free time block-booked for the next decade or so.
  19. Plenty of deliberately silly pronunciations in our house, which have now unfortunately stuck. "Loughborough" is now pronounced "Loo-guh-bar-oo-guh". The breakfast cereal "Balance" is now pronounced "Balancé", as in Beyoncé. "Melon" is now pronounced "Muh-laan" in a probably-offensive American accent. Which almost takes me onto the list of things that aren't so much mispronounced as sung ("mango" now gets followed up with "Hey mango, mango Italiano!", for instance). I'm really hoping that these only come out at home, but they're so normalised that I worry we use them in company without realising.
  20. From The Guardian: Cyber-attack to cost outsourcing firm Capita up to £20m
  21. If the laptops are slow at installing the monthly CUs, then one mitigation would be to book the trolley(s) out for a maintenance window in the days following patch Tuesday, so give them all a run at getting the latest CUs completed. We tend to find that faster laptops and/or laptops that get more frequent use are able to keep on top of their updates pretty well just in the background, without any admin attention or much T&L impact.
  22. We also apply a GPO just to that account that sets a URL allowlist for the web browsers, so that candidates can't make use of the requisite Internet access to browse after finishing early.
  23. Back when we used to lock down earlier versions of Office to prohibit the use of SPAG tools, there was a bunch of menu item IDs that we listed in a GPO to disable them in the GUI for end users. Might it be worth looking into whether the GUI buttons required to manually add an additional account can be disabled via Group Policy in this way? I know that this is for the wrong version of Office, but is there an equivalent for the version you're using? Disabling commands by using control IDs
  24. I suspect that Google's thinking is that as passwords start being used less and less by poeple (in favour of passkeys), that will allow them to treat each use of a password with more scepticism. I don't know. Passkeys are one of those slippery things where each time I think I've grasped it, I then realise that I've not quite grasped it. Much of the PR from the big firms is written for a consumer audience in a tone of "it just works, accept a little bit of magic and don't think too much about it", whereas our job as admins is to understand and account for those edge cases a bit more.
  25. Each passkey is device-specific, so a PIN would be more secure than it sounds. A stolen PIN wouldn't allow access from some other random device. If you lose your phone, then you revert to using password/2FA. If you get a new phone, you'd similarly sign into that initially using password/2FA (or a cross-device QR if bluetooth proximity can be detected) and then a passkey is probably automatically added for you for the new phone. Yes, phishable authentication is still technically in play, but there's more friction there if passwords aren't the regular way to sign in. Trying g.co/passkeys on my Workspace account, it tells me "Passkeys aren’t allowed on this account.". Not sure if that's because they're not available for Workspace yet, or just that they need enabling in Admin. In principle, I can't see why there would be any issue with Workspace users having them. It's pretty similar to how they're able to add the 2FA methods that they want/need. With passkeys available, admins would still be able to provide users' with one-time 2FA backup codes. Edit: Just read on a blog post from last week https://blog.google/technology/safety-security/the-beginning-of-the-end-of-the-password/
×
×
  • Create New...