-
Posts
2,232 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Primus
-
Just to followup on this again but students are not in school to communicate with family digitally. If they are communicating with peers digitally it should be using a school chosen platform - not something like SnapChat! I would be very interested to see these Ofsted reports as they bear no resemblance to Ofsted reports that I have read nor inspections I have been involved in.
-
Can you supply links to these reports please? I know Ofsted have been known to criticise overzealous filtering but I've never heard this applied to social networking being filtered!
-
As well they might - but SnapChat - really?! I'd consider our filtering policy and environment in general relatively relaxed but seriously SnapChat?!
-
Not at the cost of safeguarding it's not!
-
Are you seriously going to allow SnapChat?!
-
I agree with all of that but you may not need masses of training - my experience with a staff that aren't exactly tech savvy indicates it's more user-friendly than the alternatives. Obviously some training will be required and some staff may need additional hand-holding.
-
To be honest I pretty much live in G Suite now - functionality is pretty comparable with Office now - it's rare to find something that isn't possible now. Now if they'd just add native ink support to Google Slides then I'd say there's nothing a normal teacher would need that they don't have in Slides, Docs and Sheets. As a G Suite school we have lots of Chromebooks - almost as many as we have desktop Windows PCs now, other schools nearby have spent a fortune on staff CPD trying to get to grips with and use O365 and yet they've had little to no take-up. On the other hand we've run minimal CPD for staff - but offered lots for individuals or faculties and our take-up is huge. IMO and it is just an opinion G Suite is both way easier to administer and use for staff and students.
-
What? No it's not that limited at all - Unifi has full CLI support! For example.
-
UniFi / NPS / Smoothwall / RADIUS - Problems
Primus replied to SystemsAd's topic in Internet Related/Filtering/Firewall
Yes and no they don't. -
How many SIP trunks/channels do I need???
Primus replied to fiza's topic in Mobile Devices & Tablets
Yup we have an onsite PBX (Mitel) and we have 12 sip channels that are used across many many handsets with pooled minutes. -
How many SIP trunks/channels do I need???
Primus replied to fiza's topic in Mobile Devices & Tablets
Have you got an onsite PBX? -
How many SIP trunks/channels do I need???
Primus replied to fiza's topic in Mobile Devices & Tablets
Yes they will. -
Let's see if 1809 breaks anything major - we may consider a site-wide re-image in October half term depending on when it's released if it gets us anything useful. Since we don't use O365 I'm thinking it probably won't. It'd also be good if releases actually launched on time too - it's been a while since a release actually launched in the month it's numbered for!
-
Sorry that's not really how forums work and a bad idea deserves to be highlighted. If I ever came across any product that could display passwords my users had chosen I would immediately move on and never consider that product again as it shows such poor awareness of security issues that I would be constantly worried about what else had been compromised on.
-
I'm not convinced that NTLM is as bad as you portray (and it does depend on minimum length) but, even if it was, there's a big difference between a sub-optimal encryption algorithm and just giving everyone access to passwords people have chosen. You should never ever be able to see another user's password.
-
Storing passwords in cleartext is bad bad bad. Storing passwords with reversible encryption is bad bad bad. Letting people see passwords people have chosen is bad bad bad. Whatever security we have is far superior to those choices.
-
Once again we're back at the argument that because something was done in the past it should be done now. Yes the ability to crack passwords means that over time new algorithms need to be used with longer keys etc. That doesn't mean you just give up! LastPass is fine once you're logged on (though I'm a 1Password fan myself) - however your logon password needs to be something easily typed in, memorable etc. Essentially your argument is that the security could be even better so let's not have any security - eg. the lock on my front door can be defeated so I shouldn't bother with a lock...
-
Just because something has been done for a long time doesn't mean that it's right! So an IT Management company praised you for lax security - it would be useful to know their name! They weren't trying to upsell you from an audit to anything else perchance were they? I think you rather overstate how often passwords are changed! If you allow students to behave poorly then they take a lend. However if there's a consequence for repeatedly needing your password reset - perhaps like there's a consequence for not having a pen or your PE kit then students don't see this as an opportunity and learning time is not lost. Why have log ins at all - after all logging on to a computer wastes learning time, why not have all PCs just automatically log on to a default account that has access to everyone's documents. I also agree with AlanD - educating users on choosing good passwords etc and behaving properly is key but then for the school to show such poor security practices as to store the passwords in cleartext/use reversible encryption is setting a poor example and just because no one has complained doesn't mean they'd be happy about it if they actually knew. Parents tend to just sign school paperwork as do students when they start - if you asked all of your students how many do you think would realise you could see their password?
-
Also an audit by whom? There’s a lot of nonsense and unqualified people holding themselves out for audits that are little more than a sales exercise.
-
Given how critical I am being of someone’s else’s practice here do you really think I’d give all staff that level of AD access?! They have delegated privileges over particular OUs and it’s exposed through a limited utility. There really should be no arguments on seeing end user passwords. It’s no wonder IT gets such a bad rep when as an industry people just feel free to do what suits their convenience without a thought for proper security practices. No one should ever see anyone’s password once it has been changed from an initial state. The only exception is for very young students but I’d rather use something like Clever for QR logins than have guessable or shareable passwords.
-
If you read the original post I was responding to they said: "we intercept password changes in AD, this is plain text before it is encrypted. This is so staff can view the students password" Honestly it's such bad practice - no one should ever see anyone else's password. Reset passwords sure - all our staff can reset a student password no problem, but never see another user's password - I can't ever see a situation where this would be good practice.
