Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

sigma

Members
  • Posts

    1,681
  • Joined

Everything posted by sigma

  1. So you have glass walls in your bathroom? Nice! https://www.openrightsgroup.org/blog/2015/responding-to-nothing-to-hide-nothing-to-fear Debunking a myth: If you have nothing to hide, you have nothing to fear - Identity, Privacy and Trust https://en.wikipedia.org/wiki/Nothing_to_hide_argument If there are any suspicions about individual adults in schools (or any workplace), the proportionate response is to investigate that individual not the entire school population. Most schools have policies and there are legal processes to do that.
  2. I'm not suggesting that there should be no "filtering" of adults, I totally agree that there is a whole plethora of sites that should be "blocked" for the many and various reasons that we all know. Of course everybody's internet in school should be filtered. In addition to those that should rightly (or wrongly sometimes), be blocked by default, I now have access to a portal where I can custom block/unblock. ( I've never had that before. Previously I had to fill in an e-form and my request was validated by the filtering provider and then enacted. I'm not actually sure I want to be solo accountable for blocking/unblocking directly - as you say, too much responsibility. I know some small schools that will just unblock if a lesson has been prepared without considering anything or website T'S and C's or privacy policies, the Data Protection Act - just for expediency, I also recall the KS1 teacher that asked the class to search for "Asian Bears" when filtering was less capable than it is now. but I digress...) My concern is of covert surveillance of adults by the Local Authority, the exposure of Account ID's, passwords, credit card, "sensitive personal data" etc as defined by the DPA/GDPR and and also that of third parties from social media updates on BYOD devices by decryption of HTTPS, and what the legal basis is that is being relied on for doing this. Decryption is not needed to block access to HTTPS.
  3. Thank you, but as stated in my original question, I am not your customer and I don't have a Smoothwall device, the local authority in it's capacity as school broadband provider does, and I am their customer. I was surprised that compared to the previous filtering provider that just about everything was being decrypted for adults when it wasn't previously.
  4. Yes, but it's County's appliance not ours, so I'm not hopeful. It seems very heavy handed to me, and I'm not convinced it's entirely legal to be intercepting private passwords to personal accounts in this manner.
  5. My county is moving to a Smoothwall filtering solution. I am running some rudimentary tests on the adult/teacher filter. I am somewhat aghast to find that by checking the SSL certificates that the account logon pages for shops such as M&S and John Lewis, some financial institutions, my doctor's surgery and political parties - sites that might be classed as "sensitive personal data" are having the account name and password decrypted. If shop account logons are decrypted then saved credit card data is also accessible. Am I being paranoid or is this normal? This wasn't the case with the county's previous filtering provider. It seems as though they are intercepting every SSL site with the exception of a few manual exceptions. There has been no formal notification of this policy change. Does anybody know on what legal basis my County might be relying on to intercept these communications?
  6. A number of laptops supplied to families in Ipswich were observed for sale outside Portman Road football stadium very shortly after they were supplied. Was that good use of public money?
×
×
  • Create New...