Jump to content

djrscally

Members
  • Posts

    447
  • Joined

  • Last visited

Everything posted by djrscally

  1. Registration page doesn't even https
  2. You can do: https://products.office.com/en-gb/exchange/office-365-message-encryption Bit clunky though; you basically have to set up a rule that encrypts anything with particular keywords (like "Encrypt" in the subject line), and unlike some of the other offerings there's no method of revoking the message once sent.
  3. I'd be guessing I'm afraid; we actually don't use calculated columns at all. My Instinct was IF(ColA > -1, ColA, ColB), but I tried it and that doesn't work either (the 'if not, then column B' bit doesn't seem to trigger)
  4. Interception. Emails bounce around all over the place; natively they try and stick to a secure TLS tunnel, but if the next hop doesn't support that they go "Ah **** it" and send the email in the clear, meaning whoever runs that particular hop gets to read your emails. The famous example being Hillary Clinton's server, where they let the TLS certificate expire and so everything was sent to it in the clear. Whether anyone actually does intercept them, I have no idea.
  5. Do you mean Egress/GalaxyKey etc? The problem is we live in a world where hardly anyone is set up to receive S/MIME (or PGP, or whatever), so those options are not effective. If people can't immediately send an encrypted email, then they probably just won't bother.
  6. I'm not sure that's a solution. With the Outlook app it's definitely saving personal data to your device, but even if you force them to use the web app it's gonna do the same thing every time they open a PDF or a spreadsheet that's been sent to them. So I'd call that a hit to convenience without actually fixing the problems.
  7. It depends on the invite I think. If the invite is permanent and anyone clicking it can set up a validated account at any time then yeah that sucks. If it's a one-time use link and is time limited (say the invite link only works for 3 days or something) then that's fine really. My justification for that is; the risk of interception isn't GCHQ or the NSA or anything like that. It's really unlikely anyone is watching these emails in real time, so the risk would be someone finding it after trawling emails they collect over a period of time for anything containing the word "username" or "account" or something, by which point the invite has expired.
  8. This is good for sending batches of files and stuff but when it's a long spanning email conversation I think this probably becomes inconvenient enough that people might lean towards not bothering. Ideally it needs to be as transparent as possible. Egress kinda try to ameliorate the problem by letting you revoke emails after they've sent, as well as see if they've been accessed or not. It is a trade off, no method is perfect sadly. As mentioned, S/MIME (or PGP) is kind of the best transparent method, but with the generally low level of technical knowledge in schools it's unlikely to work seamlessly for our staff I think. EDIT: Well, actually when they're integrated I suppose it just picks the key based on the recipient, so probably it's no different actually.
  9. Egress have a tool that integrates with Outlook and Exchange 2013 I think.
  10. I'm finding this one a real minefield. We have people who work on their personal computers at home. All our systems are cloud based now, so this is very easy to do. We can't really technologically stop this from happening and we don't particularly want to anyway because it'll reduce people's ability to work effectively. How are you all handling this? I'm not really concerned about theft; that's a pretty low risk. I am concerned about it hanging around on their hard drives in perpetuity when they leave our employment, and when they throw away their old PCs however. The only answer I can think of is a policy that says it's the employees responsibility to save all data when they're using their own computer onto an encrypted hard drive, and simply provide encrypted drives to staff who want to use their own PC at home. Probably including a secure delete tool and instructions on how to use it if they accidentally Save As > C:\... Opinions? Emails to phones is a further nightmare. We can remote wipe (not looking forward to raising that one...) of course, but as people can download spreadsheets etc and the "wipe Outlook data" thingy won't cover that it'd have to do the whole phone to guarantee it got everything, which I'm really loath to do. Android and iOS both have pretty good device encryption; does anyone know if there's a way to enforce that on when people connect to Exchange or something? If that was an option, I think that (in combination with the "wipe outlook data") would be sufficient. The risk is really about staff losing/selling on a phone rather than nefarious data theft.
  11. lol. Why have error messages when you can cause some serious head scratching for a while instead?!
  12. We ought to do a Progresso users lunch at BETT. One for next year... I'm at a loss I'm afraid now then, I can't see any substantive difference between my formula and yours...one for support to get to I suppose.
  13. £50 for a 4GB stick, ouch. Veracrypt? Slightly more annoying to set up than Bitlocker, but free and works with Mac (and Linux).
  14. All three fields are lists, all three using the same Scale. Same for you? There's weird differences between the exporting to PDF and Word from SSRS. It's horrifically slow to export multiple graphs to PDF, but lightning fast to Word...but then the formatting is rubbish!
  15. Worked for me: IF(((Count(test111.test 1 * 1)) = (0)),test111.test 1 * 1,test111.test 2 * 1) Does it give you any clues? Or just call it invalid? What about in the audit log?
  16. I'm not sure you can actually restrict the confidential comments to particular staff. Might be wrong; can't see the option in the permissions tree though. In which case you'd have to tie down viewing behaviour entries through the front end heavily and just create reports which filter out confidential comments for the staff that aren't meant to see them.
  17. Anyone know if the Seminars are made available online somewhere? Some of the ones I want to hit are gonna clash.
  18. How did they take this when you told them?
  19. I downloaded LGFL's template: https://www.lgfl.net/ct?name=Online%20Safety%20Resource&url=http://static.lgfl.net/LgflNet/downloads/online-safety/LGfL-GDPR-Data-Audit-Log-10-2017.xlsx&source=Online%20Safety%20Section
  20. Unless they mean personal email accounts or something. If it's work emails; definitely nonsense.
  21. Keep the answers coming, but thanks everyone; I'm basically including the same group here and it's a comfort to know I'm at least doing the same as the rest of you!
  22. ...How is your school making GDPR related decisions? I assume (like for me) this has been mostly passed to the data/it manager, but I also assume you're not just dictating how it will all be and have some form of working group to make the decisions - who's on that group?
  23. Yeah to me too, I'll still go see it at BETT though, could be popcorn worthy even if it doesn't work.
  24. I actually just got an advert offering to replace manual roll calls with facial recognition...I doubt this is gonna fly but maybe they'll tweak it to a "locate photos of a specified student" jobbie instead
  25. I would say the school is the data controller, but that I think the current arrangement (I.E. a mixture of couriers and recorded delivery) is probably sufficient. As you point out, the severity of witness statements being misplaced is some orders of magnitude worse than exams material going missing. I think the severity of a package of exams papers being lost is low enough that the current level of protection is appropriate, given the boards have methods of compensating students by using other methods to approximate their grades.
×
×
  • Create New...