Jump to content

Opendium_Steve

Members
  • Posts

    385
  • Joined

  • Last visited

Reputation

779 Excellent

About Opendium_Steve

Personal Information

  • Occupation
    Technical Director, Opendium
  • Location
    Swansea
  • X

Employer (optional)

  • Company Represented
    Opendium

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. I think Frankie's death directly lead to the new Filtering and Monitoring Standards: Publishing some proper standards was definitely the right thing to do - previously schools were just told to do something "appropriate", and although the UK Safer Internet Centre's guidance was signposted by KCSiE, there was nothing from the government themselves. Schools had a lot of flexibility, but with no guidance from government it places a huge amount of work on the schools to figure it all out themselves. And frankly, most schools simply aren't capable of doing that (due to a combination of staff having not enough time and not enough knowledge). The new guidance is a lot to take in, and for some schools is going to mean a lot of work (both policy and tech) to bring things up to the standards, but in the long run it's surely got to be the right thing to do. At the moment, England has by far the best guidance of the whole of the UK, and despite being a big supported of devolution myself, I think this is a circumstance where the devolved nations really should be pointing at the DfE guidance and saying "do that." The inspectorate handbooks really need bringing up to standard too though: Ofsted's inspector's handbook just says: "We do not require schools to: * take any specific steps with regard to site security; in particular, inspectors do not have a view about the need for perimeter fences or lockdown alarms * use a digital platform to monitor pupils’ internet use, and we do not specify how these platforms should operate" Now, the guidance requires schools to have a monitoring strategy, but not necessarily a monitoring system, so its not wrong for Ofsted to say you're not required to have a monitoring system, but surely they should be checking that the risk assessments that you did to determine whether or not you need a monitoring system, and how you're using your monitoring system if you have one? The Ofsted and Estyn handbooks both say they will inspect the way you teach online safety (the ISI's handbook doesn't say anything about online safety!), but surely they should also be looking at your filtering provision, etc. They do often look at the school's filtering, monitoring, etc. but the fact that these aren't mentioned in the inspector's handbook at all makes it all very hit and miss.
  2. You may not agree with the outcome, but Ofsted did an actual study of real pupils at real schools, and their findings were that overdoing the filtering actually left kids more vulnerable. I think the distinction between what Ofsted are saying and your suggestion is that kids will have to deal with unfiltered internet outside of school so it's important that they learn how to behave safely, whereas they don't routinely have to negotiate a world littered with open 400v cabinets. Even if the parents filter their home connection, at some point in their lives your pupils are going to encounter unfiltered internet, whereas I suspect most people go through their lives without ever being presented with live exposed electrics. You're also reducing the risk of having lighter filtering by ramping up your monitoring - unlike electrocution, online dangers are generally not "one mistake and you're dead" - with proper monitoring you can catch concerning behaviour before it becomes serious. I guess a lot of this comes down to what your goals are: if you want to keep pupils safe while they are in school and reduce the chances of the school being held liable for pupils seeing harmful content over the school's internet connection, then very strict filters are for you. If you want to keep pupils safe both in and out of school over their whole lives then Ofsted says reduced filtering and better monitoring and teaching are the right thing to do. Sort of... "be careful that “over blocking” does not lead to unreasonable restrictions as to what children can be taught with regard to online teaching and safeguarding." - KCSIE (England), Paragraph 134. "It should not:  * unreasonably impact teaching and learning or school administration * restrict students from learning how to assess and manage risk themselves" - Filtering and Monitoring Standards (England) "As far as possible, such tools should be accessible and free from restrictions that constrain their worthwhile educational value." - DE Circular 2007/01 (Northern Ireland), Section 2 "appropriate internet access, is provided for boarders for the purposes of organised and private study outside school hours and for social purposes." - National Minimum Standards for Boarding Schools (England), Paragraph 4.2 So multiple guidance documents from multiple UK governments define overblocking as whether the filters "unreasonably" restrict teaching and learning (and social activities at boarding schools). You can argue about what "unreasonably" means. Also consider that pupils are safer when using the school network, since you have filtering and monitoring - if you restrict things too much, they will simply go and use mobile data for all of their internet use, and then you've lost whatever ability you had to keep them safe. Sometimes you might accept that you're allowing access to unfilterable/unmonitorable parts of the internet in order to keep them on your network so that you can filter/monitor the rest of their traffic. And obviously, there are requirements for schools to teach online safety, so the idea of being less strict with filtering shouldn't be taken in isolation, but rather supported by increased monitoring and education: "Governing bodies and proprietors should ensure that children are taught about how to keep themselves and others safe, including online." - KCSIE (England), Paragraph 129 "An effective online safety programme of education should supplement this guidance to teach children and young people the importance of responsible and considerate online behaviours." - Education Digital Standards for Schools in Wales: Web Filtering, Paragraph 4 "Ensuring that all users are taught, and that they learn and exhibit, safe, responsible, ethical, moral, legal, healthy, intelligent and effective working practices, is an important educational goal which it is the responsibility of the school to promote, and for all staff to model, at all times." - DE Circular 2007/01 (Northern Ireland), Section 2 "eSafety must be built into the delivery of the curriculum." - DE Circular 2013/25 (Northern Ireland), Paragraph 2.5 " * Pupils receive age-appropriate online safety messages that are relevant and engaging. * The school actively promotes online safety messages for pupils on how to stay safe; how to protect themselves online; and how to take responsibility for their own and others’ safety. * Online safety is actively promoted within the school, for example through the development of online safety messages by the learners themselves, and participation in events such as Safer Internet Day and associated competitions organised by agencies such as EA/C2k. " - DE Circular 2016/27 (Northern Ireland), Paragraph 9. "Schools should deliver an age-related online safety curriculum to enable pupils to become safe and responsible users of technology." - DE Circular 2016/27 (Northern Ireland), Paragraph 17.
  3. Ofsted's The Safe Use of New Technologies report (2010) said: And recommended for schools to: So the message seems to be less blocking, more monitoring. So consider turning down the sensitivity of content filters and compensating by using regular reports (and real-time alerts for serious stuff) to catch the content that now falls short of being blocked. Our block pages have a button for users to report that the website has been miscategorised. Those reports go back to us as the filtering provider and are manually reviewed. There's plenty of useless noise in the reports, but there's also some really valuable stuff that is used to recategorise content. This doesn't cater for the situation where something has been categorised correctly but the user thinks that is should still be allowed, but in the future hopefully those reports can go directly to the school admins. How well that would work depends on how engaged the school are and how well resourced their staff are - filtering *policy* is a job for the schools rather than the suppliers, so a supplier can't make decisions on whether a correctly categorised site should be allowed anyway. I'd be very interested to hear how schools are taking unblock requests from their users, and how they are being handled. The DfE's new guidance makes the point that decisions to block/unblock content need to be documented, which is something I rarely see happen (many a block list review ends with "why has the whole of Amazon AWS / Cloudflair / The Daily Mail been whitelisted?" -> "I dunno"). The guidance also says the DSL should be involved in allow/block decisions - it seems impractical for every decision to be run past the DSL at the time it is made, but having the DSL regularly review recent decisions would ensure some documentation was kept, since someone would need to explain the decisions!
  4. Both - the whole site can be in one or more categories (e.g. the whole of pornhub is in the porn category, the whole of reddit is a forum, etc.) but subsections of a site can also be categorised, so self-harmy bits of Reddit would be in the Self Harm category as well as the Forums category, the porny bits of Twitter would be in the Porn category as well as Social Networking, etc.
  5. Yes, absolutely! But that fundamentally doesn't change my point that I don't think AI is a magic bullet to solve these problems - AI can do text classification, just as keyword analysis can do. AI can probably do it slightly better, but it is way more resource heavy and I just don't think that text classification is really where the challenge is - expending orders of magnitude more resources to gain a marginal improvement in text classification doesn't actually make a significant difference to how well filtering / monitoring systems do what you want them to do. There's also the question of how capable schools are at setting this stuff up - even though its possible, in my experience its rare to see schools setting their filters up to know where/when students are being supervised and tweaking the filtering for those circumstances.
  6. AI can certainly pick up things like a page full of porn, but keyword filters work well for that sort of stuff too and need less resources. Where keyword filters struggle, AI will also struggle, because there are mainly 2 failure modes: 1. Some content just doesn't contain anything that looks concerning, when taken in isolation. A lot of the Andrew Tate stuff is a good example - you need to understand who Tate is, his background, what the problems are, etc. in order to know that it's concerning content. Current AI technologies are usually run through an extensive training cycle once, and then used to analyse content in isolation. Keeping their training up to date so that they can take this kind of background context into account is really hard. 2. Humans want to believe that things can be divided into nice simple categories, but that simply isn't true - its often extremely difficult to decide how to categorise a web page. We have written categorisation criteria for (human) analysts to follow when manually recategorising websites, but still have regular discussions internally on how to categorise specific pieces of content. Different members of staff often have conflicting opinions - this stuff is not at all clear cut. The results of those discussions not only lead to a decision being made on specific content, but feeds back into the categorisation criteria that will be used in the future. For example, what specifically should a "Weapons" category block? If you block all websites selling knives then you're blocking a really wide range of stuff (keyring penknives, craft knives, Stanley knives, kitchenware, right up to the stuff someone might carry into a fight). Wikipedia pages describing commercially available hand guns may seem like fair game, but what about Wikipedia pages documenting the weapons used in the world wars? Legitimate gun clubs / firing ranges? Info about / sale of digital items (e.g. video game weapons)? Books / movies / TV programmes which contain weapons? Arguably all of that is "weapons" but blocking it all would probably be harmful to teaching. Similar problems for a "Violence" category - News articles? Historical accounts? Fictional stories? The Bible?. Porn is the classic "I know it when I see it", and from experience different schools have very very different opinions on what they think is "porn", with some even considering the front covers of some mainstream papers that you would see if you ventured into your local Tesco to be "porn" and therefore blockable. What about historical paintings? What sets a classical nude painting apart from a modern nude cartoon? etc. These are all human problems, and are hard for humans to grapple with. Definitely not something that an AI is qualified to make decisions on. (For what it's worth, we have a separate "Tate Brothers" category, because some schools want to block it, others want to monitor it and other's don't seem to care!).
  7. I've never seen any specific advice on unauthenticated access. The UK Safer Internet Centre says you should identify users - obviously it isn't always possible to follow the guidance, so we usually recommend doing a risk assessment for situations where you are deviating from the guidance. So, your risk assessment should cover: - How you're deviating from the recommendations (i.e. interactive displays will have internet access with no user identification). - The reason why you're deviating from the recommendations. - What risks are created by the deviation. - What you're doing to mitigate the risks. - What risks are remaining following the mitigation. - Why you consider the remaining risks to be acceptable. Your mitigations will probably include things like ensuring that the traffic has student-level filtering rather than staff-level, etc.
  8. Note that TLS 1.3 isn't *necessarily* a problem in its own right. The issue with TLS 1.3 is that it optionally allows SNI encryption - software that doesn't make use of that option will be fine, and there are a few work-arounds for software that does use SNI encryption. The real killer is doing both SNI encryption and DNS-over-HTTPS to third party servers at the same time. But indications are that most DNS-over-HTTPS implementations are going to default to your local DNS-over-HTTPS server rather than a third party one.
  9. Redundancy is always a balancing act between reliability, cost and complexity (not forgetting that complexity can harm reliability). You can get your backup lines from completely independent suppliers, but even then making sure their routes are as diverse as possible is hard - when a big datacentre goes down, multiple otherwise independent suppliers are affected. In fairness to the service providers who are affected, what I'm hearing is that many of them were paying for diverse power supplies and have lost power on both supplies. So there are going to be some pointed questions directed at Equinix as to whether they were actually providing what they were paid for, and what could have failed so catastrophically to take out supplies that were supposed to be independent.
  10. I've seen a few complaints from people who have lost all of the diverse power to their racks, and the updates from Equinix seem few and far between as well. Think there will be some hard questions at the end of this.
  11. Some systems (often cloud based) are indeed entirely based on a client running on each machine, some systems use a combination of an on-machine agent and a gateway device, and some don't need any client software at all, some use DNS filtering exclusively. So there are a few different ways things work, and it does depend on the individual vendors. There are obviously pros and cons with each. Firstly, I would avoid anything that relies entirely on a client on each machine. The Safer Internet Centre's Appropriate Filtering guidelines say that filters should be "network level", so relying on a client doesn't meet their guidelines. Its worth looking at their guidelines, which are here: https://www.saferinternet.org.uk/advice-centre/teachers-and-school-staff/appropriate-filtering-and-monitoring/appropriate-filtering Also most vendors have a checklist against that advice - again, worth having a look: https://www.saferinternet.org.uk/advice-centre/teachers-and-school-staff/appropriate-filtering-and-monitoring/provider-responses-0 To get an appropriate level of filtering/monitoring, you need a system that will do HTTPS decryption. This means that you do need to install _something_ on each device - either a certificate, or an agent which takes care of the certificate installation. For Windows machines this is easy to do through group policy, and similarly for MDM managed devices the MDM will do it for you. For stand-alone devices it can be a bit of a pain, whatever system you use. So, things vary from system to system, but I can explain from the perspective of running an Opendium Web Gateway or UTM system: The device goes between your network and your internet connection - either as well as your existing router, or completely replacing it. It does both firewalling of non-web traffic, and filtering of web traffic, and this is the safest configuration since it means that all traffic to/from the internet has to pass through the device, so can be controlled. We don't use any on-device agents, so nothing to install on the machines other than a certificate. If you have multiple VLANs, you can use the UTM to control traffic between them (e.g. segregating BYOD from the rest of your LAN, etc.) Being able to identify the users is also part of the safer internet centre's guidelines - it allows you to set different filtering levels for different user groups (e.g. staff / students) and means that you can easily identify vulnerable users in safeguarding reports. For machines on your Active Directory domain this is done through Kerberos single signon, so is completely transparent to the user; for other machines there are a variety of options and exactly which you choose is dependent on your network infrastructure and your requirements - most schools use WPA2-Enterprise wifi networks, which works very well. Most of of the filters on the market are simple URL block lists, a few of them (Opendium included) do real-time content inspection. Simple URL block lists don't really cut it on sites that tailor content to the individual users, so I'd definitely say go for a filter that does content inspection (yes, I'm biassed, but we're not the only supplier that does it so you have some options). You said that this isn't your IT supplier's forte, so I very much recommend that you look at how much support you'll get from the filtering vendor themselves. It isn't reasonable to expect your IT supplier to be able to do a good job of supporting the system themselves since they have very little experience with it - make sure you can go directly to the filtering vendor and get any help / advice you need. A filtering system is not a "fit and forget" device like a simple router - it does need ongoing work to make sure the apps you want to work do work, and the things you want to block are blocked. If you need any help and advice, please give us a call. We don't do "hard sell" and are happy to answer your questions even if you go elsewhere in the end.
  12. Agreed, which is why this is being addressed. This is a thing that is very important for marketing, and not terribly important for long term customers. Then I think you are out of luck. Absolutely none of the vendors have a perfect score on all of the points in my list, if you judge a book by its cover you are basically guaranteed that it will be subpar on other aspects instead. That's definitely not to say that a product with a crappy UI is guaranteed to win on every other point, I'm simply stating our position on this: we live in a world of finite resources, some vendors have chosen to expend their resources on the things that will close a sale and let the things that are important to long term costumers slip. We have chosen to do the opposite - yes there are consequences in that this makes it harder to make a sale, but on the other hand our long term customers are very very happy and we make the majority of our sales on recommendation. In any case, you are certainly welcome to say "nope", I'm merely putting this out there for those who aren't happy with the level of support they are currently getting and want to switch to a vendor who has made that their speciality.
  13. I don't disagree that it lowers the barrier to changing product, and I'm not really wanting to get into an argument about what is worth investing resources into, but: There are a number of things that are important about a UTM appliance, things that come to mind are: General feature set (does it do what you fundamentally need it to do?) Ease of use (which is, in part, an aspect of the UI) Attractiveness of the UI Performance Compatibility Reliability Technical support Openness and honesty All of these are important, but there are only so many hours in the day. It's true that we've allowed the UI to slip a bit, which is one of the reasons we're in the middle of a big redesign at the moment for our next generation release. The reasons for letting the UI slip a little are largely because we've spent a lot of resources on the other points, especially the technical support (you will *always* get to talk to someone technical when you call for support, as a relatively small company we make sure you can talk directly to the developers if you need to, and the vast majority of issues are resolved on the spot while you're on the phone). There are frequent complaints on these forums about the quality of support, reliability, etc for many other vendors, so whilst I can't claim that we've got the balance perfect, I come back to: there are only so many hours in the day, which things are the most important to you? - none of the vendors have a perfect score. We very much feel that whilst the UI is often instrumental in making a sale, it is by no means the most important part of the package you are buying. We have a very high customer retention rate, and we strongly believe that this is largely because the things we concentrate on are the things that are important to a school in the long term. Fundamentally, the UI design is only the most important aspect of a product when making a sale and for the first couple of months. But to reiterate: we are actively addressing this at the moment.
  14. We're in the process of doing a redesign from the ground up at the moment to address this. But how important this is to you depends on whether you prioritise things working well or whizzy dials and graphs
  15. There are a few screen-shots and videos in the documentation, but you're right that we don't have much of that on the sales side - I'll feed that comment back. I will say that screen shots don't really do the products justice because we're more focussed on getting things working well than flashy graphs and dials. Here are a few links that you might want to have a quick flick through though, and we're always very happy to give you a demo and/or chat through your requirements on the phone. We don't do hard sell - we'll be the first to tell you if you need something we can't do, but we do take note of feedback from both customers and non-customers alike and use it to drive the direction of our products. https://www.opendium.com/howtos/audit-what-images-your-users-are-viewing https://www.opendium.com/howtos/using-policy-modelling-reports
×
×
  • Create New...