Jump to content

Opendium_Steve

Members
  • Posts

    385
  • Joined

  • Last visited

Everything posted by Opendium_Steve

  1. Yes, We've got several schools currently with ~90% packet loss on their SWGFL connections (doesn't appear to be a proxy issue, just a connectivity issue). Helpfully RM said "No one else has reported a problem" when they phoned them...
  2. There was some discussion here: http://www.edugeek.net/forums/internet-related-filtering-firewall/163814-monitoring-internet-usage.html Various schools and filter vendors (including ourselves) have asked many government agencies and police for such a library and unfortunately it seems that those agencies are unwilling to work with anyone to produce such a list. Therefore, every filtering vendor has had to do their own (extensive) research to come up with their own keywords and will almost universally keep that research proprietary. I really do feel that if the government is going to place these kinds of filtering/monitoring requirements on schools, they should also be willing to work with the schools and vendors; especially given that the intelligence services certainly already have keyword libraries that are far more comprehensive than anyone else.
  3. Certainly sounds like a pain if you would have to radically change the way things are done (i.e. giving every child a separate login). If there is any kind of CCTV I guess a workstation's IP address could be referenced against the video if absolutely necessary, but I imagine very few schools would have CCTV coverage of class rooms. Although maybe it is enough to be able to identify when something concerning has happened, even if you can't pinpoint a specific pupil. And you can probably figure out which class was involved just from the timing, etc. anyway. There has to be a measure of reasonableness considered I think - I don't think its reasonable for schools to be expected to exercise control over devices that are not supplied by the school and don't use any of the school's infrastructure. 3G devices are supplied by the child's parents, so it really should be the parents' responsibility to ensure that the device is being used responsibly. (Not just in regard to radicalisation).
  4. Android is a pain in the backside - you can't install a root certificate unless the device has a lock-screen, and once you have a certificate installed it has a permanent warning about a third party being able to read your communications it in the notification bar. The warning certainly isn't wrong, but it is annoying. (You can get around these problems if the device is rooted, but you're hardly going to root everyone's phone are you?! ) All devices (Android, iOS, Windows, OS X, whatever) also have a myriad of broken apps that don't use the device's trusted certificate store anyway, so the filter has to know about each app and disable interception when necessary. For normal web browsers it works pretty well though.
  5. We've been in business 10 years and not long ago I was discussing what major changes we've seen over that time - the biggest I can think of is the change in balance between filtering and monitoring. A decade ago, schools had very trigger-happy filters with all the overblocking problems you'd expect; and this was absolutely required because if a child managed to get to porn, etc, that was often considered exclusively the filter's fault, rather than a problem with the child's behaviour/education which needed to be addressed. These days schools have a far more sensible attitude to online safety, which obviously still includes (much less draconian) filters, but now also education and active monitoring to direct not only the curriculum itself, but also the care of individual children. This is certainly a good change - relaxed filtering means less overblocking, education helps keep the kids protected outside of school and monitoring helps pick up on things that even the most overzealous automated filters would have missed. Just as a straw poll here: how many of you already install certificates on users' phones/tablets so that you can monitor their HTTPS traffic? I think the vast majority of our customers do for the kids, probably a 50:50 split for the staff (we always promote having _some_ filtering for staff to prevent accidents, but I think decrypting their HTTPS traffic is probably of very questionable value.)
  6. It would be nice if the _government_ would provide a list of keywords. When we built the "Radicalisation" category for our customers earlier this year we made a lot of enquiries to relevant parts of the government and British security services. However, they appeared to consider that kind of information "sensitive" and therefore not distributable outside of the security services, so we ended up having to do a lot of our own research, which I'm sure was just duplicating what the security services have already done in far higher fidelity.
  7. I read this article this morning and was left wondering how this is different from the existing "Prevent Duty" which came into force in July?
  8. Looks like you're right - the videos come from http://.mm.bing.net/th?id= with content type video/mp4. Unfortunately all the media (images, etc) also seems to come from similar URIs. All the videos I've tried appear to have IDs starting with "OMB" so you could try blocking http://*.mm.bing.net/th?id=OMB* but I don't know if this would catch them all and/or cause other stuff to break. Alternatively you could block anything with a content type of video/mp4 but unless you can restrict that block to only the bing website it would obviously block videos on all websites! (Note: I've not actually tried any of these suggestions, they are just what occur to me having looked at the requests being made)
  9. Can you not just block bing.com/videos ?
  10. Or vendor pulls a Bloxx and discontinues their whole product line!
  11. Starting a limited company is pretty easy and there's a lot of information on the companies house website to explain how. Probably pretty easy, but beware of the legalities of unsolicited calling and emailing. In short: Cold-calling: you need to screen all the numbers you call against the telephone preference service, as it is unlawful to cold-call a number that is listed on it. Unsolicited emails: it is unlawful to send unsolicited emails to an "individual subscriber" and companies have been successfully sued for doing this. The way the law is written basically makes it impossible for a sender to know whether the recipient is considered an "individual subscriber" or not, so sending *any* unsolicited emails is questionable. You should familiarise yourself with the Privacy and Electronic Communications (EC Directive) 2003 and Information Commissioner's guidance on the subject before you start, lest you land yourself in hot water. I will say that most of our sales have always been through word of mouth rather than proactive sales pitches. This means: 1. I can't comment on how effective cold calling actually is. 2. Making a good reputation for yourself is very helpful. 3. If you screw up and end up with a bad reputation this will travel by word of mouth even faster and would be extremely damaging.
  12. Sounds surprisingly slow to me. Do you have any monitoring to give you an idea of how much bandwidth you currently use? That said, for a small school this may be ok. The schools I know of who are using Virgin connections have a separate filtering system rather than using Virgin's, so you may need to consider the costs of that if the Virgin one isn't good enough. I'm not familiar with the Virgin filter so can't comment on how good it actually is. I would say that the "IWF compliant" bit is more or less marketing BS - the IWF watch list is very small and only covers illegal websites (e.g. child porn). Whilst it's important to be protected from those sites, schools obviously need protection from inappropriate, but legal, content too.
  13. I'm pretty dubious about them offering existing customers an upgrade route, given that they didn't announce an upgrade route when they made the end of life announcement. Their announcement essentially boiled down to "go find another product from someone else". To be honest, the whole thing seems a bit odd to me - if Bloxx's products were profitable, it doesn't really make a lot of sense to completely cut that side of the business, and even less sense to do so if they hoped to retain some of those customers for an upcoming upgrade path. I know they have said they will honor their contracts, but there is a big difference between keeping on improving a product that will be sold for years to come, and just doing the work required to support a dead-end product. It remains to be seen how well they do things going forward, but I certainly wouldn't want to be tied into a long contract with them at the moment - the risks are just too high. From what I understand, they're also being a bit tight lipped about what will happen to the UK staff, and their partner companies were also taken by surprise by their announcement so I suspect it'll take some time to regain trust.
  14. Look on the bright side - at least you know Bloxx isn't an option before you look for a new filter. A few schools have just signed up for multi-year contracts with Bloxx and are now quite concerned that development will probably stop and support go very downhill.
  15. I'm not sure whether this is specifically what @JGoswell is talking about, but originally Google used to have a mechanism to force searches to be unencrypted so that filtering systems could filter them. Unfortunately, some wifi hotspot providers took to abusing that mechanism to inject advertising into Google pages so Google pulled the feature and replaced it. The replacement system allowed schools to force safesearch on whilst keeping the searches encrypted. Safe search is only part of what many schools want though - schools often want additional protection from their own filters, audit logs, etc. and all of this requires intercepting the encryption. Whilst many filter systems have supported HTTPS interception for years, it seems that the systems used by the regional broadband consortia often didn't, or at least required major changes to support it. To be completely fair, HTTPS interception does require significantly more resources than filtering HTTP traffic so its not unreasonable to need to upgrade hardware, etc. to support it. However, I'm aware that some LEAs sent memos around to schools saying that they would no longer be able to offer any filtering for Google searches (I sincerely hope that they've upgraded by now though!). The SWGFL introduced SSL interception for Google just before the summer I think. I think that's a simplification anyway. Some filtering systems rely on nothing bug a big URL database and they have big problems with Google Translate, others also do content analysis to categorise sites. Whilst not perfect, the latter type of filter will offer more protection to Google Translate abuse.
  16. Well, we've got a bunch of customers on the SWGFL who use our filter appliances on their LAN "in front" of the SWGFL filters (they do this because they want better control/reporting than they get from the Safetynet stuff on the grid). Just after term started this year, the SWGFL's HTTPS transparent proxy was completely unusable for weeks. The customer in question was having so many problems that we told them the best course of action, at least as a temporary measure, would be to just get the grid to let their traffic straight out without going via the broken transparent proxy, and that this wasn't really a big problem from a safety perspective since they still had a filter on site. Somerset county pushed back saying it was a bad idea, but the school were also chasing the SWGFL over the slow proxy and someone at the grid ended up making exactly the same suggestion as us, so Somerset agreed and that's what happened. I understand that Somerset now offer the filtering as a separate optional item, so that customer is now planning on saving some cash by opting out of the grid's filtering entirely. I don't know whether that applies to the whole SWGFL or just Somerset, and I've not heard any other people discuss filtering becoming an optional extra so I'm afraid I can't vouch for the accuracy of this information. All that said, that customer has been having plenty of other problems with SWGFL and/or Somerset county and I think their long term plan has become to just stick a leased line in and drop the grid entirely. Hope that helps anyway.
  17. I must admit I've not fiddled with restricted mode too much recently. It certainly used to be rather too restricted for most people, but I've just tried it again and am seeing similar results to you, although the results I get with restricted mode off are way more explicit! We do a thing whereby Youtube can be blocked entirely, but allow embedded videos to still be played on whitelisted websites, although that's not quite what you were asking for. I don't think Google themselves offer a way to disable all unapproved videos though. (I could be wrong - there are folks a lot more knowledgeable about GAFE than me around here )
  18. 1. Scroll down to the bottom of the youtube home page as a user who *isn't* logged into youtube and see if it says restricted mode is on or off. If restricted mode is on and it won't let you turn it off the DNS record is working and your problem must be somewhere in the Google Apps settings. If it lets you use unrestricted youtube when you're not logged in then the DNS record isn't working. 2. Do an nslookup for http://www.youtube.com from the workstation and see if it shows the DNS record you've added or Youtube's normal records.
  19. One of our customers was very surprised by that email too, since they'd already dropped all of the SWGFL proxy and filtering services weeks ago due to the ongoing performance problems.
  20. This is an odd one - I've heard of this before in relation to using iOS with Smoothwall, but we have always used unpassworded certs with iOS without any problem. I wonder if it's because Smoothwall are using PKCS#12 format certificates whereas we use PEM (shouldn't make any difference but then I've stopped assuming that Apple devices will follow any kind of logic ...
  21. To be fair to them, iPads are an almighty pain in the backside - Apple's own applications just don't follow the standards and third party apps are just as bad. But I thought SW allowed wireless controllers to use RADIUS to avoid the authentication headaches? (For what it's worth, we've settled on using RADIUS where possible, and WISPr where no suitable wifi controller is available. Although we've seen instances of Apple devices spontaneously deciding not to do the WISPr authentication - no obvious reason and of course no useful logging in iOS to explain why, it just stops happening!)
  22. There are no PTR (reverse DNS) records for this IP address - many (most?) mail servers reject emails from IP addresses that don't have reverse DNS records. You'll need to ask your ISP (Eclipse?) to set up a reverse DNS record for this IP. Also a separate word of warning: it's advisable for the source IP address of your outgoing mail to be different to the source IP address of all your other traffic, if possible. This is because if you end up with malware on your network, your IP can end up on a spam blacklist even if your firewall blocks the malware's SMTP connections (which it should), because some email blacklists are unfortunately triggered by web requests as well as spam emails - a questionable practice if you ask me, but there we go.
  23. Might be a further indication that Bloxx are indeed pulling out of the education sector entirely - they "liked" a tweet we made inviting their educational customers to contact us. Not something I expect they'd do if they were hoping to retain their schools!
  24. Not true in my experience. We may not always be the cheapest, but we have customers who stick with us year after year because they know they can rely on us to dig them out of a hole when it hits the fan (and none of this is because they are tied into multi-year contracts - all of our contracts are annual).
  25. I always got the impression that they were much more interested in the corporate market and the education market was just a easy "extra" for them. Their prices certainly weren't great last time I looked. If it were me, I would provide much more concrete details to the existing customers in the first announcement, so that they can plan for the future. If the deal falls through, they would have to continue existing as before, but their announcement has served to create a lot of uncertainty which could have been avoided and it will be hard for them to win back that trust should they need to.
×
×
  • Create New...