Jump to content

Opendium_Steve

Members
  • Posts

    385
  • Joined

  • Last visited

Everything posted by Opendium_Steve

  1. This certainly doesn't leave much time for folks to shop around for a replacement system if they were expecting to renew shortly after January...
  2. Yep, very widely used, lots of suppliers - the competition is pretty fierce so the prices are low. I may be misunderstanding the situation, but from what I've read it sounds like LGfL have signed a 15 year contract with Virgin, but only supplied the schools up to 5 year contracts. Presumably this means that if too many schools leave, they will be completely screwed with no way to cover the cost of the remaining 10 years.
  3. I'm not terribly surprised to see aggressive tactics to keep schools using the LEA systems. We saw similar things in Hants a couple of years ago - very threatening behavior towards schools who were interested in leaving the county WAN, and lots of misinformation being thrown around in an effort to make them stay. I'm sad to say that it worked in a number of cases - we had several prospective customers who were put back in line by the LEA at the last minute. Given that @exa_mark says the LGfL were informed about the emails being blocked several weeks ago and nothing was done about it, it seems fairly clear that LGfL has either been intentionally blocking competitor's emails, or at the very least they have been negligent. False positives are a fact of life in spam filtering, but there is no excuse for not bothering to fix the problem once aware of it. Irrespective of LGfL's actions, the letter from Ealing council is downright unprofessional and aggressive and I hope the people responsible have been disciplined. LEAs should be treating schools as valued parts of the community who are empowered to make their own decisions, not subordinates who can be ordered around to meet the whims of the council. [Edit: I notice the original article has now been updated to mention that the council worker who wrote that letter also happens to be a director of LGfL, so there's a conflict of interest if ever I saw one!] The service offered by the various grids and LEAs around the country is quite variable - some are absolutely excellent, whilst some seem to try and get away with doing the bare minimum. At the end of the day, the schools themselves are the ones dealing directly with both the students and the technology. They are the ones who understand what is important, what needs improving and what they need help with. It is the responsibility of all of the organisations, whether they be the local grid, LEA or private companies such as ourselves, @SchoolsBroadband, @exa_mark, etc. to ensure the schools have good information and the freedom of choice to do what is right for them. The kind of strong arm tactics and misinformation that we _do_ see occasionally to force schools one way or the other are unacceptable and those involved should be shamed very publicly every time it happens.
  4. We aren't an ISP - we supply filtering systems directly to schools, but we certainly take safeguarding very seriously. We have always worked very closely with our customers - feedback from customers, who are "at the coalface" as it were, directly drives the direction of our development efforts. Customers regularly tell us what tools would really improve safeguarding and we do our best to implement them. To be honest, the term "internet filter" is a bit of a misnomer these days and we prefer "online safety system". When we started out 10 years ago, schools stuck a filter on their internet connection and that was as far as online safety went, but these days the filtering side of things is much less significant and providing good reporting is very important. Whatever filtering system you end up using, it needs to have the ability to automatically alert staff to any concerning behavior so that they can follow up with the students, either in person or by incorporating it into the lesson plans. The internet is so integrated into everyone's lives these days that this is a great help in picking up on things like self-harm, etc. as well as the more traditional online worries. Our door is always open to provide help and answer questions, whether it be directly to our customers through our support lines, through public forums such as EduGeek or at the conferences we attend. We'll always welcome comments from anyone, but as we have never lost a customer of our online safety systems in the 10 years we've been operating, so I think we're probably getting most of it right. We have also worked with police on individual incidents, and it is always very useful to get insight from their perspective too. I'm not going to say anything specifically about LGfL, but what I will say is that the various grids and LEAs around the country are quite variable - some are absolutely excellent, whilst some seem to try and get away with doing the bare minimum. At the end of the day, the schools themselves are the ones dealing directly with both the students and the technology. They are the ones who understand what is important, what needs improving and what they need help with. It is the responsibility of all of the organisations, whether they be the local grid, LEA or companies such as ourselves, @SchoolsBroadband, @exa_mark, etc. to ensure the schools have good information and the freedom of choice to do what is right for them. The kind of strong arm tactics and misinformation that we _do_ see occasionally to force schools one way or the other are unacceptable and those involved should be shamed very publicly.
  5. What if you don't need the "superior" bits? In the original article it was pointed out that cheaper option didn't include as much stuff, but that schools often didn't want to use the missing stuff anyway.
  6. Do they not have an SLA that you can slap them around with?
  7. Not terribly surprised - we saw similar things in Hants a couple of years ago - very threatening behavior towards schools who were interested in leaving the county WAN, and lots of misinformation being thrown around in an effort to make them stay. I'm sad to say that it worked in a number of cases - we had several prospective customers who were put back in line by the LEA at the last minute. Probably should've gone to the press at the time like @exa_mark
  8. SWGfL have been having a lot of issues with their HTTPS transparent proxy this year (they've been blaming iOS update traffic, but I'm unconvinced). One of our customers just opted out of the SWGfL filtering entirely, since they already had a separate filter anyway, as it was way too slow to be usable at times. I think they've said they're working on a solution, but not exactly a speedy response since these problems have been going on since the start of term.
  9. Depending on the quality of your school's existing connection, you could VPN the traffic back to the school and use your normal filtering system. Obviously only works if your school has a decent amount of upstream bandwidth.
  10. This isn't something I've seen raised as an issue before, but possible suggestions that spring to mind: 1. When ipads are handed out, someone can log the time and who each was handed out to. That way you can link questionable web accesses from a specific ipad at a specific time to the person it was handed to. Obviously this adds a paperwork overhead which teachers may not be happy to have. 2. Captive portal, and have a system to automatically log everyone off at the end of each lesson, possibly with a "quarantine" period between lessons during which no one is allowed to log on to make sure that the "old" user doesn't just relogin if the lesson overruns. Not sure how easy this would be on most systems - our systems don't provide a mechanism for you to do this, but it would be trivial for us to do a custom job for someone if they needed it. 3. Captive portal and an app on each device. The app would run when the device is booted and tell the portal to log off the previous user, that way the user would need to log on every time the device is rebooted - at the end of each lesson, just turn the ipad off and the next time its powered up someone would need to log in. Would require someone to do some development work to put the app together though. (2) would probably be my preference as it's pretty simple and doesn't result in ongoing extra work for the teachers. Also, you can't make anything 100% foolproof because fools are just too ingenious
  11. This is how to configure the DNS server: https://support.google.com/a/answer/6214622?hl=en&ref_topic=6248111&vid=1-635805000470370906-1744061654 Boils down to adding a few CNAMEs, similar to the "forcesafesearch" bits for normal Google search.
  12. Youtube for Schools has been dieing for ages - it was working for people who had already signed up, but the signup system was broken for over a year and Google announced a replacement for Youtube for Schools at the start of August. As far as I know, its still working for people who have already signed up for it, but no telling how long that will last - I fully expect Google to retire it completely with their usual 30 days notice at some point so I'd recommend making plans to deal with that when it happens. Its been replaced with a Google-Apps integration and I can confirm it does work, but has a few drawbacks. Relevant links: https://support.google.com/a/topic/6206681 YouTube Restricted Mode | www.opendium.com http://www.edugeek.net/forums/internet-related-filtering-firewall/157004-youtube-schools-how-do-you-signup.html#post1350663
  13. A common setup we see is certificates installed on student BYOD devices, and a separate "visitor" network that doesn't require a certificate. The normal BYOD network can decrypt encrypted web traffic for filtering and auditing purposes; the "visitor" network doesn't decrypt traffic, so doesn't provide anywhere near the same level of filtering or audit logging. Whether staff are treated similar to "students" or "visitors" depends on the school's policies - both ways seem pretty common. As well as improving filtering, decrypting the traffic allows systems to analyse the keywords students have been googling for, etc. and give staff a heads up about any worrying stuff like self-harm, radicalisation, etc. so they can follow up, so this isn't just the traditional "blocking porn" stuff.
  14. I'm not sure what is meant by "wirespeed" in this context. As an example, if you have a 100Mbps internet connection connected to a 1Gbps LAN, your filter only needs to be capable of handling 100Mbps of throughput, unless you're also using it to filter traffic within the LAN, instead of just internet traffic. So if by "wirespeed" they mean that your filter should be able to handle the gigabit network, even though your internet connection is only 100Mbps, that sounds nuts to me and a complete waste of money. The amount of throughput a filter can handle isn't a completely trivial number to come up with either because it depends on usage patterns. For example, our web filter will examine the web address you're connecting to, HTTP headers and analyse the start of the content (i.e. once its determined that you're downloading a massive non-text file, it will stop trying to do text analysis on it), generate SSL certificates, etc; this means that the filter has to do a lot of work at the start of each HTTP request, but then the work-load goes down while it handles the rest of the download. So lots of small web requests will require far more processing than a few large downloads. I think latency is probably a more important factor than raw throughput. But that's affected by a great many different factors - the majority of the "slow internet" problems we investigate are caused by a misbehaving DNS server somewhere rather than a UTM problem.
  15. The school who has been having problems reported that the latest pre-release version that Google sent them fixes their problems, so hopefully Google will release this to the general public soon.
  16. I'd say that everyone needs a transparent proxy these days - there's just too much software out there that has broken proxy support. That said, getting applications to use the proxy properly wherever possible is usually best, leaving the transparent proxy as a backup for those that can't be made to work - transparent proxies are generally a little more limited than non-transparent ones. The "pre-release" version of Google Drive that Google asked one of our customers to try didn't resolve the issue, so Google have sent yet another pre-release version to test... If you want to send me a wireshark log, I can have a look at it for you, although I suspect I won't be able to tell you anything new.
  17. Google Drive has a couple of problems with filtering systems: 1. It validates certificates against its own internal list of trusted certification authorities, rather than using your machine's certificate store. So if your filter does HTTPS interception on Google Drive connections it'll break. 2. Google periodically release versions that have broken support for proxies, so all bets are off as to whether its using the proxy or not (and therefore probably being caught by a transparent proxy, which may behave differently). A few days ago Google confirmed to us that there is a problem with the latest Google Drive release and proxies. (As mentioned, this has happened a few times, so I'm guessing that Google don't test with a proxy before releasing). They have asked one of our customers to test a new version that has not yet been released (I've got no feedback on that yet though). See (2) above - it may not be using the proxy. A couple of things to check with wireshark: 1. is it using the proxy or not? (if its using the proxy you'll see connections to port 8080, if not it'll be connecting to 443). 2. which certification authority has signed the certificate Google is presenting - you should be able to see whether its a real Google certificate or if the SWGfL have intercepted it. As mentioned, in my experience Google Drive can't be made to work with interception because it doesn't use the machine's certificate store to validate certificates. With regards to Google Support, they don't seem too bad once you've convinced them that there _is_ actually a problem. The first couple of times you raise an issue they seem to just send back a standard list of trouble shooting steps that are no good to anyone
  18. Sounds good
  19. We don't bother to deal directly with the LAs (unless we're liaising with them on behalf of a customer). Schools usually just talk to us directly because it turns out we're usually somewhat better at supporting them than the LA.
  20. I'm in Swansea
  21. Depends what's blocking the line of sight - some of the (fairly cheap) point-to-point links these days can cope with a few buildings and trees in the way. A hill in the way is another matter though. Also in some cases it doesn't cost the earth to get a fibre link between sites, but again, that's quite geography dependent.
  22. Any other schools nearby that you could share with? We've helped a few schools club together to share a connection that would be too expensive for them to afford individually. i.e. figure out which of a group of schools is geographically in the best place, put an internet connection in there and then point-to-point microwave or laser links between the schools to share out the connection.
  23. Happened a week ago We published an analysis at the time: America Runs out of Internet Addresses | www.opendium.com
  24. There have been serious problems in Somerset for the past few days - the transparent HTTPS proxy has been more or less dead (we were seeing speeds of 17Kbps yesterday at multiple schools - i.e. dial-up modem speeds) despite RM's status page saying that it is "stable" and one of our customers has had a complete outage since yesterday morning (BT network problems, apparently affecting other schools too - luckily they have an ADSL line as a backup). As far as I'm aware, there are still ongoing DNS problems with Somerset's DNS server (but that one is specifically Somerset, not SWGfL). I'm hearing a lot of complaints at the moment, quite a few schools looking elsewhere for their Internet access. That said, SWGfL have proven to be relatively responsive to complaints on Twitter.
  25. How do the Smoothwall and Lightspeed prices compare? I was always under the impression that LS was the more expensive of the two?
×
×
  • Create New...