-
Posts
6,216 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Ditto
-
DKIM - would you expect the norm for it to be configured?
Ditto replied to Ditto's topic in Cloud Services
ChatGPT? Well it's hard to be sure! It was my words but heavily influenced but what was the written in the email to me. I really appreciate the feedback and a second perspective. I will relay the thoughts back, and any others posted. I also note what NCSC advise. Does anyone know if Cyber Essentials gets in to this low a detail. Broadening out on this topic, here is background info that perhaps makes it clearer the challenge in hand: My line manager who ultimately has been lumbered with IT responsibility for the organisation has no enterprise IT experience. When the out-sourced IT company was appointed, the said they'd be 'our IT department' and advise best practice. But they haven't delivered that. The LM has on more than one occasion said to me they have no choice but to accept what they tell him as fact as has no means to validate it. It's the IT provider is paid to do. If I wasn't there to dig deeper, then that wouldn't happen. There has been a little bit of talk about recruiting an IT manager. Basically my LM had IT dumped on them as a role. They don't won't that role, and it wasn't in their role originally AFAIK. To give an idea of the level of knowledge, the visiting OT technician was to so a new Windows install on an older laptop that was playing up. Early on, the install stopped as it couldn't see a drive. So that was abandoned for the they. I said as a first step I'd be stepping in to the BIOS to check settings. My LM admitted he had no idea what I was talking about. So, given how much time is burnt between me, another colleague and my LM, I think a dedicate IT manager, with the right level of knowledge could help. I don't think it needs a full time role, but I do think it could lead to tension between the IT provider and us. A big advantage I see is the P/T manager would be working for the charity with the goal of getting the right decisions and directions made. At the end of the day, the IT provider is there to make a profit. I've also suggested we have an IT Manager, possibly full time and ditch the outsource. That won't get off the ground though. A bit like consultancy services being brought in, the SLT seem to think expertise needs to be outsourced as it is an area that they personally don't really understand. But I can see an internal IT manager providing a better experience than this outsources solution. They'd never look to out-source the work of our front line team, but it's because that's their backgrounds mostly. The next few weeks/months will be interesting to see how thing pan out, in part as budgeting cycles are underway. -
Displaying Data Registration Certificate - do you?
Ditto replied to Ditto's topic in Data Protection & Information Handling
Yep, that's the one. Broadly that's the advice I gave - effectively if you do for other compliance topics, like HSE, liability and you think it helps, you could, but there is no requirement to do so. -
DKIM - would you expect the norm for it to be configured?
Ditto replied to Ditto's topic in Cloud Services
I decided to communicate with the IT providers solution architect directly and got a very thorough reply. In essence the statement on DMARC was p=none is their default policy for al lclients, in part as additional costs would be incurred to setup monitoring tools and implementation work to have p=quarantine or p=reject. It was stated that DMARC policy is something that has been discussed internally and with other clients. At this point it was advised p=none is OK and no need to do anything currently. It was acknowledge that the likes of gmail had tightened up in this area, but that tightening was restricted to having a policy, rather than none at all, hence p=none. It was also stated with that policy in place, we were less likely to find emails 'junked' at the receiving end. Although there is no proposal to use them, it was suggested products like EASYDmarc, DMarian or DMARC analyzer. It was explained this is an area that is more important to high volume marketing emails, especially if related to revenue streams. This may be applicable for us as we do a marketing team (they call themselves Engagement, formerly known as Development!). This might link in to chatter I have heard about MailChimp, but i don't yet have the details. What was added, was if the policy was changed from none whilst they could set this up (chargeable) they would, they don't offer a monitoring solution so that would need need to be assigned to someone internally. It's fair to say we probably don't have anyone suitable to do that, certainly no one is likely to volunteer! I raised the topic of MTA-STS. The view from the IT Provider was it is something that is becoming more prevalent in use. Something that could be turned on, but would equally need setup and then internal monitoring. It was stated that outgoing emails would be at least TLS 1.2, but we have no way of knowing if the same if the case for incoming emails. It was stated that if incoming data was highly sensitive (it absolutely is) then deploying MTA-SYS does need serious consideration. They have few clients with it enabled, but we probably, with the nature of the data that comes in, should look in to it carefully. -
I agree. What makes life really difficult for us, is we don't have internal IT support and perhaps more importantly expertise. But our IT service provider isn't guiding the organisation appropriately. As a charity, we are very cost sensitive, but when advised convincingly, it will spend/invest in a solution that is not on paper the cheapest. In this instance, I do believe the charity did go out and select a printer, but due to advice from the customer service chap, not an IT technical chap! But, I do feel Xerox support on the face of it has been attentive, but I don't get the feeling the IT consultant has much experience with printer installation and setup. Of a list of 13 tasks, 1 got done, 1 partially and the remainder not tackled. So far we estimate we have charged time to get the printer working great than the cost of the printer! And to top it, we were advised that the remote messaging to report toner usage and support automatic supply replenishment was fixed. We received an email this morning saying could we send current readings manually. Some issues do sound challenging, like the member of staff who found in the morning they could print fine, but then in the afternoon not. However, I saw no evidence of logs being investigated, which I would have thought been an avenue of enquiry. It's causing a lot of tension between my LM and the IT provider, but let's see how the next week or so goes - we have asked for a report on the tasklist and what steps were taken to try to find what things are leading to failure.
-
And the saga continues to roll! Today the IT technician was in. I don't have full details but will seek them to see if I can clarify in more details. However, today's activity included the statement, "I can't change the default paper size from 'Letter' to 'A4'.". There then seemed to be talk of working around this by trying to get everyone to work with legal as a setting. I advised against this - we have A4 paper that is surprise, surprise A4 size. There was also talk of a piece of paper being stuck to the printer to advised people what to do in terms of selecting a tray if printing doesn't work first time. There seems to be different experience from different staff and printing from different products (Adobe, Word, Publisher (dunno why that's still being used!). On the correct colour printing, I believe IT technician and Xerox engineer did come to site a while back but were unsuccessful. The official office line is now "If the precise corporate colours are important to you, go to a professional print shop". There was further talk of Printix, but for our needs it's looking excessively expenses. All that is being asked is for staff to be able to print from their laptops whilst in the office and not to have to go to the print to select source, tray or anything else - just to print! If A3 is selected, just print from that tray. No restrictions, no departmental pricing, literally just print when asked to. I believe the XDA software has now been moved from a boardroom laptop (a massive confidentiality risk was found on the use of that device (common account!) so it's been removed. Same software now on the receptionists device. Oh, and then I learn neither printer is supporting scanning, specifically scan to email I believe. The technician was trying to setup that as I finished for the day. I don't think I've seen any projects that had such simple requirements be such a complete disaster. But the original MFD was purchased by someone with little knowledge and no implementation experience and definitely not the level of knowledge to know what questions to ask. Then when the MSP provider are called upon to get the very basics to work, they appear to just not have the skills. If I get clearer details I will post, and maybe the expertise within Edugeek will help me with pointing some people in the right direction!
-
There are few threads out there that show Printix is/has been used within schools. Can any Printix users give me an idea of their licensing costs, in particular as Printix website suggests there is a not-for-profit arrangement.
-
Amazing! Not a single post on DeepSeek - well not until now
-
DKIM - would you expect the norm for it to be configured?
Ditto replied to Ditto's topic in Cloud Services
Unfortunately I can not do that personally, I have no access and it's not my role. But, it should be something done by our IT service provider. Trouble is, I have enough knowledge and experience to hold them to account, especially when they propose work that is chargeable beyond standard support. My view is after 2+ years this should have been done ages ago. Unfortunately my line manager suggested he has 20% of my knowledge, and that could be an over estimated. On more than one occasion, he has said he just has to accept what they say, which is understandable to a point, but I know that can leave us exposed and not just from unnecessary project expense. Their sales pitch was that they would be our IT department. I feel they have fallen short in this role in several areas. 1st line support is very good, but elsewhere not so much. -
DKIM - would you expect the norm for it to be configured?
Ditto replied to Ditto's topic in Cloud Services
Thanks for this - I will ask the technician to have a go. I suspect the tool on NCSC is similar. I ran that one myself at it reported: DMARC policy in place, but policy is set to 'none' (p=none). It points out this fake (spoof) emails are likely to be delivered. Should I be kicking up a big fuss with our provider, or could there be other protections in place that mitigate this. Other items reported: SPF - all good DKIM and PTR not assessed ( as just the domain provided, not an email sent). TLS - all good MTA-STS - not configured, meaning email privacy at higher risk due to possibility of downgrade - must admit I've not come across this setting before. -
Without wanting to stir, honestly, was there any sign of progress with ESS's cloud based MIS?
-
Early reports suggested 25% - 30% of running PCs could not move to W11 and meet compatibility requirements. The most optimistic figure I could find was just under 50%, but that was based on Steam users. It is acknowledge the gaming community is more likely to be running more modern kit. https://www.theverge.com/2024/9/2/24234091/microsoft-windows-11-popular-steam-pc-gaming-survey?utm_source=chatgpt.com That still leaves a huge pile of waste! I guess many will just move to an 'officially unsupported' model, be that by staying on Win 10 or moving to Win via by-pass installs.
-
White Bird recently released on Amazon. Good, very very good. I'd thoroughly recommend watching this and hearing others views.
-
Their loss - I'm sure you could have given them some appropriate Edugeek advice
-
You've got to wonder what accounts and passwords were not secured after the former employee was dismissed.
-
DKIM - would you expect the norm for it to be configured?
Ditto replied to Ditto's topic in Cloud Services
I guess my thinking was it should have been dealt with as part of the on-boarding process. Our outsourced provider market themselves as leader in the cyber-security space. My feeling is they preach at a much higher level than they deliver. Apparent I'm told this topic came up as a part of there own cyber-security certification - at bronze level. This is apparently a process before we target Cyber Security Essentials. Their certification would have costs associated. My gripe is it appears we are incurring expenses on stuff that shouls have been covered 3 years ago. They pointed the charity at NCSC for free cyber security training. This DKIM topic is mentioned on NCSC at https://www.ncsc.gov.uk/collection/email-security-and-anti-spoofing. They've not even adhered to NCSC basic recommendations from 2019. -
DKIM - would you expect the norm for it to be configured?
Ditto replied to Ditto's topic in Cloud Services
I'll raise that with the technician too. Out of interest, how does that work on a live system - presumably timing is relevant? -
DKIM - would you expect the norm for it to be configured?
Ditto replied to Ditto's topic in Cloud Services
Purely DKIM as far as I am aware, DMARC and SPF already configured, but unfortunately I don't have access to check myself and getting the info would take a little effort, which as we have a technician visiting next week, I can check. I'm not sure I follow you on the bit about sending emails - could you add more details, -
I agree. I even wonder whether our MSP as ever had direct advice or support from MS staff. But, even as a domestic customer, I do want to stay as patched up as possible without having to be forced to new hardware. Based on details above, that would not put me at significantly more risk. So, allowing me to migrate to Windows 11 (and it doesn't appear to be that difficult) maybe better than lingering in Windows 10. Even better, MS support an alternative solution to upgrade to TPM 2.0 as highlighted in the ChatGPT reply. If everyone switched from older non-upgradeable PCs to new kit, a huge number of OEM Windows licenses are going to generate MS a huge chunk of money, but also a huge mountain of e-waste. Profit over planet! I guess given the location of the company, that comes as no surprise currently.
-
I can see that being agreeable to a number of education establishments, giving more time upgrade kit. Do you know if there is a 'Not for Profit' price. Not applicable for my charity employer as all our kit is Win 11 compatible as we built in a 4 year refresh programme not so many years ago. It doesn't help the domestic home user environment though. I do wonder is there will be some last minute change by MS though. At present, I have some old, but super expensive to replace kit that I appear to have 2 choices on. a) stay on unsupported Windows 10; b) move to an unsupported Windows 11 install; c) Convert the devices to a Linux flavour or some of the smaller units could go ChromeOS I guess. Fortunately, the kids PC/gaming machines are the newest machines in the household around and are Windows 11 compatible.
-
So in the main, it looks like many are in good shape, and those that aren't, it isn't for the lack of trying. What we really haven't discussed, is it all worth the expense and e-wastage that results. Well, at an enterprise level, and I include schools in that category, on balance I guess I have to agree it is a necessary expense. However, for the home domestic user I think the case is much less clear cut. I had an interesting session with ChatGPT on this very topic. ChatGPT once again impressed. I thought simplest to post the ChatGPT response to my topic around e-wastage for domestic users as a result of MS insistency on requiring TPM 2.0 support.
-
As a default position would you expect DKIM to be have been set up and configured by your IT provider. It would appear following a cyber security certification, run by our IT provider that it has not been the case before. Whilst not directly charging for the update, they are indirectly, by using time we have allocated once a quarter onsite IT Technician time we have. I would have thought it should have been covered when we onboarded. I also don't agree it needs to be done during our 'on-site' time. I don't have the details, but apparently MailChimp use by our fund raising team came up in discussion - ring an bells for anyone?
-
I've been doing some background reading in to the end of Windows 10 support later this year, unless you cough up some cash to MS. The requirements for Windows 11 effectively kill a huge number of older devices if you wish to stay up to date OS wise. I know personally it will kill all bar one of my devices. I tend to buy older, but big devices. For example, I'm writing this on a 10 year+ Dell T5500 and to replace it with an equivalent W11 compatible machine is prohibitive. TPM is a big factor but I am aware of reports that TPM 2.0 has already been compromised. Background reading shows a huge backlash against Microsoft and whilst I accept legacy can have it's risks and limitations, not many people are trusting Microsofts arguments. Are all the Linux flavours inherently less secure if they don't require TPM 2.0? Some articles estimate up to a quarter of billion devices will become e-waste almost overnnight. That's not a good outcome. Specifically, within your schools, have you assessed what devices will become e-waste later this year and what is the plan to deal with those devices.
-
What caused the issue and what was the fix?
-
Just out of curiosity, what methodology of development would you say you are working too, but not wanting to unnecessarily label it. I can see elements of iterative design and elements of minimum viable product (MVP), I term I total loathe when used as an excuse for producing rubbish! I certainly can see an argument for Agile, but that is a bandwagon risk and actually quite an old one now!
